Short message security transmission method and system based on post-quantum algorithm and electronic device
By employing a hybrid public-key and private-key encryption method based on post-quantum algorithms, combined with national cryptographic algorithms and quantum-resistant cryptographic algorithms, the security problem of SMS encryption in a quantum computing environment is solved, achieving quantum-resistant protection and information integrity verification of SMS data.
Patent Information
- Application Number
- CN202411801710.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-12-09
AI Technical Summary
Existing SMS encryption algorithms are vulnerable to quantum computing threats, have low security, and cannot effectively prevent information from being intercepted or tampered with.
A hybrid public-key and private-key encryption method based on post-quantum algorithms is adopted, combining national cryptographic algorithms and quantum-resistant cryptographic algorithms for key encapsulation and decryption to ensure the secure transmission of SMS data.
It provides quantum-resistant key negotiation functionality to prevent information from being intercepted or tampered with, thereby enhancing the security of SMS transmission.
Smart Images

Figure CN119766502B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum computer technology, and in particular to a secure SMS transmission method, system, and electronic device based on a post-quantum algorithm. Background Technology
[0002] With the rapid development of communication technology, the security of SMS messages during transmission is of paramount importance. Therefore, SMS services require strong encryption protection during transmission to prevent interception or tampering. However, traditional encryption algorithms (such as RSA and ECC) are becoming increasingly insecure in the face of quantum computing. Quantum computing can quickly crack these algorithms using Shor's algorithm, making current SMS messages easily tampered with.
[0003] The main challenge in encrypting SMS data lies in balancing security, performance, and network compatibility. While PQC (PostQuantum Cryptography) algorithms may increase the size of encryption keys and signatures, they have gradually become suitable for SMS transmission through optimization of computational performance and communication protocols. Therefore, how to achieve a smooth transition to secure information transmission based on postquantum cryptography combined with traditional encryption to prevent information interception or tampering is a pressing issue that needs to be addressed. Summary of the Invention
[0004] This invention provides a secure SMS transmission method, system, and electronic device based on a post-quantum algorithm, which solves the problem of low SMS transmission security caused by the inability to achieve quantum-resistant security protection during SMS transmission in the prior art.
[0005] This specification provides an embodiment of a secure SMS transmission method based on a post-quantum algorithm, applied to a first terminal, comprising:
[0006] The system acquires signed SMS data and uses the first hybrid public key provided by the second terminal to perform key encapsulation calculations to obtain the key-encapsulated ciphertext and symmetric key; wherein the first hybrid public key is a hybrid public key generated based on the first national cryptographic algorithm and the first quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on the first international algorithm and the first quantum-resistant cryptographic encapsulation algorithm.
[0007] The symmetric key is used to encrypt the signed SMS data to obtain the SMS data ciphertext;
[0008] The key-encapsulated ciphertext and the SMS data ciphertext are sent to the second terminal. The second terminal uses the first hybrid private key provided by the second terminal to decapsulate the key-encapsulated ciphertext to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain the SMS data plaintext. The first hybrid private key is a hybrid private key generated based on the first national cryptographic algorithm and the first quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on the first international algorithm and the first quantum-resistant cryptographic encapsulation algorithm.
[0009] Optionally, the first terminal includes a second hybrid public key, and the second terminal includes a first hybrid public key. The second hybrid public key is composed of a public key generated by a second national cryptographic algorithm and a public key generated by a first quantum-resistant cryptographic signature algorithm in the first terminal, or it is composed of a public key generated by a second international algorithm and a public key generated by a first quantum-resistant cryptographic signature algorithm.
[0010] Before obtaining the signed SMS data, the method further includes:
[0011] The first terminal sends a certificate request for the first hybrid public key to the CA authority, and the second terminal sends a certificate request for the second hybrid public key to the CA authority;
[0012] The CA (Certificate Authority) issues certificates to the first hybrid public key and the second hybrid public key based on the certificate requests of the first hybrid public key and the second hybrid public key, thereby making the first hybrid public key and the second hybrid public key trustworthy.
[0013] Optionally, obtaining the signed SMS data includes:
[0014] The SMS data is calculated according to the first preset digest algorithm to obtain the information digest of the SMS data;
[0015] The message digest is signed using the second hybrid private key provided by the first terminal to obtain signed SMS data; wherein the second hybrid private key consists of a private key generated by a second national cryptographic algorithm and a private key generated by a first quantum-resistant cryptographic signature algorithm in the first terminal, or consists of a private key generated by a second international algorithm and a private key generated by a first quantum-resistant cryptographic signature algorithm.
[0016] Optionally, the symmetric key is a first symmetric key or a second symmetric key; the step of using the first hybrid public key provided by the second terminal to perform key encapsulation calculation to obtain the key-encapsulated ciphertext and the symmetric key includes:
[0017] A first random number is generated by calling a first random number generator, and the first random number is encrypted using the public key generated by the first national cryptographic algorithm and the first national cryptographic algorithm, or the first random number is encrypted using the public key generated by the first international algorithm and the first international algorithm to obtain a first encryption key;
[0018] A second random number generator is invoked to generate a second random number. A subkey is generated based on the second random number and the first quantum-resistant cryptographic encapsulation algorithm. The subkey is then encrypted using the public key generated by the first quantum-resistant cryptographic encapsulation algorithm in the second terminal and the first quantum-resistant cryptographic encapsulation algorithm to obtain a second encryption key. The first encryption key and the second encryption key constitute the key encapsulation ciphertext.
[0019] A first symmetric key is generated based on the subkey, the first random number, and the third national cryptographic algorithm in the first terminal; or a second symmetric key is generated based on the subkey, the first random number, and the third international algorithm in the first terminal.
[0020] Optionally, the second terminal uses the first hybrid private key provided by the second terminal to deseal the key-encapsulated ciphertext to obtain the symmetric key, including:
[0021] The second terminal uses the private key generated by the first national cryptographic algorithm and the first national cryptographic algorithm to decrypt the first encryption key, or the second terminal uses the private key generated by the first international algorithm and the first international algorithm to decrypt the first encryption key to obtain the first random number;
[0022] The second terminal uses the private key generated by the first quantum-resistant cryptographic encapsulation algorithm in the second terminal and the first quantum-resistant cryptographic encapsulation algorithm to decrypt the second encryption key to obtain the subkey;
[0023] The second terminal generates a first symmetric key based on a first random number, the subkey, and the fourth national cryptographic algorithm in the second terminal, or the second terminal generates a second symmetric key based on a first random number, the subkey, and the fourth international algorithm in the second terminal.
[0024] Optionally, the step of decrypting the ciphertext of the SMS data based on the symmetric key to obtain the plaintext of the SMS data includes:
[0025] The ciphertext of the SMS data is decrypted using the symmetric key and the fifth national cryptographic algorithm in the second terminal to obtain the plaintext of the SMS data.
[0026] Optionally, after decrypting the ciphertext of the SMS data based on the symmetric key to obtain the plaintext of the SMS data, the method further includes:
[0027] The second terminal calculates the message digest of the SMS data plaintext according to the second preset digest algorithm;
[0028] The second terminal uses the second hybrid public key to sign and verify the message digest of the plaintext SMS data;
[0029] When the signature verification is successful, the plaintext SMS data is marked as trusted data.
[0030] Optionally, the first terminal and the second terminal communicate based on a SIM card, which is one of a regular SIM card, an ISIM card, an ESIM card, a Super SIM card, a TF card, or an NM card.
[0031] This specification provides an embodiment of a secure SMS transmission method based on a post-quantum algorithm, applied to a second terminal, comprising:
[0032] The system acquires signed SMS data and uses the third hybrid public key provided by the first terminal to perform key encapsulation calculations to obtain the key-encapsulated ciphertext and symmetric key; wherein the third hybrid public key is a hybrid public key generated based on the sixth national cryptographic algorithm and the second quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on the sixth international algorithm and the second quantum-resistant cryptographic encapsulation algorithm.
[0033] The symmetric key is used to encrypt the signed SMS data to obtain the SMS data ciphertext;
[0034] The key-encapsulated ciphertext and the SMS data ciphertext are sent to the first terminal. The first terminal uses the third hybrid private key provided by the first terminal to decapsulate the key-encapsulated ciphertext to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain the SMS data plaintext. The third hybrid private key is a hybrid private key generated based on the sixth national cryptographic algorithm and the second quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on the fifth international algorithm and the second quantum-resistant cryptographic encapsulation algorithm.
[0035] This specification also provides an embodiment of a secure SMS transmission system based on a post-quantum algorithm, including a first terminal and a second terminal, the system comprising:
[0036] The first terminal acquires signed SMS data and uses the first hybrid public key provided by the second terminal to perform key encapsulation calculation to obtain key-encapsulated ciphertext and symmetric key; wherein, the first hybrid public key is a hybrid public key generated based on the first national cryptographic algorithm and the first quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on the first international algorithm and the first quantum-resistant cryptographic encapsulation algorithm;
[0037] The first terminal uses the symmetric key to encrypt the signed SMS data to obtain SMS data ciphertext;
[0038] The first terminal sends the key-encapsulated ciphertext and the SMS data ciphertext to the second terminal;
[0039] The second terminal uses the first hybrid private key provided by the second terminal to deseal the key-encapsulated ciphertext to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain the SMS data plaintext; wherein, the first hybrid private key is a hybrid private key generated based on the first national cryptographic algorithm and the first quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on the first international algorithm and the first quantum-resistant cryptographic encapsulation algorithm.
[0040] An electronic device includes a memory and a processor, the memory storing computer instructions, and the processor being configured to execute the computer instructions to perform the method described above.
[0041] A storage medium, characterized in that the storage medium stores computer instructions, the computer instructions being configured to execute the method described above at runtime.
[0042] Its beneficial effects are as follows: This application first obtains signed SMS data, and uses a first hybrid public key provided by a second terminal to perform key encapsulation calculation to obtain key-encapsulated ciphertext and a symmetric key; it then uses the symmetric key to encrypt the signed SMS data to obtain SMS data ciphertext; the key-encapsulated ciphertext and the SMS data ciphertext are sent to the second terminal, and the second terminal uses a first hybrid private key provided by the second terminal to decapsulate the key-encapsulated ciphertext to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain SMS data plaintext; by adopting a hybrid key encryption method, it provides a quantum-safe key negotiation function for SMS, provides quantum attack-resistant protection for SMS content, and, combined with signature verification, prevents information from being intercepted or tampered with, further improving the security of SMS transmission. Attached Figure Description
[0043] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0044] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0045] Figure 1 A flowchart of a secure SMS transmission method applied to a first terminal, provided as an embodiment of this specification;
[0046] Figure 2 A schematic diagram of certificate issuance provided for an embodiment of this specification;
[0047] Figure 3 This is a schematic diagram illustrating a certificate query provided in an embodiment of this specification.
[0048] Figure 4 A flowchart illustrating a secure SMS transmission method for a second terminal, provided as an embodiment of this specification;
[0049] Figure 5 A schematic diagram of a secure SMS transmission system based on a post-quantum algorithm is provided for embodiments of this specification.
[0050] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this specification;
[0051] Figure 7 This is a schematic diagram of a computer-readable medium provided for embodiments of this specification. Detailed Implementation
[0052] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0053] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0054] It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps described in these embodiments do not limit the scope of the invention.
[0055] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the invention or its application or use.
[0056] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.
[0057] In all the examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values.
[0058] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.
[0059] Reference Figure 1A flowchart of a secure SMS transmission method applied to a first terminal, provided in an embodiment of this specification, includes: S101: acquiring signed SMS data and performing key encapsulation calculation using a first hybrid public key provided by a second terminal to obtain key-encapsulated ciphertext and a symmetric key; wherein, the first hybrid public key is a hybrid public key generated based on a first national cryptographic algorithm and a first quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on a first international algorithm and a first quantum-resistant cryptographic encapsulation algorithm; S102: encrypting the signed SMS data using the symmetric key to obtain SMS data ciphertext; S103: sending the key-encapsulated ciphertext and the SMS data ciphertext to the second terminal, wherein the second terminal uses a first hybrid private key provided by the second terminal to decapsulate the key-encapsulated ciphertext to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain SMS data plaintext; wherein, the first hybrid private key is a hybrid private key generated based on a first national cryptographic algorithm and a first quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on a first international algorithm and a first quantum-resistant cryptographic encapsulation algorithm.
[0060] In one optional embodiment, the first terminal first acquires signed SMS data. Simultaneously, it uses a first hybrid public key provided by the second terminal to perform key encapsulation calculation to obtain key encapsulation ciphertext C and symmetric key K. Then, the first terminal uses symmetric key K to encrypt the signed SMS data to obtain SMS data ciphertext, and sends the key encapsulation ciphertext C and SMS data ciphertext to the second terminal. The second terminal uses a first hybrid private key provided by the second terminal to decapsulate the key encapsulation ciphertext C to obtain symmetric key K. Finally, the second terminal decrypts the SMS data ciphertext based on symmetric key K to obtain SMS data plaintext, thereby completing the encrypted transmission of the SMS. The SMS data adopts a hybrid key encryption method, providing quantum-safe key negotiation functionality for the SMS, protecting the SMS content from quantum attacks, and improving the security of SMS transmission. It should be noted that the first hybrid public key is a hybrid public key generated based on the first national cryptographic algorithm and the first quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on the first international algorithm and the first quantum-resistant cryptographic encapsulation algorithm. The first hybrid private key is a hybrid private key generated based on the first national cryptographic algorithm and the first quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on the first international algorithm and the first quantum-resistant cryptographic encapsulation algorithm. Taking the first national cryptographic algorithm as SM2 and the first quantum-resistant cryptographic encapsulation algorithm as Kyber as an example, the first hybrid public key includes the public key K1 generated by the SM2 algorithm and the public key K2 generated by the Kyber algorithm. The first hybrid private key includes the private key S1 generated by the SM2 algorithm and the private key S2 generated by the Kyber algorithm.
[0061] Optionally, the first terminal includes a second hybrid public key, and the second terminal includes a first hybrid public key. The second hybrid public key is composed of a public key generated by a second national cryptographic algorithm and a public key generated by a first quantum-resistant cryptographic signature algorithm in the first terminal, or it is composed of a public key generated by a second international algorithm and a public key generated by a first quantum-resistant cryptographic signature algorithm. Before obtaining the signed SMS data, the method further includes: the first terminal sending a certificate request for the first hybrid public key to a CA (Certificate Authority), and the second terminal sending a certificate request for the second hybrid public key to the CA. The CA issues certificates to the first hybrid public key and the second hybrid public key based on the certificate requests for the first and second hybrid public keys to make the first hybrid public key and the second hybrid public key trustworthy.
[0062] In one alternative embodiment, such as Figure 2 As shown, to ensure the trustworthiness of the first and second hybrid public keys, the first terminal needs to send the second hybrid public key to the CA (Certificate Authority), and the second terminal needs to send the first hybrid public key to the CA. This allows the CA to issue certificates for the first and second hybrid public keys. Specifically, the first terminal receives a certificate for the first hybrid public key from the CA, and the second terminal receives a certificate for the second hybrid public key from the CA. Only after certificate issuance can the trustworthiness of the first and second hybrid public keys be ensured, allowing for subsequent encryption, signing, and other operations. This ensures the security of hybrid key usage and improves the security of SMS data transmission. It should be noted that the second hybrid public key consists of a public key generated by the second national cryptographic algorithm and a public key generated by the first quantum-resistant cryptographic signature algorithm in the first terminal, or a public key generated by the second international algorithm and a public key generated by the first quantum-resistant cryptographic signature algorithm. Taking the SM2 algorithm as the first national cryptographic algorithm and the Kyber algorithm as the first quantum-resistant cryptographic encapsulation algorithm as an example, the second hybrid public key contains a public key K3 generated by the SM2 algorithm and a public key K4 generated by the Kyber algorithm.
[0063] In one optional embodiment, after obtaining the certificate, the first terminal and the second terminal expose their hybrid public key certificates to the communication server. The first terminal can obtain the hybrid public key certificate of the second terminal's second hybrid public key through the communicator. Taking user terminal a and user terminal b as an example, the communication server is selected as an SMS center server, such as... Figure 3As shown, user terminal A submits its hybrid public key certificate to the SMS center server. User terminal B can directly query the hybrid public key certificate provided by user terminal A through user terminal A's mobile phone number on the SMS center server. Therefore, user terminal B can use the queried hybrid public key certificate provided by user terminal A to perform corresponding signature verification on the SMS data sent by user terminal A. Similarly, the second terminal can obtain the hybrid public key certificate of the first terminal's first hybrid public key through the communication server; this will not be elaborated further here.
[0064] Because the certificate contains the user's mobile phone number, any entity that knows the user's mobile phone number can query the SMS center server for the corresponding hybrid public key certificate, which facilitates subsequent operations such as signature verification and encapsulation using the hybrid public key.
[0065] Optionally, obtaining the signed SMS data includes: calculating the SMS data according to a first preset digest algorithm to obtain a message digest of the SMS data; signing the message digest using a second hybrid private key provided by the first terminal to obtain the signed SMS data; wherein the second hybrid private key consists of a private key generated by a second national cryptographic algorithm in the first terminal and a private key generated by a first quantum-resistant cryptographic signature algorithm, or consists of a private key generated by a second international algorithm and a private key generated by a first quantum-resistant cryptographic signature algorithm.
[0066] In one optional embodiment, the first terminal calculates the message digest of the SMS data according to a first preset digest algorithm. Then, the first terminal signs the message digest using a second hybrid private key provided by the first terminal, thereby obtaining signed SMS data. When the SMS data is received and decrypted by the second terminal, the second terminal calculates the message digest of the decrypted plaintext SMS data according to the second preset digest algorithm. Then, the second terminal verifies the signature of the message digest using the second hybrid public key. When the signature verification is successful, the plaintext SMS data is marked as trustworthy data. The first preset digest algorithm is a hash algorithm, and the message digest is the hash value. The hash value of the SMS data is calculated using the hash algorithm. By using the second hybrid public key and the second hybrid private key to sign and verify SMS data, information tampering can be effectively prevented, ensuring that the received SMS data is trustworthy. When the signature verification fails, it indicates that the SMS data has been tampered with, and therefore the SMS data is not trusted. The user can be alerted by a message notification that the SMS data is fake, or the SMS data can be blocked directly through message blocking, preventing the user from being deceived. It should be noted that the second hybrid private key consists of a private key generated by the second national cryptographic algorithm and a private key generated by the first quantum-resistant cryptographic signature algorithm in the first terminal, or it consists of a private key generated by the second international algorithm and a private key generated by the first quantum-resistant cryptographic signature algorithm. Taking the second national cryptographic algorithm as SM2 and the first quantum-resistant cryptographic signature algorithm as Dilithium algorithm as an example, the second hybrid private key contains a private key S3 generated by the SM2 algorithm and a private key S4 generated by the Dilithium algorithm.
[0067] Optionally, the symmetric key is a first symmetric key or a second symmetric key; the step of using the first hybrid public key provided by the second terminal to perform key encapsulation calculation to obtain the key-encapsulated ciphertext and the symmetric key includes: calling a first random number generator to generate a first random number, encrypting the first random number according to the public key generated by the first national cryptographic algorithm and the first national cryptographic algorithm, or encrypting the first random number according to the public key generated by the first international algorithm and the first international algorithm to obtain a first encryption key; calling a second random number generator to generate a second random number, generating a subkey according to the second random number and the first quantum-resistant cryptographic encapsulation algorithm, and encrypting the subkey according to the public key generated by the first quantum-resistant cryptographic encapsulation algorithm in the second terminal and the first quantum-resistant cryptographic encapsulation algorithm to obtain a second encryption key; wherein, the first encryption key and the second encryption key constitute the key-encapsulated ciphertext; generating a first symmetric key according to the subkey, the first random number, and the third national cryptographic algorithm in the first terminal, or generating a second symmetric key according to the subkey, the first random number, and the third international algorithm in the first terminal.
[0068] In one optional embodiment, the explanation is based on Chinese national cryptographic algorithms. Taking the SM2 algorithm as the first national cryptographic algorithm, the Kyber algorithm as the first quantum-resistant cryptographic encapsulation algorithm, and the SM3 hash algorithm as the third national cryptographic algorithm as an example, the first terminal calls the first random number generator in the first terminal to generate a first random number 1, and encrypts the first random number 1 according to the public key K1 and the SM2 algorithm in the second terminal to obtain a first encryption key C1. Then, the first terminal calls the second random number generator to generate a second random number 2, generates a subkey according to the second random number 2 and the Kyber algorithm in the second terminal, and encrypts the subkey according to the public key K4 and the Kyber algorithm in the second terminal to obtain a second encryption key C2. The first encryption key C1 and the second encryption key C2 constitute the key encapsulation ciphertext C. Finally, the first terminal generates a symmetric key K according to the subkey, the first random number 1, and the SM3 hash algorithm in the first terminal. By adopting a hybrid key encryption method, a quantum-resistant key negotiation function is provided for SMS, and the SMS content is protected against quantum attacks, thereby improving the security of SMS data transmission. The first random number generator and the second random number generator can be the same random number generator. International algorithms and Chinese national cryptographic algorithms are parallel algorithms; therefore, relevant embodiments from the perspective of international algorithms will not be elaborated here.
[0069] Optionally, the second terminal uses the first hybrid private key provided by the second terminal to deseal the key-encapsulated ciphertext to obtain the symmetric key, including: the second terminal using a private key generated by a first national cryptographic algorithm and the first national cryptographic algorithm to decrypt the first encryption key, or the second terminal using a private key generated by a first international algorithm and the first international algorithm to decrypt the first encryption key to obtain the first random number; the second terminal using a private key generated by a first quantum-resistant cryptographic encapsulation algorithm in the second terminal and the first quantum-resistant cryptographic encapsulation algorithm to decrypt the second encryption key to obtain the subkey; the second terminal generating a first symmetric key based on the first random number, the subkey, and a fourth national cryptographic algorithm in the second terminal, or the second terminal generating a second symmetric key based on the first random number, the subkey, and a fourth international algorithm in the second terminal.
[0070] In one optional embodiment, the explanation still focuses on national cryptographic algorithms. Taking the first national cryptographic algorithm as SM2, the first quantum-resistant cryptographic encapsulation algorithm as Kyber, and the fourth national cryptographic algorithm as SM3 hash algorithm as an example, the second terminal uses the private key S1 generated by the SM2 algorithm in the second terminal and the SM2 algorithm in the second terminal to decrypt the first encryption key C1, obtaining the first random number 1. Then, the second terminal uses the private key S2 generated by the Kyber algorithm in the second terminal and the Kyber algorithm in the second terminal to decrypt the second encryption key C2, obtaining the subkey. Finally, the second terminal generates the symmetric key K based on the first random number 1, the subkey, and the SM3 hash algorithm in the second terminal. This completes the decryption process of the SMS data. The same session key is used to encrypt and decrypt SMS messages, allowing secure transmission of the symmetric key K over an insecure channel, thus ensuring the confidentiality of SMS messages during transmission.
[0071] The step of decrypting the ciphertext of the SMS data based on the symmetric key to obtain the plaintext of the SMS data includes: using the symmetric key and the fifth national cryptographic algorithm in the second terminal to decrypt the ciphertext of the SMS data to obtain the plaintext of the SMS data.
[0072] Specifically, still from the perspective of Chinese national cryptographic algorithms, in the process of encrypting the signed SMS data using the symmetric key to obtain the ciphertext SMS data, the seventh national cryptographic algorithm provided by the first terminal is used in conjunction with the symmetric key to encrypt the signed SMS data. Taking the seventh national cryptographic algorithm as SM4 as an example, when decrypting the ciphertext SMS data using the symmetric key and the fifth national cryptographic algorithm in the second terminal, the fifth national cryptographic algorithm should be SM4. Using the symmetric key K and the SM4 algorithm in the second terminal to decrypt the ciphertext SMS data yields the plaintext SMS data. Using the same symmetric key and algorithm ensures that the ciphertext SMS data can be correctly decrypted, avoiding the inability to receive SMS data due to different encryption and decryption algorithms or keys.
[0073] In one optional embodiment, the first terminal and the second terminal communicate based on a SIM card, which is one of a regular SIM card, an ISIM card, an ESIM card, a Super SIM card, a TF card, or an NM card.
[0074] This application first obtains signed SMS data and uses a first hybrid public key provided by a second terminal to perform key encapsulation calculations to obtain key-encapsulated ciphertext and a symmetric key. The first hybrid public key is a hybrid public key generated based on a first national cryptographic algorithm and a first quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on a first international algorithm and a first quantum-resistant cryptographic encapsulation algorithm. The symmetric key is used to encrypt the signed SMS data to obtain SMS data ciphertext. The key-encapsulated ciphertext and the SMS data ciphertext are sent to the second terminal. The second terminal uses a first hybrid private key provided by the second terminal to decapsulate the key-encapsulated ciphertext to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain SMS data plaintext. The first hybrid private key is a hybrid private key generated based on a first national cryptographic algorithm and a first quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on a first international algorithm and a first quantum-resistant cryptographic encapsulation algorithm. By employing a hybrid key encryption method, a quantum-resistant key negotiation function is provided for SMS, protecting the SMS content from quantum attacks. Combined with signature verification, this prevents information from being intercepted or tampered with, further enhancing the security of SMS transmission.
[0075] Reference Figure 4 A flowchart of a secure SMS transmission method applied to a second terminal, provided as an embodiment of this specification, includes: acquiring signed SMS data, and performing key encapsulation calculation using a third hybrid public key provided by a first terminal to obtain key-encapsulated ciphertext and a symmetric key; wherein the third hybrid public key is a hybrid public key generated based on the sixth national cryptographic algorithm and the second quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on the sixth international algorithm and the second quantum-resistant cryptographic encapsulation algorithm; encrypting the signed SMS data using the symmetric key to obtain SMS data ciphertext; sending the key-encapsulated ciphertext and the SMS data ciphertext to the first terminal, wherein the first terminal decapsulates the key-encapsulated ciphertext using the third hybrid private key provided by the first terminal to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain SMS data plaintext; wherein the third hybrid private key is a hybrid private key generated based on the sixth national cryptographic algorithm and the second quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on the fifth international algorithm and the second quantum-resistant cryptographic encapsulation algorithm.
[0076] In one optional embodiment, the second terminal first acquires the signed SMS data. Simultaneously, it uses the third hybrid public key provided by the first terminal to perform key encapsulation calculations to obtain a key-encapsulated ciphertext C and a symmetric key K. Then, the second terminal uses the symmetric key K to encrypt the signed SMS data to obtain ciphertext SMS data. It then sends the key-encapsulated ciphertext C and the ciphertext SMS data to the first terminal. The first terminal uses the second hybrid private key provided by the first terminal to decapsulate the key-encapsulated ciphertext C to obtain the symmetric key K. Finally, the first terminal decrypts the ciphertext SMS data based on the symmetric key K to obtain the plaintext SMS data, thus completing the encrypted transmission of the SMS. The SMS data uses a hybrid key encryption method, providing quantum-resistant key negotiation functionality and quantum attack-resistant protection for the SMS content, thereby improving the security of SMS transmission. It should be noted that the third hybrid public key is a hybrid public key generated based on the sixth national cryptographic algorithm and the second quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on the sixth international algorithm and the second quantum-resistant cryptographic encapsulation algorithm. The third hybrid private key is a hybrid private key generated based on the sixth national cryptographic algorithm and the second quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on the sixth international algorithm and the second quantum-resistant cryptographic encapsulation algorithm.
[0077] Reference Figure 5 This specification also provides an embodiment of a secure SMS transmission system based on a post-quantum algorithm, including a first terminal 1 and a second terminal 2. The system includes: the first terminal 1 acquiring signed SMS data and using a first hybrid public key provided by the second terminal 2 to perform key encapsulation calculation to obtain key-encapsulated ciphertext and a symmetric key; wherein, the first hybrid public key is a hybrid public key generated based on a first national cryptographic algorithm and a first quantum-resistant cryptographic encapsulation algorithm, or a hybrid public key generated based on a first international algorithm and a first quantum-resistant cryptographic encapsulation algorithm; the first terminal 1 encrypts the signed SMS data using the symmetric key to obtain SMS data ciphertext; the first terminal 1 sends the key-encapsulated ciphertext and the SMS data ciphertext to the second terminal 2; the second terminal 2 uses a first hybrid private key provided by the second terminal 2 to decapsulate the key-encapsulated ciphertext to obtain the symmetric key, and decrypts the SMS data ciphertext based on the symmetric key to obtain SMS data plaintext, thereby completing the encrypted transmission of the SMS. The SMS data adopts a hybrid key encryption method, providing a quantum-resistant key negotiation function for the SMS, providing quantum attack-resistant protection for the SMS content, and improving the security of SMS transmission. The first hybrid private key is a hybrid private key generated based on the first national cryptographic algorithm and the first quantum-resistant cryptographic encapsulation algorithm, or a hybrid private key generated based on the first international algorithm and the first quantum-resistant cryptographic encapsulation algorithm.
[0078] Regarding the system in the above embodiments, the process of performing each step has been described in detail in the embodiments of the method, and will not be elaborated here.
[0079] Based on the same inventive concept, embodiments of this specification also provide an electronic device.
[0080] The following describes embodiments of the electronic device of the present invention, which can be considered as specific implementations of the methods and apparatus embodiments of the present invention described above. Details described in the embodiments of the electronic device of the present invention should be considered as supplements to the methods or apparatus embodiments described above; details not disclosed in the embodiments of the electronic device of the present invention can be implemented with reference to the methods or apparatus embodiments described above.
[0081] Reference Figure 6 This is a schematic diagram of an electronic device provided as an embodiment of this specification. Refer to the following... Figure 6 The electronic device 300 according to this embodiment of the present invention will be described. Figure 6 The electronic device 300 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0082] like Figure 6 As shown, the electronic device 300 is presented in the form of a general-purpose computing device. The components of the electronic device 300 may include, but are not limited to: at least one processing unit 310, at least one storage unit 320, a bus 330 connecting different device components (including storage unit 320 and processing unit 310), a display unit 340, etc.
[0083] The storage unit stores program code that can be executed by the processing unit 310, causing the processing unit 310 to perform the steps described in the processing method section of this specification according to various exemplary embodiments of the present invention. For example, the processing unit 310 can perform, for example... Figure 1 The steps are shown.
[0084] The storage unit 320 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 3201 and / or a cache storage unit 3202, and may further include a read-only memory unit (ROM) 3203.
[0085] The storage unit 320 may also include a program / utility 3204 having a set (at least one) of program modules 3205, such program modules 3205 including but not limited to: operating devices, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0086] Bus 330 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.
[0087] Electronic device 300 can also communicate with one or more external devices 400 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with the electronic device 300, and / or with any device that enables the electronic device 300 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 350. Furthermore, electronic device 300 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 360. Network adapter 360 can communicate with other modules of electronic device 300 via bus 330. It should be understood that, although... Figure 6 As not shown, other hardware and / or software modules may be used in conjunction with electronic device 300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID devices, tape drives, and data backup storage devices.
[0088] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described in this invention can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this invention can be embodied in the form of a software product, which can be stored in a computer-readable storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, or network device, etc.) to execute the method described above according to this invention. When the computer instructions are executed by a data processing device, the computer-readable medium is able to implement the method described above, i.e., as follows: Figure 1 The method shown.
[0089] Reference Figure 7 This is a schematic diagram of a computer-readable medium provided for embodiments of this specification.
[0090] accomplish Figure 1The computer instructions of the method shown can be stored on one or more computer-readable media. A computer-readable medium can be a readable signal medium or a readable storage medium. A readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0091] The computer-readable storage medium may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting a program for use by or in connection with an instruction execution device, apparatus, or apparatus. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0092] Program code for performing the operations of this invention can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0093] In summary, this invention can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that in practice, general-purpose data processing devices such as microprocessors or digital signal processors (DSPs) can be used to implement some or all of the functions of some or all of the components according to the embodiments of the invention. The invention can also be implemented as a device or apparatus program (e.g., a computer program and computer program product) for performing part or all of the methods described herein. Such programs implementing the invention can be stored on a computer-readable medium or can take the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
[0094] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the present invention is not inherently related to any specific computer, virtual device, or electronic device, and various general-purpose devices can also implement the present invention. The above descriptions are merely specific embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
[0095] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
[0096] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for secure transmission of SMS based on post-quantum algorithm, applied to a first terminal, characterized in that, The method comprises the following steps: obtaining short message data with signature, and performing key encapsulation calculation on the short message data with a first hybrid public key provided by a second terminal to obtain key encapsulation ciphertext and a symmetric key; wherein the first hybrid public key is a hybrid public key generated based on a first national encryption algorithm and a first quantum-resistant encryption encapsulation algorithm, or a hybrid public key generated based on a first international encryption algorithm and the first quantum-resistant encryption encapsulation algorithm; the key encapsulation calculation on the short message data with the first hybrid public key provided by the second terminal comprises the following steps: generating a first random number by calling a first random number generator, encrypting the first random number based on a public key generated by the first national encryption algorithm or based on a public key generated by the first international encryption algorithm, to obtain a first encrypted key; generating a second random number by calling a second random number generator, generating a sub-key based on the second random number and the first quantum-resistant encryption encapsulation algorithm, and encrypting the sub-key based on a public key generated by the first quantum-resistant encryption encapsulation algorithm in the second terminal and the first quantum-resistant encryption encapsulation algorithm, to obtain a second encrypted key; generating a first symmetric key based on the sub-key, the first random number, and a third national encryption algorithm in the first terminal, or generating a second symmetric key based on the sub-key, the first random number, and a third international encryption algorithm in the first terminal; wherein the first encrypted key and the second encrypted key constitute the key encapsulation ciphertext, and the symmetric key is the first symmetric key or the second symmetric key; encrypting the short message data with signature by using the symmetric key to obtain short message data ciphertext; sending the key encapsulation ciphertext and the short message data ciphertext to the second terminal, wherein the second terminal decrypts the key encapsulation ciphertext by using a first hybrid private key provided by the second terminal to obtain the symmetric key, and decrypts the short message data ciphertext based on the symmetric key to obtain short message data plaintext; wherein the first hybrid private key is a hybrid private key generated based on a first national encryption algorithm and a first quantum-resistant encryption encapsulation algorithm, or a hybrid private key generated based on a first international encryption algorithm and the first quantum-resistant encryption encapsulation algorithm.
2. The method of claim 1, wherein, The first terminal comprises a second hybrid public key, and the second terminal comprises a first hybrid public key, wherein the second hybrid public key is composed of a public key generated by a second national encryption algorithm in the first terminal and a public key generated by a first quantum-resistant encryption signature algorithm, or is composed of a public key generated by a second international encryption algorithm and a public key generated by the first quantum-resistant encryption signature algorithm; Before obtaining the short message data with signature, the method further comprises the following steps: The first terminal sends a certificate request of the first hybrid public key to a CA institution, and the second terminal sends a certificate request of the second hybrid public key to the CA institution; The CA institution performs certificate issuance on the first hybrid public key and the second hybrid public key based on the certificate request of the first hybrid public key and the certificate request of the second hybrid public key, so that the first hybrid public key and the second hybrid public key are trusted.
3. The method of claim 1, wherein, The obtaining of the short message data with signature comprises the following steps: According to the first preset abstract algorithm, the short message data is calculated to obtain an information abstract of the short message data; The information abstract is signed by using a second hybrid private key provided by the first terminal to obtain the short message data with signature; wherein the second hybrid private key is composed of a private key generated by a second national encryption algorithm and a private key generated by a first anti-quantum password signature algorithm in the first terminal, or is composed of a private key generated by a second international algorithm and a private key generated by the first anti-quantum password signature algorithm.
4. The method of claim 1, wherein, The second terminal uses a first hybrid private key provided by the second terminal to unseal the key encapsulation ciphertext to obtain the symmetric key, including: The second terminal uses a private key generated by the first national encryption algorithm to decrypt the first encryption key, or uses a private key generated by the first international algorithm to decrypt the first encryption key, to obtain the first random number; The second terminal uses a private key generated by the first anti-quantum password encapsulation algorithm in the second terminal to decrypt the second encryption key, to obtain the sub-key; The second terminal generates a first symmetric key according to the first random number, the sub-key, and a fourth national encryption algorithm in the second terminal, or generates a second symmetric key according to the first random number, the sub-key, and a fourth international algorithm in the second terminal.
5. The method of claim 1, wherein, The short message data ciphertext is decrypted based on the symmetric key to obtain short message data plaintext, including: The short message data ciphertext is decrypted by using the symmetric key and a fifth national encryption algorithm in the second terminal to obtain short message data plaintext.
6. The method of claim 2, wherein, After the short message data ciphertext is decrypted based on the symmetric key to obtain short message data plaintext, the method further includes: The second terminal calculates the short message data plaintext according to a second preset abstract algorithm to obtain an information abstract of the short message data plaintext; The second terminal uses the second hybrid public key to sign and verify the information abstract of the short message data plaintext; When the signature verification is successful, the short message data plaintext is marked as trusted data.
7. The method of claim 1, wherein, The first terminal and the second terminal realize communication based on a SIM card, and the SIM card is one of a common SIM card, an ISIM card, an ESIM card, a super SIM card, a TF card, and an NM card.
8. A short message security transmission system based on a post-quantum algorithm, characterized by The system includes a first terminal and a second terminal, and the system includes The first terminal obtains short message data with a signature, and performs key wrapping calculation using a first mixed public key provided by the second terminal to obtain key wrapping ciphertext and a symmetric key; the key wrapping calculation using the first mixed public key provided by the second terminal to obtain the key wrapping ciphertext and the symmetric key comprises: generating a first random number by calling a first random number generator, generating a first encryption key according to a public key generated by a first national encryption algorithm, or encrypting the first random number by the first national encryption algorithm, or generating a first encryption key according to a public key generated by a first international encryption algorithm, or encrypting the first random number by the first international encryption algorithm; generating a second random number by calling a second random number generator, generating a sub-key according to the second random number and a first quantum-resistant encryption wrapping algorithm, and encrypting the sub-key according to a public key generated by the first quantum-resistant encryption wrapping algorithm in the second terminal and the first quantum-resistant encryption wrapping algorithm to obtain a second encryption key; generating a first symmetric key according to the sub-key, the first random number and a third national encryption algorithm in the first terminal, or generating a second symmetric key according to the sub-key, the first random number and a third international encryption algorithm in the first terminal; wherein the first mixed public key is a mixed public key generated based on the first national encryption algorithm and the first quantum-resistant encryption wrapping algorithm, or a mixed public key generated based on the first international encryption algorithm and the first quantum-resistant encryption wrapping algorithm; the first encryption key and the second encryption key constitute the key wrapping ciphertext, and the symmetric key is the first symmetric key or the second symmetric key; The first terminal encrypts the short message data with the signature using the symmetric key to obtain short message data ciphertext; The first terminal sends the key wrapping ciphertext and the short message data ciphertext to the second terminal; The second terminal performs unwrapping on the key wrapping ciphertext using a first mixed private key provided by the second terminal to obtain the symmetric key, and decrypts the short message data ciphertext based on the symmetric key to obtain short message data plaintext; wherein the first mixed private key is a mixed private key generated based on the first national encryption algorithm and the first quantum-resistant encryption wrapping algorithm, or a mixed private key generated based on the first international encryption algorithm and the first quantum-resistant encryption wrapping algorithm.
9. An electronic device, comprising: The storage medium stores computer instructions, and the computer instructions are configured to execute the method in any one of claims 1 to 7 when executed.
10. A storage medium, characterized by The storage medium stores computer instructions, and the computer instructions are configured to execute the method in any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
National password IPSec secure communication method supporting quantum cryptography resistance
CN118631448A
Short message encryption method and short message decryption method
CN118900411A