Mobile communication method and mobile terminal based on anti-quantum and national secret algorithm hybrid
By integrating the quantum random number module and national cryptographic algorithm module of the SIM card into the mobile terminal, a hybrid verification public key and a signature private key are generated, which solves the security threat of communication between the mobile terminal and the server and realizes secure communication in a quantum computing environment.
Patent Information
- Application Number
- CN202411683927.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-22
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-11-22
AI Technical Summary
Existing mobile terminal-server communication faces security threats from man-in-the-middle attacks and quantum computing, and traditional encryption algorithms fail in a quantum computing environment.
A hybrid scheme based on quantum-resistant and national cryptographic algorithms is adopted. A hybrid verification public key and a signature private key are generated through the SIM card. By combining quantum random number and national cryptographic algorithm modules and quantum-resistant algorithm modules, secure communication between the mobile terminal and the server is achieved.
It ensures secure communication between mobile terminals and servers, maintaining data confidentiality and integrity even under quantum computing threats, thus enhancing defenses against quantum computing.
Smart Images

Figure CN119766474B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mobile communication technology, and in particular to a mobile communication method and mobile terminal based on a hybrid of quantum-resistant and Chinese cryptographic algorithms. Background Technology
[0002] With the rapid development of mobile internet and cloud computing, communication between mobile terminals and servers has become crucial in today's digital world. An increasing amount of sensitive information is being exchanged between mobile devices and servers, such as online payments, personal privacy data, and confidential corporate information. Mobile terminals often operate in public or untrusted networks, such as public Wi-Fi and 4G / 5G networks. The openness and complexity of these networks increase security threats such as man-in-the-middle attacks and eavesdropping. Therefore, ensuring the security of these communications is a critical task.
[0003] On the other hand, with the rapid development of quantum computing technology, the security of traditional encryption algorithms based on mathematical complexity (such as RSA and ECC) is facing unprecedented challenges. Quantum computers can efficiently factor large integers and discrete logarithms using Shor's algorithm, which may render encryption algorithms based on such problems ineffective in future quantum computing environments. Therefore, traditional encryption systems need to be upgraded to address the potential security threats posed by quantum computing. To address this issue, post-quantum cryptography (PQC) has emerged. The goal of post-quantum cryptography design is to maintain sufficient security even with the advent of quantum computers.
[0004] Therefore, this application proposes a secure communication method specifically for mobile terminals and servers based on a hybrid scheme of quantum-resistant and classical algorithms. Summary of the Invention
[0005] The purpose of this invention is to provide a mobile communication method and mobile terminal based on a hybrid of quantum-resistant and Chinese cryptographic algorithms, in order to solve the technical problems in the prior art.
[0006] In a first aspect, the present invention provides a mobile communication method based on a hybrid of quantum-resistant and Chinese cryptographic algorithms, for realizing communication between a mobile terminal and a server, the method comprising:
[0007] The mobile terminal generates a first hybrid verification public key and a first hybrid signature private key;
[0008] The device information of the mobile terminal and the first hybrid verification public key are sent to the server for signing to obtain a hybrid signature certificate.
[0009] The mobile terminal uses the second hybrid encryption public key on the server to execute a hybrid key encapsulation algorithm to obtain hybrid ciphertext and a first symmetric key. The mobile terminal uses the first hybrid signature private key to sign the hybrid ciphertext to obtain a hybrid signature.
[0010] The hybrid ciphertext, the hybrid signature, and the hybrid signature certificate are sent to the server. The hybrid signature certificate is validated by the server using a second hybrid verification public key. The hybrid signature is validated by the first hybrid verification public key embedded in the hybrid signature certificate. The hybrid ciphertext is decrypted by the server using a second hybrid decryption private key to obtain the first symmetric key. The mobile terminal and the server use the first symmetric key for encrypted communication.
[0011] In the mobile communication method based on a hybrid quantum-resistant and Chinese cryptographic algorithm as described above, preferably, the mobile terminal integrates a SIM card, the SIM card generates a quantum random number, and combines the Chinese cryptographic algorithm and the quantum-resistant algorithm to generate a first hybrid verification public key and a first hybrid signature private key. The first hybrid verification public key includes a first Chinese cryptographic algorithm verification public key and a first quantum-resistant algorithm verification public key, and the first hybrid signature private key includes a first Chinese cryptographic algorithm signature private key and a first quantum-resistant algorithm signature private key.
[0012] As described above, a mobile communication method based on a hybrid of quantum-resistant and Chinese cryptographic algorithms is preferably provided, wherein the SIM card includes a main control chip, a network communication module, an information storage module, a Chinese cryptographic algorithm module, a quantum-resistant algorithm module, a quantum random number module, and an SD card module. The network communication module, the information storage module, the Chinese cryptographic algorithm module, the quantum-resistant algorithm module, the quantum random number module, and the SD card module are respectively signal-connected to the main control chip, wherein:
[0013] The network communication module can be used to control the network communication of the SIM card;
[0014] The information storage module can be used to store program files and device information of the SIM card;
[0015] The national cryptographic algorithm module can be used to provide national cryptographic algorithms;
[0016] The quantum-resistant algorithm module can be used to provide quantum-resistant algorithms;
[0017] The quantum random number module can be used to provide quantum random numbers;
[0018] The SD card module can be used to store keys.
[0019] The mobile communication method based on a combination of quantum-resistant and Chinese cryptographic algorithms, as described above, preferably includes one or more of the following Chinese cryptographic algorithms: SM1, SM2, SM3, SM4, SM7, SM9, and ZUC, and the quantum-resistant algorithm includes one or more of the following: Kyber and Dilithum.
[0020] In the mobile communication method based on a hybrid quantum-resistant and Chinese cryptographic algorithm as described above, preferably, the mobile terminal sends a user registration request message to the server. The user registration request message includes device information, a first Chinese cryptographic algorithm verification public key, and a first quantum-resistant algorithm verification public key. The device information, the first Chinese cryptographic algorithm verification public key, and the first quantum-resistant algorithm verification public key are signed by the server using a second Chinese cryptographic algorithm signing private key and a second quantum-resistant algorithm signing private key to obtain the hybrid signature certificate. The hybrid signature certificate is then sent to the mobile terminal.
[0021] In the mobile communication method based on a hybrid quantum-resistant and Chinese cryptographic algorithm as described above, preferably, the second hybrid encryption public key includes a second Chinese cryptographic algorithm encryption public key and a second quantum-resistant algorithm encryption public key, wherein:
[0022] The mobile terminal uses the second national cryptographic algorithm encryption public key and the second quantum-resistant algorithm encryption public key to execute a hybrid key encapsulation algorithm to obtain hybrid ciphertext and a first symmetric key. The mobile terminal uses the first national cryptographic algorithm signature private key and the first quantum-resistant algorithm signature private key to sign the hybrid ciphertext to obtain a hybrid signature.
[0023] In the mobile communication method based on a hybrid of quantum-resistant and Chinese cryptographic algorithms as described above, preferably, the second hybrid verification public key includes a second Chinese cryptographic algorithm verification public key and a second quantum-resistant algorithm verification public key, and the second hybrid decryption private key includes a second Chinese cryptographic algorithm decryption private key and a second quantum-resistant algorithm decryption private key, wherein:
[0024] The hybrid signature certificate is validated by the server using the second national cryptographic algorithm verification public key and the second quantum-resistant algorithm verification public key. The hybrid signature is validated by the first national cryptographic algorithm verification public key and the first quantum-resistant algorithm verification public key built into the hybrid signature certificate. The hybrid ciphertext is decrypted by the server using the second national cryptographic algorithm decryption private key and the second quantum-resistant algorithm decryption private key to obtain the first symmetric key.
[0025] The mobile communication method based on a hybrid of quantum-resistant and national cryptographic algorithms, as described above, preferably includes...
[0026] The first hybrid encryption public key and the first hybrid decryption private key are generated by the server.
[0027] The first hybrid encryption public key and the device information are signed by the server using the second hybrid signature private key to obtain a hybrid key encapsulated certificate;
[0028] A second symmetric key is generated by the server, the first hybrid decryption private key is encrypted by the second symmetric key to obtain the first ciphertext, and the second symmetric key is encrypted by the first national cryptographic algorithm verification public key to obtain the second ciphertext.
[0029] The hybrid signature certificate, the hybrid key encapsulation certificate, the first ciphertext, and the second ciphertext are all sent to the mobile terminal. The mobile terminal uses the first national cryptographic algorithm signature private key to decrypt the second ciphertext to obtain the second symmetric key, and then uses the second symmetric key to decrypt the first ciphertext to obtain the first hybrid decryption private key.
[0030] The mobile communication method based on a hybrid of quantum-resistant and national cryptographic algorithms, as described above, preferably includes...
[0031] The first hybrid encryption public key includes a first national cryptographic algorithm encryption public key and a first quantum-resistant algorithm encryption public key;
[0032] The first hybrid decryption private key includes a first national cryptographic algorithm decryption private key and a first quantum-resistant algorithm decryption private key;
[0033] The second hybrid signature private key includes a second national cryptographic algorithm signature private key and a second quantum-resistant algorithm signature private key.
[0034] Secondly, the present invention provides a mobile terminal applied to the aforementioned mobile communication method.
[0035] Compared with existing technologies, the mobile communication method based on a combination of quantum-resistant and national cryptographic algorithms provided by this invention ensures secure communication between the client and the server, maintaining the confidentiality and integrity of data even under the threat of quantum computing. Attached Figure Description
[0036] Figure 1 This is a flowchart illustrating the principle of the user registration portion of the mobile communication method provided in this embodiment of the invention.
[0037] Figure 2 This is a flowchart illustrating the principle of the secure communication portion of the mobile communication method provided in this embodiment of the invention.
[0038] Figure 3 This is a structural block diagram of the SIM card provided in an embodiment of the present invention. Detailed Implementation
[0039] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0040] Firstly, referring to Figure 1 as well as Figure 2 As shown, this embodiment of the invention provides a mobile communication method based on a hybrid of quantum-resistant and national cryptographic algorithms, used to realize communication between a mobile terminal and a server. The mobile communication method includes a user registration part and a secure communication part, wherein:
[0041] [User Registration Section]
[0042] The user registration process includes the following steps:
[0043] Step S101: Key generation.
[0044] The mobile terminal generates a first hybrid verification public key and a first hybrid signature private key. Preferably, the mobile terminal has a built-in SIM card. The mobile terminal uses the quantum random number generation function of the SIM card, combined with the national cryptographic algorithm and the anti-quantum algorithm, to generate the first hybrid verification public key and the first hybrid signature private key as a hybrid signature public-private key pair.
[0045] The quantum random numbers generated by the SIM card are true random numbers based on the principles of quantum mechanics. The intrinsic randomness of quantum mechanics means that the results of some quantum experiments are unpredictable. This unpredictability is used to generate true random numbers. The random number sequence is unpredictable and non-repeatable.
[0046] The full name of the national cryptographic algorithm is the national commercial cryptographic algorithm. In the embodiments provided by this invention, the national cryptographic algorithm includes one or more of the following algorithms: SM1, SM2, SM3, SM4, SM7, SM9 and Zu Chongzhi Cryptographic Algorithm (ZUC). Preferably, the SM2 algorithm is used as an example for illustration. SM2 is an asymmetric encryption algorithm based on ECC (Elliptic Curve Cryptography) and includes functions such as digital signature, key exchange and public key encryption.
[0047] Quantum-resistant algorithms, also known as post-quantum cryptography (PQC), are a class of encryption algorithms designed to resist attacks by quantum computers. In the embodiments provided in this invention, quantum-resistant algorithms include one or more of Kyber and Dilithum algorithms.
[0048] In the embodiments provided by the present invention, the first hybrid verification public key includes a first national cryptographic algorithm verification public key and a first quantum-resistant algorithm verification public key, and the first hybrid signature private key includes a first national cryptographic algorithm signature private key and a first quantum-resistant algorithm signature private key. The first national cryptographic algorithm verification public key and the first national cryptographic algorithm signature private key are both generated by the SM2 algorithm, and the first quantum-resistant algorithm verification public key and the first quantum-resistant algorithm signature private key are both generated by the Dilithum algorithm.
[0049] The hybrid signature public-private key pair provided by the SIM card combines the advantages of Chinese cryptographic algorithms and quantum-resistant algorithms through the use of SM2 and Dilithium hybrid signatures, thereby improving overall security. This hybrid signature method combines the efficiency of SM2 with the post-quantum security of Dilithium, providing a robust secure communication solution. It can enhance the defense against quantum computing threats while maintaining compatibility with existing cryptographic infrastructure, preparing for future quantum computing threats. Through SM2+Dilithium hybrid signatures, the defense against quantum computing threats can be enhanced on the basis of existing Chinese cryptographic algorithms, ensuring long-term data security.
[0050] In one feasible implementation, refer to Figure 3 As shown, the SIM card in the mobile terminal integrates multiple security functions for handling network communication, data storage, encryption operations, and key management. Specifically, the SIM card includes a main control chip, a network communication module, an information storage module, a national cryptographic algorithm module, a quantum-resistant algorithm module, a quantum random number module, and an SD card module. These modules are all connected to the main control chip via signals.
[0051] The main control chip, as the central processing unit of the SIM card, is responsible for controlling and coordinating all functions of the SIM card, managing the network communication module to ensure that the SIM card can perform operations such as internet access and making phone calls; controlling the generation of the quantum random number module to provide quantum random numbers for the encryption process; managing the storage operations of the SD card module, including key storage and backup; and coordinating the operation of the national cryptographic algorithm and the quantum-resistant algorithm.
[0052] The network communication module can be used to control the network communication of the SIM card, and is responsible for the network connection of the SIM card, including data transmission and voice calls. At the same time, it works with the main control chip to execute network-related instructions.
[0053] The information storage module can be used to store program files and SIM card device information. It is divided into two parts: one part is used to store program files, and the other part is used to store sensitive information, such as mobile phone number, card information, PIN code, certificate and public and private key information, to ensure the secure storage and access of all sensitive data.
[0054] The national cryptographic algorithm module can be used to provide national cryptographic algorithms and execute encryption algorithms such as SM2, SM3, and SM4 issued by the State Cryptography Administration for data encryption, decryption, digital signature, and verification.
[0055] The quantum-resistant algorithm module provides quantum-resistant algorithms, such as Kyber and Dilithium, to ensure data security in the era of quantum computing. It is also used to generate and verify quantum-resistant signatures.
[0056] The quantum random number module can be used to provide quantum random numbers, which are unpredictable, high-quality, truly random numbers used for key generation and secure communication in encryption processes.
[0057] The SD card module can be used to store keys for large-scale key storage and backup, preventing key loss, and works with the main control chip to perform storage and backup operations.
[0058] The entire system, coordinated by the main control chip, integrates network communication, data storage, encryption operations, and key management. This not only enhances the security of the SIM card but also ensures long-term security against quantum computing threats. By using national cryptographic algorithms and quantum-resistant algorithms, the SIM card provides robust security, protecting user data and communication security. Furthermore, the introduction of the SD card module provides additional key storage and backup solutions, further enhancing the SIM card's reliability and data protection capabilities.
[0059] Step S102: Send a user registration request message.
[0060] The mobile terminal sends a user registration request message to the server. The user registration request message includes device information, the first national cryptographic algorithm verification public key, and the first quantum-resistant algorithm verification public key.
[0061] Step S103: Generate hybrid signature certificate.
[0062] The device information, the first national cryptographic algorithm verification public key, and the first quantum-resistant algorithm verification public key are signed by the server using the second national cryptographic algorithm signing private key and the second quantum-resistant algorithm signing private key to obtain a hybrid signature certificate. This step ensures the verification of the user's identity and the trustworthiness of the public key.
[0063] Preferably, the private key for the second national cryptographic algorithm signature is generated using the SM2 algorithm, and the private key for the second quantum-resistant algorithm signature is generated using the Dilithium algorithm.
[0064] Step S104: Key encapsulation.
[0065] The server generates a first hybrid encryption public key and a first hybrid decryption private key, which are used as a hybrid key to encapsulate the public-private key pair. The first hybrid encryption public key includes a first national cryptographic algorithm encryption public key and a first quantum-resistant algorithm encryption public key. The first hybrid decryption private key includes a first national cryptographic algorithm decryption private key and a first quantum-resistant algorithm decryption private key. Both the first national cryptographic algorithm encryption public key and the first national cryptographic algorithm decryption private key are generated using the SM2 algorithm. Both the first quantum-resistant algorithm encryption public key and the first quantum-resistant algorithm decryption private key are generated using the Kyber algorithm.
[0066] Step S105: Generate certificate by encapsulating the hybrid key.
[0067] The first hybrid encryption public key and device information are signed by the server using the second hybrid signature private key to obtain a hybrid key encapsulated certificate. The second hybrid signature private key includes a second national cryptographic algorithm signature private key and a second quantum-resistant algorithm signature private key. The second national cryptographic algorithm signature private key is generated using the SM2 algorithm, and the second quantum-resistant algorithm signature private key is generated using the Dilithium algorithm.
[0068] Step S106: Key encryption.
[0069] The server generates a second symmetric key. The first hybrid decryption private key is encrypted with the second symmetric key to obtain the first ciphertext. The second symmetric key is then encrypted with the first national cryptographic algorithm verification public key to obtain the second ciphertext. This multi-layer encryption method increases the security of data transmission.
[0070] Step S107: Send the certificate and ciphertext.
[0071] The hybrid signature certificate, the hybrid key encapsulation certificate, the first ciphertext, and the second ciphertext are all sent to the mobile terminal.
[0072] Step S108: Key decryption.
[0073] The mobile terminal uses the first national cryptographic algorithm signature private key to decrypt the second ciphertext to obtain the second symmetric key, and then uses the second symmetric key to decrypt the first ciphertext to obtain the first hybrid decryption private key. This process ensures the secure transmission and correct decryption of the key.
[0074] Through these steps, the quantum encryption process utilizes the principles of quantum mechanics, combined with advanced encryption algorithms, to provide a high level of security for data transmission. Quantum key distribution technology ensures the security of the keys, while hybrid encryption technology improves both the security and efficiency of data transmission. This strategy, combining quantum technology with traditional encryption methods, can effectively resist security threats in the era of quantum computing.
[0075] [Secure Communication Section]
[0076] Reference Figure 2As shown, the secure communication steps include:
[0077] Step S201: Mobile terminal configuration.
[0078] The mobile terminal has a built-in server-side public key for verification of the second national cryptographic algorithm, a public key for verification of the second quantum-resistant algorithm, a public key for encryption of the second national cryptographic algorithm, and a public key for encryption of the second quantum-resistant algorithm. In the embodiments provided by the present invention, the public key for verification of the second national cryptographic algorithm and the public key for encryption of the second national cryptographic algorithm are generated using the SM2 algorithm, the public key for verification of the second quantum-resistant algorithm is generated using the Dilithium algorithm, and the public key for encryption of the second quantum-resistant algorithm is generated using the Kyber algorithm.
[0079] Step S202: Decryption and signing.
[0080] The mobile terminal uses the server-side second national cryptographic algorithm encryption public key and second quantum-resistant algorithm encryption public key to execute a hybrid key encapsulation algorithm to obtain hybrid ciphertext and a first symmetric key. The use of the SM2+Kyber hybrid key encapsulation algorithm ensures that data is encrypted during transmission, preventing decryption or tampering even if an attacker intercepts the communication data, thus effectively preventing man-in-the-middle attacks.
[0081] The mobile terminal uses the first national cryptographic algorithm signature private key and the first quantum-resistant algorithm signature private key to sign the mixed ciphertext to obtain a mixed signature. The mixed signature is the process of signing the encrypted mixed ciphertext using the mobile terminal's signature private key. The signature verifies the source and integrity of the message, ensuring that the message has not been tampered with during transmission.
[0082] Step S203: Send a secure communication request message.
[0083] The mobile terminal sends a secure communication request message to the server. The secure communication request message contains mixed ciphertext, mixed signature, and mixed signature certificate, which are sent to the server.
[0084] When a mobile terminal sends a secure communication request message, it includes a signature and verification certificate generated using its own signature private key. After receiving the request, the server verifies the validity of the terminal's verification certificate and signature to ensure the authenticity of the identities of both parties and prevent attackers from impersonating the communicating parties.
[0085] Step S204: Server-side verification.
[0086] The hybrid signature certificate is validated by the server using the second national cryptographic algorithm to verify the public key and the second quantum-resistant algorithm to verify the validity of the public key.
[0087] The hybrid signature is validated by the first national cryptographic algorithm verification public key and the first quantum-resistant algorithm verification public key built into the hybrid signature certificate.
[0088] The mixed ciphertext is decrypted by the server using the second national cryptographic algorithm and the second anti-quantum algorithm to obtain the first symmetric key.
[0089] The server first verifies the validity of the mobile terminal's verification certificate using its own verification public key, and then verifies the validity of the signature using the verification public key from the hybrid signature certificate. This ensures that the signature was indeed generated by the mobile terminal and that the message has not been tampered with during transmission. The server then uses its own decryption private key to decrypt the ciphertext, obtaining the first symmetric key, which is used for subsequent secure communication to ensure the confidentiality of the communication.
[0090] Step S205: Implement encrypted communication.
[0091] The mobile terminal and the server use a first symmetric key for encrypted communication.
[0092] This process ensures the security of key exchange and data transmission by using hybrid key encapsulation and hybrid signature technology.
[0093] Secondly, the present invention provides a mobile terminal applied to the aforementioned mobile communication method.
[0094] The above description, based on the embodiments shown in the figures, details the structure, features, and effects of the present invention. The above description is only a preferred embodiment of the present invention, but the present invention is not limited to the scope of implementation shown in the figures. Any changes made in accordance with the concept of the present invention, or equivalent embodiments modified to have equivalent changes, that do not exceed the spirit covered by the specification and figures, should be within the protection scope of the present invention.
Claims
1. A mobile communication method based on a hybrid of quantum-resistant and national cryptographic algorithms, used to realize communication between a mobile terminal and a server, characterized in that, The methods include: The mobile terminal generates a first hybrid verification public key and a first hybrid signature private key; The device information of the mobile terminal and the first hybrid verification public key are sent to the server for signing to obtain a hybrid signature certificate. The mobile terminal uses the second hybrid encryption public key on the server to execute a hybrid key encapsulation algorithm to obtain hybrid ciphertext and a first symmetric key. The mobile terminal uses the first hybrid signature private key to sign the hybrid ciphertext to obtain a hybrid signature. The hybrid ciphertext, the hybrid signature, and the hybrid signature certificate are sent to the server. The hybrid signature certificate is validated by the server using a second hybrid verification public key. The hybrid signature is validated by the first hybrid verification public key embedded in the hybrid signature certificate. The hybrid ciphertext is decrypted by the server using a second hybrid decryption private key to obtain the first symmetric key. The mobile terminal and the server use the first symmetric key for encrypted communication.
2. The method according to claim 1, characterized in that: The mobile terminal integrates a SIM card, which generates a quantum random number and combines it with a national cryptographic algorithm and a quantum-resistant algorithm to generate the first hybrid verification public key and the first hybrid signature private key. The first hybrid verification public key includes a first national cryptographic algorithm verification public key and a first quantum-resistant algorithm verification public key, and the first hybrid signature private key includes a first national cryptographic algorithm signature private key and a first quantum-resistant algorithm signature private key.
3. The method according to claim 2, characterized in that: The SIM card includes a main control chip, a network communication module, an information storage module, a national cryptographic algorithm module, a quantum-resistant algorithm module, a quantum random number module, and an SD card module. The network communication module, the information storage module, the national cryptographic algorithm module, the quantum-resistant algorithm module, the quantum random number module, and the SD card module are respectively connected to the main control chip via signals. The network communication module can be used to control the network communication of the SIM card; The information storage module can be used to store program files and device information of the SIM card; The national cryptographic algorithm module can be used to provide national cryptographic algorithms; The quantum-resistant algorithm module can be used to provide quantum-resistant algorithms; The quantum random number module can be used to provide quantum random numbers; The SD card module can be used to store keys.
4. The method according to claim 3, characterized in that: The national cryptographic algorithm includes one or more of SM1, SM2, SM3, SM4, SM7, SM9 and ZUC, and the quantum-resistant algorithm includes one or more of Kyber and Dilithum.
5. The method according to claim 2, characterized in that: The mobile terminal sends a user registration request message to the server. The user registration request message includes device information, a first national cryptographic algorithm verification public key, and a first quantum-resistant algorithm verification public key. The device information, the first national cryptographic algorithm verification public key, and the first quantum-resistant algorithm verification public key are signed by the server using a second national cryptographic algorithm signing private key and a second quantum-resistant algorithm signing private key to obtain the hybrid signature certificate. The hybrid signature certificate is then sent to the mobile terminal.
6. The method according to claim 2, characterized in that: The second hybrid encryption public key includes a second national cryptographic algorithm encryption public key and a second quantum-resistant algorithm encryption public key, wherein: The mobile terminal uses the second national cryptographic algorithm encryption public key and the second quantum-resistant algorithm encryption public key to execute a hybrid key encapsulation algorithm to obtain hybrid ciphertext and a first symmetric key. The mobile terminal uses the first national cryptographic algorithm signature private key and the first quantum-resistant algorithm signature private key to sign the hybrid ciphertext to obtain a hybrid signature.
7. The method according to claim 2, characterized in that: The second hybrid verification public key includes a second national cryptographic algorithm verification public key and a second quantum-resistant algorithm verification public key; the second hybrid decryption private key includes a second national cryptographic algorithm decryption private key and a second quantum-resistant algorithm decryption private key, wherein: The hybrid signature certificate is validated by the server using the second national cryptographic algorithm to verify the public key and the second quantum-resistant algorithm to verify the public key. The hybrid signature is validated by the first national cryptographic algorithm to verify the public key and the first quantum-resistant algorithm to verify the public key built into the hybrid signature certificate. The hybrid ciphertext is decrypted by the server using the second national cryptographic algorithm to decrypt the private key and the second quantum-resistant algorithm to decrypt the private key to obtain the first symmetric key.
8. The method according to claim 2, characterized in that: The first hybrid encryption public key and the first hybrid decryption private key are generated by the server. The first hybrid encryption public key and the device information are signed by the server using the second hybrid signature private key to obtain a hybrid key encapsulated certificate; A second symmetric key is generated by the server, the first hybrid decryption private key is encrypted by the second symmetric key to obtain the first ciphertext, and the second symmetric key is encrypted by the first national cryptographic algorithm verification public key to obtain the second ciphertext. The hybrid signature certificate, the hybrid key encapsulation certificate, the first ciphertext, and the second ciphertext are all sent to the mobile terminal. The mobile terminal uses the first national cryptographic algorithm signature private key to decrypt the second ciphertext to obtain the second symmetric key, and then uses the second symmetric key to decrypt the first ciphertext to obtain the first hybrid decryption private key.
9. The method according to claim 8, characterized in that: The first hybrid encryption public key includes a first national cryptographic algorithm encryption public key and a first quantum-resistant algorithm encryption public key; The first hybrid decryption private key includes a first national cryptographic algorithm decryption private key and a first quantum-resistant algorithm decryption private key; The second hybrid signature private key includes a second national cryptographic algorithm signature private key and a second quantum-resistant algorithm signature private key.
10. A mobile terminal, comprising a SIM card, characterized in that, The mobile communication method applicable to any one of claims 1-9.
Citation Information
Patent Citations
Certificate authentication system and authentication method based on post-quantum signature
CN116388986A
National password IPSec secure communication method supporting quantum cryptography resistance
CN118631448A