A key exchange method, apparatus, device, and storage medium

By introducing a post-quantum public-key cryptography algorithm and a secure association payload into the national cryptographic protocol ISAKMP, the security vulnerabilities of existing public-key cryptography algorithms in a quantum computing environment are resolved, achieving quantum security and authentication of key exchange and ensuring the reliability of key exchange.

CN119496614BActive Publication Date: 2025-12-19CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411751905.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-02
Publication Date
2025-12-19
Estimated Expiration
2044-12-02

AI Technical Summary

Technical Problem

Current public-key cryptography algorithms have security vulnerabilities in quantum computing environments. The national standard ISAKMP protocol lacks quantum security and identity authentication functions during key exchange, while the international IKEv2 protocol has a complex processing flow and does not have post-quantum identity authentication functions.

Method used

A post-quantum public-key cryptographic algorithm is introduced into the national cryptographic ISAKMP protocol framework to construct a secure association payload and perform key exchange. Authentication is performed through a post-quantum key encapsulation algorithm to ensure the reliability of key exchange.

Benefits of technology

It achieves both the security of existing public-key cryptography and quantum security, ensuring the reliability of the key exchange process and authentication, and solving the security and authentication problems of existing protocols.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119496614B_ABST
    Figure CN119496614B_ABST
Patent Text Reader

Abstract

The application discloses a key exchange method and device, equipment and storage medium, and relates to the technical field of information security, and comprises the following steps: constructing a notification message and sending the notification message to a message responder, so that the message responder returns a response message according to the notification message; constructing a first post-quantum key exchange notification and sending the first post-quantum key exchange notification to the message responder, so that the message responder constructs a first key exchange response and sends the first key exchange response to the message initiator; generating a first post-quantum signature result, and constructing a second post-quantum key exchange notification and sending the second post-quantum key exchange notification to the message responder, so that the message responder receives the second post-quantum key exchange notification, generates a second post-quantum key ciphertext, and constructs a second key exchange response and sends the second key exchange response to the message initiator; and performing identity authentication between the message initiator and the message responder. The application realizes quantum security of key exchange by constructing a post-quantum key exchange notification by using a post-quantum public key algorithm, and realizes key exchange and identity authentication between the message initiator and the message responder.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and in particular to a key exchange method, device, equipment and storage medium. BACKGROUND

[0002] With the development of quantum computing technology, the security of active public key cryptography algorithms has been seriously challenged, especially the algorithms based on large integer factorization and discrete logarithm problem. In order to solve this potential problem, cryptographers have developed a batch of algorithms that can resist quantum computing attacks, called post-quantum public key cryptography algorithms. However, because of the short application time, these algorithms are not mature, so the mixed use of active public key cryptography algorithms and post-quantum public key cryptography algorithms is the mainstream use at present, such as in cryptographic protocols.

[0003] At present, the national ISAKMP (Internet Security Association and Key Management Protocol) protocol based on the national algorithm uses the SM2 algorithm for key exchange and identity authentication in the key exchange process, while the SM2 algorithm has serious security risks in the quantum computing environment. At the same time, the international IKEv2 protocol is used for post-quantum public key cryptography fusion design, and the protocol processing flow is complex, and only the key exchange function is considered, and the identity authentication function is not considered. SUMMARY

[0004] Therefore, the purpose of the present application is to provide a key exchange method, device, equipment and storage medium, which can retain the active public key cryptography algorithm and function, and place the post-quantum public key cryptography algorithm into the national ISAKMP protocol framework, so as to realize the quantum security while maintaining the security of the active public key cryptography algorithm. At the same time, in the post-quantum public key cryptography fusion design, identity verification is performed after key exchange, ensuring the reliability of the key exchange process. The specific scheme is as follows:

[0005] In a first aspect, the present application provides a key exchange method applied to a message initiator of an Internet Security Association and Key Management Protocol, comprising:

[0006] constructing a security alliance payload based on a post-quantum key encapsulation algorithm and a preset national algorithm, and constructing a notification message based on the security alliance payload and a corresponding post-quantum key exchange notification payload according to the Internet Security Association and Key Management Protocol, and sending the notification message to a message responder, so that the message responder returns a corresponding response message to the message initiator according to the security alliance payload and the post-quantum key exchange notification payload in the notification message;

[0007] According to the post-quantum key encapsulation algorithm, several post-quantum key encapsulation public keys are determined. Based on each post-quantum key encapsulation public key, a corresponding first post-quantum key exchange notification is constructed and sent to the message responder, so that the message responder receives the current first post-quantum key exchange notification, uses the post-quantum key encapsulation public key to encrypt the corresponding temporary shared key to generate a first post-quantum key ciphertext, and constructs a first key exchange response based on the first post-quantum key ciphertext and sends it to the message initiator.

[0008] The system determines a new post-quantum key encapsulation public key and its own first post-quantum signature certificate based on the post-quantum key encapsulation algorithm. It then generates a first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys. Finally, it constructs a second post-quantum key exchange notification based on the new post-quantum key encapsulation public key, the first post-quantum signature certificate, and the first post-quantum signature result, and sends it to the message responder. The message responder receives the second post-quantum key exchange notification, encrypts the new temporary shared key using the new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, generates a second post-quantum signature result based on its own second post-quantum signature certificate and all temporary shared keys, and constructs a second key exchange response based on the second post-quantum key ciphertext, the second post-quantum signature certificate, and the second post-quantum signature result, sending it to the message initiator.

[0009] Based on the Internet security association and key management protocol, the authentication between itself and the message responder is performed according to the second post-quantum key exchange notification and the second key exchange response.

[0010] Optional, also includes:

[0011] Collect all the temporary shared keys currently received by the message initiator, and generate the current base key of the message initiator using the random number of the initial interaction message between the initiator and the responder and all the temporary shared keys currently received.

[0012] Optionally, the process of constructing the corresponding first post-quantum key exchange notification based on each of the post-quantum key encapsulated public keys and sending it to the message responder includes:

[0013] Based on the public keys of each of the post-quantum key encapsulations, construct the corresponding first post-quantum key exchange notification, determine the current reference key of the message initiator, and encrypt the first post-quantum key exchange notification based on the reference key to obtain the notification ciphertext;

[0014] sending the notification ciphertext to the message responder, so that the message responder receives and decrypts the notification ciphertext to obtain the first post-quantum key exchange notification, and encrypts the corresponding temporary shared key using the post-quantum key encapsulation public key to generate the first post-quantum key ciphertext, and constructs the first key exchange response according to the first post-quantum key ciphertext and sends it to the message initiator.

[0015] Optionally, the notification message is constructed according to the security association payload and the corresponding post-quantum key exchange notification payload based on the Internet Key Exchange protocol, and the notification message is sent to the message responder, so that the message responder returns the corresponding response message to the message initiator according to the security association payload and the post-quantum key exchange notification payload in the notification message, including:

[0016] The message fragment notification payload is constructed, and the notification message is constructed according to the security association payload, the post-quantum key exchange notification payload and the message fragment notification payload based on the Internet Key Exchange protocol, and the notification message is sent to the message responder, so that the message responder returns the corresponding response message to the message initiator according to the security association payload, the post-quantum key exchange notification payload and the message fragment notification payload in the notification message;

[0017] Correspondingly, the notification ciphertext is sent to the message responder, including:

[0018] determining whether the message data quantity of the first post-quantum key exchange notification is greater than the data transmission quantity of the preset network maximum transmission unit, if the message data quantity is greater than the data transmission quantity of the preset network maximum transmission unit, determining whether the reference key currently exists;

[0019] If the reference key currently exists, the notification ciphertext is fragmented based on the reference key, and the fragmented notification ciphertext is sent to the message responder.

[0020] Optionally, the notification ciphertext is fragmented based on the reference key, and the fragmented notification ciphertext is sent to the message responder, including:

[0021] The notification ciphertext is fragmented based on the reference key to obtain a plurality of fragmented packages;

[0022] The number of fragmented packages of the notification ciphertext and the fragment sequence numbers of each fragmented package are determined, and a first identifier corresponding to the number of fragmented packages and a second identifier corresponding to the fragment sequence number of each fragmented package are added to a target position of the corresponding fragmented package respectively; the target position is a position after the message header of the fragmented package.

[0023] generate an integrity verification key based on the reference key, encrypt each of the fragment packages by using the integrity verification key, and send the encrypted fragment packages to the message responder.

[0024] In a second aspect, the present application discloses a key exchange method applied to a message responder of an Internet Security Association and Key Management Protocol, comprising:

[0025] receive a notification message sent by a message initiator, and send a response message corresponding to the notification message to the message initiator according to a security alliance payload and a post-quantum key exchange notification payload in the notification message; the notification message is a message constructed by the message initiator based on a post-quantum key encapsulation algorithm and a preset national encryption algorithm, and then based on an Internet Security Association and Key Management Protocol according to the security alliance payload and a corresponding post-quantum key exchange notification payload;

[0026] receive a first post-quantum key exchange notification of the message initiator, encrypt a corresponding temporary shared key by using a post-quantum key encapsulation public key to generate a first post-quantum key ciphertext, and send a first key exchange response to the message initiator according to the first post-quantum key ciphertext; the first post-quantum key exchange notification is a message constructed and sent by the message initiator based on a plurality of post-quantum key encapsulation public keys determined according to the post-quantum key encapsulation algorithm;

[0027] receive a second post-quantum key exchange notification of the message initiator, encrypt a new temporary shared key by using a new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, and generate a second post-quantum signature result based on a second post-quantum signature certificate of itself and all temporary shared keys, and send a second key exchange response to the message initiator according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result; the second post-quantum key exchange notification is a message constructed and sent by the message initiator according to the new post-quantum key encapsulation public key, a first post-quantum signature certificate of itself and a first post-quantum signature result after determining the new post-quantum key encapsulation public key and the first post-quantum signature certificate of itself according to the post-quantum key encapsulation algorithm, and generating the first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys;

[0028] perform identity authentication between itself and the message initiator according to the second post-quantum key exchange notification and the second key exchange response based on the Internet Security Association and Key Management Protocol.

[0029] In a third aspect, the present application discloses a key exchange device, applied to a message initiator of an Internet Security Association and Key Management Protocol, comprising:

[0030] A first message construction module, configured to construct a security association payload based on a post-quantum key encapsulation algorithm and a preset national secret algorithm, and construct a notification message based on the security association payload and a corresponding post-quantum key exchange notification payload according to the Internet Security Association and Key Management Protocol, and send the notification message to a message responder, so that the message responder returns a corresponding response message to the message initiator according to the security association payload and the post-quantum key exchange notification payload in the notification message;

[0031] A first notification construction module, configured to determine a plurality of post-quantum key encapsulation public keys according to the post-quantum key encapsulation algorithm, construct a corresponding first post-quantum key exchange notification based on each post-quantum key encapsulation public key and send it to the message responder, so that the message responder receives the first post-quantum key exchange notification, encrypts a corresponding temporary shared key using the post-quantum key encapsulation public key to generate a first post-quantum key ciphertext, and constructs a first key exchange response according to the first post-quantum key ciphertext and sends it to the message initiator;

[0032] A second notification construction module, configured to determine a new post-quantum key encapsulation public key and a first post-quantum signature certificate of itself according to the post-quantum key encapsulation algorithm, generate a first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys, and construct a second post-quantum key exchange notification according to the new post-quantum key encapsulation public key, the first post-quantum signature certificate and the first post-quantum signature result and send it to the message responder, so that the message responder receives the second post-quantum key exchange notification, encrypts a new temporary shared key using the new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, generates a second post-quantum signature result based on its own second post-quantum signature certificate and all temporary shared keys, and constructs a second key exchange response according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result and sends it to the message initiator;

[0033] A first identity verification module, configured to perform identity verification between itself and the message responder according to the second post-quantum key exchange notification and the second key exchange response based on the Internet Security Association and Key Management Protocol.

[0034] In a fourth aspect, the present application discloses a key exchange device, applied to a message responder of an Internet Security Association and Key Management Protocol, comprising:

[0035] The second message construction module is configured to receive a notification message sent by a message initiator, and send a response message corresponding to the notification message to the message initiator according to a security alliance payload and a post-quantum key exchange notification payload in the notification message; the notification message is a message constructed by the message initiator based on an Internet Security Association and Key Management Protocol according to the security alliance payload and the corresponding post-quantum key exchange notification payload after the message initiator constructs the security alliance payload based on a post-quantum key encapsulation algorithm and a preset national encryption algorithm;

[0036] The first response construction module is configured to receive a first post-quantum key exchange notification of the message initiator, encrypt a corresponding temporary shared key by using a post-quantum key encapsulation public key to generate a first post-quantum key ciphertext, and construct a first key exchange response according to the first post-quantum key ciphertext and send the first key exchange response to the message initiator; the first post-quantum key exchange notification is a message constructed and sent by the message initiator based on a plurality of post-quantum key encapsulation public keys determined according to the post-quantum key encapsulation algorithm;

[0037] The second response construction module is configured to receive a second post-quantum key exchange notification of the message initiator, encrypt a new temporary shared key by using a new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, and generate a second post-quantum signature result based on a second post-quantum signature certificate of itself and all temporary shared keys, and construct a second key exchange response according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result and send the second key exchange response to the message initiator; the second post-quantum key exchange notification is a message constructed and sent by the message initiator according to the new post-quantum key encapsulation public key, the first post-quantum signature certificate of itself and the first post-quantum signature result after determining the new post-quantum key encapsulation public key and the first post-quantum signature certificate of itself based on the post-quantum key encapsulation algorithm, and generating the first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys;

[0038] The second identity verification module is configured to perform identity verification between itself and the message initiator based on the Internet Security Association and Key Management Protocol according to the second post-quantum key exchange notification and the second key exchange response.

[0039] In a fifth aspect, the present application provides an electronic device, comprising:

[0040] a memory configured to save a computer program;

[0041] a processor configured to execute the computer program to implement the key exchange method described above.

[0042] In a sixth aspect, the present application provides a computer readable storage medium for storing a computer program, wherein the computer program is executed by a processor to implement the key exchange method as described above.

[0043] In the present application, the message initiator of the Internet security association and key management protocol first constructs a security alliance payload based on a post-quantum key encapsulation algorithm and a preset national secret algorithm, constructs a notification message based on the security alliance payload and a corresponding post-quantum key exchange notification payload according to the Internet security association and key management protocol, and sends the notification message to the message responder, so that the message responder returns a corresponding response message to the message initiator according to the security alliance payload and the post-quantum key exchange notification payload in the notification message, then determines a plurality of post-quantum key encapsulation public keys according to the post-quantum key encapsulation algorithm, constructs a corresponding first post-quantum key exchange notification based on each post-quantum key encapsulation public key and sends it to the message responder, so that the message responder receives the current first post-quantum key exchange notification, encrypts a corresponding temporary shared key using the post-quantum key encapsulation public key to generate a first post-quantum key ciphertext, and constructs a first key exchange response according to the first post-quantum key ciphertext and sends it to the message initiator, then determines a new post-quantum key encapsulation public key and a first post-quantum signature certificate of itself according to the post-quantum key encapsulation algorithm, generates a first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys, and constructs a second post-quantum key exchange notification according to the new post-quantum key encapsulation public key, the first post-quantum signature certificate and the first post-quantum signature result and sends it to the message responder, so that the message responder receives the second post-quantum key exchange notification, encrypts a new temporary shared key using the new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, and generates a second post-quantum signature result based on its own second post-quantum signature certificate and all temporary shared keys, constructs a second key exchange response according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result and sends it to the message initiator, and finally performs identity authentication between itself and the message responder according to the second post-quantum key exchange notification and the second key exchange response based on the Internet security association and key management protocol. In this way, the message initiator sends a key exchange request based on a preset post-quantum algorithm, the responder performs key exchange with the message initiator based on the key exchange request, constructs a security alliance payload by using a post-quantum encapsulation algorithm, constructs a notification message by using the security alliance payload, and performs key exchange by using the notification message, so that the Internet security association and key management protocol has active public key cryptography security and quantum security, thereby solving the problem that the current international protocol does not have quantum security; and the post-quantum key exchange notification based on the post-quantum algorithm is used to perform key exchange and identity authentication between the message initiator and the message responder, thereby ensuring the reliability of the key exchange. BRIEF DESCRIPTION OF DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the description of the embodiments or the prior art will be briefly introduced. Obviously, the accompanying drawings in the following description only only the embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of the provided drawings.

[0045] Figure 1 A key exchange method flow chart disclosed by the present application;

[0046] Figure 2 A key exchange flow chart disclosed by the present application;

[0047] Figure 3 A specific key exchange flow chart disclosed by the present application;

[0048] Figure 4 A message fragmentation method flow chart disclosed by the present application;

[0049] Figure 5 A message fragmentation flow chart disclosed by the present application;

[0050] Figure 6 Another key exchange method flow chart disclosed by the present application;

[0051] Figure 7 A key exchange device structure schematic diagram disclosed by the present application;

[0052] Figure 8 Another key exchange device structure schematic diagram disclosed by the present application;

[0053] Figure 9 An electronic device structure diagram disclosed by the present application. DETAILED DESCRIPTION

[0054] The technical solutions in the embodiments of the present application will be described clearly and completely below with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0055] At present, the national secret ISAKMP protocol has serious security risks in the quantum computing environment, meanwhile, the international IKEv2 (Internet Key Exchange) protocol processing procedure is complex, only the key exchange function is considered, and the post-quantum identity authentication function is not considered, therefore, the application provides a key exchange method, a secure alliance payload is constructed by using a post-quantum encapsulation algorithm, a notification message is constructed by using the secure alliance payload, the key exchange is carried out through the notification message, the national secret ISAKMP protocol realizes quantum security while having the active public key encryption security, and the identity authentication between the message initiator and the message responder is guaranteed by constructing the second post-quantum key exchange notification and the second key exchange response, so that the reliability of the key exchange is guaranteed.

[0056] Referring to Figure 1 As shown in the figure, the application discloses a key exchange method, applied to a message initiator of an Internet Security Association and Key Management Protocol, comprising:

[0057] Step S11, a secure alliance payload is constructed based on a post-quantum key encapsulation algorithm and a preset national secret algorithm, a notification message is constructed based on the secure alliance payload and a corresponding post-quantum key exchange notification payload according to the Internet Security Association and Key Management Protocol, the notification message is sent to a message responder, so that the message responder returns a corresponding response message to the message initiator according to the secure alliance payload and the post-quantum key exchange notification payload in the notification message.

[0058] It can be understood that the active public key encryption algorithm and function are retained in the embodiment, and the national secret ISAKMP protocol framework is modified by using the post-quantum public key encryption algorithm, that is, the post-quantum public key encryption algorithm is put into the national secret ISAKMP protocol framework, the secure alliance payload is constructed based on the post-quantum key encapsulation algorithm and the preset national secret algorithm, and the notification message is constructed based on the secure alliance payload and the corresponding post-quantum key exchange notification payload according to the Internet Security Association and Key Management Protocol, in the embodiment, the specific modification of the protocol is shown in Table 1, and the specific protocol payload modification is shown in Table 2, wherein GPH (Gallons Per Hour) represents a public payload header, and the bold part represents the specific modification of the payload.

[0059] Table 1 Protocol modification explanation

[0060]

[0061] Table 2 Payload modification explanation

[0062]

[0063] After constructing the secure alliance payload based on the post-quantum key packaging algorithm and the preset national secret algorithm, the notification message is sent to the message responder based on the Internet security association and key management protocol according to the secure alliance payload and the corresponding post-quantum key exchange notification payload, so that the message responder returns the corresponding response message to the message initiator according to the secure alliance payload and the post-quantum key exchange notification payload in the notification message. Specifically, it can include: constructing a message fragment notification payload, i.e. the N(Fragment) notification payload in Table 1, and constructing a notification message based on the Internet security association and key management protocol, i.e. the national secret ISAKMP protocol, according to the secure alliance payload, i.e. the SA (Security Association) payload in Table 1, the post-quantum key exchange notification payload, i.e. the N(Intermedia) and N(Multi_Key) notification payloads in Table 1, and the message fragment notification payload N(Fragment), and sending the notification message to the message responder, so that the message responder returns the corresponding response message to the message initiator according to the SA payload, the N(Intermedia) and N(Multi_Key) notification payloads, and the N(Fragment) payload in the notification message; correspondingly, the notification ciphertext is sent to the message responder, which can specifically include: judging whether the message data quantity of the first post-quantum key exchange notification is greater than the data transmission quantity of the preset network maximum transmission unit, i.e. MTU (Maximum Transmission Unit, maximum transmission unit); if the message data quantity is greater than the data transmission quantity of the MTU, it is judged whether there is a reference key, i.e. SKEYID; in one specific embodiment, if there is a reference key SKEYID at present, the notification ciphertext is fragmented based on the reference key SKEYID, and the fragmented notification ciphertext is sent to the message responder. It should be noted that because the post-quantum public key algorithm password parameter is greater than 2000 bytes, a message will exceed the network transmission MTU (about 1500 bytes) as long as the post-quantum public key algorithm parameter is placed. In this embodiment, the notification ciphertext is fragmented based on the reference key, which effectively solves the problem of key agreement failure during ISAKMP protocol interaction caused by the random discarding of IP (Internet Protocol, Internet Protocol address) fragments by the firewall and other devices in the network.

[0064] Step S12, determining a plurality of post-quantum key packaging public keys according to the post-quantum key packaging algorithm, constructing a corresponding first post-quantum key exchange notification based on each post-quantum key packaging public key and sending it to the message responder, so that the message responder receives the current first post-quantum key exchange notification, encrypts the corresponding temporary shared key using the post-quantum key packaging public key to generate a first post-quantum key ciphertext, and constructs a first key exchange response according to the first post-quantum key ciphertext and sends it to the message initiator.

[0065] It should be noted that, as Figure 2 shown, the new protocol framework in the embodiment is modified under the original protocol framework, Figure 2 the original protocol framework is message 1, 2, 3, 4, 5, 6, which has the functions of key exchange and identity authentication (signature verification), but uses SM2 to complete it; and in the embodiment, based on the content in the previous step, the payload in message 1, 2 is modified based on the post-quantum algorithm, and (optional) 3.1 / (optional) 4.1 is added, which is the first post-quantum key exchange, (optional) 3.2 / (optional) 4.2..., which is the second post-quantum key exchange, and accordingly, the third, fourth, and nth post-quantum key exchange can be continued, and in the nth post-quantum key exchange, both post-quantum key exchange and post-quantum identity authentication (signature verification) are performed, and this time identity authentication identifies all the key exchange data generated in the previous post-quantum key exchange. That is, as Figure 2 shown, in the process of complete identity authentication based on the post-quantum algorithm and the national secret ISAKMP protocol, the post-quantum key exchange is performed multiple times, but the post-quantum two-way identity is authenticated only once.

[0066] In the embodiment, in the process of constructing the corresponding first post-quantum key exchange notification based on the post-quantum key encapsulation public key and sending it to the message responder, specifically, the corresponding first post-quantum key exchange notification can be constructed based on the post-quantum key encapsulation public key, i.e. the post-quantum KEM (Key Encapsulation Mechanism, a kind of key encapsulation mechanism) public key, the current reference key SYEYID of the message initiator is determined, and the first post-quantum key exchange notification is encrypted based on the reference key SYEYID to obtain the notification ciphertext; the notification ciphertext is sent to the message responder, so that the message responder receives and decrypts the notification ciphertext to obtain the first post-quantum key exchange notification, and encrypts the corresponding temporary shared key, i.e. Skrn, using the post-quantum KEM public key to generate the first post-quantum key ciphertext, i.e. the first KEM ciphertext, and constructs the first key exchange response according to the first post-quantum key ciphertext and sends it to the message initiator. In the embodiment, the post-quantum key exchange notification is encrypted by the reference key, which ensures the security of the information in the key exchange process.

[0067] Step S13, determining a new post-quantum key encapsulation public key and a first post-quantum signature certificate of the message initiator according to the post-quantum key encapsulation algorithm, generating a first post-quantum signature result based on the first post-quantum signature certificate and all the determined post-quantum key encapsulation public keys, and constructing a second post-quantum key exchange notification according to the new post-quantum key encapsulation public key, the first post-quantum signature certificate and the first post-quantum signature result, and sending the second post-quantum key exchange notification to the message responder, so that the message responder receives the second post-quantum key exchange notification, encrypts a new temporary shared key using the new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, generates a second post-quantum signature result based on a second post-quantum signature certificate of the message responder and all the temporary shared keys, and constructs a second key exchange response according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result, and sends the second key exchange response to the message initiator.

[0068] In the embodiment, in the process of constructing the second post-quantum key exchange notification and sending the second post-quantum key exchange notification to the message responder according to the new post-quantum key encapsulation public key, the first post-quantum signature certificate and the first post-quantum signature result, the process can specifically include: constructing a corresponding second post-quantum key exchange notification based on each post-quantum key encapsulation public key, determining a reference key SKEYID of the message initiator, and encrypting the second post-quantum key exchange notification based on the reference key SKEYID to obtain a notification ciphertext; sending the notification ciphertext to the message responder, so that the message responder receives and decrypts the notification ciphertext to obtain the second post-quantum key exchange notification, and encrypts a corresponding temporary shared key Skrn using the post-quantum KEM public key to generate a second post-quantum key ciphertext, i.e., a second KEM ciphertext, and constructs a first key exchange response according to the second KEM ciphertext and sends the first key exchange response to the message initiator. In the embodiment, the post-quantum key exchange notification is encrypted by the reference key, which ensures the security of information in the key exchange process.

[0069] Step S14, performing identity authentication between the message initiator and the message responder according to the second post-quantum key exchange notification and the second key exchange response based on the Internet security association and key management protocol.

[0070] In the embodiment, identity authentication between the message initiator and the message responder is performed according to the second post-quantum key exchange notification and the second key exchange response based on the ISAKMP protocol, and by performing identity authentication between the message initiator and the message responder, the reliability of the key exchange process is ensured.

[0071] The specific process of the embodiment is as follows Figure 2As shown, the initiator adds N(Intermedia) and N(Multi_Key) notification load after the SA load of message 1 and adds post-quantum KEM algorithm information in the Transform sub-load in the SA load; the responder agrees to use the post-quantum KEM algorithm for key exchange, adds the same N(Intermedia) and N(Multi_Key) load after the SA load of message 2, and selects the determined post-quantum KEM algorithm information in the Transform load in the SA load; messages 3 and 4 remain unchanged, using the national secret ISAKMP protocol message format; the message initiator sends its own post-quantum KEM public key in message 3.1; the message responder sends the KEM ciphertext encapsulated with the post-quantum KEM public key of the message initiator in message 4.1; the message initiator and the message responder send several times of post-quantum KEM key exchange information 3.2~4.n-1 based on messages 3.1 and 4.1; the message initiator sends the post-quantum KEM key exchange information 3.n for the last time, this time sending the local post-quantum KEM public key, the local post-quantum signature certificate, and the post-quantum signature result of all previous post-quantum KEM public key data; the message responder sends the post-quantum KEM key exchange information 4.n for the last time, this time sending the KEM ciphertext encapsulated with the post-quantum KEM public key of the message initiator, the local post-quantum signature certificate, and the post-quantum signature result of all previous post-quantum KEM encapsulated shared keys; messages 5 and 6 remain unchanged, using the national secret ISAKMP protocol message format, and completing the verification of the entire protocol interaction process. In a specific embodiment, the modified national secret ISAKMP protocol is instantiated by using the post-quantum public key cryptography algorithms Kyber-768 / Falcon-1024 and Kyber-1024 / Falcon-1024 twice key exchange, and the protocol interaction process is as follows Figure 3As shown, the message initiator adds N(Intermedia) and N(Multi_Key) notification load after the SA load of message 1, and adds the algorithm ID of post-quantum KEM algorithms Kyber-768 and Kyber-1024 in the Transform load in the SA load; the message responder agrees to use post-quantum KEM algorithms for key exchange, adds the same N(Intermedia) and N(Multi_Key) load after the SA load of message 2, and selects the algorithm ID of the determined post-quantum KEM algorithms Kyber-768 and Kyber-1024 in the Transform load in the SA load; messages 3 and 4 remain unchanged, using the national standard ISAKMP protocol message format; the message initiator generates a temporary Kyber-768 public and private key, sends the Kyber-768 public key data in message 3.1, and saves the private key; the message responder performs KEM encapsulation using the Kyber-768 public key of the message initiator, and obtains a shared key SKr1, and sends the KEM encapsulation ciphertext in message 4.1; the message initiator generates a temporary Kyber-1024 public and private key, sends the Kyber-1024 public key data in message 3.2, saves the private key, and sends the Falcon-1024 signature certificate and the Falcon-1024 signature result on the splicing result data of the Kyber-768 public key and the Kyber-1024 public key; the message responder sends the KEM ciphertext encapsulated by the Kyber-1024 public key of the message initiator in message 4.2, the local Falcon-1024 signature certificate, and the Falcon-1024 signature result on the splicing (i.e., SKr1|SKr2) of the shared keys of all previous post-quantum KEM encapsulation; messages 5 and 6 remain unchanged, using the national standard ISAKMP protocol message format, and completing the verification of the entire interaction process of the protocol. It should be noted that if the domestic post-quantum public key cryptography algorithm is standardized, the Kyber-768 / Falcon-1024 and Kyber-1024 / Falcon-1024 algorithms described above can be replaced by the corresponding domestic algorithms.

[0072] It can be seen that, by constructing a secure alliance payload by using a post-quantum encapsulation algorithm, constructing a notification message by using the secure alliance payload, and performing key exchange by using the notification message, the Internet security association and key management protocol is provided with both active public key cryptography security and quantum security, thereby solving the problem that current international protocols do not have quantum security. The identity authentication between the message initiator and the message responder by constructing a post-quantum key exchange notification and a key exchange response ensures the reliability of the key exchange, supports multiple post-quantum key encapsulation algorithms for key exchange, supports multiple digital signature algorithms for post-quantum identity authentication, and has good expansibility. Moreover, the original protocol framework is modified at the message level, new message flows are added to transmit and process post-quantum public key cryptography parameters, but no new payload is added, only the original payload category and content are added or modified, the amount of protocol implementation modification is reduced, the modified protocol is more practical, and is easy to be compatible, easy to be implemented, and easy to be proved secure.

[0073] Further, in order to avoid the problem that the message volume is greater than the preset network maximum transmission unit transmission data volume, resulting in key negotiation failure of the SM ISAKMP protocol interaction, the message needs to be fragmented. In order to illustrate the specific operation of fragmenting the message, as shown in Figure 4 The message fragmentation method disclosed by the application comprises the following steps:

[0074] Step S21, collect all the temporary shared keys currently received by the message initiator, and generate a current reference key by using the random number in the initial interaction message of the initiator and the responder and all the temporary shared keys currently received.

[0075] In the embodiment, all the temporary shared keys Skrn currently received by the collection message are collected, the all the temporary shared keys Skrn can include specific temporary shared keys, such as Skr1, Skr2, etc., and the current reference key of the message initiator is generated according to all the temporary shared keys currently received by using a pseudo-random number algorithm, and it should be noted that the reference key is dynamically changed with the transmission of the message. The generation method of the reference key of the original national secret ISAKMP protocol is SKEYID=PRF(HASH(Ni_b | Nr_b), CKY-I | CKY-R), and the generation method of the reference key in the modified protocol in the embodiment is changed to, in a specific embodiment, if no temporary shared key is currently generated, the current reference key of the message initiator is generated by using a pseudo-random number algorithm, that is, a PRF (Pseudo Random Function) algorithm, a statistical statement analysis algorithm, that is, a CKY (Cocke-Kasami-Younger) algorithm, and a HASH algorithm, and the generation method is SKEYID=PRF(HASH(Ni_b | Nr_b), CKY-I | CKY-R), and the key is used to derive the encryption protection of the next group of messages; in another specific embodiment, if the first group of temporary shared keys Skr1 is generated, the generation method of the reference key is SKEYID=PRF(HASH(Ni_b | Nr_b | Skr1), CKY-I | CKY-R). In the embodiment, the generated reference key is used to encrypt the message in the key exchange process, and the reliability of the message transmission is ensured.

[0076] In step S22, the notification ciphertext is fragmented based on the reference key to obtain a plurality of fragmented packages.

[0077] Because of the addition of the post-quantum public key cryptography algorithm, the protocol message volume is increased, and it is preliminarily estimated that the transmission amount of the ISAKMP protocol will be increased by 20,000 bytes. Among them, a key exchange message using the post-quantum public key cryptography algorithm is about 10,000 bytes, therefore, the protocol needs to support the IKE fragmentation function, and the IKE fragmentation function is optional, and the N(Fragment) notification payload is used to define, the payload is placed after the SA payload, if the responder agrees to perform the IKE fragmentation, the same N(Fragment) notification is sent. In the embodiment, the notification ciphertext is fragmented based on the reference key to obtain a plurality of fragmented packages, that is, the IKE fragmentation. The problem of key agreement failure in the ISAKMP protocol interaction caused by the random discarding of the IP fragmentation by the firewall and other devices in the network is solved by fragmenting the notification ciphertext.

[0078] Step S23, determining the number of the slice packages of the notification ciphertext and the slice sequence number of each of the slice packages, and adding the first identifier corresponding to the number of the slice packages and the second identifier corresponding to the slice sequence number of each of the slice packages to the target position of the corresponding slice package respectively; the target position is the position after the message header of the slice package.

[0079] In the embodiment, the number of the slice packages of the notification ciphertext and the slice sequence number of each of the slice packages are determined, and the first identifier corresponding to the number of the slice packages and the second identifier corresponding to the slice sequence number of each of the slice packages are added to the target position of the corresponding slice package. In a specific implementation, 4 bytes of slice information are added after the message header of each slice package, which respectively represent the current slice number and the total slice number, and then the actual slice data is spliced. In the embodiment, by adding the first identifier corresponding to the number of the slice packages and the second identifier corresponding to the slice sequence number of each of the slice packages to the target position of the corresponding slice package, the information of the slice package is more clear, and the reliability of the message slicing is improved.

[0080] Step S24, generating an integrity verification key based on the reference key, encrypting each of the slice packages by using the integrity verification key, and sending the encrypted slice packages to a message responder.

[0081] In a specific implementation, after the reference key SKEYID is generated, if the message slicing notification payload is the encrypted payload ciphertext, the payload itself and the slice package are encrypted respectively, and the encrypted slice packages are sent to the message responder. It should be noted that the slice package is encrypted for protection and integrity verification. If the IKE slicing is not performed, the original message needs to be encrypted for protection, and the encryption protection rule of the national ISAKMP protocol is followed, that is, the integrity verification of the slice package is not needed. In the embodiment, the IKE slice package is encrypted by using the integrity verification key, the integrity of the slice information is ensured, the encrypted slice packages are sent to the message responder, and the data security in the message transmission process is improved.

[0082] In a specific implementation, the flow of the message slicing is as follows Figure 5As shown, the message initiator adds the N(Fragment) notification load after the SA load of message 1 to send to the message responder; the message responder does not send the load if it does not agree, and subsequent data packets do not perform IKE fragmentation, and if it agrees to perform IKE fragmentation, the same N(Fragment) load is added after the SA load of message 2, and if message 2 exceeds the MTU length, it is fragmented in plaintext, that is, no encryption and integrity check is performed; for messages n and n+1, if the message length is less than the MTU, no IKE fragmentation is performed, otherwise, fragmentation is performed. If SKEYID has not been generated, plaintext fragmentation is performed, and if SKEYID has been generated, SKEYID is used for key derivation to obtain an encryption key and an integrity key, and IKE ciphertext fragmentation is performed, wherein SKF{} represents IKE ciphertext fragmentation.

[0083] In the embodiment, the generated reference key is used to encrypt messages in the key exchange process, ensuring the reliability of message transmission, the first identifier corresponding to the number of fragmented packets and the second identifier corresponding to the fragment sequence number of each fragmented packet are added to the target position of the corresponding fragmented packet, so that the information of the fragmented packet is more clear, and the reliability of message fragmentation is improved. The encrypted fragmented packets are sent to the message responder, improving the data security in the message transmission process.

[0084] Since the national secret ISAKMP protocol has serious security risks in a quantum computing environment, and the international IKEv2 protocol has a complex processing flow and only considers the key exchange function without considering the post-quantum identity authentication function, the application provides a key exchange method, constructs a security alliance load by using a post-quantum encapsulation algorithm, constructs a notification message by using the security alliance load, performs key exchange by using the notification message, so that the national secret ISAKMP protocol has active public key encryption security and quantum security, and the identity authentication between the message initiator and the message responder is ensured by constructing a second post-quantum key exchange notification and a second key exchange response, ensuring the reliability of the key exchange.

[0085] Referring to Figure 6 The application discloses a key exchange method, which is applied to a message responder of an Internet Security Association and Key Management Protocol, and includes the following steps:

[0086] Step S31, receiving a notification message sent by a message initiator, and sending a response message corresponding to the notification message to the message initiator according to a security alliance load and a post-quantum key exchange notification load in the notification message; the notification message is a message constructed by the message initiator based on a post-quantum key encapsulation algorithm and a preset national secret algorithm, and then based on the security alliance load and the corresponding post-quantum key exchange notification load according to the Internet Security Association and Key Management Protocol.

[0087] Step S32, receiving a first post-quantum key exchange notification of the current message initiator, encrypting a corresponding temporary shared key by using a post-quantum key wrapping public key to generate a first post-quantum key ciphertext, and sending a first key exchange response to the message initiator according to the first post-quantum key ciphertext; the first post-quantum key exchange notification is a message sent by the message initiator based on a plurality of post-quantum key wrapping public keys determined according to the post-quantum key wrapping algorithm.

[0088] Step S33, receiving a second post-quantum key exchange notification of the message initiator, encrypting a new temporary shared key by using a new post-quantum key wrapping public key to generate a second post-quantum key ciphertext, and generating a second post-quantum signature result based on a second post-quantum signature certificate of itself and all temporary shared keys, and sending a second key exchange response to the message initiator according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result; the second post-quantum key exchange notification is a message sent by the message initiator according to the new post-quantum key wrapping public key, the first post-quantum signature certificate of itself and the first post-quantum signature result after determining the new post-quantum key wrapping public key and the first post-quantum signature certificate of itself according to the post-quantum key wrapping algorithm, and generating a first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key wrapping public keys.

[0089] Step S34, performing identity authentication between itself and the message initiator according to the second post-quantum key exchange notification and the second key exchange response based on the internet security association and key management protocol.

[0090] As can be seen, in the embodiment of the application, the post-quantum wrapping algorithm is used to construct a secure alliance payload, and a notification message is constructed through the secure alliance payload, and key exchange is performed through the notification message, so that the internet security association and key management protocol has both active public key cryptographic security and quantum security, thereby solving the problem that the current international protocol does not have quantum security; the identity authentication between the message initiator and the message responder through the second post-quantum key exchange notification and the second key exchange response ensures the reliability of the key exchange.

[0091] Referring to Figure 7 The embodiment of the application also discloses a key exchange device applied to a message initiator of an internet security association and key management protocol, and comprising:

[0092] The first message construction module 11 is configured to construct a secure alliance payload based on a post-quantum key encapsulation algorithm and a preset national secret algorithm, and construct a notification message based on the secure alliance payload and a corresponding post-quantum key exchange notification payload according to the Internet security association and key management protocol, and send the notification message to a message responder, so that the message responder returns a corresponding response message to the message initiator according to the secure alliance payload and the post-quantum key exchange notification payload in the notification message.

[0093] The first notification construction module 12 is configured to determine a plurality of post-quantum key encapsulation public keys according to the post-quantum key encapsulation algorithm, construct a corresponding first post-quantum key exchange notification based on each post-quantum key encapsulation public key and send it to the message responder, so that the message responder receives the first post-quantum key exchange notification, encrypts a corresponding temporary shared key using the post-quantum key encapsulation public key to generate a first post-quantum key ciphertext, and constructs a first key exchange response according to the first post-quantum key ciphertext and sends it to the message initiator.

[0094] The second notification construction module 13 is configured to determine a new post-quantum key encapsulation public key and a first post-quantum signature certificate of itself according to the post-quantum key encapsulation algorithm, generate a first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys, and construct a second post-quantum key exchange notification according to the new post-quantum key encapsulation public key, the first post-quantum signature certificate and the first post-quantum signature result and send it to the message responder, so that the message responder receives the second post-quantum key exchange notification, encrypts a new temporary shared key using the new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, and generates a second post-quantum signature result based on its own second post-quantum signature certificate and all temporary shared keys, constructs a second key exchange response according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result and sends it to the message initiator.

[0095] The first identity verification module 14 is configured to perform identity verification between itself and the message responder based on the second post-quantum key exchange notification and the second key exchange response according to the Internet security association and key management protocol.

[0096] In some embodiments, the first message construction module 11 can specifically include:

[0097] The load construction unit is configured to construct a message fragment notification load, and construct the notification message according to the security alliance load, the post-quantum key exchange notification load and the message fragment notification load based on the Internet security association and key management protocol, and send the notification message to the message responder, so that the message responder returns the corresponding response message to the message initiator according to the security alliance load, the post-quantum key exchange notification load and the message fragment notification load in the notification message.

[0098] The data amount judgment unit is configured to judge whether the message data amount of the first post-quantum key exchange notification is greater than the data transmission amount of a preset network maximum transmission unit, and if the message data amount is greater than the data transmission amount of the preset network maximum transmission unit, judge whether the reference key currently exists.

[0099] The ciphertext fragment submodule is configured to, if the reference key currently exists, fragment the notification ciphertext based on the reference key, and send the fragmented notification ciphertext to the message responder.

[0100] In some specific embodiments, the ciphertext fragment submodule can specifically include:

[0101] The ciphertext fragment unit is configured to fragment the notification ciphertext based on the reference key to obtain a plurality of fragment packages.

[0102] The identifier adding unit is configured to determine the number of fragment packages of the notification ciphertext and the fragment serial numbers of the fragment packages, and add a first identifier corresponding to the number of fragment packages and a second identifier corresponding to the fragment serial numbers of the fragment packages to target positions of the corresponding fragment packages respectively; the target position is a position after a message header of the fragment package.

[0103] The fragment package encryption unit is configured to generate an integrity verification key based on the reference key, encrypt the fragment packages based on the integrity verification key, and send the encrypted fragment packages to the message responder.

[0104] In some specific embodiments, the first notification construction module 12 can specifically include:

[0105] The notification encryption unit is configured to construct the first post-quantum key exchange notification based on the post-quantum key encapsulation public key, determine the reference key of the message initiator currently, and encrypt the first post-quantum key exchange notification based on the reference key to obtain notification ciphertext.

[0106] The ciphertext sending unit is configured to send the notification ciphertext to the message responder, so that the message responder receives and decrypts the notification ciphertext to obtain the first post-quantum key exchange notification, encrypts the corresponding temporary shared key by using the post-quantum key encapsulation public key to generate the first post-quantum key ciphertext, and constructs the first key exchange response according to the first post-quantum key ciphertext and sends the first key exchange response to the message initiator.

[0107] Referring to Figure 8 As shown in the figure, the embodiments of the present application further disclose a key exchange device applied to a message responder of an Internet Security Association and Key Management Protocol, comprising:

[0108] The second message construction module 21 is configured to receive a notification message sent by a message initiator, and send a response message corresponding to the notification message to the message initiator according to a security alliance payload and a post-quantum key exchange notification payload in the notification message; the notification message is a message constructed by the message initiator according to the security alliance payload and the corresponding post-quantum key exchange notification payload based on an Internet Security Association and Key Management Protocol after the message initiator constructs the security alliance payload based on a post-quantum key encapsulation algorithm and a preset national secret algorithm;

[0109] The first response construction module 22 is configured to receive a first post-quantum key exchange notification of the current message initiator, encrypt a corresponding temporary shared key by using a post-quantum key encapsulation public key to generate a first post-quantum key ciphertext, and construct a first key exchange response according to the first post-quantum key ciphertext and send the first key exchange response to the message initiator; the first post-quantum key exchange notification is a message constructed and sent by the message initiator based on a plurality of post-quantum key encapsulation public keys determined according to the post-quantum key encapsulation algorithm;

[0110] The second response construction module 23 is configured to receive a second post-quantum key exchange notification of the message initiator, encrypt a new temporary shared key by using a new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, generate a second post-quantum signature result based on a second post-quantum signature certificate of itself and all temporary shared keys, and construct a second key exchange response according to the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result and send the second key exchange response to the message initiator; the second post-quantum key exchange notification is a message constructed and sent by the message initiator according to the new post-quantum key encapsulation public key, a first post-quantum signature certificate of itself and a first post-quantum signature result after the message initiator determines the new post-quantum key encapsulation public key and the first post-quantum signature certificate of itself according to the post-quantum key encapsulation algorithm, and generates the first post-quantum signature result based on the first post-quantum signature certificate and all post-quantum key encapsulation public keys determined;

[0111] The second identity authentication module 24 is configured to perform identity authentication between the second identity authentication module 24 and the message initiator based on the second post-quantum key exchange notification and the second key exchange response according to the Internet Security Association and Key Management Protocol.

[0112] Further, the application further discloses an electronic device, Figure 9 The electronic device 30 shown in the figure is according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation on the use range of the application.

[0113] Figure 9 The electronic device 30 shown in the figure is according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation on the use range of the application.

[0114] In the embodiment, the power supply 33 is configured to provide working voltage for each hardware device on the electronic device 30; the communication interface 34 can create a data transmission channel between the electronic device 30 and external devices, and the communication protocol followed by the communication interface 34 can be any communication protocol applicable to the technical solution of the application, which is not limited here; the input and output interface 35 is configured to obtain external input data or output data to the outside, and the specific interface type can be selected according to the specific application needs, which is not limited here.

[0115] In addition, the memory 32 as a carrier of resource storage can be a read-only memory, a random access memory, a magnetic disk or an optical disk, and the resources stored thereon can include an operating system 321, a computer program 322, etc., and the storage mode can be temporary storage or permanent storage.

[0116] The operating system 321 is configured to manage and control each hardware device on the electronic device 30 and the computer program 322, and can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of completing the key exchange method executed by the electronic device 30 disclosed in any of the foregoing embodiments, the computer program 322 can further include a computer program capable of completing other specific work.

[0117] Further, the application also discloses a computer readable storage medium for storing a computer program, wherein the computer program is executed by a processor to realize the key exchange method disclosed above. For the specific steps of the method, refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.

[0118] The various embodiments are described in the specification by progressive stages, and each embodiment focuses on the difference from other embodiments. For the same or similar parts between the embodiments, refer to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and refer to the method part for the relevant content.

[0119] The skilled person can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in the above description in general. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0120] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium known in the art.

[0121] Finally, it should be noted that in this document, relationship terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0122] The technical solutions provided by the present application are described in detail above, and the principles and implementation manners of the present application are described by using specific examples. The above description of the examples is only used to help understand the method of the present application and its core idea; meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges will be changed, and the above description of the content of the specification should not be understood as a limitation on the present application.

Claims

1. A key exchange method, characterized in that, Message initiators used in Internet security association and key management protocols include: A security alliance payload is constructed based on the post-quantum key encapsulation algorithm and the preset national cryptographic algorithm. A notification message is constructed based on the Internet security association and key management protocol according to the security alliance payload and the corresponding post-quantum key exchange notification payload. The notification message is sent to the message responder so that the message responder can return a corresponding response message to the message initiator according to the security alliance payload and the post-quantum key exchange notification payload in the notification message. According to the post-quantum key encapsulation algorithm, several post-quantum key encapsulation public keys are determined. Based on each post-quantum key encapsulation public key, a corresponding first post-quantum key exchange notification is constructed and sent to the message responder, so that the message responder receives the current first post-quantum key exchange notification, uses the post-quantum key encapsulation public key to encrypt the corresponding temporary shared key to generate a first post-quantum key ciphertext, and constructs a first key exchange response based on the first post-quantum key ciphertext and sends it to the message initiator. The system determines a new post-quantum key encapsulation public key and its own first post-quantum signature certificate based on the post-quantum key encapsulation algorithm. It then generates a first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys. Finally, it constructs a second post-quantum key exchange notification based on the new post-quantum key encapsulation public key, the first post-quantum signature certificate, and the first post-quantum signature result, and sends it to the message responder. The message responder receives the second post-quantum key exchange notification, encrypts the new temporary shared key using the new post-quantum key encapsulation public key to generate a second post-quantum key ciphertext, generates a second post-quantum signature result based on its own second post-quantum signature certificate and all temporary shared keys, and constructs a second key exchange response based on the second post-quantum key ciphertext, the second post-quantum signature certificate, and the second post-quantum signature result, sending it to the message initiator. Based on the Internet security association and key management protocol, the authentication between itself and the message responder is performed according to the second post-quantum key exchange notification and the second key exchange response.

2. The key exchange method according to claim 1, characterized in that, Also includes: Collect all the temporary shared keys currently received by the message initiator, and generate the current base key using the random number in the initial interaction message between the initiator and the responder and all the temporary shared keys currently received.

3. The key exchange method according to claim 2, characterized in that, The process of constructing the corresponding post-quantum key exchange notification based on each of the post-quantum key encapsulated public keys and sending it to the message responder includes: Based on the public keys of each of the post-quantum key encapsulations, construct the corresponding post-quantum key exchange notification, determine the current reference key of the message initiator, and encrypt the post-quantum key exchange notification based on the reference key to obtain the notification ciphertext; The ciphertext of the notification is sent to the message responder so that the message responder can receive and decrypt the ciphertext of the notification to obtain the post-quantum key exchange notification. The message responder then uses the post-quantum key encapsulation public key to encrypt the corresponding temporary shared key to generate the post-quantum key ciphertext. Based on the post-quantum key ciphertext, the message responder constructs the key exchange response and sends it to the message initiator.

4. The key exchange method according to claim 3, characterized in that, The notification message, constructed based on the Internet security association and key management protocol according to the security association payload and the corresponding post-quantum key exchange notification payload, is sent to the message responder. The message responder then returns a corresponding response message to the message initiator based on the security association payload and the post-quantum key exchange notification payload in the notification message, including: A message fragmentation notification payload is constructed, and a notification message is constructed based on the Internet Security Association and Key Management Protocol according to the Security Association payload, the Post-Quantum Key Exchange Notification payload, and the Message Fragmentation Notification payload. The notification message is then sent to the message responder, so that the message responder can return the corresponding response message to the message initiator according to the Security Association payload, the Post-Quantum Key Exchange Notification payload, and the Message Fragmentation Notification payload in the notification message. Accordingly, sending the encrypted notification to the message responder includes: Determine whether the message data volume of the post-quantum key exchange notification is greater than the data transmission volume of the preset maximum network transmission unit. If the message data volume is greater than the data transmission volume of the preset maximum network transmission unit, then determine whether the reference key currently exists. If the reference key exists, the notification ciphertext is fragmented based on the reference key, and the fragmented notification ciphertext is sent to the message responder.

5. The key exchange method according to claim 4, characterized in that, The step of fragmenting the ciphertext of the notification based on the base key and sending the fragmented ciphertext of the notification to the message responder includes: The notification ciphertext is fragmented based on the base key to obtain several fragment packets; The number of fragments in the ciphertext and the fragment number of each fragment are determined, and a first identifier corresponding to the number of fragments and a second identifier corresponding to the fragment number of each fragment are added to the target position of the corresponding fragment; the target position is the position after the message header of the fragment. An integrity verification key is generated based on the base key, and the integrity verification key is used to encrypt each of the fragment packets, and the encrypted fragment packets are sent to the message responder.

6. A key exchange method, characterized in that, Message responders used in Internet security association and key management protocols include: The system receives a notification message from the message initiator and sends a corresponding response message to the message initiator based on the security association payload and the post-quantum key exchange notification payload in the notification message. The notification message is a message constructed by the message initiator based on the Internet security association and key management protocol after constructing the security association payload based on the post-quantum key encapsulation algorithm and the preset national cryptographic algorithm, according to the security association payload and the corresponding post-quantum key exchange notification payload. Upon receiving the first post-quantum key exchange notification from the current message initiator, the system encrypts the corresponding temporary shared key using the post-quantum key encapsulation public key to generate the first post-quantum key ciphertext, and constructs a first key exchange response based on the first post-quantum key ciphertext, which is then sent to the message initiator. The first post-quantum key exchange notification is a message constructed and sent by the message initiator based on several post-quantum key encapsulation public keys determined according to the post-quantum key encapsulation algorithm. Upon receiving the second post-quantum key exchange notification from the message initiator, the system encrypts the new temporary shared key using the new post-quantum key encapsulation public key to generate the second post-quantum key ciphertext. Based on its own second post-quantum signature certificate and all temporary shared keys, the system generates a second post-quantum signature result. A second key exchange response is constructed based on the second post-quantum key ciphertext, the second post-quantum signature certificate, and the second post-quantum signature result and sent to the message initiator. The second post-quantum key exchange notification is a message constructed and sent by the message initiator after determining the new post-quantum key encapsulation public key and its own first post-quantum signature certificate according to the post-quantum key encapsulation algorithm, generating the first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys, and then constructing and sending the message based on the new post-quantum key encapsulation public key, the first post-quantum signature certificate, and the first post-quantum signature result. Based on the Internet security association and key management protocol, the authentication between itself and the message initiator is performed according to the second post-quantum key exchange notification and the second key exchange response.

7. A key exchange device, characterized in that, Message initiators used in Internet security association and key management protocols include: The first message construction module is used to construct a security association payload based on the post-quantum key encapsulation algorithm and the preset national cryptographic algorithm, and construct a notification message based on the Internet security association and key management protocol according to the security association payload and the corresponding post-quantum key exchange notification payload, and send the notification message to the message responder, so that the message responder can return a corresponding response message to the message initiator according to the security association payload and the post-quantum key exchange notification payload in the notification message; The first notification construction module is used to determine several post-quantum key encapsulation public keys according to the post-quantum key encapsulation algorithm, construct a corresponding first post-quantum key exchange notification based on each post-quantum key encapsulation public key, and send it to the message responder, so that the message responder receives the first post-quantum key exchange notification, uses the post-quantum key encapsulation public key to encrypt the corresponding temporary shared key to generate a first post-quantum key ciphertext, and constructs a first key exchange response based on the first post-quantum key ciphertext and sends it to the message initiator; The second notification construction module is used to determine a new post-quantum key encapsulation public key and its own first post-quantum signature certificate according to the post-quantum key encapsulation algorithm, generate a first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys, and construct a second post-quantum key exchange notification based on the new post-quantum key encapsulation public key, the first post-quantum signature certificate and the first post-quantum signature result and send it to the message responder, so that the message responder receives the second post-quantum key exchange notification, uses the new post-quantum key encapsulation public key to encrypt the new temporary shared key to generate a second post-quantum key ciphertext, generates a second post-quantum signature result based on its own second post-quantum signature certificate and all temporary shared keys, and constructs a second key exchange response based on the second post-quantum key ciphertext, the second post-quantum signature certificate and the second post-quantum signature result and sends it to the message initiator; The first authentication module is used to authenticate itself and the message responder based on the Internet security association and key management protocol, according to the second post-quantum key exchange notification and the second key exchange response.

8. A key exchange device, characterized in that, Message responders used in Internet security association and key management protocols include: The second message construction module is used to receive a notification message sent by the message initiator, and send a corresponding response message to the message initiator based on the security association payload and the post-quantum key exchange notification payload in the notification message; the notification message is a message constructed by the message initiator based on the Internet security association and key management protocol after constructing the security association payload based on the post-quantum key encapsulation algorithm and the preset national cryptographic algorithm, according to the security association payload and the corresponding post-quantum key exchange notification payload. The first response construction module is used to receive the first post-quantum key exchange notification from the current message initiator, encrypt the corresponding temporary shared key using the post-quantum key encapsulation public key to generate the first post-quantum key ciphertext, and construct the first key exchange response based on the first post-quantum key ciphertext and send it to the message initiator; the first post-quantum key exchange notification is a message constructed and sent by the message initiator based on several post-quantum key encapsulation public keys determined according to the post-quantum key encapsulation algorithm. The second response construction module is used to receive the second post-quantum key exchange notification from the message initiator, encrypt the new temporary shared key using the new post-quantum key encapsulation public key to generate the second post-quantum key ciphertext, generate the second post-quantum signature result based on its own second post-quantum signature certificate and all temporary shared keys, and construct a second key exchange response based on the second post-quantum key ciphertext, the second post-quantum signature certificate, and the second post-quantum signature result, and send it to the message initiator; the second post-quantum key exchange notification is a message constructed and sent by the message initiator after determining the new post-quantum key encapsulation public key and its own first post-quantum signature certificate according to the post-quantum key encapsulation algorithm, generating the first post-quantum signature result based on the first post-quantum signature certificate and all determined post-quantum key encapsulation public keys, and then constructing and sending the message based on the new post-quantum key encapsulation public key, the first post-quantum signature certificate, and the first post-quantum signature result. The second authentication module is used to authenticate itself and the message initiator based on the Internet security association and key management protocol, according to the second post-quantum key exchange notification and the second key exchange response.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the key exchange method as described in any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that, Used to store a computer program, which, when executed by a processor, implements the key exchange method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Communication data transmission method and device, equipment and storage medium

    CN119011287A

  • Data transmission method, device, and storage medium

    WO2024113724A1