Quantum-resistant secure communication method, device and equipment applied to public network channels
By generating and updating public and private key information and temporary session keys in public network channels, the problems of storage overhead and key leakage of both communicating parties are solved, achieving high security and low storage overhead in quantum secure communication.
Patent Information
- Application Number
- CN202411529659.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-30
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2044-10-30
AI Technical Summary
In public network channels, existing technologies require both communicating parties to store multiple shared keys, which increases storage overhead and increases the risk of shared key leakage, reducing the security of communication encryption.
Send user authentication information and encryption confirmation requests through public network channels, generate public and private key information of the sender, generate random number pairs and perform public key encryption, determine the temporary session key and validity period based on the master secret information, and periodically update the encryption algorithm to reduce storage and leakage risks.
It reduces the storage resource overhead of both communicating parties, improves the security of communication encryption, resists quantum attacks, and ensures the security and privacy of communication sessions.
Smart Images

Figure CN119402168B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to the field of computer technology, and more particularly to quantum-resistant secure communication methods, devices, and apparatuses applied to public network channels. Background Art
[0002] When users communicate information or businesses transmit data over public network channels, there is a need to protect personal privacy or prevent data leaks. Furthermore, with the development of quantum computing technology, classical public key cryptography algorithms will no longer be able to protect the communication security of public network channels in the future. A transition solution from classical secure communication to quantum-resistant secure communication is urgently needed. Currently, when using conventional quantum-resistant encryption methods to encrypt communication information, the usual approach is that both parties must pre-agreed on a national cryptographic standard encryption algorithm and use a preset set of shared keys for communication encryption.
[0003] However, when using this method for communication encryption, the following technical issues often arise: In actual network communications, each communication end often has multiple communication partners. Therefore, each communication end needs to agree on and store independent shared keys with multiple communication partners, as well as record the correspondence between multiple shared keys, resulting in increased storage overhead for both communicating parties. In addition, the shared key is also at risk of being leaked during the process of agreeing on the shared key (for example, in person, via email, or on social media), which reduces the security of communication encryption.
[0004] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the Invention
[0005] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0006] Some embodiments of the present disclosure propose quantum-resistant secure communication methods, devices, and apparatuses applied to public network channels to solve one or more of the technical problems mentioned in the above background technology section.
[0007] In a first aspect, some embodiments of the present disclosure provide a quantum-resistant secure communication method applied to a public network channel, the method comprising: sending user authentication information and an encryption confirmation request to a communication receiving end through a public network channel, wherein the user authentication information comprises: identity information of the sending end and a first information list, the first information in the first information list representing a description of an encryption algorithm used to encrypt information; in response to receiving target encryption information confirmed by the communication receiving end, generating public and private key information of the sending end according to the target encryption information, wherein the target encryption information is the first information confirmed by the communication receiving end from the first information list after receiving the encryption confirmation request, and the public and private key information of the sending end comprises public key information of the sending end and private key information of the sending end; based on the public and private key information of the sending end, executing the following first loop steps: generating a random number pair of the sending end; sending the public and private key information of the sending end to the communication receiving end through the public network channel; public key information and receiving end public key information request; in response to receiving the receiving end public key information sent by the above-mentioned communication receiving end, according to the above-mentioned receiving end public key information, the sending end random number pair is encrypted with a public key scheme to obtain the sending end encrypted information; according to the sending end random number pair and the above-mentioned sending end private key information, the master secret information is generated, wherein the above-mentioned master secret information corresponds to the generation time; in response to determining that the current time does not meet the preset time period condition corresponding to the generation time, the above-mentioned first loop step is executed again; in response to determining that the current time meets the period time bar corresponding to the generation time, based on the master secret information, the following second loop step is executed: according to the master secret information, a temporary session key and a temporary session validity period are determined; in response to determining that the current communication duration is less than or equal to the temporary session key validity period, the communication information is encrypted according to the temporary session key; in response to determining that the current communication duration is greater than the temporary session key validity period, the above-mentioned second loop step is executed again.
[0008] In a second aspect, some embodiments of the present disclosure provide a quantum-resistant secure communication device for use in a public network channel, the device comprising: a sending unit, configured to send user authentication information and an encryption confirmation request to a communication receiving end through a public network channel, wherein the user authentication information comprises: identity information of the sending end and a first information list, the first information in the first information list representing a description of an encryption algorithm for information encryption; a generating unit, configured to generate public and private key information of the sending end in response to target encryption information received and confirmed by the communication receiving end, according to the target encryption information, wherein the target encryption information is the first information confirmed by the communication receiving end from the first information list after receiving the encryption confirmation request, and the public and private key information of the sending end comprises public key information of the sending end and private key information of the sending end; an executing unit, configured to generate a random number pair of the sending end; and send the above-mentioned sending end to the communication receiving end through the public network channel. in response to receiving the public key information of the receiving end sent by the above-mentioned communication receiving end, encrypting the random number pair of the sending end according to the public key information of the receiving end to obtain the encrypted information of the sending end; generating the master secret information according to the random number pair of the sending end and the private key information of the sending end, wherein the master secret information corresponds to the generation time; in response to determining that the current time does not meet the preset time period condition corresponding to the generation time, executing the first loop step again; in response to determining that the current time meets the period time bar corresponding to the generation time, executing the following second loop step based on the master secret information: determining the temporary session key and the temporary session validity period according to the master secret information; in response to determining that the current communication duration is less than or equal to the validity period of the temporary session key, encrypting the communication information according to the temporary session key; in response to determining that the current communication duration is greater than the validity period of the temporary session key, executing the second loop step again.
[0009] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.
[0010] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation of the first aspect is implemented.
[0011] The various embodiments disclosed above have the following beneficial effects: The quantum-resistant secure communication methods applied to public network channels according to some embodiments of the present disclosure can reduce the storage resource overhead of both communicating parties while resisting quantum attacks, and further improve the security of communication encryption. Specifically, the increased storage overhead and reduced encryption security of both communicating parties are caused by the fact that in actual network communications, each communicating end often has multiple communication partners. Therefore, each communicating end needs to agree on and store independent shared keys with multiple communication partners, as well as record the correspondence between multiple shared keys, resulting in increased storage overhead for the communication sending end. Furthermore, there is a risk of shared keys being leaked during the process of agreeing on the shared keys between the communicating parties (for example, in person or via email), which reduces the security of communication encryption. Based on this, the quantum-resistant secure communication methods applied to public network channels according to some embodiments of the present disclosure first send user authentication information and an encryption confirmation request to the communication receiving end via the public network channel. The user authentication information includes the identity information of the sending end and a first information list. The first information in the first information list represents a description of the encryption algorithm used to encrypt the information. Therefore, when initiating network communication, the communication sending end can send user authentication information and an encryption confirmation request to the communication receiving end, allowing the communication receiving end to verify its identity and agree on the encryption algorithm to be used for subsequent communication encryption. Then, in response to receiving the target encryption information confirmed by the communication receiving end, the sending end generates the public and private key information of the sending end based on the target encryption information. The target encryption information is the first information confirmed by the communication receiving end from the first information list after receiving the encryption confirmation request. The sending end public and private key information includes the sending end public key information and the sending end private key information. Therefore, when the communication sending end receives the encryption algorithm representing the selected encryption algorithm of the communication receiving end, it can generate two pairs of public and private keys for encryption. Finally, based on the sending end public and private key information, the following first loop steps are executed: First, generate a sending end random number pair. This can add randomness to the encryption of communication information by generating random numbers, thereby improving the security of communication encryption. Second, send the sending end public key information and the receiving end public key information request to the communication receiving end via a public network channel. In the third step, in response to receiving the public key information sent by the communication receiving end, the sending end random number pair is encrypted using a public key scheme based on the receiving end public key information to obtain the sending end encrypted information. Thus, the communicating parties can exchange public keys and encrypt their respective random numbers using each other's public keys to obtain the sending end encrypted information and the receiving end encrypted information. In the fourth step, master secret information is generated based on the sending end random number pair and the sending end private key information. The generated master secret information is associated with a generation time. Thus, through the interaction of random encrypted information between the communication sending end and the communication receiving end, time-sensitive master secret information can be generated for generating the communication encryption key.In step 5, in response to determining that the current time does not meet the preset time period corresponding to the generation time, the first loop step is executed again. This allows the timeliness of the generated master key information to be determined, and a new master secret information is generated when it expires. In step 6, in response to determining that the current time meets the periodic time condition corresponding to the generation time, the following second loop step is executed based on the master secret information: First, a temporary session key and a temporary session validity period are determined based on the master secret information. Thus, using the generated master secret information, a temporary session key with high complexity, randomness, and timeliness, as well as the validity period of the communication session, can be ultimately determined. In step 2, in response to determining that the current communication duration is less than or equal to the validity period of the temporary session key, the communication information is encrypted using the temporary session key. This allows the communication information to be encrypted using the temporary session key, significantly improving the security of the communication encryption. In step 3, in response to determining that the current communication duration is greater than the validity period of the temporary session key, the second loop step is executed again. Because both communicating parties only select a random encryption algorithm when initiating network communication and exchange random encrypted information using the selected encryption algorithm, they ultimately generate a temporary session key with extremely high complexity and randomness. Even if a temporary session key expires or is at risk of being leaked, attackers cannot decrypt communications encrypted with other temporary session keys, further enhancing the security of the communication session. At the end of the communication session, neither party needs to store the expired temporary session key. Because the encryption algorithms selected by both communicating parties include post-quantum cryptographic algorithms, storage resource overhead for both parties is reduced while also improving the security of communication encryption, while also resisting quantum attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.
[0013] Figure 1 is a flow chart of some embodiments of a quantum-resistant secure communication method applied to a public network channel according to the present disclosure;
[0014] Figure 2 1 is a schematic structural diagram of some embodiments of a quantum-resistant secure communication device applied to a public network channel according to the present disclosure;
[0015] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure;
[0016] Figure 4is a schematic communication flow chart of a quantum-resistant secure communication method applied to a public network channel according to the present disclosure;
[0017] Figure 5 A schematic system functional architecture diagram of the quantum-resistant secure communication method applied to a public network channel according to the present disclosure. DETAILED DESCRIPTION
[0018] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0019] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.
[0020] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0021] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0023] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0024] Figure 1 A process 100 of some embodiments of a quantum-resistant secure communication method applied to a public network channel according to the present disclosure is shown. The quantum-resistant secure communication method applied to a public network channel includes the following steps:
[0025] Step 101: Send user authentication information and an encryption confirmation request to a communication receiving end through a public network channel.
[0026] In some embodiments, the execution subject (e.g., a computing device) of the quantum-resistant secure communication method applied to a public network channel can send user authentication information and an encryption determination request to the communication receiving end through the public network channel. The user authentication information includes: the identity information of the sending end and a first information list. Each first information in the first information list represents a description of an encryption algorithm used for information encryption. For example, the first information in the first information list can be the algorithm name of the encryption algorithm. The sender identity information can be information representing the identity of the execution subject (i.e., the communication sending end). The sender identity information can be, but is not limited to, the serial number of the communication sending end device or the network IP address of the communication sending end. The encryption determination request can be a request for the communication receiving end to determine the target encryption algorithm.
[0027] Step 102: In response to receiving the target encryption information confirmed by the communication receiving end, generate the sending end public and private key information according to the target encryption information.
[0028] In some embodiments, the execution entity may generate sender public and private key information based on the target encryption information in response to receiving target encryption information confirmed by the communication receiving end. The target encryption information is the first information confirmed by the communication receiving end from the first information list after receiving the encryption confirmation request. The sender public and private key information includes sender public key information and sender private key information. The target encryption information may include: first encryption information and second encryption information. The sender public key information may include: first sender public key and second sender public key. The sender private key information may include: first sender private key and second sender private key. The first encryption information may represent the encryption algorithm selected by the communication receiving end user for the first type of encryption algorithm. The second encryption information may represent the encryption algorithm selected by the communication receiving end user for the second type of encryption algorithm. The first type of encryption algorithm may be a classical encryption algorithm. The second type of encryption algorithm may be a post-quantum encryption algorithm. Classical encryption algorithms may include, but are not limited to, symmetric encryption algorithms and asymmetric encryption algorithms. Post-quantum cryptographic algorithms may include, but are not limited to, lattice-based cryptographic algorithms, encoding-based cryptographic algorithms, multivariate-based cryptographic algorithms, hash function-based cryptographic algorithms, and curve homology-based cryptographic algorithms. The first sender public key and the first sender private key may be a pair of public-private keys generated by the execution entity using the first type of encryption algorithm represented by the first encrypted information. The second sender public key and the second sender private key may be a pair of public-private keys generated by the execution entity using the second type of encryption algorithm represented by the second encrypted information.
[0029] In some optional implementations of some embodiments, the execution entity may generate a sender public and private key information and a sender random number pair based on the target encryption information through the following steps:
[0030] The first step is to generate first sender public key information and first sender private key information based on the first encrypted information. In practice, the execution entity may generate the first sender public key information and the first sender private key information using the first type of encryption algorithm represented by the first encrypted information. For example, if the first type of encryption algorithm represented by the first encrypted information is the SM2 algorithm (elliptic curve public key cryptography algorithm), the execution entity may generate a pair of SM2 public and private keys as the first sender public key information and the first sender private key information, respectively.
[0031] In the second step, based on the second encrypted information, the second sender public key information and the second sender private key information are generated. In practice, the execution entity may generate the second sender public key information and the second sender private key information using the second type of encryption algorithm represented by the second encrypted information. For example, if the second type of encryption algorithm represented by the second encrypted information is a lattice-based post-quantum encryption algorithm (CRYSTALS-Kyber encryption algorithm), the execution entity may generate a pair of CRYSTALS-Kyber public and private keys as the second sender public key information and the second sender private key information, respectively.
[0032] In the third step, the first sender public key information and the second sender public key information are determined as the sender public key information included in the sender public-private key information.
[0033] In the fourth step, the first sender private key information and the second sender private key information are determined as the sender private key information included in the sender public and private key information.
[0034] Step 103: Based on the public and private key information of the sender, execute the following first loop steps:
[0035] Step 1031: Generate a sending end random number pair.
[0036] In some embodiments, the execution entity may generate a sender random number pair. In practice, the execution entity may first generate two random numbers with a bit length greater than or equal to a preset bit length as a first sender random number and a second sender random number, respectively. The first sender random number and the second sender random number are independent of each other. The execution entity may then determine the first sender random number and the second sender random number as a sender random number pair. For example, the preset bit length is 256 bits.
[0037] Step 1032: Send the sender's public key information and the receiver's public key information request to the communication receiving end through the public network channel.
[0038] In some embodiments, the execution entity may send the sender public key information and the receiver public key information request to the communication receiving end through a public network channel, wherein the receiver public key information request may be used to request the communication receiving end to generate the receiver public key information.
[0039] Step 1033: In response to receiving the receiving end public key information sent by the communication receiving end, the sending end random number pair is encrypted using a public key scheme according to the receiving end public key information to obtain the sending end encrypted information.
[0040] In some embodiments, the execution subject may, in response to receiving the receiving end public key information sent by the communication receiving end, perform public key scheme encryption on the sending end random number pair according to the receiving end public key information to obtain the encrypted information of the sending end.
[0041] Optionally, the receiving end public key information may be generated by the communication receiving end by executing the following steps based on the target encryption information:
[0042] The first step is to generate first receiving end public key information based on the first encryption information included in the target encryption information. In practice, the communication receiving end can generate the first receiving end public key information and the first receiving end private key information using the first type of encryption algorithm represented by the first encryption information.
[0043] The second step is to generate the second receiving end public key information based on the second encryption information included in the target encryption information. In practice, the communication receiving end can generate the second receiving end public key information and the second receiving end private key information using the second type of encryption algorithm represented by the second encryption information.
[0044] In a third step, the first receiving end public key information and the second receiving end public key information are determined as the receiving end public key information. Furthermore, after receiving the receiving end public key information request, the communication receiving end may also generate two random numbers, respectively, as a first receiving end random number and a second receiving end random number. The first receiving end random number and the second receiving end random number are independent of each other.
[0045] In some optional implementations of some embodiments, the execution entity may perform a public key encryption on the sending end random number pair according to the receiving end public key information through the following steps to obtain the sending end encrypted information:
[0046] In the first step, the first sending end random number is encrypted using a public key scheme based on the first receiving end public key information to obtain first sending end encrypted information. In practice, the execution entity may perform the public key scheme to encrypt the first sending end random number using a public key encryption function of the first type of encryption algorithm represented by the first receiving end public key information and the first encrypted information to obtain first sending end encrypted information.
[0047] In the second step, the second sending end random number is encrypted using a public key scheme based on the second receiving end public key information to obtain the second sending end encrypted information. In practice, the execution entity may perform the public key scheme encryption on the second sending end random number using a public key encryption function of the second type of encryption algorithm represented by the second receiving end public key information and the second encrypted information to obtain the second sending end encrypted information.
[0048] In the third step, the first sending end encrypted information and the second sending end encrypted information are determined as the sending end encrypted information.
[0049] Step 1034: Generate master secret information based on the sender's random number pair and the sender's private key information.
[0050] In some embodiments, the execution entity may generate master secret information based on the sender's random number pair and the sender's private key information. The generated master secret information may be associated with a generation time. The generated master secret information may include: first master secret information, second master secret information, and third master secret information. The master secret information may be used to generate a temporary session key.
[0051] In the process of adopting technical solutions to solve the problems mentioned in the background technology, the following problems are often accompanied: the communicating parties usually use random numbers as session keys. The generated session keys are relatively simple and have a high risk of attack and cracking, which leads to a decrease in communication security.
[0052] Faced with the above technical problems, the inventors decided to adopt the following solutions:
[0053] In some optional implementations of some embodiments, the execution entity may generate the master secret information according to the sending end random number pair and the sending end private key information through the following steps:
[0054] The first step is to transmit encrypted information from the transmitting end and a request for encrypted information from the receiving end to the communication receiving end via the public network channel. The request for encrypted information from the receiving end is used to request encrypted information from the communication receiving end. The encrypted information from the receiving end includes: first encrypted information from the receiving end and second encrypted information from the receiving end.
[0055] In the second step, in response to receiving the encrypted receiving information sent by the communication receiving end, the first receiving end encrypted information included in the encrypted receiving information is decrypted using a public key scheme based on the first sending end private key information to obtain a first receiving end random number. It should be noted that the first receiving end encrypted information is obtained by the communication receiving end using the first type of encryption algorithm represented by the first sending end public key information and the first encryption information to encrypt the first receiving end random number. In addition, the encryption algorithm represented by the first encryption information agreed upon by the communication receiving end and the communication sending end is the same. Therefore, in practice, the execution entity can decrypt the first receiving end encrypted information included in the encrypted receiving information using a public key decryption function of the first type of encryption algorithm represented by the first sending end private key information and the first encryption information to obtain the first receiving end random number.
[0056] In the third step, the second receiving-end encrypted information included in the receiving-end encrypted information is decrypted using a public key scheme based on the second sending-end private key information to obtain a second receiving-end random number. In practice, the execution entity may decrypt the second receiving-end encrypted information included in the receiving-end encrypted information using a public key decryption function of the second type of encryption algorithm represented by the second sending-end private key information and the second encrypted information to obtain the second receiving-end random number.
[0057] Step 4: Generate the first master secret information based on the first sending end random number and the first receiving end random number. In practice, the execution master performs bitwise exclusive-OR processing on the first sending end random number and the first receiving end random number to generate the first master secret information.
[0058] Step 5: Generate the second master secret information based on the second sending end random number and the second receiving end random number. In practice, the master performs bitwise exclusive-OR processing on the second sending end random number and the second receiving end random number to generate the second master secret information.
[0059] Step 6: Generate third master secret information based on the first master secret information and the second master secret information. In practice, the execution master performs bitwise exclusive-OR processing on the first master secret information and the second master secret information to generate the third master secret information.
[0060] Optionally, the encrypted information of the receiving end is obtained by the communication receiving end according to the public key information of the sending end through the following steps:
[0061] In the first step, the first receiving-end random number is encrypted using a public key scheme based on the first sending-end public key information included in the sending-end public key information to obtain first receiving-end encrypted information. In practice, the communication receiving end may perform public key scheme encryption on the first receiving-end random number using a public key encryption function of a first type of encryption algorithm represented by the first sending-end public key information and the first encrypted information to obtain first receiving-end encrypted information.
[0062] In a second step, the second receiving-end random number is encrypted using a public key scheme based on the second sending-end public key information included in the sending-end public key information to obtain second receiving-end encrypted information. In practice, the communication receiving end may perform public key scheme encryption on the second receiving-end random number using a public key encryption function of the second type of encryption algorithm represented by the second sending-end public key information and the second encrypted information to obtain second receiving-end encrypted information.
[0063] In the third step, the first receiving end encrypted information and the second receiving end encrypted information are determined as the receiving end encrypted information.
[0064] The above-described technical solution and its related contents, as an inventive feature of an embodiment of the present disclosure, address the technical problem that "communicating parties typically use random numbers as session keys. These generated session keys are relatively simple and pose a high risk of attack and cracking, resulting in reduced communication security." Factors that often contribute to reduced communication security include the following: The communicating parties typically use random numbers as session keys. These generated session keys are relatively simple and pose a high risk of attack and cracking, resulting in reduced communication security. Resolving these factors can improve network communication security. To achieve this, in this application, the communication sending and receiving ends exchange information using their own generated random number pairs, thereby each generating a master secret. A single-end session key is then generated based on the master secret and the random number. Finally, the communication sending and receiving ends exchange their respective generated session keys to generate a temporary session key. The session key generated using the above-described method exhibits high randomness and complexity, thereby improving the security of the communication session.
[0065] Step 1035 , in response to determining that the current time does not satisfy the preset time period condition corresponding to the generation time, executing the first loop step again.
[0066] In some embodiments, the execution entity may, in response to determining that the current time does not satisfy the preset time period condition corresponding to the generation time, re-execute the first loop step. The preset time period condition corresponding to the generation time may be that the current time is within the periodic time range corresponding to the generation time. For example, the preset time period is 7 days. The generation time may be "2024-10-12-08:00", and the periodic time range corresponding to the generation time may be "2024-10-12-08:00" to "2024-10-19-08:00".
[0067] Step 1036: In response to determining that the current time satisfies the periodic time bar corresponding to the generation time, the following second loop steps are executed based on the master secret information:
[0068] Step 10361: Determine the temporary session key and the validity period of the temporary session based on the master secret information.
[0069] In some embodiments, the execution entity may determine a temporary session key and a temporary session validity period based on the master secret information. The temporary session key may be a temporary key used to encrypt communication information. The temporary session validity period may be the validity period of the current communication session. The maximum value of the temporary session validity period may be 64 minutes.
[0070] In the process of adopting technical solutions to solve the problems mentioned in the background technology, the following problems often arise: when multiple communications are carried out in a public network, there is a risk of leakage when using fixed session keys, which leads to a decrease in communication security and privacy.
[0071] Faced with the above technical problems, the inventors decided to adopt the following solutions:
[0072] In some optional implementations of some embodiments, the execution entity may determine the temporary session key and the temporary session validity period based on the master secret information through the following steps:
[0073] The first step is to determine the target master secret information based on the master secret information. In practice, the execution entity may randomly select one master secret information from the first master secret information, the second master secret information, and the third master secret information included in the master secret information to determine it as the target master secret information. It should be noted that the first master secret information, the second master secret information, and the third master secret information each correspond to a prefix information with a preset number of bits to distinguish them from each other. The preset number of bits of the prefix information corresponding to the master secret information agreed upon by the communicating parties is the same. For example, the preset number of bits may be 2. The prefix information corresponding to the first master secret information may be 00. The prefix information corresponding to the second master secret information may be 01. The prefix information corresponding to the third master secret information may be 11.
[0074] The second step is to generate a sending end session key. In practice, the execution subject may generate a random number with a number of bits greater than or equal to the preset number of bits as the sending end session key.
[0075] The third step is to concatenate the sender session key and the sender session validity duration to obtain the concatenated sender session key. In practice, the execution entity may concatenate the binary string corresponding to the sender session validity duration to the end of the sender session key to obtain the concatenated sender session key. It should be noted that the sender session validity duration may be a user-defined setting on the communication sender. The binary string corresponding to the sender session validity duration has a fixed number of bits. If the number of bits is insufficient, the binary string may be padded with zeros at the beginning. As an example, the fixed number of bits may be 6.
[0076] Step 4: Based on the target master secret, the concatenated sender session key is symmetrically encrypted to obtain the encrypted session key. In practice, the execution entity can use the target master secret as a symmetric key to symmetrically encrypt the concatenated sender session key (for example, using the SymEnc() symmetric encryption function) to obtain the encrypted session key.
[0077] Step 5: Concatenate the encrypted session key with the prefix information corresponding to the target master secret to obtain the sender's target session key. In practice, the execution entity can concatenate the prefix information corresponding to the target master secret to the header of the encrypted session key to obtain the sender's target session key.
[0078] Step 6: Send the sender's target session key and the receiver's target session key request to the communication receiving end via the public network channel. The receiver's target session key request is used to request the receiver's target session key from the communication receiving end.
[0079] In step 7, in response to receiving the receiving end target session key sent by the above-mentioned communication receiving end, the receiving end target session key is decrypted to obtain decrypted session key information, wherein the decrypted session key information includes: the receiving end session key and the receiving end session validity period. The receiving end target session key is a key generated by the above-mentioned communication receiving end based on the encrypted information of the sending end. The steps for generating the above-mentioned receiving end target session key can refer to the implementation steps of the sending end target session key. The implementation steps of the two are symmetrical and the symmetric encryption function used is the same (for example, the above-mentioned communication receiving end can use the receiving end private key information to decrypt the encrypted information of the sending end to obtain the first sending end random number and the second sending end random number. Then, the receiving end master secret information is generated based on the first sending end random number, the second sending end random number, and the receiving end random number. Finally, the receiving end target session key is generated based on the receiving end master secret information). In practice, first, the above-mentioned execution entity can delete a preset number of bits in the header of the receiving end target session key. Then, a symmetric decryption function (e.g., the SymDec() symmetric decryption function) can be used to decrypt the deleted target receiving session key to obtain the decrypted receiving session key. Furthermore, because the binary strings corresponding to the session validity periods of the communication receiving and sending ends have the same number of bits and are concatenated in the same manner, the receiving session key and the receiving session validity period can be directly determined using the decrypted receiving session key.
[0080] Step 8: Determine a temporary session key based on the receiving end session key and the sending end session key. In practice, the execution master determines the result of bitwise XOR processing of the receiving end session key and the sending end session key as the temporary session key.
[0081] In step 9, the temporary session validity period is determined based on the receiving end session validity period and the sending end session validity period. In practice, the execution subject may determine the minimum value of the receiving end session validity period and the sending end session validity period as the temporary session validity period.
[0082] The above technical solution and its related contents, as an inventive point of an embodiment of the present disclosure, solve the technical problem that "when multiple communications are carried out in a public network, the use of fixed session keys poses a risk of leakage, resulting in a decrease in communication security and privacy". The factors that lead to a decrease in communication security and privacy are often as follows: only one set of fixed session keys is agreed upon with the communication partner, and during the public network communication process, there is a risk of leakage of the session keys, which leads to the risk of cracking the communication information encrypted by the session keys during the communication process. If the above factors are solved, the effect of improving the security and privacy of network communications can be achieved. In order to achieve this effect, in this application, the communication sending end and the communication receiving end exchange information through the random number pairs generated by each of them, thereby each generating a master secret information. And a single-end session key is generated based on the master secret information and the random number. Finally, the communication sending end and the communication receiving end generate a temporary session key by exchanging the session keys generated by each of them. Using the above method, a temporary session key will be generated by both parties during each communication in the public network, so that the encryption key used in each communication is different. Even when a temporary session key expires or there is a risk of leakage, attackers cannot crack the communication information encrypted by other temporary session keys, thereby improving the security and privacy of public network communication sessions.
[0083] Step 10362: In response to determining that the current communication duration is less than or equal to the validity duration of the temporary session key, encrypt the communication information according to the temporary session key.
[0084] In some embodiments, the execution entity may, in response to determining that the current communication duration is less than or equal to the validity period of the temporary session key, encrypt the communication information using the temporary session key. In practice, the execution entity may use the temporary session key as a symmetric encryption key to symmetric encrypt the communication information. For example, the symmetric encryption algorithm used may be the AES algorithm. It should be noted that the implementation steps for generating the temporary session key at the communication receiving end can refer to the steps for generating the temporary session key at the communication sending end described above, and will not be repeated here.
[0085] Step 10363, in response to determining that the current communication duration is greater than the validity period of the temporary session key, the second loop step is executed again.
[0086] In some embodiments, the execution subject may execute the second loop step again in response to determining that the current communication duration is greater than the validity duration of the temporary session key.
[0087] It should be noted that the communication process between the communication receiving end and the communication sending end is as follows: Figure 4 As shown by Figure 4 It can be seen that the relevant encryption processing steps performed by the communication receiving end and the communication sending end are symmetrical. In addition, Figure 4 There is no specific restriction on the actual communication order between the two communicating parties. For example, if the receiving end generates the receiving end's public and private key information first, the receiving end's public key information may be sent to the sending end first. For another example, if the receiving end completes the encryption of the receiving end's random number pair first, the encrypted receiving end information may be sent to the sending end first.
[0088] The various embodiments disclosed above have the following beneficial effects: The quantum-resistant secure communication methods applied to public network channels according to some embodiments of the present disclosure can reduce the storage resource overhead of both communicating parties while resisting quantum attacks, and further improve the security of communication encryption. Specifically, the increased storage overhead and reduced encryption security of both communicating parties are caused by the fact that in actual network communications, each communicating end often has multiple communication partners. Therefore, each communicating end needs to agree on and store independent shared keys with multiple communication partners, as well as record the correspondence between multiple shared keys, resulting in increased storage overhead for the communication sending end. Furthermore, there is a risk of shared keys being leaked during the process of agreeing on the shared keys between the communicating parties (for example, in person or via email), which reduces the security of communication encryption. Based on this, the quantum-resistant secure communication methods applied to public network channels according to some embodiments of the present disclosure first send user authentication information and an encryption confirmation request to the communication receiving end via the public network channel. The user authentication information includes the identity information of the sending end and a first information list. The first information in the first information list represents a description of the encryption algorithm used to encrypt the information. Therefore, when initiating network communication, the communication sending end can send user authentication information and an encryption confirmation request to the communication receiving end, allowing the communication receiving end to verify its identity and agree on the encryption algorithm to be used for subsequent communication encryption. Then, in response to receiving the target encryption information confirmed by the communication receiving end, the sending end generates the public and private key information of the sending end based on the target encryption information. The target encryption information is the first information confirmed by the communication receiving end from the first information list after receiving the encryption confirmation request. The sending end public and private key information includes the sending end public key information and the sending end private key information. Therefore, when the communication sending end receives the encryption algorithm representing the selected encryption algorithm of the communication receiving end, it can generate two pairs of public and private keys for encryption. Finally, based on the sending end public and private key information, the following first loop steps are executed: First, generate a sending end random number pair. This can add randomness to the encryption of communication information by generating random numbers, thereby improving the security of communication encryption. Second, send the sending end public key information and the receiving end public key information request to the communication receiving end via a public network channel. In the third step, in response to receiving the public key information sent by the communication receiving end, the sending end random number pair is encrypted using a public key scheme based on the receiving end public key information to obtain the sending end encrypted information. Thus, the communicating parties can exchange public keys and encrypt their respective random numbers using each other's public keys to obtain the sending end encrypted information and the receiving end encrypted information. In the fourth step, master secret information is generated based on the sending end random number pair and the sending end private key information. The generated master secret information is associated with a generation time. Thus, through the interaction of random encrypted information between the communication sending end and the communication receiving end, time-sensitive master secret information can be generated for generating the communication encryption key.In step 5, in response to determining that the current time does not meet the preset time period corresponding to the generation time, the first loop step is executed again. This allows the timeliness of the generated master key information to be determined, and a new master secret information is generated when it expires. In step 6, in response to determining that the current time meets the periodic time condition corresponding to the generation time, the following second loop step is executed based on the master secret information: First, a temporary session key and a temporary session validity period are determined based on the master secret information. Thus, using the generated master secret information, a temporary session key with high complexity, randomness, and timeliness, as well as the validity period of the communication session, can be ultimately determined. In step 2, in response to determining that the current communication duration is less than or equal to the validity period of the temporary session key, the communication information is encrypted using the temporary session key. This allows the communication information to be encrypted using the temporary session key, significantly improving the security of the communication encryption. In step 3, in response to determining that the current communication duration is greater than the validity period of the temporary session key, the second loop step is executed again. Because both communicating parties only select a random encryption algorithm when initiating network communication and exchange random encrypted information using the selected encryption algorithm, they ultimately generate a temporary session key with extremely high complexity and randomness. Even if a temporary session key expires or is at risk of being leaked, attackers cannot decrypt communications encrypted with other temporary session keys, further enhancing the security of the communication session. At the end of the communication session, neither party needs to store the expired temporary session key. Because the encryption algorithms selected by both communicating parties include post-quantum cryptographic algorithms, storage resource overhead for both parties is reduced while also improving the security of communication encryption, while also resisting quantum attacks.
[0089] Further references Figure 2 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a quantum-resistant secure communication device applied to a public network channel. These device embodiments are similar to Figure 1 Corresponding to the method embodiments shown, the quantum-resistant secure communication device applied to a public network channel can be specifically applied to various electronic devices.
[0090] like Figure 2As shown, some embodiments of the quantum-resistant secure communication device 200 applied to a public network channel include: a sending unit 201 is configured to send user authentication information and an encryption confirmation request to a communication receiving end through a public network channel, wherein the above-mentioned user authentication information includes: sender identity information and a first information list, and the first information in the above-mentioned first information list represents a description of the encryption algorithm used to encrypt information; a generating unit 202 is configured to generate sender public and private key information in response to the target encryption information confirmed by the above-mentioned communication receiving end, according to the above-mentioned target encryption information, wherein the above-mentioned target encryption information is the first information confirmed by the above-mentioned communication receiving end from the first information list after receiving the above-mentioned encryption confirmation request, and the above-mentioned sender public and private key information includes sender public key information and sender private key information; an executing unit 203 is configured to generate a sender random number pair; and send the above-mentioned sender public key to the above-mentioned communication receiving end through the above-mentioned public network channel. information and a request for the public key information of the receiving end; in response to receiving the public key information of the receiving end sent by the above-mentioned communication receiving end, encrypting the random number pair of the sending end according to the public key information of the receiving end to obtain the encrypted information of the sending end; generating master secret information according to the random number pair of the sending end and the private key information of the sending end, wherein the generated master secret information corresponds to a generation time; in response to determining that the current time does not meet the preset time period condition corresponding to the generation time, executing the above-mentioned first loop step again; in response to determining that the current time meets the period time bar corresponding to the generation time, executing the following second loop step based on the master secret information: determining the temporary session key and the temporary session validity period according to the master secret information; in response to determining that the current communication duration is less than or equal to the validity period of the temporary session key, encrypting the communication information according to the temporary session key; in response to determining that the current communication duration is greater than the validity period of the temporary session key, executing the above-mentioned second loop step again.
[0091] It is understood that the units described in the quantum secure communication device 200 for public network channels are similar to those described in the reference Figure 1 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the quantum-resistant secure communication device 200 applied to the public network channel and the units contained therein, and will not be repeated here.
[0092] Reference below Figure 3 , which shows a structural diagram of an electronic device 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0093] like Figure 3As shown, the electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory 302 or a program loaded from a storage device 308 into a random access memory 303. Various programs and data required for the operation of the electronic device 300 are also stored in the random access memory 303. The processing device 301, the read-only memory 302, and the random access memory 303 are connected to each other via a bus 304. An input / output interface 305 is also connected to the bus 304.
[0094] Typically, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or by wire to exchange data. Figure 3 The electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 3 Each block shown in the figure may represent one device, or may represent multiple devices as needed.
[0095] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 309, or installed from the storage device 308, or installed from the read-only memory 302. When the computer program is executed by the processing device 301, the above-mentioned functions defined in the method of some embodiments of the present disclosure are performed.
[0096] It should be noted that the computer-readable medium described in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0097] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (Hypertext Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0098] The above-mentioned computer-readable medium may be included in the above-mentioned electronic device; or it may exist independently without being assembled into the electronic device. The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device: sends user authentication information and an encryption confirmation request to the communication receiving end through a public network channel, wherein the above-mentioned user authentication information includes: the identity information of the sending end and a first information list, and the first information in the above-mentioned first information list represents the description of the encryption algorithm used for information encryption; in response to receiving the target encryption information confirmed by the above-mentioned communication receiving end, generates the public and private key information of the sending end according to the above-mentioned target encryption information, wherein the above-mentioned target encryption information is the first information confirmed by the above-mentioned communication receiving end from the first information list after receiving the above-mentioned encryption confirmation request, and the above-mentioned public and private key information of the sending end includes the public key information of the sending end and the private key information of the sending end; based on the above-mentioned public and private key information of the sending end, performs the following first loop steps: generates a random number pair of the sending end; sends the above-mentioned to the above-mentioned communication receiving end through the above-mentioned public network channel. The present invention provides a method for transmitting the public key information of the transmitting end and the public key information of the receiving end; in response to receiving the public key information of the receiving end sent by the above-mentioned communication receiving end, encrypting the sending end random number pair according to the public key information of the receiving end to obtain the encrypted information of the transmitting end; generating the master secret information according to the sending end random number pair and the above-mentioned sending end private key information, wherein the above-mentioned master secret information corresponds to the generation time; in response to determining that the current time does not meet the preset time period condition corresponding to the generation time, executing the above-mentioned first loop step again; in response to determining that the current time meets the period time bar corresponding to the generation time, executing the following second loop step based on the master secret information: determining the temporary session key and the temporary session validity period according to the master secret information; in response to determining that the current communication duration is less than or equal to the validity period of the temporary session key, encrypting the communication information according to the temporary session key; in response to determining that the current communication duration is greater than the validity period of the temporary session key, executing the above-mentioned second loop step again.
[0099] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0100] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0101] The units described in some embodiments of the present disclosure may be implemented in software or hardware. The units described may also be provided in a processor. For example, they may be described as: a processor including a sending unit, a generating unit, and an executing unit. The names of these units do not, in some cases, constitute limitations on the units themselves. For example, the sending unit may also be described as "a unit that sends user authentication information and an encryption confirmation request to a communication receiving end through a public network channel."
[0102] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0103] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A quantum-resistant secure communication method applied to a public network channel, comprising: Sending user authentication information and an encryption confirmation request to a communication receiving end through a public network channel, wherein the user authentication information includes: identity information of the sending end and a first information list, wherein the first information in the first information list represents a description of an encryption algorithm used for information encryption; In response to receiving the target encryption information confirmed by the communication receiving end, generating the sending end public and private key information according to the target encryption information, wherein the target encryption information is the first information confirmed by the communication receiving end from the first information list after receiving the encryption confirmation request, and the sending end public and private key information includes the sending end public key information and the sending end private key information; Based on the public and private key information of the sender, the following first loop steps are performed: Generate a pair of random numbers for the sender; Sending the sending end public key information and the receiving end public key information request to the communication receiving end through a public network channel; In response to receiving the receiving end public key information sent by the communication receiving end, encrypting the sending end random number pair according to the receiving end public key information to obtain the sending end encrypted information; Generate master secret information according to the sending end random number pair and the sending end private key information, wherein the generated master secret information corresponds to a generation time; In response to determining that the current time does not satisfy the preset time period condition corresponding to the generated time, executing the first loop step again; In response to determining that the current time satisfies the periodic time condition corresponding to the generation time, the following second loop steps are performed based on the master secret information: Determine the temporary session key and the validity period of the temporary session based on the master secret information; In response to determining that the current communication duration is less than or equal to the validity duration of the temporary session key, encrypting the communication information according to the temporary session key; In response to determining that the current communication duration is greater than the validity duration of the temporary session key, the second loop step is performed again.
2. The method according to claim 1, wherein The target encryption information includes: first encryption information and second encryption information, the sender public key information includes: first sender public key and second sender public key, and the sender private key information includes: first sender private key and second sender private key; and generating the sender public-private key information and the sender random number pair based on the target encryption information includes: Generate first sending end public key information and first sending end private key information according to the first encrypted information; Generate second sending end public key information and second sending end private key information according to the second encrypted information; Determine the first sender public key information and the second sender public key information as the sender public key information included in the sender public-private key information; The first sender private key information and the second sender private key information are determined as the sender private key information included in the sender public and private key information.
3. The method according to claim 1, wherein Generating a sending end random number pair includes: Generate two random numbers as a first sending end random number and a second sending end random number, respectively, wherein the first sending end random number and the second sending end random number are independent of each other; The first sending end random number and the second sending end random number are determined as a sending end random number pair.
4. The method according to claim 3, wherein: The receiving end public key information is generated by the communication receiving end based on the target encryption information by performing the following steps: Generate first receiving end public key information according to the first encryption information included in the target encryption information; Generate second receiving end public key information according to the second encryption information included in the target encryption information; The first receiving end public key information and the second receiving end public key information are determined as the receiving end public key information.
5. The method according to claim 4, wherein The step of encrypting the random number pair of the sending end according to the public key information of the receiving end to obtain encrypted information of the sending end includes: Encrypting the first sending end random number using a public key scheme according to the first receiving end public key information to obtain first sending end encrypted information; Encrypting the second sending end random number using a public key scheme according to the second receiving end public key information to obtain the second sending end encrypted information; The first sending end encrypted information and the second sending end encrypted information are determined as the sending end encrypted information.
6. A quantum-resistant secure communication device for a public network channel, comprising: a sending unit configured to send user authentication information and an encryption confirmation request to a communication receiving end through a public network channel, wherein the user authentication information includes: identity information of the sending end and a first information list, wherein the first information in the first information list represents a description of an encryption algorithm used for information encryption; a generating unit configured to, in response to receiving target encryption information confirmed by the communication receiving end, generate sending end public and private key information based on the target encryption information, wherein the target encryption information is first information confirmed by the communication receiving end from the first information list after receiving the encryption confirmation request, and the sending end public and private key information includes sending end public key information and sending end private key information; The execution unit is configured to, based on the sender public-private key information, execute the following first loop step: generate a sender random number pair; send the sender public key information and a receiver public key information request to the communication receiving end through the public network channel; in response to receiving the receiver public key information sent by the communication receiving end, encrypt the sender random number pair using a public key scheme according to the receiver public key information to obtain sender encrypted information; generate master secret information according to the sender random number pair and the sender private key information, wherein the generated master secret information corresponds to a generation time; in response to determining that the current time does not meet a preset time period condition corresponding to the generation time, execute the first loop step again; in response to determining that the current time meets a period time condition corresponding to the generation time, execute the following second loop step based on the master secret information: determine a temporary session key and a temporary session validity period according to the master secret information; in response to determining that the current communication duration is less than or equal to the validity period of the temporary session key, encrypt the communication information according to the temporary session key; in response to determining that the current communication duration is greater than the validity period of the temporary session key, execute the second loop step again.
7. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.
8. A computer-readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Secure communication method of session data, post-quantum secure channel device and system
CN117812581A
Cryptographic device, system and method therof
US20230155825A1