A session key distribution method and system
By hybridizing the QKD system and the PQC algorithm, the shared key is divided into two parts and sent by two servers for hash verification, which solves the security issues of traditional public key cryptography algorithms under quantum computers and achieves higher communication security.
Patent Information
- Application Number
- CN202411559524.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-04
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2044-11-04
AI Technical Summary
The security of traditional public key cryptography algorithms is threatened when facing quantum computers, and how to improve the ability of secure communication becomes a difficult problem.
A hybrid QKD system is used to establish a shared key through quantum devices and encrypt it using the PQC algorithm. The shared key is divided into two parts and sent separately through two servers for hash verification and splicing to ensure secure communication.
It improves the security of shared key distribution, resists quantum computer attacks, and enhances the security of communications.
Smart Images

Figure CN119420552B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encrypted communications, and in particular to a session key distribution method and system. Background Art
[0002] In today's business environment, secure communication between enterprises is crucial. Traditional public key cryptography algorithms, such as RSA, elliptic curve cryptography, and Elliptic Curve Diffie-Hellman (ECDH), have been used for decades as shared secret key exchange schemes. Traditional public key schemes are also used to digitally sign messages and certificates (for example, to authenticate clients and servers).
[0003] However, the advent of quantum computers has necessitated a rethink of traditional public-key cryptography. Quantum computers undermine RSA and elliptic curve-based cryptography. Further improving secure communications has become a challenge for those skilled in the art. Summary of the Invention
[0004] The purpose of the present invention is to provide a session key distribution method and system to improve the above-mentioned problem.
[0005] In order to achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:
[0006] In a first aspect, an embodiment of the present invention provides a session key distribution method, which is applied to a key distribution system, wherein the key distribution system includes a first user terminal, a second user terminal, a first server, and a second server. The session key distribution method includes:
[0007] After obtaining the shared key, the first user terminal sends a first session establishment request to the second user terminal, where the shared key is a key for secure communication between the first user terminal and the second user terminal, and the first session establishment request includes an ID of the shared key and verification information, where the verification information includes a hash value of the first half of the shared key and a hash value of the second half of the shared key;
[0008] After receiving the first session establishment request, the second user terminal sends a third key distribution request to the first server and the second server, wherein the third key distribution request includes the ID of the shared key;
[0009] The second user terminal performs verification based on a third response message fed back by the first server, a fourth response message fed back by the second server, and the verification information transmitted by the first user terminal, wherein the third response message includes a hash value of a first half of the shared key and a second half of the shared key, and the fourth response message includes a hash value of the second half of the shared key and a first half of the shared key;
[0010] If the verification is passed, the second user end concatenates the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain the shared key, so that the first user end and the second user end use the shared key to communicate securely.
[0011] In a second aspect, an embodiment of the present invention provides a key distribution system, the key distribution system including a first user terminal, a second user terminal, a first server, and a second server, and the session key distribution method including:
[0012] The first user terminal is configured to send a first session establishment request to the second user terminal after obtaining the shared key, wherein the shared key is a key for secure communication between the first user terminal and the second user terminal, and the first session establishment request includes an ID of the shared key and verification information, wherein the verification information includes a hash value of a first half of the shared key and a hash value of a second half of the shared key;
[0013] The second user terminal is configured to send a third key distribution request to the first server and the second server after receiving the first session establishment request, wherein the third key distribution request includes the ID of the shared key;
[0014] The second user terminal is configured to perform verification based on a third response message fed back by the first server, a fourth response message fed back by the second server, and the verification information transmitted by the first user terminal, wherein the third response message includes a hash value of a first half of the shared key and a second half of the shared key, and the fourth response message includes a hash value of the second half of the shared key and a first half of the shared key;
[0015] The second user terminal is used to splice the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain the shared key when the verification passes, so that the first user terminal and the second user terminal use the shared key to communicate securely.
[0016] Optionally, the first user terminal is used to send a first key distribution request to the first server;
[0017] The first server is configured to feed back a first response message to the first user terminal after receiving the first key distribution request, wherein the first response message includes the first half of the shared key, the hash value of the second half of the shared key, and the ID of the shared key;
[0018] The first user terminal is configured to send a second key distribution request to the second server after receiving the first response message fed back by the first server, wherein the second key distribution request includes the ID of the shared key;
[0019] The second server is configured to feed back a second response message to the first user terminal after receiving the second key distribution request, wherein the second response message includes a hash value of the second half of the shared key and the first half of the shared key;
[0020] The first user terminal is used to perform hash verification based on the first response message and the second response message after receiving the second response message fed back by the second server. After the verification passes, the first user terminal splices the first half of the shared key and the second half of the shared key to obtain the shared key.
[0021] Compared to existing technologies, the present invention provides a session key distribution method and system. After obtaining a shared key, a first user terminal sends a first session establishment request to a second user terminal. After receiving the first session establishment request, the second user terminal sends a third key distribution request to the first server and the second server. The second user terminal verifies the key based on the third response message fed back by the first server, the fourth response message fed back by the second server, and the verification information transmitted by the first user terminal. If the verification is successful, the second user terminal concatenates the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain a shared key, allowing the first and second users to communicate securely using the shared key. By having each server send a portion of the shared key, the security of shared key distribution is improved.
[0022] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0024] Figure 1 A schematic diagram of the architecture of a key distribution system provided by an embodiment of the present invention.
[0025] Figure 2 A flowchart of a session key distribution method provided by an embodiment of the present invention.
[0026] Figure 3 This is an interactive diagram of the session key distribution method provided by an embodiment of the present invention.
[0027] Figure 4 A schematic diagram of the target agreement key distribution process provided by an embodiment of the present invention.
[0028] In the figure: 10 - first user terminal; 20 - first server; 30 - second server; 40 - second user terminal. DETAILED DESCRIPTION
[0029] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.
[0030] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.
[0031] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0032] The following embodiments of the present invention are described in detail with reference to the accompanying drawings. In the absence of conflict, the following embodiments and features in the embodiments may be combined with each other.
[0033] With the growing demand for quantum-safe cryptography, several technologies are being developed to protect sensitive information from attacks by quantum computers. The first is post-quantum cryptography (PQC), which provides quantum-resistant public-key algorithms (suitable for classical computers) for key exchange and digital signatures. The second is quantum key distribution (QKD), which provides a secure method for distributing cryptographic keys over quantum communication channels, typically implemented as optical links. The laws of quantum mechanics ensure that we can detect if the key has been eavesdropped or tampered with.
[0034] But the large-scale use of both PQC and QKD faces challenges: the theoretical security of QKD is hindered by the cost and complexity of the required hardware; while the theoretical security of PQC is promising, its practical implementation can be fragile.
[0035] To this end, embodiments of the present invention propose a key distribution system based on hybrid QKD, a secure communication system that can use PQC and smart cards for key distribution. A point-to-point QKD link between quantum devices is used to establish a shared key, and then the PQC algorithm is used to encrypt and decrypt data.
[0036] Please refer to Figure 1 , Figure 1 A schematic diagram of the architecture of a key distribution system provided in an embodiment of the present invention. The key distribution system includes a first client 10, a second client 40, a first server 20, and a second server 30. The first client 10, the second client 40, the first server 20, and the second server 30 can communicate with each other via a wired network, a wireless network, and a quantum network.
[0037] Optionally, information can be transmitted between the client and the server via a TLS communication link.
[0038] The embodiment of the present invention provides a session key distribution method, which is applied to Figure 1 The key distribution system shown in Figure 2 , Figure 2 Schematic diagram of the process of distributing session keys provided by the embodiment of the present invention. Figure 2 As shown, after the first user terminal obtains the shared key, the session key distribution method includes: S15, S40, S42 and S43, which are described in detail as follows.
[0039] S15: After obtaining the shared key, the first user terminal sends a first session establishment request to the second user terminal.
[0040] The shared key is a key for secure communication between the first user terminal and the second user terminal. The first session establishment request includes the ID of the shared key and verification information. The verification information includes the hash value of the first half of the shared key and the hash value of the second half of the shared key.
[0041] S40: After receiving the first session establishment request, the second client sends a third key distribution request to the first server and the second server.
[0042] The third key distribution request includes the ID of the shared key.
[0043] S42: The second user terminal performs verification based on the third response message fed back by the first server, the fourth response message fed back by the second server, and the verification information transmitted by the first user terminal.
[0044] The third response message includes the hash value of the first half of the shared key and the second half of the shared key, and the fourth response message includes the hash value of the second half of the shared key and the first half of the shared key.
[0045] The way in which the second user terminal performs verification includes: by comparing the hash value of the second half of the shared key in the third response message and the hash value of the first half of the shared key in the fourth response message with the verification information transmitted by the first user terminal. If the result of the first comparison does not match, it means that the verification has failed. If the result of the first comparison matches, the second user terminal performs a hash operation on the first half of the shared key in the third response message, and compares the operation result with the hash value of the first half of the shared key in the fourth response message for a second time. If the result of the second comparison does not match, it means that the verification has failed. If the result of the second comparison matches, the second user terminal performs a hash operation on the second half of the shared key in the fourth response message, and compares the operation result with the hash value of the second half of the shared key in the third response message for three times. If the results of the three comparisons do not match, it means that the verification has failed. If the results of the three comparisons match, it means that the verification has passed.
[0046] S43: If the verification is successful, the second user terminal concatenates the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain a shared key.
[0047] This enables the first user end and the second user end to communicate securely using the shared key.
[0048] From a QKD perspective, the classical link between the end user and the KDC is the weakest part of the key distribution process. Splitting the shared key into two parts and sending them over two different classical channels means that a man-in-the-middle attack would require compromising two independent TLS communication links.
[0049] The session key distribution method provided by the embodiment of the present invention improves the security of the shared key distribution by having two servers respectively send a part of the shared key.
[0050] Please refer to Figure 3 , Figure 3 Schematic diagram of interaction of the session key distribution method provided by an embodiment of the present invention. After the second user terminal sends a third key distribution request to the first server and the second server, the session key distribution method may further include: S21 and S31, which are described in detail as follows.
[0051] S21: After receiving the third key distribution request, the first server feeds back a third response message to the second user terminal.
[0052] S31: After receiving the third key distribution request, the second server feeds back a fourth response message to the second user terminal.
[0053] It should be noted that the third key distribution request received by the first server and the second server includes the ID of the shared key. The first server and the second server can query in the QKD system according to the ID of the shared key to obtain the content of the shared key, and then generate a third response message and a fourth response message.
[0054] On the basis of the above, regarding how the first user terminal obtains the shared key, the embodiment of the present invention also provides an optional implementation method, please refer to Figure 3 The session key distribution method further includes: S10, S20, S12, S30 and S14, which are described in detail as follows.
[0055] S10: The first client sends a first key distribution request to the first server.
[0056] S20: After receiving the first key distribution request, the first server feeds back a first response message to the first user terminal.
[0057] The first response message includes the first half of the shared key, the hash value of the second half of the shared key, and the ID of the shared key.
[0058] S12: After receiving the first response message fed back by the first server, the first user terminal sends a second key distribution request to the second server.
[0059] The second key distribution request includes the ID of the shared key.
[0060] S30: After receiving the second key distribution request, the second server feeds back a second response message to the first user terminal.
[0061] The second response message includes the second half of the shared key and a hash value of the first half of the shared key.
[0062] S14, after receiving the second response message fed back by the second server, the first user terminal performs hash verification based on the first response message and the second response message. After the verification passes, the first half of the shared key and the second half of the shared key are spliced to obtain the shared key.
[0063] In an optional implementation, the first key distribution request includes a temporary public key of the first user terminal, and the first response message is encrypted using the temporary public key of the first user terminal.
[0064] After the first user terminal receives the first response message fed back by the first server, the session key distribution method further includes: S11, which is specifically as follows.
[0065] S11, the first user terminal uses the temporary private key of the first user terminal to decrypt the first response message to obtain the first half of the shared key, the hash value of the second half of the shared key, and the ID of the shared key.
[0066] In an optional implementation, the second key distribution request further includes a temporary public key of the first user terminal, and the second response message is encrypted using the temporary public key of the first user terminal.
[0067] After the first user terminal receives the second response message, the session key distribution method further includes: S13, which is specifically as follows.
[0068] S13, the first user terminal uses the temporary private key of the first user terminal to decrypt the second response message to obtain the second half of the shared key and the hash value of the first half of the shared key.
[0069] Based on the foregoing, regarding the content in S14, an embodiment of the present invention also provides an optional implementation method. After the first user terminal receives the second response message fed back by the second server, the step of performing hash verification based on the first response message and the second response message includes: performing hash verification based on the decryption result of the first response message and the decryption result of the second response message.
[0070] Among them, the decryption result of the first response message includes the first half of the shared key, the hash value of the second half of the shared key and the ID of the shared key, and the decryption result of the second response message includes the hash value of the second half of the shared key and the first half of the shared key.
[0071] The verification process of the first user end is as follows: the first user end performs a hash operation on the first half of the shared key in the first response message, and compares the result of the operation with the hash value of the first half of the shared key in the second response message. If the result of the first comparison does not match, the verification has failed. If the result of the first comparison does match, the first user end performs a hash operation on the second half of the shared key in the second response message, and compares the result of the operation with the hash value of the second half of the shared key in the first response message a second time. If the result of the second comparison does not match, the verification has failed. If the result of the second comparison does match, the verification has passed.
[0072] In an optional implementation, the third key distribution request further includes a temporary public key of the second user terminal, and the third response message and the fourth response message are encrypted using the temporary public key of the second user terminal.
[0073] After the second user terminal receives the third response message fed back by the first server and the fourth response message fed back by the second server, the session key distribution method further includes: S41, which is specifically as follows.
[0074] S41: After receiving the third response message and the fourth response message, the second user terminal uses the temporary private key of the second user terminal to decrypt the messages to obtain a decryption result of the third response message and a decryption result of the fourth response message. The decryption result of the third response message includes a hash value of the first half of the shared key and the second half of the shared key, and the decryption result of the fourth response message includes a hash value of the second half of the shared key and the first half of the shared key.
[0075] Regarding the verification process in S42, the embodiment of the present invention also provides an optional implementation method, please refer to the following. The step of the second user terminal performing verification based on the third response message fed back by the first server, the fourth response message fed back by the second server, and the verification information transmitted by the first user terminal includes: the second user terminal performs verification based on the decryption result of the third response message obtained by decryption, the decryption result of the fourth response message, and the verification information transmitted by the first user terminal.
[0076] In order to further ensure communication security, the embodiment of the present invention also provides an optional implementation method, please continue to refer to Figure 3 After the second user terminal obtains the shared key, the session key distribution method further includes: S44 and S16, which are described in detail as follows.
[0077] S44: The second user terminal sends the complete hash value corresponding to the shared key to the first user terminal.
[0078] S16, the first user terminal verifies the complete hash value transmitted by the second user terminal, and if the verification passes, uses the shared key to communicate securely with the second user terminal.
[0079] Optionally, the first user terminal performs a hash operation on the shared key stored therein, and compares the obtained hash value with the complete hash value transmitted by the second user terminal to determine whether the verification passes.
[0080] In an optional embodiment, the target key distribution request sent by the target user terminal to the target server needs to be encrypted by the target agreement key, wherein the target user terminal is the first user terminal or the second user terminal, the target server is the first server or the second server, and the target key distribution request is the first key distribution request sent by the first user terminal to the first server, or the second key distribution request sent by the first user terminal to the second server, or the third key distribution request sent by the second user terminal to the first server, or the third key distribution request sent by the second user terminal to the second server.
[0081] After receiving the target key distribution request, the target server needs to decrypt the target key distribution request according to the target agreement key to obtain the content.
[0082] On this basis, regarding how to distribute the target agreement key between the target user terminal and the target server, the embodiment of the present invention also provides an optional implementation method, please refer to Figure 4 , Figure 4 The target agreement key distribution process diagram provided by the embodiment of the present invention is as follows: The session key distribution method further includes: S51 to S56, which are described in detail as follows.
[0083] S51: The target user terminal sends the first public key and the second public key to the target server.
[0084] The first public key belongs to a first public-private key pair, and the second public key belongs to a second public-private key pair.
[0085] Optionally, the first public-private key pair is a public-private key pair generated based on an ECC algorithm, and the second public-private key pair is a public-private key pair generated based on a PQC algorithm.
[0086] S52: After obtaining the first public key and the second public key, the target server generates a first temporary shared key, first index information, a second temporary shared key, and second index information.
[0087] The first index information is index information corresponding to the first temporary shared key and the first public key, and the second index information is index information corresponding to the second temporary shared key and the second public key.
[0088] S53: The target server sends the first index information and the second index information to the target client.
[0089] S54, the target user end solves the first index information according to the first private key in the first public-private key pair to obtain a first temporary shared key; and solves the second index information according to the second private key in the second public-private key pair to obtain a second temporary shared key.
[0090] S55 , the target user terminal performs an XOR operation on the first temporary shared key and the second temporary shared key to obtain a target agreed key.
[0091] S56: The target server performs an XOR operation on the first temporary shared key and the second temporary shared key to obtain a target agreed key.
[0092] In an optional implementation, before the target server and the target client agree on the target agreement key, the session key distribution method further includes: the target server and the target client perform signature authentication.
[0093] The target server and target client both store their own first-class signature certificate (e.g., PQC signature certificate), second-class signature certificate (e.g., ECC signature certificate, which may be long-term valid), first-class signature private key (e.g., PQC signature private key), and second-class signature private key (e.g., ECC signature private key). The first-class signature certificate includes the first-class signature public key (e.g., PQC signature public key), and the second-class signature certificate includes the second-class signature public key (e.g., ECC signature public key).
[0094] The first type of signature certificate and the first type of signature private key are stored on the smart card, which acts as a tamper-proof device. The second type of signature certificate and the second type of signature private key are stored in the smart card's read-only memory (JavaCard technology ensures that classic ECC keys cannot be extracted from the card).
[0095] The process of signature authentication between the target server and the target client is as follows:
[0096] The target user terminal sends a signature authentication request to the target server, where the signature authentication request includes the target content.
[0097] The target server signs the target content according to the first-class signature private key and the second-class signature private key of the target server respectively, and sends the obtained first server signature result (corresponding to the first-class signature private key), the second server signature result (corresponding to the second-class signature private key), the first-class signature certificate of the target server and the second-class signature certificate of the target server to the target user end.
[0098] The target user end performs decryption verification based on the feedback from the target server, and if the decryption verification is successful, it signs the target content according to the first-class signature private key and the second-class signature private key of the target user end respectively, and sends the obtained first-class signature result (corresponding to the first-class signature private key), the second-class signature result (corresponding to the second-class signature private key), the first-class signature certificate of the target user end, and the second-class signature certificate of the target user end to the target server.
[0099] The target server performs decryption verification based on the feedback from the target user, and if the decryption verification succeeds, the target server and the target user agree on the target agreement key.
[0100] The embodiment of the present invention further provides a key distribution system, which can execute the method flow shown in the above method flow embodiment to achieve the corresponding technical effect. For the sake of brevity, for parts not mentioned in this embodiment, please refer to the corresponding content in the above embodiment.
[0101] The first client is used to send a first key distribution request to the first server;
[0102] The first server is configured to feed back a first response message to the first user terminal after receiving the first key distribution request, wherein the first response message includes the first half of the shared key, the hash value of the second half of the shared key, and the ID of the shared key;
[0103] The first user terminal is configured to send a second key distribution request to the second server after receiving the first response message fed back by the first server, wherein the second key distribution request includes the ID of the shared key;
[0104] The second server is configured to feed back a second response message to the first user terminal after receiving the second key distribution request, wherein the second response message includes a hash value of the second half of the shared key and the first half of the shared key;
[0105] After receiving the second response message fed back by the second server, the first user terminal performs hash verification based on the first response message and the second response message. After the verification passes, the first half of the shared key and the second half of the shared key are spliced to obtain the shared key.
[0106] The first user terminal is configured to send a first session establishment request to the second user terminal after obtaining the shared key, wherein the shared key is a key for secure communication between the first user terminal and the second user terminal, and the first session establishment request includes an ID of the shared key and verification information, wherein the verification information includes a hash value of the first half of the shared key and a hash value of the second half of the shared key;
[0107] The second user terminal is configured to send a third key distribution request to the first server and the second server after receiving the first session establishment request, wherein the third key distribution request includes the ID of the shared key;
[0108] The second user terminal is used to perform verification based on the third response message fed back by the first server, the fourth response message fed back by the second server, and the verification information transmitted by the first user terminal, wherein the third response message includes a hash value of the first half of the shared key and the second half of the shared key, and the fourth response message includes a hash value of the second half of the shared key and the first half of the shared key;
[0109] The second user end is used to splice the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain the shared key when the verification passes, so that the first user end and the second user end use the shared key to communicate securely.
[0110] In summary, embodiments of the present invention provide a session key distribution method and system. After obtaining a shared key, a first user terminal sends a first session establishment request to a second user terminal. After receiving the first session establishment request, the second user terminal sends a third key distribution request to the first server and the second server. The second user terminal performs verification based on a third response message fed back by the first server, a fourth response message fed back by the second server, and verification information transmitted by the first user terminal. If the verification passes, the second user terminal concatenates the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain a shared key, enabling the first and second user terminals to communicate securely using the shared key. By having two servers separately send a portion of the shared key, the security of shared key distribution is enhanced.
[0111] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
[0112] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be included therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.
Claims
1. A session key distribution method, characterized in that: Applied to a key distribution system, the key distribution system includes a first user terminal, a second user terminal, a first server, and a second server, and the session key distribution method includes: After obtaining the shared key, the first user terminal sends a first session establishment request to the second user terminal, where the shared key is a key for secure communication between the first user terminal and the second user terminal, and the first session establishment request includes an ID of the shared key and verification information, where the verification information includes a hash value of the first half of the shared key and a hash value of the second half of the shared key; After receiving the first session establishment request, the second user terminal sends a third key distribution request to the first server and the second server, wherein the third key distribution request includes the ID of the shared key; The second user terminal performs verification based on a third response message fed back by the first server, a fourth response message fed back by the second server, and the verification information transmitted by the first user terminal, wherein the third response message includes a hash value of a first half of the shared key and a second half of the shared key, and the fourth response message includes a hash value of the second half of the shared key and a first half of the shared key; If the verification is passed, the second user end concatenates the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain the shared key, so that the first user end and the second user end use the shared key to communicate securely.
2. The session key distribution method according to claim 1, wherein: The method further comprises: The first client sends a first key distribution request to the first server; After receiving the first key distribution request, the first server feeds back a first response message to the first user terminal, wherein the first response message includes the first half of the shared key, the hash value of the second half of the shared key, and the ID of the shared key; After receiving the first response message fed back by the first server, the first user terminal sends a second key distribution request to the second server, wherein the second key distribution request includes the ID of the shared key; After receiving the second key distribution request, the second server feeds back a second response message to the first user terminal, wherein the second response message includes a hash value of the second half of the shared key and the first half of the shared key; After receiving the second response message fed back by the second server, the first user terminal performs a hash verification based on the first response message and the second response message. After the verification passes, the first half of the shared key and the second half of the shared key are spliced to obtain the shared key.
3. The session key distribution method according to claim 2, wherein: The first key distribution request includes the temporary public key of the first user terminal, and the first response message is encrypted using the temporary public key of the first user terminal; After the first user terminal receives the first response message fed back by the first server, the method further includes: The first user terminal decrypts the first response message using the temporary private key of the first user terminal to obtain the first half of the shared key, the hash value of the second half of the shared key, and the ID of the shared key; The second key distribution request also includes the temporary public key of the first user terminal, and the second response message is encrypted using the temporary public key of the first user terminal; After the first user terminal receives the second response message, the method further includes: The first user terminal decrypts the second response message using the temporary private key of the first user terminal to obtain a hash value of the second half of the shared key and the first half of the shared key; After the first user terminal receives the second response message fed back by the second server, the step of performing hash verification based on the first response message and the second response message includes: performing hash verification based on the decryption result of the first response message and the decryption result of the second response message.
4. The session key distribution method according to claim 1, wherein: The third key distribution request also includes the temporary public key of the second user terminal, and the third response message and the fourth response message are encrypted using the temporary public key of the second user terminal; After the second user terminal receives the third response message fed back by the first server and the fourth response message fed back by the second server, the method further includes: After receiving the third response message and the fourth response message, the second user terminal uses the temporary private key of the second user terminal to decrypt them to obtain a decryption result of the third response message and a decryption result of the fourth response message, wherein the decryption result of the third response message includes a hash value of the first half of the shared key and the second half of the shared key, and the decryption result of the fourth response message includes a hash value of the second half of the shared key and the first half of the shared key; The step of the second user terminal performing verification based on the third response message fed back by the first server, the fourth response message fed back by the second server, and the verification information transmitted by the first user terminal includes: the second user terminal performs verification based on the decryption result of the third response message obtained by decryption, the decryption result of the fourth response message, and the verification information transmitted by the first user terminal.
5. The session key distribution method according to claim 1, wherein: After the second user terminal obtains the shared key, the method further includes: The second user terminal sends the complete hash value corresponding to the shared key to the first user terminal; The first user terminal performs verification based on the complete hash value transmitted by the second user terminal, and if the verification passes, uses the shared key to communicate securely with the second user terminal.
6. The session key distribution method according to claim 2, wherein: A target key distribution request sent by a target client to a target server needs to be encrypted using a target agreement key, wherein the target client is a first client or a second client, the target server is the first server or the second server, and the target key distribution request is a first key distribution request sent by the first client to the first server, or a second key distribution request sent by the first client to the second server, or a third key distribution request sent by the second client to the first server, or a third key distribution request sent by the second client to the second server; After receiving the target key distribution request, the target server needs to decrypt the target key distribution request according to the target agreement key to obtain the content therein.
7. The session key distribution method according to claim 6, wherein: The method further comprises: The target client sends a first public key and a second public key to the target server, wherein the first public key belongs to a first public-private key pair, and the second public key belongs to a second public-private key pair; After obtaining the first public key and the second public key, the target server generates a first temporary shared key, first index information, a second temporary shared key, and second index information, wherein the first index information is index information corresponding to the first temporary shared key and the first public key, and the second index information is index information corresponding to the second temporary shared key and the second public key; The target server sends the first index information and the second index information to the target user terminal; The target user terminal solves the first index information according to the first private key in the first public-private key pair to obtain the first temporary shared key; and solves the second index information according to the second private key in the second public-private key pair to obtain the second temporary shared key; The target user terminal performs an XOR operation on the first temporary shared key and the second temporary shared key to obtain the target agreed key; The target server performs an exclusive OR operation on the first temporary shared key and the second temporary shared key to obtain the target agreed key.
8. The session key distribution method according to claim 7, wherein: Before the target server and the target client agree on the target agreement key, the method further includes: The target server performs signature authentication with the target client.
9. A key distribution system, characterized in that: The key distribution system includes a first user terminal, a second user terminal, a first server and a second server; The first user terminal is configured to send a first session establishment request to the second user terminal after obtaining the shared key, wherein the shared key is a key for secure communication between the first user terminal and the second user terminal, and the first session establishment request includes an ID of the shared key and verification information, wherein the verification information includes a hash value of a first half of the shared key and a hash value of a second half of the shared key; The second user terminal is configured to send a third key distribution request to the first server and the second server after receiving the first session establishment request, wherein the third key distribution request includes the ID of the shared key; The second user terminal is configured to perform verification based on a third response message fed back by the first server, a fourth response message fed back by the second server, and the verification information transmitted by the first user terminal, wherein the third response message includes a hash value of a first half of the shared key and a second half of the shared key, and the fourth response message includes a hash value of the second half of the shared key and a first half of the shared key; The second user terminal is used to splice the first half of the shared key in the third response message and the second half of the shared key in the fourth response message to obtain the shared key when the verification passes, so that the first user terminal and the second user terminal use the shared key to communicate securely.
10. The key distribution system according to claim 9, wherein: The first client is used to send a first key distribution request to the first server; The first server is configured to feed back a first response message to the first user terminal after receiving the first key distribution request, wherein the first response message includes the first half of the shared key, the hash value of the second half of the shared key, and the ID of the shared key; The first user terminal is configured to send a second key distribution request to the second server after receiving the first response message fed back by the first server, wherein the second key distribution request includes the ID of the shared key; The second server is configured to feed back a second response message to the first user terminal after receiving the second key distribution request, wherein the second response message includes a hash value of the second half of the shared key and the first half of the shared key; The first user terminal is used to perform hash verification based on the first response message and the second response message after receiving the second response message fed back by the second server. After the verification passes, the first user terminal splices the first half of the shared key and the second half of the shared key to obtain the shared key.
Citation Information
Patent Citations
Secret key negotiation method and system
CN110896348A
Information verification method and related equipment
CN118174967A