Identity authentication method, terminal device, identity authentication system and storage medium

By integrating post-quantum cryptographic algorithms and asymmetric cryptographic algorithms into smart password keys, dual authentication is achieved, which solves the security issues of smart password keys in the post-quantum era, improves the security and accuracy of identity authentication, and resists quantum computing attacks.

CN119276505BActive Publication Date: 2025-10-10CHINA TELECOM QUANTUM TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411301201.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-18
Publication Date
2025-10-10
Estimated Expiration
2044-09-18

AI Technical Summary

Technical Problem

Existing smart cryptographic keys face the problem of being unable to effectively resist quantum computing attacks in the post-quantum era. Traditional ECC and SM2 asymmetric cryptographic algorithms become vulnerable to quantum computers and cannot meet the security requirements of the post-quantum era.

Method used

Combining post-quantum cryptography and asymmetric cryptography, the key information of post-quantum cryptography and asymmetric cryptography is generated through the smart cryptographic key, the corresponding user signature certificate is applied for, and this information is stored in the secure storage area of ​​the smart cryptographic key for dual authentication.

Benefits of technology

It improves the security and accuracy of identity authentication, meets the requirements of the existing security system, resists quantum computing attacks, and provides security capabilities in the post-quantum era.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276505B_ABST
    Figure CN119276505B_ABST
Patent Text Reader

Abstract

The application provides an identity authentication method, a terminal device, an identity authentication system and a storage medium, and relates to the technical field of information security. The method comprises the following steps: obtaining key information of a post-quantum cryptographic algorithm and key information of an asymmetric cryptographic algorithm based on an intelligent password key; applying, according to a public key of the post-quantum cryptographic algorithm, a first user signature certificate corresponding to the post-quantum cryptographic algorithm to a certificate issuing server; applying, according to a public key of the asymmetric cryptographic algorithm, a second user signature certificate corresponding to the asymmetric cryptographic algorithm to the certificate issuing server; writing the key information of the post-quantum cryptographic algorithm, the key information of the asymmetric cryptographic algorithm, the first user signature certificate and the second user signature certificate into a secure storage area of the intelligent password key as authentication information; and performing identity authentication according to the authentication information stored in the secure storage area of the intelligent password key. The method fuses the post-quantum cryptographic algorithm on the basis of the asymmetric cryptographic algorithm, and effectively resists attacks of quantum computing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and specifically to an identity authentication method, terminal equipment, identity authentication system and storage medium. Background Art

[0002] Identity authentication is an important part of ensuring the security of information systems. Smart password keys are widely used in user management of information systems due to their convenience and security.

[0003] With the improvement of computer capabilities and the advancement of mathematics, asymmetric cryptographic algorithms such as traditional ECC (Elliptic Curves Cryptography) and SM2 (Elliptic Curve Algorithm) used by smart password keys face huge security risks in the post-quantum era and cannot effectively resist quantum computing attacks.

[0004] Therefore, how to balance the requirements of the existing cryptographic system and provide security capabilities in the post-quantum era has become an urgent problem that needs to be solved in the identity authentication system. Summary of the Invention

[0005] The purpose of this application is to provide an identity authentication method, terminal device, identity authentication system and storage medium to address the deficiencies in the above-mentioned prior art, so as to improve the security and accuracy of identity authentication.

[0006] To achieve the above objectives, the technical solutions adopted in the embodiments of the present application are as follows:

[0007] In a first aspect, an embodiment of the present application provides an identity authentication method, comprising:

[0008] Log in to the smart password key according to the login password input by the user, obtain key information of the post-quantum cryptographic algorithm based on the smart password key, and obtain key information of the asymmetric cryptographic algorithm based on the smart password key; the key information includes: a public key and a private key;

[0009] Applying for a first user signature certificate corresponding to the post-quantum cryptographic algorithm from a certificate issuing server based on the public key of the post-quantum cryptographic algorithm; and applying for a second user signature certificate corresponding to the asymmetric cryptographic algorithm from the certificate issuing server based on the public key of the asymmetric cryptographic algorithm;

[0010] Writing the key information of the post-quantum cryptographic algorithm, the key information of the asymmetric cryptographic algorithm, the first user signature certificate, and the second user signature certificate as authentication information into the secure storage area of ​​the smart password key;

[0011] Identity authentication is performed according to the authentication information stored in the secure storage area of ​​the smart password key.

[0012] Optionally, obtaining key information of a post-quantum cryptographic algorithm based on the smart cryptographic key includes:

[0013] If the smart cryptographic key supports the post-quantum cryptographic algorithm, calling the post-quantum cryptographic algorithm program running in the smart cryptographic key to generate key information of the post-quantum cryptographic algorithm;

[0014] If the smart password key does not support the post-quantum cryptographic algorithm, key information of the post-quantum cryptographic algorithm is generated, and the generated key information of the post-quantum cryptographic algorithm is encrypted according to the login password to obtain the processed key information of the post-quantum cryptographic algorithm.

[0015] Optionally, encrypting the generated key information of the post-quantum cryptographic algorithm according to the login password to obtain the processed key information of the post-quantum cryptographic algorithm includes:

[0016] generating a derived key of the login password according to the login password;

[0017] Using the derived key to encrypt the private key in the key information of the post-quantum cryptographic algorithm to obtain the private key ciphertext of the post-quantum cryptographic algorithm;

[0018] The processed key information of the post-quantum cryptographic algorithm is obtained according to the private key ciphertext of the post-quantum cryptographic algorithm and the public key in the key information of the post-quantum cryptographic algorithm.

[0019] Optionally, obtaining key information of an asymmetric cryptographic algorithm based on the smart cryptographic key includes:

[0020] The asymmetric cryptographic algorithm program running in the smart cryptographic key is called to generate key information of the asymmetric cryptographic algorithm.

[0021] Optionally, applying for a first user signature certificate corresponding to the post-quantum cryptography algorithm from a certificate issuing server according to the public key of the post-quantum cryptography algorithm; and applying for a second user signature certificate corresponding to the asymmetric cryptography algorithm from the certificate issuing server according to the public key of the asymmetric cryptography algorithm includes:

[0022] Initiate a certificate application to the certificate issuing server according to the public key of the post-quantum cryptographic algorithm, and receive a first user signature certificate corresponding to the post-quantum cryptographic algorithm returned by the certificate issuing server;

[0023] A certificate application is initiated to the certificate issuing server according to the public key of the asymmetric cryptographic algorithm, and a second user signature certificate corresponding to the asymmetric cryptographic algorithm returned by the certificate issuing server is received.

[0024] Optionally, performing identity authentication according to the authentication information stored in the secure storage area of ​​the smart password key includes:

[0025] Invoking the smart password key, generating and receiving signature information of the authentication data and the user signature certificate returned by the smart password key; the signature information is generated by the smart password key based on the key information stored in the secure storage area of ​​the smart password key;

[0026] Initiate an authentication request to the issuing server based on the signature information, the user signature certificate and the authentication data; receive the authentication result returned by the certificate issuing server, and determine the identity authentication result of the user based on the authentication result.

[0027] Optionally, before calling the smart password key and generating and receiving signature information of the authentication data returned by the smart password key, the method includes:

[0028] Initiate a login request to the certificate issuing server, and obtain a first message field returned by the certificate issuing server; the first message field includes a first random number;

[0029] Calling the smart password key to generate a second message field; the second message field includes: a second random number;

[0030] The authentication data is generated according to the first message field, the second message field and the user message field.

[0031] Optionally, calling the smart password key to generate and receive signature information of the authentication data returned by the smart password key includes:

[0032] The smart cryptographic key is called to generate first signature information of the authentication data according to the key information of the post-quantum cryptographic algorithm; and second signature information of the authentication data is generated according to the key information of the asymmetric cryptographic algorithm; the signature information of the authentication data includes the first signature information and the second signature information.

[0033] Optionally, calling the smart cryptographic key to generate first signature information of the authentication data according to key information of the post-quantum cryptographic algorithm includes:

[0034] If the smart cryptographic key supports the post-quantum cryptographic algorithm, the post-quantum cryptographic algorithm program running in the smart cryptographic key is called, and the smart cryptographic key performs a signature calculation on the authentication data according to the private key of the post-quantum cryptographic algorithm stored in the secure storage area to generate first signature information of the authentication data.

[0035] Optionally, calling the smart cryptographic key to generate first signature information of the authentication data according to key information of the post-quantum cryptographic algorithm includes:

[0036] If the smart cryptographic key does not support the post-quantum cryptographic algorithm, reading the private key ciphertext of the post-quantum cryptographic algorithm;

[0037] Decrypting the private key ciphertext of the post-quantum cryptographic algorithm according to the derived key of the login password;

[0038] Perform signature calculation on the authentication data according to the private key of the post-quantum cryptography algorithm obtained after decryption to generate first signature information of the authentication data.

[0039] Optionally, generating the second signature information of the authentication data according to the key information of the asymmetric cryptographic algorithm includes:

[0040] The asymmetric cryptographic algorithm program running in the smart cryptographic key is called, and the smart cryptographic key performs signature calculation on the authentication data according to the private key of the asymmetric cryptographic algorithm stored in the secure storage area to generate second signature information of the authentication data.

[0041] Optionally, initiating an authentication request to the issuing server based on the signature information, the user signing certificate, and the authentication data; receiving an authentication result returned by the certificate issuing server, and determining an identity authentication result of the user based on the authentication result, includes:

[0042] Initiate an authentication request to the certificate issuing server based on the first signature information, the second signature information, the first user signature certificate, the second user signature certificate, and the authentication data;

[0043] Receive the authentication result returned by the certificate issuing server, and determine the identity authentication result of the user according to the authentication result.

[0044] Optionally, the receiving an authentication result returned by the certificate issuing server and determining the identity authentication result of the user according to the authentication result includes:

[0045] Receiving a first authentication result corresponding to the post-quantum cryptography algorithm and a second authentication result corresponding to the asymmetric cryptography algorithm returned by the certificate issuing server;

[0046] If both the first authentication result and the second authentication result are authenticated, the identity authentication result of the user is determined to be authenticated.

[0047] In the second aspect, an embodiment of the present application also provides a terminal device, comprising: a processor, a storage medium and a bus, wherein the storage medium stores program instructions executable by the processor. When the terminal device is running, the processor and the storage medium communicate through the bus, and the processor executes the program instructions to implement the identity authentication method provided in the first aspect above.

[0048] In a third aspect, an embodiment of the present application further provides an identity authentication system, comprising: the terminal device, the smart password key, and the certificate issuing server described in the second aspect above;

[0049] The terminal device is used to perform identity authentication using the identity authentication method described in the first aspect above;

[0050] The smart password key is used to interact with the terminal device to obtain key information of the cryptographic algorithm, store and provide authentication information containing the key information, and perform signature calculation based on the key information;

[0051] The certificate issuing server is used to interact with the terminal device to perform identity authentication.

[0052] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, executes the identity authentication method provided in the first aspect.

[0053] The beneficial effects of this application are:

[0054] The application provides an identity authentication method, a terminal device, an identity authentication system and a storage medium, and comprises the following steps: logging in an intelligent password key according to a login password input by a user, obtaining key information of a post-quantum cryptographic algorithm based on the intelligent password key, and obtaining key information of an asymmetric cryptographic algorithm based on the intelligent password key; applying for a first user signature certificate corresponding to the post-quantum cryptographic algorithm to a certificate issuing server according to a public key of the post-quantum cryptographic algorithm; and applying for a second user signature certificate corresponding to the asymmetric cryptographic algorithm to the certificate issuing server according to a public key of the asymmetric cryptographic algorithm; writing the key information of the post-quantum cryptographic algorithm, the key information of the asymmetric cryptographic algorithm, the first user signature certificate and the second user signature certificate into a secure storage area of the intelligent password key as authentication information; and performing identity authentication according to the authentication information stored in the secure storage area of the intelligent password key. The method combines the post-quantum cryptographic algorithm with the asymmetric cryptographic algorithm, and on the basis of the identity authentication of the traditional intelligent password key by means of the asymmetric cryptographic algorithm, the identity authentication means of the post-quantum cryptographic algorithm is fused, the security and accuracy of the identity authentication are improved by means of double-algorithm authentication, the requirements of the existing security system are met, the security capability in the post-quantum era is provided, and the attack of quantum computing is effectively resisted.

[0055] In addition, different processing procedures are given according to whether the intelligent password key supports the post-quantum cryptographic algorithm, so that the generation of the key information of the post-quantum cryptographic algorithm and the signature calculation can be realized in the two cases that the intelligent password key supports the post-quantum cryptographic algorithm and does not support the post-quantum cryptographic algorithm, and the current situation that most intelligent password keys do not support the post-quantum cryptographic algorithm can be well adapted. BRIEF DESCRIPTION OF DRAWINGS

[0056] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the application, and therefore should not be regarded as a limitation to the scope. Other related drawings can also be obtained by those skilled in the art without any creative effort.

[0057] Figure 1 An architecture schematic diagram of an identity authentication system provided by the embodiments of the application;

[0058] Figure 2 A flowchart of an identity authentication method provided by the embodiments of the application;

[0059] Figure 3 A flowchart of another identity authentication method provided by the embodiments of the application;

[0060] Figure 4A flowchart of another identity authentication method provided in an embodiment of the present application;

[0061] Figure 5 A flowchart of another identity authentication method provided in an embodiment of the present application;

[0062] Figure 6 A flowchart of another identity authentication method provided in an embodiment of the present application;

[0063] Figure 7 A flowchart of another identity authentication method provided in an embodiment of the present application;

[0064] Figure 8 A flowchart of another identity authentication method provided in an embodiment of the present application;

[0065] Figure 9 A flowchart of another identity authentication method provided in an embodiment of the present application;

[0066] Figure 10 A signaling interaction diagram provided in an embodiment of the present application;

[0067] Figure 11 Another signaling interaction diagram provided in an embodiment of the present application;

[0068] Figure 12 A schematic diagram of the structure of a terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0069] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of illustration and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowcharts can be implemented out of sequence, and steps without logical context can be reversed or implemented simultaneously. In addition, those skilled in the art, under the guidance of the contents of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart.

[0070] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application.

[0071] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0072] With the continuous development of information technology, protecting the security, confidentiality, and integrity of information has become increasingly important. As an important means of ensuring information security, cryptographic algorithms continue to develop and improve.

[0073] Cryptographic algorithms are widely used in many fields, mainly including the following aspects:

[0074] Data encryption:

[0075] Symmetric cryptographic algorithms, such as AES (Advanced Encryption Standard) and SM4 (National Security Block Cipher), are widely used for data encryption and confidentiality protection. These algorithms use the same key for encryption and decryption, resulting in high speed and efficiency, making them suitable for encrypting large amounts of data.

[0076] Asymmetric cryptographic algorithms (such as RSA (public key cryptography algorithm) and ECC (Elliptic Curve Cryptography, a public key encryption algorithm based on elliptic curve mathematics)) are used in scenarios such as key exchange and digital signatures to provide higher security.

[0077] Network communication security:

[0078] In network communications, cryptographic algorithms are used to protect the confidentiality and integrity of communications. For example, in the SSL (Secure Sockets Layer) / TLS (Transport Layer Security) protocols, asymmetric cryptographic algorithms are used for key exchange, followed by symmetric cryptographic algorithms to encrypt communications.

[0079] Virtual Private Networks (VPNs) also widely use symmetric cryptographic algorithms to encrypt network communications and ensure the confidentiality and integrity of data transmission.

[0080] Digital signature:

[0081] Asymmetric cryptography algorithms are used to generate digital signatures to verify the integrity and authenticity of data. The sender signs the data using a private key, and the receiver verifies it using a public key.

[0082] Identity authentication and access control:

[0083] Cryptographic algorithms are also used for identity authentication and access control. For example, in remote access control, cryptographic algorithms are used to verify the identity of remote users and encrypt data for remote access.

[0084] Internet of Things security:

[0085] With the development of the Internet of Things, cryptographic algorithms play an important role in the security of Internet of Things devices. Lightweight cryptographic algorithms are particularly suitable for Internet of Things devices and wireless sensor networks due to their simple design, high computational efficiency and low resource consumption.

[0086] Cloud computing and big data security:

[0087] In the field of cloud computing and big data, cryptographic algorithms are used to protect the confidentiality and integrity of data. By encrypting data storage and transmission, data leakage and tampering can be prevented.

[0088] With the rapid development of quantum computing technology, traditional encryption algorithms such as RSA and elliptic curve cryptography have become vulnerable in the face of quantum computers, so it is particularly important to develop encryption algorithms that can maintain security in the quantum computing era.

[0089] Post-quantum cryptography (PQC) is a class of encryption algorithms designed to resist quantum computer attacks, which can meet the security requirements of the post-quantum era. However, post-quantum cryptography also has problems such as lack of effective security proof and inability to meet existing security evaluation standards. Therefore, how to balance the requirements of existing cryptographic systems and provide security capabilities in the post-quantum era is a problem that needs to be solved.

[0090] Based on this, the identity authentication method provided by the present application mixes the use of PQC cryptographic algorithms on the basis of traditional authentication of smart cryptographic keys, and uses traditional asymmetric cryptographic algorithms and PQC cryptographic algorithms for dual authentication, which can meet the requirements of existing security systems, resist quantum computing attacks, provide security capabilities in the post-quantum era, and ensure the security and accuracy of identity authentication.

[0091] Figure 1 The architecture of an identity authentication system provided by an embodiment of the present application is shown in the figure. Figure 1As shown, the identity authentication system may include a client and a certificate issuance server. The client may run a post-quantum cryptography terminal service, also known as a PQC terminal service. The smart password key, an important hardware security device deployed on the client, can be connected to the client computer via a USB port, allowing users to conveniently use the cryptographic services provided by the smart password key on their computer.

[0092] Users can log in to the smart password key through the PQC terminal service and generate key information for the cryptographic algorithm based on the smart password key. The smart password key can also store the key information and signature certificate of the cryptographic algorithm. The smart key can also calculate the signature of the user's authentication data based on the stored key information of the cryptographic algorithm. Based on the signature information of the authentication data and the signature certificate, the user can initiate an authentication request to the certificate issuing server to obtain the authentication result.

[0093] The intelligent cryptographic key can be used to create key information for both traditional asymmetric and PQC cryptographic algorithms. During signature calculation, it supports both traditional asymmetric and PQC signature calculations, combining traditional asymmetric and PQC cryptographic algorithms to achieve user identity authentication. This dual authentication approach not only meets the requirements of existing security systems but also provides security capabilities for the post-quantum era.

[0094] Figure 2 A flow chart of an identity authentication method provided in an embodiment of the present application; the execution subject of this method can be the above Figure 1 The PQC terminal service running in the client. Figure 2 As shown, the method may include:

[0095] S101. Log in to the smart cryptographic key according to the login password input by the user, obtain key information of the post-quantum cryptographic algorithm based on the smart cryptographic key, and obtain key information of the asymmetric cryptographic algorithm based on the smart cryptographic key.

[0096] The key information includes: public key and private key.

[0097] Users can enter a login password through the PQC terminal service. The login password is the password used to log in to the smart password key. The login password for the smart password key is set by the user or system administrator during configuration or use and is stored in an encrypted manner in the associated management system or database. Users must enter the correct login password to pass authentication and access sensitive information on the smart password key.

[0098] After logging in to the smart password key, the key information of the post-quantum cryptographic algorithm and the key information of the asymmetric cryptographic algorithm can be obtained based on the smart password key.

[0099] Generally, asymmetric cryptographic algorithms can include multiple types, including but not limited to: SM2 cryptographic algorithm, RSA (Rivest-Shamir-Adleman, asymmetric cryptographic algorithm), ECC (Elliptic Curve Cryptography, elliptic curve cryptography), DSA (Digital Signature Algorithm, digital signature algorithm), etc.; post-quantum cryptographic algorithms can also include multiple types, including but not limited to: PQC cryptographic algorithm, lattice-based cryptographic algorithm, encoding-based cryptographic algorithm, multivariate-based cryptographic algorithm, etc.

[0100] In the subsequent embodiments of this solution, the post-quantum cryptographic algorithm will be exemplified by the PQC cryptographic algorithm, and the asymmetric cryptographic algorithm will be exemplified by the SM2 cryptographic algorithm.

[0101] Optionally, the obtained key information of the PQC cryptographic algorithm includes: a PQC public key and a PQC private key; the obtained key information of the SM2 cryptographic algorithm includes: an SM2 public key and an SM2 private key.

[0102] By creating key information for post-quantum cryptography algorithms and asymmetric cryptography algorithms respectively, we can lay the foundation for identity authentication by integrating post-quantum cryptography algorithms and asymmetric cryptography algorithms.

[0103] S102. Apply for a first user signature certificate corresponding to the post-quantum cryptography algorithm from the certificate issuing server based on the public key of the post-quantum cryptography algorithm; and apply for a second user signature certificate corresponding to the asymmetric cryptography algorithm from the certificate issuing server based on the public key of the asymmetric cryptography algorithm.

[0104] In some embodiments, the PQC terminal service may apply for a first user signature certificate from the certificate issuing server based on the obtained PQC public key; and apply for a second user signature certificate from the certificate issuing server based on the SM2 public key.

[0105] A key function of a signing certificate is to verify the identity of the holder. By applying for a signing certificate using a public key, the issuing server can verify the binding between the public key and the holder's identity, ensuring the authenticity and validity of the certificate. This allows the recipient to trust the identity represented by the certificate when used in scenarios such as encrypted communications and digital signatures.

[0106] Typically, you can send the public key and the user's identity information to a certificate signing server to request a signed certificate. The certificate signing server will verify the user's identity to ensure that the public key actually belongs to the user. Once the user's identity is verified, the certificate signing server will use the private key of the cryptographic algorithm initialized locally to sign the public key sent by the user. The server will then generate a certificate containing the public key, signature, certificate validity period, issuer information, and other content, thus obtaining the user's signed certificate.

[0107] Optionally, during the initialization process, the certificate issuing server may respectively initialize the key pair of the PQC cryptographic algorithm and the key pair of the SM2 cryptographic algorithm, and generate the root certificate of the PQC cryptographic algorithm and the root certificate of the SM2 cryptographic algorithm.

[0108] When the PQC terminal service applies for a first user signature certificate from the certificate issuing server based on the PQC public key, the certificate issuing service can sign the PQC public key based on the private key of the initialized PQC cryptographic algorithm to generate a first user signature certificate containing the PQC public key, signature, certificate validity period, issuer information and other contents.

[0109] When the PQC terminal service applies for a second user signature certificate from the certificate issuing server based on the SM2 public key, the certificate issuing service can sign the SM2 public key based on the private key of the initialized SM2 cryptographic algorithm to generate a second user signature certificate containing the SM2 public key, signature, certificate validity period, issuer information and other contents.

[0110] S103: Write the key information of the post-quantum cryptographic algorithm, the key information of the asymmetric cryptographic algorithm, the first user signature certificate, and the second user signature certificate as authentication information into the secure storage area of ​​the smart cryptographic key.

[0111] Optionally, the smart cryptographic algorithm may import the generated key information for the PQC cryptographic algorithm and the key information for the SM2 cryptographic algorithm into the secure storage area of ​​the smart cryptographic key for storage. Of course, in some cases, the key information for the PQC cryptographic algorithm may be generated by the PQC terminal service, in which case the PQC terminal service will import the generated key information for the PQC cryptographic algorithm into the secure storage area of ​​the smart cryptographic key for storage.

[0112] In addition, the PQC terminal service can also import the first user signature certificate and the second user signature certificate returned by the certificate issuance service into the secure storage area of ​​the smart password key for storage, so as to be used in the subsequent identity authentication process.

[0113] S104: Perform identity authentication based on the authentication information stored in the secure storage area of ​​the smart password key.

[0114] Optionally, the PQC terminal service can perform signature calculation on the user message based on the authentication information stored in the secure storage area of the smart password key, obtain signature information, and initiate a login request to the certificate issuing service based on the signature information, the user signature certificate provided by the smart password key, and the authentication data of the user, etc. The certificate issuing service can check the fields in the authentication data, verify the user signature certificate according to the root certificate of the generated password algorithm, and verify the signature information according to the user signature certificate, and finally complete the identity authentication.

[0115] The certificate signing server can jointly perform signature calculation on the user message based on the post-quantum cryptography algorithm and the asymmetric cryptography algorithm to realize dual authentication combining the post-quantum cryptography algorithm and the asymmetric cryptography algorithm.

[0116] In summary, the identity authentication method provided in the embodiment includes: logging into the smart password key according to the login password input by the user, obtaining the key information of the post-quantum cryptography algorithm based on the smart password key, and obtaining the key information of the asymmetric cryptography algorithm based on the smart password key; applying for the first user signature certificate corresponding to the post-quantum cryptography algorithm to the certificate issuing service according to the public key of the post-quantum cryptography algorithm; and applying for the second user signature certificate corresponding to the asymmetric cryptography algorithm to the certificate issuing service according to the public key of the asymmetric cryptography algorithm; writing the key information of the post-quantum cryptography algorithm, the key information of the asymmetric cryptography algorithm, the first user signature certificate, and the second user signature certificate into the secure storage area of the smart password key as authentication information; and performing identity authentication according to the authentication information stored in the secure storage area of the smart password key. This method combines the post-quantum cryptography algorithm with the asymmetric cryptography algorithm, and on the basis of the identity authentication of the traditional smart password key using the asymmetric cryptography algorithm, it integrates the identity authentication means of the post-quantum cryptography algorithm, improves the security and accuracy of identity authentication through dual algorithm authentication, meets the requirements of the existing security system, provides security capabilities in the post-quantum era, and effectively resists quantum computing attacks.

[0117] Optionally, in step S101, obtaining the key information of the post-quantum cryptography algorithm based on the smart password key can include: if the smart password key supports the post-quantum cryptography algorithm, calling the post-quantum cryptography algorithm program running in the smart password key to generate the key information of the post-quantum cryptography algorithm.

[0118] If the smart password key does not support the post-quantum cryptography algorithm, the key information of the post-quantum cryptography algorithm is generated, and the generated key information of the post-quantum cryptography algorithm is encrypted according to the login password to obtain the processed key information of the post-quantum cryptography algorithm.

[0119] The method gives different processing procedures for the two cases of smart password key supporting and not supporting post-quantum cryptography algorithm, which can better adapt to the current situation that most smart password keys do not support post-quantum cryptography algorithm.

[0120] Optionally, if the smart password key supports the PQC cryptography algorithm, the PQC terminal service can directly call the program of the PQC cryptography algorithm running in the smart password key, so that the smart password key generates the key information of the PQC cryptography algorithm based on the PQC cryptography algorithm. And store the generated PQC cryptography algorithm key information in the local secure storage area. At the same time, the generated PQC cryptography algorithm public key is fed back to the PQC terminal service, so that the PQC terminal service uses the PQC cryptography algorithm public key to apply for the first user signature certificate to the certificate issuing service.

[0121] And if the smart password key does not support the PQC cryptography algorithm, the PQC terminal service generates the key information of the PQC cryptography algorithm, and in order to prevent the private key in the generated key information from being leaked or attacked, the private key in the generated PQC cryptography algorithm key information can be further encrypted according to the login password used when logging in to the smart password key to obtain the processed PQC cryptography algorithm key information.

[0122] Figure 3 Another flowchart of an identity authentication method provided by an embodiment of the present application; optionally, as shown in Figure 3 The above step of encrypting the generated post-quantum cryptography algorithm key information according to the login password to obtain the processed post-quantum cryptography algorithm key information can include:

[0123] S201, generating a login password derivative key according to the login password.

[0124] Generating a login password derivative key usually involves using a key derivation function, which is an algorithm that securely generates another key from a password, key, or other secret value.

[0125] There are many types of key derivation functions, such as PBKDF2 (Password-Base Key Derivation Function), bcrypt (a file encryption tool), HKDF (a key derivation function based on HMAC), etc. These functions have different characteristics in terms of security, computational cost, and memory usage. For example:

[0126] PBKDF2: Password-Based Key Derivation Function, which uses a hash function and a salt value (salt) to resist rainbow table attacks. PBKDF2 requires high computational cost to resist malicious cracking.

[0127] bcrypt: A hash function designed specifically for password storage that includes salt and cost parameters so that the computational cost can be adjusted to suit different hardware.

[0128] HKDF: A key derivation function based on HMAC (Hash-based Message Authentication Code, an algorithm that uses a hash function and a key to calculate a message authentication code), suitable for extracting uniformly distributed keys from non-uniformly distributed key material.

[0129] Optionally, a suitable key derivation function may be selected, and the login password may be used as an input of the key derivation function to generate a derived key of the login password.

[0130] Of course, there are other ways to generate derived keys, which can be understood by referring to existing technologies.

[0131] S202. Use the derived key to encrypt the private key in the key information of the post-quantum cryptography algorithm to obtain the private key ciphertext of the post-quantum cryptography algorithm.

[0132] The derived key generated above is used to encrypt the private key of the PQC cryptographic algorithm to obtain the private key ciphertext of the PQC cryptographic algorithm.

[0133] S203. Obtain processed key information of the post-quantum cryptographic algorithm according to the private key ciphertext of the post-quantum cryptographic algorithm and the public key in the key information of the post-quantum cryptographic algorithm.

[0134] The processed key information of the PQC cryptographic algorithm may include: the public key of the PQC cryptographic algorithm and the ciphertext of the private key of the PQC cryptographic algorithm.

[0135] The PQC terminal service then writes the generated public key of the PQC cryptographic algorithm and the private key ciphertext of the PQC cryptographic algorithm into the secure storage area of ​​the smart cryptographic key.

[0136] Optionally, obtaining the key information of the asymmetric cryptographic algorithm based on the smart cryptographic key may include: calling an asymmetric cryptographic algorithm program running in the smart cryptographic key to generate the key information of the asymmetric cryptographic algorithm.

[0137] Because the smart key itself supports asymmetric cryptographic algorithms, it can directly call the SM2 algorithm program running in the smart key. This generates SM2 key information based on the SM2 algorithm and directly imports the SM2 key information into the local secure storage area. The public key in the SM2 key information is then sent to the PQC terminal service. The PQC terminal service then applies to the certificate issuance service for a second user signature certificate based on the SM2 public key.

[0138] Figure 4 A flowchart of another identity authentication method provided in an embodiment of the present application; optionally, as Figure 4 As shown, in step S102, applying for a first user signature certificate corresponding to the post-quantum cryptography algorithm from a certificate issuing server according to the public key of the post-quantum cryptography algorithm; and applying for a second user signature certificate corresponding to the asymmetric cryptography algorithm from a certificate issuing server according to the public key of the asymmetric cryptography algorithm may include:

[0139] S301. Initiate a certificate application to a certificate issuing server according to the public key of the post-quantum cryptography algorithm, and receive a first user signature certificate corresponding to the post-quantum cryptography algorithm returned by the certificate issuing server.

[0140] The PQC terminal service can send the public key of the PQC cryptographic algorithm and the user's identity information to the certificate issuing server. After successfully verifying the user's identity information, the certificate issuing server will sign the public key of the PQC cryptographic algorithm sent by the PQC terminal service based on the private key information of the PQC cryptographic algorithm generated during the initialization phase, generate a first user signature certificate corresponding to the PQC cryptographic algorithm, and return the generated first user signature certificate to the PQC terminal service. The first user signature certificate can also be understood as a public key signature certificate for the PQC cryptographic algorithm, which is used to prove that the public key of the PQC cryptographic algorithm indeed belongs to a specific user and prevent other users from tampering with the public key.

[0141] S302: Initiate a certificate application to a certificate issuing server according to the public key of the asymmetric cryptographic algorithm, and receive a second user signature certificate corresponding to the asymmetric cryptographic algorithm returned by the certificate issuing server.

[0142] Similar to the above process of generating the first user signature certificate, the PQC terminal service sends the public key of the SM2 cryptographic algorithm and the user's identity information to the certificate issuing server, and the certificate issuing service generates the second user signature certificate corresponding to the SM2 cryptographic algorithm, and returns the generated second user signature certificate to the PQC terminal service.

[0143] The above embodiment illustrates the process of user creation for two cryptographic algorithms, and the following embodiment illustrates the process of user identity authentication based on the created user information.

[0144] Figure 5 A flowchart of another identity authentication method provided in an embodiment of the present application; optionally, in step S104, identity authentication is performed based on the authentication information stored in the secure storage area of ​​the smart password key, which may include:

[0145] S401, calling the smart password key, generating and receiving signature information of the authentication data and the user signature certificate returned by the smart password key; the signature information is generated by the smart password key according to the key information stored in the secure storage area of ​​the smart password key.

[0146] After logging in with the smart password key, the user can initiate a login request to the certificate issuing server. The user can only log in successfully after the certificate issuing server successfully authenticates the user's identity, thereby realizing the interaction between the client and the server.

[0147] Signature calculation by the smart key is an important step in the identity authentication process. In this embodiment, the smart key can use the PQC cryptographic algorithm to verify the user's identity. At the same time, it also uses the SM2 cryptographic algorithm to verify the user's identity, thereby realizing an authentication method that combines post-quantum cryptography and asymmetric cryptography.

[0148] Optionally, during the authentication process, the PQC terminal service may call the key information of the cryptographic algorithm stored in the smart cryptographic key, perform signature calculation, generate signature information, and feed the signature information and the user signature certificate back to the PQC terminal service.

[0149] S402: Initiate an authentication request to the issuing server based on the signature information, the user's signature certificate, and the authentication data; receive the authentication result returned by the certificate issuing server, and determine the user's identity authentication result based on the authentication result.

[0150] The PQC terminal service sends the signature information, user signature certificate, and authentication data to the certificate issuing server. The certificate issuing server performs authentication based on the PQC cryptographic algorithm and the SM2 cryptographic algorithm, and returns the authentication results to the PQC terminal service. The user's identity authentication result can be determined based on the authentication results.

[0151] Figure 6 A flowchart of another identity authentication method provided in an embodiment of the present application; optionally, in step S401, before calling the smart password key and generating and receiving the signature information of the authentication data returned by the smart password key, the following steps may be included:

[0152] S501, initiate a login request to the certificate issuing server, and obtain a first message field returned by the certificate issuing server; the first message field includes a first random number.

[0153] Here, the mechanism of the digital signature technology in the GB / T 15843.3-2008 standard can be referred to for implementation.

[0154] After the PQC terminal service initiates the login request to the certificate issuing server, the PQC terminal service can obtain the first message field returned by the certificate issuing server. The first message field can include the first random number, and can also include a first protocol field. The first protocol field can be a field previously negotiated by the PQC terminal service and the certificate issuing server, and is used to confirm the identity of each other.

[0155] S502, the intelligent password key is called to generate a second message field; the second message field includes a second random number.

[0156] The PQC terminal service calls the intelligent password key to generate the second message field, and the second message field includes the second random number. The intelligent password key returns the generated second message field to the PQC terminal service.

[0157] S503, generating authentication data according to the first message field, the second message field, and the user message field.

[0158] The PQC terminal service generates authentication data according to the first message field, the second message field, and the user message field. The user message field can refer to a user message. In addition, when the authentication data is sent to the intelligent password key for signature calculation, the second protocol field can be carried on the basis of the authentication data, which has a similar function to the first protocol field. In different interaction stages, the protocol fields included in the interaction data can be different, but the function is to confirm the identity of each other.

[0159] Exemplarily, after the PQC terminal service initiates the login request to the certificate issuing server, the PQC terminal service can receive the first message field returned by the certificate issuing server: RB+“QHSM1”; wherein, RB is the first random number, and QHSM1 is the first protocol field.

[0160] The PQC terminal service calls the intelligent password key to generate the second message field, and receives the second message field returned by the intelligent password key: RA; wherein, RA is the second random number.

[0161] The PQC terminal service generates authentication data based on RB, RA, and the user message field "qhsm_server." The generated authentication data is: RA + RB + "qhsm_server." The PQC terminal service sends the authentication data, along with the second protocol field "QHSM2," to the smart cryptographic key for signature calculation.

[0162] Next, the signature calculation of the authentication data is performed based on the smart password key, which involves signature calculation based on the PQC cryptographic algorithm and signature calculation based on the SM2 cryptographic algorithm.

[0163] Optionally, in step S401, calling the smart cryptographic key to generate and receive signature information of the authentication data returned by the smart cryptographic key may include: calling the smart cryptographic key to generate first signature information of the authentication data according to the key information of the post-quantum cryptographic algorithm; and generating second signature information of the authentication data according to the key information of the asymmetric cryptographic algorithm; the signature information of the authentication data includes the first signature information and the second signature information.

[0164] In one possible implementation, the smart password key can perform signature calculation on the authentication data according to the PQC cryptographic algorithm to generate first signature information corresponding to the authentication data; at the same time, it can also perform signature calculation on the authentication data according to the SM2 cryptographic algorithm to generate second signature information corresponding to the authentication data.

[0165] Optionally, calling the smart cryptographic key to generate first signature information of the authentication data based on the key information of the post-quantum cryptographic algorithm may include: if the smart cryptographic key supports the post-quantum cryptographic algorithm, calling the post-quantum cryptographic algorithm program running in the smart cryptographic key, and the smart cryptographic key performing a signature calculation on the authentication data based on the private key of the post-quantum cryptographic algorithm stored in the secure storage area to generate the first signature information of the authentication data.

[0166] For the PQC cryptographic algorithm, there are two situations in the signature calculation process: one is that the smart password key supports the PQC cryptographic algorithm, and the other is that the smart password key does not support the PQC cryptographic algorithm. This solution also provides different processing flows for different situations.

[0167] Optionally, if the smart key supports the PQC cryptographic algorithm, the smart key uses the private key in the key information of the PQC cryptographic algorithm stored in the secure storage area to perform signature calculation on the authentication data using the PQC cryptographic algorithm to obtain first signature information corresponding to the authentication data. The smart key then feeds the first signature information and the first user signature certificate stored in the secure storage area back to the PQC terminal service.

[0168] Figure 7A flowchart of another identity authentication method provided in an embodiment of the present application; optionally, in step S401, calling a smart cryptographic key to generate first signature information of authentication data based on key information of a post-quantum cryptographic algorithm may include:

[0169] S601: If the smart cryptographic key does not support the post-quantum cryptographic algorithm, read the private key ciphertext of the post-quantum cryptographic algorithm.

[0170] If the smart password key does not support the PQC cryptographic algorithm, the PQC terminal service will read the private key ciphertext of the PQC cryptographic algorithm. This can be read from the background database of the PQC terminal service.

[0171] S602. Decrypt the private key ciphertext of the post-quantum cryptography algorithm according to the derived key of the login password.

[0172] Since the private key ciphertext is encrypted data, and the encryption process has been explained above, it is obtained by encryption based on the derived key of the login password. Therefore, the private key ciphertext can be decrypted according to the derived key of the login password to obtain the private key of the PQC cryptographic algorithm.

[0173] S603: Perform signature calculation on the authentication data according to the private key of the post-quantum cryptography algorithm obtained after decryption to generate first signature information of the authentication data.

[0174] The PQC terminal service performs signature calculation on the authentication data according to the private key of the PQC cryptographic algorithm obtained by decryption to generate first signature information of the authentication data.

[0175] Optionally, the step of generating second signature information of the authentication data based on the key information of the asymmetric cryptographic algorithm may include: calling the asymmetric cryptographic algorithm program running in the smart cryptographic key, and the smart cryptographic key performing a signature calculation on the authentication data based on the private key of the asymmetric cryptographic algorithm stored in the secure storage area to generate the second signature information of the authentication data.

[0176] Regarding the signature calculation under the SM2 cryptographic algorithm, since the smart cryptographic key itself supports the asymmetric cryptographic algorithm, the smart cryptographic algorithm can use the SM2 key algorithm based on the private key in the key information of the SM2 cryptographic algorithm stored in the secure storage area to perform signature calculation on the authentication data and generate the second signature information of the authentication data.

[0177] Figure 8 A flowchart of another identity authentication method provided in an embodiment of the present application; optionally, in step S402, an authentication request is initiated to the issuing server based on the signature information, the user signature certificate, and the authentication data; an authentication result returned by the certificate issuing server is received, and the user's identity authentication result is determined based on the authentication result, which may include:

[0178] S701: Initiate an authentication request to a certificate issuing server based on the first signature information, the second signature information, the first user signature certificate, the second user signature certificate, and the authentication data.

[0179] Optionally, when performing authentication based on the PQC cryptographic algorithm, the PQC terminal service may send the first signature information, the authentication data, and the first user signature certificate to the certificate issuing server for authentication. The authentication data may include a third protocol field and be sent to the certificate issuing server. The third protocol field has the same function as the first and second protocol fields.

[0180] When authentication is performed based on the SM2 cryptographic algorithm, the PQC terminal service may send the second signature information, the authentication data, and the second user signature certificate together to the certificate issuing server for authentication. The authentication data carrying the third protocol field may be sent to the certificate issuing server.

[0181] S702: Receive the authentication result returned by the certificate issuing server, and determine the user's identity authentication result based on the authentication result.

[0182] To verify the SM2 cryptographic algorithm, the certificate issuing server can first check the first random number in the authentication data. If the first random number is the same as the first random number sent by the certificate issuing server to the PQC terminal service, the first random number verification is successful. The user message field and the third protocol field carried in the authentication data can also be verified. If the field is consistent with the agreed field, the verification is successful. Then, the second user signature certificate can be used to verify the second signature information, that is, the public key in the second user signature certificate is used to decrypt the second signature information. The second user signature certificate is then verified based on the root certificate of the SM2 cryptographic algorithm generated during initialization. After all verifications are completed, the authentication result based on the SM2 cryptographic algorithm is returned to the PQC terminal service.

[0183] Similarly, for verification of the PQC cryptographic algorithm, since the first random number, user message field, and third protocol field have already been verified during the SM2 cryptographic algorithm verification process, only the first user signature certificate is used to verify the first signature information. That is, the first signature information is decrypted using the public key in the first user signature certificate. The first user signature certificate is then verified using the root certificate of the PQC cryptographic algorithm generated during initialization. Similarly, after verification is complete, the authentication result based on the PQC cryptographic algorithm is returned to the PQC terminal service.

[0184] Figure 9A flowchart of another identity authentication method provided in an embodiment of the present application; optionally, in step S702, receiving the authentication result returned by the certificate issuing server and determining the user's identity authentication result based on the authentication result may include:

[0185] S801. Receive a first authentication result corresponding to a post-quantum cryptography algorithm and a second authentication result corresponding to an asymmetric cryptography algorithm returned by a certificate issuing server.

[0186] Optionally, the PQC terminal service may receive a first authentication result corresponding to the PQC cryptographic algorithm and a second authentication result corresponding to the SM2 algorithm returned by the certificate issuing server.

[0187] S802: If both the first authentication result and the second authentication result are authenticated, determine that the user's identity authentication result is authenticated.

[0188] If both the first authentication result and the second authentication result are authentication passed, it can be determined that the user's identity authentication result is authentication passed.

[0189] User identity authentication is achieved through dual authentication of post-quantum cryptographic algorithms and asymmetric cryptographic algorithms. Compared with the traditional authentication method of only using asymmetric cryptographic algorithms, it effectively resists quantum computing attacks, the authentication process is more secure, and the authentication results are more accurate.

[0190] In summary, the identity authentication method provided in this embodiment includes: logging in to a smart password key according to a login password entered by a user, obtaining key information of a post-quantum cryptographic algorithm based on the smart password key, and obtaining key information of an asymmetric cryptographic algorithm based on the smart password key; applying for a first user signature certificate corresponding to the post-quantum cryptographic algorithm from a certificate issuing server based on the public key of the post-quantum cryptographic algorithm; and applying for a second user signature certificate corresponding to the asymmetric cryptographic algorithm from a certificate issuing server based on the public key of the asymmetric cryptographic algorithm; writing the key information of the post-quantum cryptographic algorithm, the key information of the asymmetric cryptographic algorithm, the first user signature certificate, and the second user signature certificate as authentication information into a secure storage area of ​​the smart password key; and performing identity authentication based on the authentication information stored in the secure storage area of ​​the smart password key. This method combines the post-quantum cryptographic algorithm with the asymmetric cryptographic algorithm. On the basis of the traditional smart password key identity authentication using the asymmetric cryptographic algorithm, it integrates the identity authentication means of the post-quantum cryptographic algorithm. Through the dual algorithm authentication method, the security and accuracy of identity authentication are improved. This method not only meets the requirements of the existing security system, but also provides security capabilities in the post-quantum era, effectively resisting quantum computing attacks.

[0191] In addition, this solution provides different processing flows depending on whether the smart password key supports the post-quantum cryptographic algorithm, so that the key information generation and signature calculation of the post-quantum cryptographic algorithm can be realized in both cases: the smart password key supports the post-quantum cryptographic algorithm and the smart password key does not support the post-quantum cryptographic algorithm. This solution can better adapt to the situation where most current smart password keys do not support the post-quantum cryptographic algorithm.

[0192] Optionally, this application also provides an identity authentication system. The architecture diagram of the identity authentication system can be referenced. Figure 1 The identity authentication system may include: a terminal device, a smart password key, and a certificate issuing server; the terminal device is deployed with the above-mentioned PQC terminal service.

[0193] The terminal device is used to perform identity authentication based on the identity authentication method provided in the embodiment of the application;

[0194] The smart password key is used to interact with the terminal device to obtain the key information of the cryptographic algorithm, store and provide authentication information containing the key information, and perform signature calculation based on the key information;

[0195] The certificate issuing server is used to interact with the terminal device for identity authentication.

[0196] Figure 10 A signaling interaction diagram provided for an embodiment of the present application. Figure 10 This paper shows the method flow of generating key information of cryptographic algorithm based on intelligent cryptographic key. It mainly involves the following steps:

[0197] First: Initialize the certificate signing server:

[0198] The certificate signing server initializes the key pair of the SM2 cryptographic algorithm and the key pair of the PQC cryptographic algorithm as the root signing key pair of the certificate signing server; and generates the root certificate corresponding to the SM2 cryptographic algorithm and the root certificate of the PQC cryptographic algorithm.

[0199] Second: User creation (including generating key information for the SM2 cryptographic algorithm and the PQC cryptographic algorithm respectively):

[0200] (1) Key information generation for the SM2 cryptographic algorithm:

[0201] After successfully logging into the smart password key, the smart password key is called to generate the key information of the SM2 cryptographic algorithm, and an application is made to the certificate signing server for a second user signature certificate based on the received public key of the SM2 cryptographic algorithm; the second user signature certificate is imported into the secure storage area of ​​the smart password key.

[0202] (2) Key information generation of PQC cryptographic algorithm:

[0203] If the smart password key supports the PQC cryptographic algorithm, the smart password key is called to generate the key information of the PQC cryptographic algorithm and receive the public key of the PQC cryptographic algorithm.

[0204] If the smart password key does not support the PQC cryptographic algorithm, the key information of the PQC cryptographic algorithm is generated, and the private key of the PQC cryptographic algorithm is encrypted using the derived key of the smart password key's login password; the encrypted private key ciphertext and the public key of the PQC cryptographic algorithm are written into the secure storage area of ​​the smart password key.

[0205] Apply for the first user signature certificate from the certificate issuing server based on the public key of the PQC cryptographic algorithm, and write the obtained first user signature certificate into the secure storage area of ​​the smart password key.

[0206] Figure 11 Another signaling interaction diagram provided for an embodiment of the present application. Figure 11 This article demonstrates the process of user identity authentication based on the authentication information provided by the smart key. It mainly involves the following steps:

[0207] First: Authentication based on the SM2 cryptographic algorithm:

[0208] The PQC terminal service initiates a login request to the certificate issuing server, and receives the first random number and the first protocol field returned by the certificate issuing server.

[0209] The PQC terminal service calls the smart password key to generate a second random number.

[0210] Generate authentication data according to the first random number, the second random number, and the user message field, send the authentication data carrying the second protocol field to the smart password key, calculate the signature by the smart password key, and receive the second signature information and the second user signature certificate returned by the smart password key.

[0211] The authentication data carrying the third protocol field, the second signature information, and the second user signature certificate are sent to the certificate issuing server for authentication.

[0212] The certificate issuing server verifies the second random number, verifies the user message field and the third protocol field, verifies the second signature information using the second user signature certificate, verifies the second user signature certificate using the root certificate of the SM2 cryptographic algorithm, and returns the second authentication result to the PQC terminal service.

[0213] Second: Authentication based on PQC cryptographic algorithm:

[0214] Some steps are the same as the authentication process based on the SM2 password algorithm, such as logging into the smart password key and generating authentication data, and will not be repeated here.

[0215] The authentication data carrying the second protocol field is sent to the smart password key, and the smart password key performs signature calculation.

[0216] When the smart password key supports the PQC cryptographic algorithm, the smart password key uses the private key of the PQC cryptographic algorithm stored in the secure area to perform signature calculation on the authentication data and returns the first signature information to the PQC terminal service.

[0217] When the smart password key does not support the PQC cryptographic algorithm, the PQC terminal service reads the private key ciphertext of the PQC cryptographic algorithm, decrypts the private key ciphertext using the derived key of the login password, and performs signature calculation on the authentication data based on the decrypted private key of the PQC cryptographic algorithm to obtain the first signature information, and receives the first user signature certificate returned by the smart password key.

[0218] The authentication data carrying the third protocol field, the first signature information, and the first user signature certificate are sent to the certificate issuing server for authentication.

[0219] The certificate issuing server verifies the first signature information using the first user signature certificate, verifies the first user signature certificate using the root certificate of the PQC cryptographic algorithm, and returns the first authentication result to the PQC terminal service.

[0220] The following describes the apparatus, terminal equipment, storage medium, etc. used to execute the identity authentication method provided in this application. The specific implementation process and technical effects are described above and will not be repeated below.

[0221] Figure 12 A schematic diagram of the structure of a terminal device provided in an embodiment of the present application, which terminal device may be a computing device with data processing capabilities.

[0222] The device may include: a processor 801 and a storage medium 802 .

[0223] The storage medium 802 is used to store programs, and the processor 801 calls the programs stored in the storage medium 802 to execute the above method embodiment. The specific implementation methods and technical effects are similar and will not be repeated here.

[0224] Among them, the storage medium 802 stores program code, and when the program code is executed by the processor 801, the processor 801 executes various steps in the identity authentication method according to various exemplary embodiments of the present application described in the above "Exemplary Method" section of this specification.

[0225] The processor 801 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly implemented as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor.

[0226] The storage medium 802 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs, and modules. The storage medium may include at least one type of storage medium, such as flash memory, a hard disk, a multimedia card, a card-type storage medium, a random access memory (RAM), a static random access memory (SRAM), a programmable read-only memory (PROM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic storage medium, a magnetic disk, an optical disk, and the like. The storage medium is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these. The storage medium 802 in the embodiments of the present application may also be a circuit or any other device capable of performing a storage function, used to store program instructions and / or data.

[0227] Optionally, the present application also provides a program product, such as a computer-readable storage medium, comprising a program, which is used to perform the above method embodiment when executed by a processor.

[0228] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0229] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0230] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0231] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor (English: processor) to perform some steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard drives, read-only storage media (English: Read-Only Memory, abbreviated: ROM), random access storage media (English: Random Access Memory, abbreviated: RAM), magnetic disks or optical disks, and other media that can store program code.

Claims

1. An identity authentication method, characterized in that: include: Logging in to the smart cryptographic key according to the login password input by the user, obtaining key information of the post-quantum cryptographic algorithm based on the smart cryptographic key, and obtaining key information of the asymmetric cryptographic algorithm based on the smart cryptographic key; The key information includes: a public key and a private key; Applying for a first user signature certificate corresponding to the post-quantum cryptographic algorithm from a certificate issuing server based on the public key of the post-quantum cryptographic algorithm; and applying for a second user signature certificate corresponding to the asymmetric cryptographic algorithm from the certificate issuing server based on the public key of the asymmetric cryptographic algorithm; Writing the key information of the post-quantum cryptographic algorithm, the key information of the asymmetric cryptographic algorithm, the first user signature certificate, and the second user signature certificate as authentication information into the secure storage area of ​​the smart password key; Perform identity authentication based on the authentication information stored in the secure storage area of ​​the smart password key; The obtaining key information of the post-quantum cryptographic algorithm based on the smart cryptographic key includes: If the smart cryptographic key supports the post-quantum cryptographic algorithm, calling the post-quantum cryptographic algorithm program running in the smart cryptographic key to generate key information of the post-quantum cryptographic algorithm; If the smart password key does not support the post-quantum cryptographic algorithm, key information of the post-quantum cryptographic algorithm is generated, and the generated key information of the post-quantum cryptographic algorithm is encrypted according to the login password to obtain the processed key information of the post-quantum cryptographic algorithm.

2. The method according to claim 1, characterized in that The step of encrypting the generated key information of the post-quantum cryptographic algorithm according to the login password to obtain the processed key information of the post-quantum cryptographic algorithm includes: generating a derived key of the login password according to the login password; Using the derived key to encrypt the private key in the key information of the post-quantum cryptographic algorithm to obtain the private key ciphertext of the post-quantum cryptographic algorithm; The processed key information of the post-quantum cryptographic algorithm is obtained according to the private key ciphertext of the post-quantum cryptographic algorithm and the public key in the key information of the post-quantum cryptographic algorithm.

3. The method according to claim 1, characterized in that The obtaining of key information of an asymmetric cryptographic algorithm based on the smart cryptographic key includes: The asymmetric cryptographic algorithm program running in the smart cryptographic key is called to generate key information of the asymmetric cryptographic algorithm.

4. The method according to claim 1, wherein applying for a first user signature certificate corresponding to the post-quantum cryptography algorithm from a certificate issuing server according to the public key of the post-quantum cryptography algorithm; Applying for a second user signature certificate corresponding to the asymmetric cryptographic algorithm from the certificate issuing server according to the public key of the asymmetric cryptographic algorithm includes: Initiate a certificate application to the certificate issuing server according to the public key of the post-quantum cryptographic algorithm, and receive a first user signature certificate corresponding to the post-quantum cryptographic algorithm returned by the certificate issuing server; A certificate application is initiated to the certificate issuing server according to the public key of the asymmetric cryptographic algorithm, and a second user signature certificate corresponding to the asymmetric cryptographic algorithm returned by the certificate issuing server is received.

5. The method according to any one of claims 1 to 4, characterized in that The performing identity authentication according to the authentication information stored in the secure storage area of ​​the smart password key includes: Invoking the smart password key, generating and receiving signature information of the authentication data and the user signature certificate returned by the smart password key; the signature information is generated by the smart password key based on the key information stored in the secure storage area of ​​the smart password key; Initiate an authentication request to the issuing server based on the signature information, the user signature certificate and the authentication data; receive the authentication result returned by the certificate issuing server, and determine the identity authentication result of the user based on the authentication result.

6. The method according to claim 5, characterized in that Before calling the smart password key and generating and receiving signature information of the authentication data returned by the smart password key, the method includes: Initiate a login request to the certificate issuing server, and obtain a first message field returned by the certificate issuing server; the first message field includes a first random number; Calling the smart password key to generate a second message field; the second message field includes: a second random number; The authentication data is generated according to the first message field, the second message field and the user message field.

7. The method according to claim 5, characterized in that The calling of the smart password key, generating and receiving signature information of the authentication data returned by the smart password key, includes: The smart cryptographic key is called to generate first signature information of the authentication data according to the key information of the post-quantum cryptographic algorithm; and second signature information of the authentication data is generated according to the key information of the asymmetric cryptographic algorithm; the signature information of the authentication data includes the first signature information and the second signature information.

8. The method according to claim 7, characterized in that The calling of the smart cryptographic key to generate first signature information of the authentication data according to key information of the post-quantum cryptographic algorithm includes: If the smart cryptographic key supports the post-quantum cryptographic algorithm, the post-quantum cryptographic algorithm program running in the smart cryptographic key is called, and the smart cryptographic key performs a signature calculation on the authentication data according to the private key of the post-quantum cryptographic algorithm stored in the secure storage area to generate first signature information of the authentication data.

9. The method according to claim 7, characterized in that The calling of the smart cryptographic key to generate first signature information of the authentication data according to key information of the post-quantum cryptographic algorithm includes: If the smart cryptographic key does not support the post-quantum cryptographic algorithm, reading the private key ciphertext of the post-quantum cryptographic algorithm; Decrypting the private key ciphertext of the post-quantum cryptographic algorithm according to the derived key of the login password; Perform signature calculation on the authentication data according to the private key of the post-quantum cryptography algorithm obtained after decryption to generate first signature information of the authentication data.

10. The method according to claim 7, characterized in that The generating the second signature information of the authentication data according to the key information of the asymmetric cryptographic algorithm includes: The asymmetric cryptographic algorithm program running in the smart cryptographic key is called, and the smart cryptographic key performs signature calculation on the authentication data according to the private key of the asymmetric cryptographic algorithm stored in the secure storage area to generate second signature information of the authentication data.

11. The method according to claim 7, characterized in that Initiating an authentication request to the issuing server based on the signature information, the user signature certificate, and the authentication data; Receiving the authentication result returned by the certificate issuing server and determining the identity authentication result of the user according to the authentication result, including: Initiate an authentication request to the certificate issuing server based on the first signature information, the second signature information, the first user signature certificate, the second user signature certificate, and the authentication data; Receive the authentication result returned by the certificate issuing server, and determine the identity authentication result of the user according to the authentication result.

12. The method according to claim 11, characterized in that The receiving the authentication result returned by the certificate issuing server and determining the identity authentication result of the user according to the authentication result includes: Receiving a first authentication result corresponding to the post-quantum cryptography algorithm and a second authentication result corresponding to the asymmetric cryptography algorithm returned by the certificate issuing server; If both the first authentication result and the second authentication result are authenticated, the identity authentication result of the user is determined to be authenticated.

13. A terminal device, characterized in that: include: A processor, a storage medium and a bus, wherein the storage medium stores program instructions executable by the processor. When the terminal device is running, the processor and the storage medium communicate via the bus, and the processor executes the program instructions to implement the identity authentication method as described in any one of claims 1 to 12.

14. An identity authentication system, characterized in that: include: The terminal device, smart password key and certificate issuing server according to claim 13; The terminal device is used to perform identity authentication based on the identity authentication method according to any one of claims 1 to 12; The smart password key is used to interact with the terminal device to obtain key information of the cryptographic algorithm, store and provide authentication information containing the key information, and perform signature calculation based on the key information; The certificate issuing server is used to interact with the terminal device to perform identity authentication.

15. A computer-readable storage medium, characterized in that The storage medium stores a computer program, which is used to implement the identity authentication method according to any one of claims 1 to 12 when executed by a processor.

Citation Information

Patent Citations

  • Combined Digital Signature Algorithms for Security Against Quantum Computers

    US20210377049A1