Super SIM Card Key Generation System and Method Supporting National Cryptography SM9 Algorithm
By adopting a super SIM card key generation system that supports the National Secret SM9 algorithm in IoT devices, using the key generation center to participate in the generation of keys and perform two-way identity authentication, the existing technology China Secret SM2 algorithm has solved the problems of high cost and complex management, and the certificate-free encryption and authentication have been realized, the key management process is simplified, and the information security of IoT devices is improved.
Patent Information
- Application Number
- CN202510260265.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-03-06
AI Technical Summary
The prior art uses the Guoxin SM2 algorithm in IoT devices with high cost and complex management problems, and lacks a solution for uncertified encryption and authentication, making it difficult to simplify the key management process.
A super SIM card key generation system that supports the National Secretariat SM9 algorithm is adopted. The system includes terminal devices, super SIM cards, Internet of Things platforms and key generation centers. It participates in the generation of keys through the key generation center, and uses the root key calculation authentication code for two-way identity authentication to simplify the key management process.
It realizes certificate-free encryption and authentication, simplifies the key management process, reduces system complexity and operation and maintenance costs, and improves the information security of IoT devices.
Smart Images

Figure CN119766579B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to a super SIM card key generation system and method supporting the national cryptographic SM9 algorithm. Background Art
[0002] With the rapid development of the Internet of Things (IoT), its application scenarios have been continuously expanded, covering many fields such as smart home, industrial automation, and intelligent transportation. The IoT connects a large number of devices, sensors, etc. together, realizing efficient data transmission and interaction. However, at the same time, the security requirements of the IoT are also increasing day by day. In the IoT environment, the communication between devices needs to ensure the confidentiality, integrity, and authenticity of data to prevent information from being stolen, tampered with, or forged.
[0003] Currently, using a super SIM card integrated with the national cryptographic SM2 algorithm is a common technical solution to ensure the information security of the IoT. The national cryptographic SM2 algorithm is an elliptic curve public key cryptography algorithm with high security. However, this algorithm requires a certificate authority to issue certificates, which increases the cost and management complexity for a large number of IoT devices. The national cryptographic SM9 algorithm is an identity-based encryption (IBE) algorithm with significant application advantages on IoT devices. The most important one is that it can perform encryption and authentication without certificates, which greatly simplifies the key management process and reduces the system complexity and operation and maintenance costs. In view of the problems of high cost and complex management existing in the use of the national cryptographic SM2 algorithm in the existing technical solutions, and the advantages of the national cryptographic SM9 algorithm on IoT devices, the purpose of the present invention is to provide a super SIM card key generation system and method supporting the national cryptographic SM9 algorithm, aiming to utilize the advantages of the national cryptographic SM9 algorithm to simplify the key management process and reduce costs and system complexity. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide a super SIM card key generation system and method supporting the national cryptographic SM9 algorithm, aiming to utilize the advantages of the national cryptographic SM9 algorithm to simplify the key management process and reduce costs and system complexity.
[0005] To achieve the above object, the embodiments of the present invention provide the following technical solutions:
[0006] A super SIM card key generation system supporting the national cryptographic SM9 algorithm specifically includes a terminal device, a super SIM card installed in the terminal device, an IoT platform, and a key generation center. The terminal device communicates with the key generation center through the IoT platform;
[0007] The terminal device is used to generate a key generation instruction;
[0008] The super SIM card is used to generate an SM2 temporary key pair in response to the key generation instruction, generate a first key request including the public key of the SM2 temporary key pair and the preset unique chip serial number, and calculate a first authentication code for the first key request using the preset root key;
[0009] The terminal device is used to generate a second key request including the first key request and the first authentication code in response to the first key request and send it to the Internet of Things platform;
[0010] The Internet of Things platform is used to send the second key request to the key generation center;
[0011] The key generation center is used to respond to the second key request, obtain the corresponding salt value from the relationship table according to the unique chip serial number in the first key request, generate a root key through a key derivation algorithm, calculate a second authentication code for the first key request using the root key, generate a user key when the second authentication code matches the first authentication code, encrypt the user key using the public key of the SM2 temporary key pair in the first key request to obtain a user key ciphertext, and then calculate a third authentication code for the key packet composed of the user key ciphertext and the key generation center identifier using the root key, and send the key packet and the third authentication code to the Internet of Things platform;
[0012] The Internet of Things platform is used to send the key packet and the third authentication code to the terminal device;
[0013] The terminal device is used to forward the key packet and the third authentication code to the super SIM card;
[0014] The super SIM card is used to calculate a fourth authentication code for the key packet using the root key, decrypt the user key ciphertext in the key packet using the private key of the SM2 temporary key pair when the fourth authentication code matches the third authentication code, and store the user key and the key generation center identifier in the key packet in the memory.
[0015] As a further technical solution of the present invention, the terminal device includes an MCU and a communication module, and the MCU communicates with the super SIM card through the communication module;
[0016] The MCU is used to generate a key generation instruction and transparently transmit the key generation instruction to the super SIM card through the communication module;
[0017] The communication module is used to transparently transmit the first key request and the first authentication code generated by the super SIM card to the MCU;
[0018] The MCU is further used to generate a network request instruction in response to the first key request and send it to the communication module;
[0019] The communication module is further configured to respond to the network request instruction, generate a second key request including the first key request and a first authentication code, and send the second key request to the IoT platform.
[0020] As a further technical solution of the present invention, the key generation center is configured to respond to the second key request, obtain a corresponding salt value from the relationship table according to the chip unique serial number in the first key request, generate a root key through a key derivation algorithm, calculate a second authentication code for the first key request using the root key, when the second authentication code matches the first authentication code, generate a user key, encrypt the user key using the public key of the SM2 temporary key pair in the first key request to obtain a user key ciphertext, and then calculate a third authentication code for the key packet composed of the user key ciphertext and the key generation center identifier using the root key, and send the key packet and the third authentication code to the IoT platform;
[0021] The IoT platform is further configured to send the key packet and the third authentication code to the communication module.
[0022] As a further technical solution of the present invention, the communication module is further configured to forward the key packet and the third authentication code to the MCU;
[0023] The MCU is further configured to generate a parsing instruction including the key packet and the third authentication code, and transmit the parsing instruction transparently to the super SIM card through the communication module;
[0024] The super SIM card is further configured to respond to the parsing instruction, calculate a fourth authentication code for the key packet using the root key, and when the fourth authentication code matches the third authentication code, decrypt the user key ciphertext in the key packet using the private key of the SM2 temporary key pair to obtain a user key, and store the user key and the key generation center identifier in the key packet in the memory.
[0025] As a further technical solution of the present invention, the calculation algorithms for the first authentication code, the second authentication code, the third authentication code, and the fourth authentication code are hash algorithms using the root key.
[0026] As a further technical solution of the present invention, the IoT platform communicates with the key generation center through a secure channel.
[0027] As a further technical solution of the present invention, the super SIM card includes an application layer and a hardware layer, the hardware layer includes a non-volatile memory, and the application layer is configured to store the user key and the key generation center identifier in the non-volatile memory.
[0028] As a further technical solution of the present invention, the application layer is further configured to store the key generation center identifier and the key operation parameters in the non-volatile memory.
[0029] As a further technical solution of the present invention, the hardware layer further includes a random access memory, and the application layer is further configured to:
[0030] Load the user key and the key operation parameters from the non-volatile memory into the random access memory according to the received key generation center identifier.
[0031] A method for generating a super SIM card key supporting the national cryptography SM9 algorithm, which is applied to any one of the super SIM card key generation systems supporting the national cryptography SM9 algorithm of the present invention, specifically includes the following steps:
[0032] The terminal device generates a key generation instruction;
[0033] The super SIM card responds to the key generation instruction to generate an SM2 temporary key pair, generates a first key request including the public key of the SM2 temporary key pair and the pre-set chip unique serial number, and calculates a first authentication code for the first key request by using the pre-set root key;
[0034] The terminal device responds to the first key request to generate a second key request including the first key request, the first authentication code and the pre-set device information, and sends it to the Internet of Things platform;
[0035] The Internet of Things platform sends the second key request to the key generation center;
[0036] The key generation center responds to the second key request, obtains the corresponding salt value from the relationship table according to the chip unique serial number in the first key request, generates a root key through a key derivation algorithm, calculates a second authentication code for the first key request by using the root key, when the second authentication code and the first authentication code match, generates a user key, encrypts the user key by using the public key of the SM2 temporary key pair in the first key request to obtain a user key ciphertext, and then calculates a third authentication code for the key packet composed of the user key ciphertext and the key generation center identifier by using the root key, and sends the key packet and the third authentication code to the Internet of Things platform;
[0037] The Internet of Things platform sends the key packet and the third authentication code to the terminal device;
[0038] The terminal device forwards the key packet and the third authentication code to the super SIM card;
[0039] The super SIM card calculates a fourth authentication code for the key package using the root key. When the fourth authentication code matches the third authentication code, the private key of the SM2 temporary key pair is used to decrypt the user key ciphertext in the key package to obtain the user key, and the user key and the key generation center identifier in the key package are stored in the memory.
[0040] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0041] The super SIM card key generation system supporting the national cryptographic SM9 algorithm according to the embodiment of the present invention. The terminal device installed with the super SIM card forwards information through the Internet of Things platform or directly communicates with the key generation center, providing an architecture for the key generation center to participate in generating keys for the national cryptographic SM9 algorithm. Moreover, the super SIM card calculates the authentication code using the root key, and the key generation center also calculates the authentication code using the root key. This enables the terminal device installed with the super SIM card and the key generation center to perform two-way identity authentication by calculating the authentication code using the root key during the interaction in the key generation stage, ensuring the security and integrity of the communication during the key generation stage. That is, the super SIM card key generation system supporting the national cryptographic SM9 algorithm according to the embodiment of the present invention provides a key generation architecture for the national cryptographic SM9 algorithm, enabling the national cryptographic SM9 algorithm to be applied to the super SIM card, which is beneficial to using the national cryptographic SM9 algorithm for information encryption in the Internet of Things and improving the network information security of the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention.
[0043] Figure 1 Fig. shows the application architecture diagram of the super SIM card key generation system supporting the national cryptographic SM9 algorithm provided by an embodiment of the present invention.
[0044] Figure 2 Fig. shows the application architecture diagram of the super SIM card key generation system supporting the national cryptographic SM9 algorithm provided by another embodiment of the present invention.
[0045] Figure 3 Fig. shows the interaction schematic diagram of the super SIM card key generation supporting the national cryptographic SM9 algorithm provided by an embodiment of the invention.
[0046] Figure 4 Fig. shows the memory management strategy diagram of the super SIM card supporting the national cryptographic SM9 algorithm provided by an embodiment of the present invention.
[0047] Figure 5The figure shows the hardware architecture diagram of a super SIM card supporting the national cryptographic SM9 algorithm provided by an embodiment of the present invention.
[0048] Figure 6 The figure shows the flowchart of a method for generating keys of a super SIM card supporting the national cryptographic SM9 algorithm provided by an embodiment of the present invention. Detailed implementation manners
[0049] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0050] Figure 1 The figure shows the application architecture diagram of a system for generating keys of a super SIM card supporting the national cryptographic SM9 algorithm provided by an embodiment of the present invention. As Figure 1 shown, the system for generating keys of a super SIM card supporting the national cryptographic SM9 algorithm according to an embodiment of the present invention includes a terminal device, a super SIM card installed in the terminal device, an Internet of Things platform, and a key generation center. Among them, the terminal device forwards information through the Internet of Things platform or communicates directly with the key generation center.
[0051] The terminal device can be various Internet of Things devices in the Internet of Things, or can also be a mobile terminal such as a mobile phone or a tablet. The terminal device may include a communication module, such as wireless communication modules of 2G, 3G, 4G, 5G, etc. After installing the super SIM card on the terminal device, communication can be realized. Among them, the super SIM (Subscriber Identity Module) card is a new type of smart card that integrates the communication function of a traditional SIM card with advanced technologies such as large-capacity storage and security encryption.
[0052] The Internet of Things platform can be an Internet of Things server, a gateway, etc. Each terminal device in the Internet of Things is connected to the Internet of Things platform. The key generation center (Key Generation Center, KGC) is mainly responsible for generating, storing, and managing keys to ensure information security and data privacy. In the KGC, the user key is an identity-based key.
[0053] Specifically, in this embodiment, the terminal device is used to generate a key generation instruction, and the super SIM card is used to respond to the key generation instruction to generate an SM2 temporary key pair, generate a first key request including the public key of the SM2 temporary key pair and the pre-set unique chip serial number, and calculate a first authentication code for the first key request using the pre-set root key. The terminal device is used to respond to the first key request to generate a second key request including the first key request and the first authentication code and send it to the Internet of Things platform. The Internet of Things platform is used to transparently transmit the second key request to the key generation center. The key generation center is used to respond to the second key request, obtain the corresponding salt value from the relationship table according to the unique chip serial number in the first key request, and generate a root key through a key derivation algorithm. The root key is used to calculate a second authentication code for the first key request. When the second authentication code matches the first authentication code, a user key is generated and the public key of the SM2 temporary key pair in the first key request is used to encrypt the user key to obtain a user key ciphertext. Then, the root key is used to calculate a third authentication code for the key package composed of the user key ciphertext and the key generation center identifier, and the key package and the third authentication code are sent to the Internet of Things platform. The Internet of Things platform is used to send the key package and the third authentication code to the terminal device. The terminal device is used to forward the key package and the third authentication code to the super SIM card. The super SIM card is used to calculate a fourth authentication code for the key package using the root key. When the fourth authentication code matches the third authentication code, the private key of the SM2 temporary key pair is used to decrypt the user key ciphertext in the key package to obtain the user key, and the user key and the key generation center identifier in the key package are stored in the memory.
[0054] Specifically, the root key pre - set in the super SIM card can be generated in the following way: The salt value (i.e., random number) permanently solidified in the super SIM card during production and the chip - unique serial number (ICCID) are used to generate a key by means of a key - derivation algorithm. The root key of the key generation center is generated as follows: The super SIM card manufacturer provides a relationship table of the chip - unique serial number (ICCID) and the salt value (i.e., random number), obtains the salt value from this relationship table, and combines it with the chip - unique serial number to also generate a key through the key - derivation algorithm. By operating in this way, the security of the root key can be effectively guaranteed. Calculating the authentication code through the root key can be done by calculating the message digest through HMAC (Hash - based Message Authentication Code). HMAC is a key - based hash function used to ensure the integrity and security of information. It involves a hash function, a key, and a specific exclusive - OR operation, and generates a message authentication code through a two - step hash process. The algorithm includes key processing, content splicing, and two hash operations. Specifically in this embodiment, the root key is defined as the key, the HMAC object is initialized using the hmac.new function, specifying the key, the message, and the hash function (such as SHA - 256), and the hexdigest method is called to obtain the hexadecimal representation of the HMAC as the authentication code.
[0055] The terminal device forwards information through the Internet of Things platform or communicates directly with the key generation center, providing an architecture for the key generation center to participate in generating keys for the national cryptography SM9 algorithm. Moreover, the super SIM card calculates the authentication code using the root key, and the key generation center also calculates the authentication code using the root key. This enables the terminal device installed with the super SIM card and the key generation center to perform two - way identity authentication by calculating the authentication code through the root key during the interaction in the key - generation stage, ensuring the security and integrity of the communication in the key - generation stage. That is, the super SIM card key - generation system supporting the national cryptography SM9 algorithm in the embodiment of the present invention provides a key - generation architecture for the national cryptography SM9 algorithm, enabling the national cryptography SM9 algorithm to be applied to the super SIM card, which is beneficial to using the national cryptography SM9 algorithm for information encryption in the Internet of Things and improving the network information security of the Internet of Things.
[0056] Such as Figure 2As shown, in another embodiment, the terminal device includes an MCU and a communication module. The MCU communicates with the super SIM card through the communication module. Among them, the MCU is used to generate a key generation instruction and transparently transmit the key generation instruction to the super SIM card through the communication module. The communication module is used to transparently transmit the first key request and the first authentication code generated by the super SIM card to the MCU. The MCU is further used to generate a network request instruction in response to the first key request and send it to the communication module. The communication module is further used to generate a second key request including the first key request and the first authentication code in response to the network request instruction and send it to the Internet of Things platform.
[0057] Among them, the key generation center is specifically used to respond to the second key request, obtain the corresponding salt value from the relationship table according to the chip unique serial number in the first key request, generate the root key through the key derivation algorithm, calculate the second authentication code for the first key request using the root key, generate the user key when the second authentication code matches the first authentication code, encrypt the user key using the public key of the SM2 temporary key pair in the first key request to obtain the user key ciphertext, then calculate the third authentication code for the key package composed of the user key ciphertext and the key generation center identifier using the root key, send the key package and the third authentication code to the Internet of Things platform. The Internet of Things platform is further used to send the key package and the third authentication code to the communication module. The communication module is further used to forward the key package and the third authentication code to the MCU. The MCU is further used to generate a parsing instruction including the key package and the third authentication code and transparently transmit the parsing instruction to the super SIM card through the communication module. The super SIM card is further used to calculate the fourth authentication code for the key package using the root key in response to the parsing instruction, and when the fourth authentication code matches the third authentication code, decrypt the user key ciphertext in the key package using the private key of the SM2 temporary key pair to obtain the user key, and store the user key and the key generation center identifier in the key package in the memory.
[0058] In this embodiment, each super SIM card is assigned a unique chip unique serial number (ICCID) as device information to identify the identity of the super SIM card. Each key generation center is responsible for generating the master key and the user key, and assigns a unique key generation center identifier KGCID to each master key. And the key generation center and the Internet of Things platform can communicate through a secure channel, such as through a proprietary communication tunnel.
[0059] To more clearly illustrate the super SIM card key generation system supporting the national secret SM9 algorithm in the embodiments of the present invention, the following combines Figure 3 the interaction schematic diagram to illustrate the key generation process, as Figure 3As shown in the figure, the super SIM card and the communication module can communicate through the 7816 protocol (APDU). The communication module and the MCU can communicate through the SPI / I2C bus. The communication module and the Internet of Things platform can communicate through the MQTT (Message Queuing Telemetry Transport) / COAP (The Constrained Application Protocol) method. The Internet of Things platform and the KGC (Key Generation Center) communicate through a secure channel. The specific key generation process is as follows:
[0060] S1. The MCU generates a key generation instruction;
[0061] S2. The communication module transparently transmits the key generation instruction;
[0062] S3. The super SIM card generates an SM2 temporary key pair and generates a first key request including the public key of the SM2 temporary key pair and the unique chip serial number, and calculates a first authentication code using the root key;
[0063] S4. The communication module transparently transmits the first key request and the first authentication code;
[0064] S5. The MCU sends a network request instruction;
[0065] S6. The communication module generates and sends a second key request including the first key request and the first authentication code;
[0066] S7. The Internet of Things platform sends the second key request;
[0067] S8. The key generation center obtains the salt value from the relationship table according to the unique chip serial number in the first key request and generates the root key through the key derivation algorithm, and calculates a second authentication code for the first key request in the second key request using the root key;
[0068] S9. If the authentication is passed, the key generation center generates a user key and encrypts it using the public key of the SM2 temporary key pair in the first key request to obtain the user key ciphertext, encapsulates the user key ciphertext and the key generation center identifier into a key package, and calculates a third authentication code using the root key;
[0069] S10. The key generation center sends the key package and the third authentication code;
[0070] S11. The Internet of Things platform sends the key package and the third authentication code;
[0071] S12. The communication module transparently transmits the key package and the third authentication code to the MCU;
[0072] S13. The MCU sends a parsing instruction;
[0073] S14. Communication module transparent transmission and parsing instruction;
[0074] S15. The super SIM card calculates the fourth authentication code for the key package using the root key, decrypts the user key ciphertext using the private key of the SM2 temporary key pair when the authentication is passed, and associates and stores the user key and the key generation center identifier.
[0075] On the terminal device, when the key is needed, the super SIM card requests the corresponding user key for password operation service to encrypt data information.
[0076] Such as Figure 4 shown, in an optional embodiment, the super SIM card includes an application layer and a hardware layer. The hardware layer includes a non-volatile memory. The application layer is used to store the user key and the key generation center identifier in the non-volatile memory when receiving them. That is, the Applet (application) stores the corresponding user key in the EEPROM / Flash according to the received key generation center identifier KGCID, ensuring the security and fast retrieval of the user key. For example, when the Applet needs to perform encryption services, it can quickly retrieve different keys from the EEPROM / Flash through the KGCID and load the keys into the RAM, significantly improving the management efficiency and security of the key data of the super SIM card.
[0077] In another embodiment, such as Figure 4 shown, the application layer is also used to store the key generation center identifier and the key operation parameters in the non-volatile memory. Exemplarily, a relationship table of KGCID and password parameters is maintained in the super SIM card, realizing the unified management of user keys and public parameters generated by different KGCs. Further, by pre-computing the key G value (i.e., the bilinear pair generated by the master key and the public parameters) in the password operation and loading it into the relationship table of KGCID and password parameters, repeated calculations are reduced, significantly improving the performance of the password operation and the overall system operation efficiency.
[0078] Of course, the hardware layer may also include an SE chip. The SE chip is a customized security chip that supports the SM9 algorithm. By executing identity authentication, password operation, and security operations through the SE chip, the security and performance of the system are improved. The application layer can call the resources of the hardware layer for cryptography operations, password retrieval, etc.
[0079] Such as Figure 5 shown is the hardware architecture diagram of the super SIM card. In Figure 5In the shown super SIM card, the super SIM card includes a main control module, a storage module, a system bus, an algorithm coprocessor, and an interface module. Among them, the main control module, as the central processing unit of the super SIM card, may include a CPU and a DMA, and is responsible for executing programs and processing data. The storage module, as the memory of the super SIM card, may include Flash, Cache, and SRAM, and can be used to store the operating system, application programs, user data, and other contents. The system bus connects each component to provide a data transmission channel. The algorithm coprocessor can be various processors with digital logic operations and is used to execute complex cryptographic algorithms. The interface module may include interface modules such as SPI, 7816, and SWP, and is used to implement communication. Various interfaces of the interface module support the download, import, deletion, and enumeration of the public key and identification key of the national cryptographic SM9 algorithm, and support cryptographic operations such as signature, signature verification, encryption, and decryption of the national cryptographic SM9 algorithm.
[0080] Among them, the 7816 protocol enables the super SIM card to follow the ISO / IEC 7816 standard to achieve communication with external devices. The super SIM card adopts the APDU instruction set for key management and cryptographic operations. In addition, a JavaCard Applet is integrated on the super SIM card as the application program of the super SIM card, following the Java Card specification and running on the smart card using Java Card technology, and is responsible for encapsulating and processing APDU instructions.
[0081] For the super SIM card key generation system supporting the national cryptographic SM9 algorithm in this embodiment, the terminal device forwards information through the Internet of Things platform or directly communicates with the key generation center, providing an architecture for the key generation center to participate in generating keys for the national cryptographic SM9 algorithm. Moreover, the super SIM card calculates the authentication code using the root key, and the key generation center also calculates the authentication code using the root key. This enables the terminal device installed with the super SIM card and the key generation center to perform two-way identity authentication through calculating the authentication code using the root key during the interaction in the key generation stage, ensuring the security and integrity of the communication in the key generation stage. That is, the super SIM card key generation system supporting the national cryptographic SM9 algorithm in this embodiment of the invention provides a key generation architecture for the national cryptographic SM9 algorithm, enabling the national cryptographic SM9 algorithm to be applied to the super SIM card, which is beneficial to using the national cryptographic SM9 algorithm for information encryption in the Internet of Things and improving the network information security of the Internet of Things.
[0082] Furthermore, by associatively storing the key generation center identifier and the corresponding user key and encryption operation parameters, a memory mechanism for associating user keys supporting multiple key generation centers is realized, effectively managing and quickly retrieving the user keys generated by different key generation centers and the public parameters, and ensuring the orderly storage of key data.
[0083] Furthermore, the super SIM card can load the key data corresponding to the key generation center identifier into the cache after being powered on, call the SE chip to pre-compute the key encryption operation parameter G value (i.e., the bilinear pair generated by the master key and the public parameter) and store it in the cache, reducing the repeated calculation of the encryption operation parameters, providing performance improvement for the password operation, and improving the system operation efficiency.
[0084] Figure 6 The flowchart of the super SIM card key generation method supporting the national cryptography SM9 algorithm provided by an embodiment of the present invention is shown as Figure 6 As shown, the super SIM card key generation method supporting the national cryptography SM9 algorithm of the embodiment of the present invention specifically includes the following steps:
[0085] S601. The terminal device generates a key generation instruction.
[0086] As Figure 1 shown, the super SIM card key generation system supporting the national cryptography SM9 algorithm of the embodiment of the present invention includes a terminal device, a super SIM card installed in the terminal device, an Internet of Things platform, and a key generation center. Among them, the terminal device forwards information through the Internet of Things platform or directly communicates with the key generation center.
[0087] The terminal device can generate a key generation instruction. As Figure 2 shown, in an optional embodiment, the terminal device includes an MCU and a communication module. The MCU communicates with the super SIM card through the communication module. Among them, the MCU is used to generate a key generation instruction and transparently transmit the key generation instruction to the super SIM card through the communication module.
[0088] S602. The super SIM card responds to the key generation instruction to generate an SM2 temporary key pair, generates a first key request including the public key of the SM2 temporary key pair and the unique serial number of the chip, and calculates a first authentication code for the first key request using the preset root key.
[0089] After receiving the key generation instruction, the super SIM card can respond to the key generation instruction to generate an SM2 temporary key pair, generate a first key request including the public key of the SM2 temporary key pair and the unique serial number of the chip, and calculate a first authentication code for the first key request using a preset root key. Specifically, the root key preset in the super SIM card can be generated in the following way: a salt value (i.e., a random number) permanently solidified in the super SIM card during production and the unique serial number of the chip (ICCID) are used to generate a key by means of a key derivation algorithm. Calculating the authentication code through the root key can be to calculate the message digest of the first key request through HMAC (Hash-based Message Authentication Code). Exemplarily, defining the root key as key and the key request as message, initializing the HMAC object using the hmac.new function, specifying the key, message, and hash function (such as SHA-256), and calling the hexdigest method to obtain the hexadecimal representation of the HMAC as the authentication code.
[0090] S603. The terminal device responds to the first key request to generate a second key request including the first key request and the first authentication code and sends it to the Internet of Things platform.
[0091] After the super SIM card generates the first key request and the first authentication code, it can transmit them to the MCU through the communication module. The MCU responds to the first key request to generate a second key request including the first key request and the first authentication code, and transmits the second key request to the communication module. The communication module sends the second key request to the Internet of Things platform.
[0092] S604. The Internet of Things platform sends the second key request to the key generation center.
[0093] Specifically, after receiving the second key request, the Internet of Things platform sends the second key request to the key generation center.
[0094] S605. The key generation center responds to the second key request, obtains the corresponding salt value from the relationship table according to the unique serial number of the chip in the first key request, generates a root key through the key derivation algorithm, calculates a second authentication code for the first key request using the root key, generates a user key when the second authentication code matches the first authentication code, and encrypts the user key using the public key of the SM2 temporary key pair in the first key request to obtain the user key ciphertext.
[0095] The key generation center first obtains the corresponding salt value from the relationship table according to the unique chip serial number in the first key request and generates the root key through the key derivation algorithm. Then, it calculates the second authentication code for the first key request in the root key. Specifically, the root key generation method of the key generation center is as follows: The super SIM card manufacturer provides the relationship table between the unique chip serial number (ICCID) and the salt value (i.e., random number). The salt value is obtained from this relationship table according to the unique chip serial number, and combined with the unique chip serial number, the key is also generated through the key derivation algorithm. If the second authentication code is equal to the first authentication code, it is determined that the authentication is passed. The user key can be generated using the key generation method in the national cryptographic SM9, and the user key can be encrypted using the encryption algorithm in the national cryptographic SM2. This embodiment does not limit the algorithm for the key generation center to generate the user key. If the second authentication code is not equal to the first authentication code, it is determined that the identity authentication fails, and an alarm message indicating that the identity authentication is not notified can be returned to the Internet of Things platform.
[0096] S606. The key generation center calculates the third authentication code for the key package composed of the user key ciphertext and the key generation center identifier using the root key, and sends the key package and the third authentication code to the Internet of Things platform.
[0097] In one embodiment, the key generation center packs the user key ciphertext and the key generation center identifier into a key package, calculates the third authentication code for the key package using the root key, and sends the key package and the third authentication code to the Internet of Things platform.
[0098] S607. The Internet of Things platform sends the key package and the third authentication code to the terminal device.
[0099] Specifically, after receiving the key package and the third authentication code, the Internet of Things platform sends the key package and the third authentication code to the key terminal device.
[0100] S607. The terminal device forwards the key package and the third authentication code to the super SIM card.
[0101] Specifically, the communication module of the terminal device can first send the key package including the user key and the key generation center identifier and the third authentication code to the MCU, and the MCU transmits it to the super SIM card through the communication module by parsing the instruction.
[0102] S608. The super SIM card calculates the fourth authentication code for the key package using the root key. When the fourth authentication code matches the third authentication code, it decrypts the user key ciphertext in the key package using the private key of the SM2 temporary key pair to obtain the user key, and stores the user key and the key generation center identifier in the key package in the memory.
[0103] Specifically, the super SIM card calculates the fourth authentication code for the key package through the root key. When the fourth authentication code matches the third authentication code, the private key of the SM2 temporary key pair is used to decrypt the user key ciphertext in the key package to obtain the user key, and the user key and the key generation center identifier in the key package are stored in the memory.
[0104] It should be noted that for the method embodiments, since they are basically similar to the system embodiments, the description is relatively simple. For the relevant parts, please refer to the description of the system embodiments.
[0105] The super SIM card key generation method supporting the national cryptography SM9 algorithm provided by the embodiments of the present invention is applied to the super SIM card key generation system supporting the national cryptography SM9 algorithm provided by the embodiments of the present invention, so that the super SIM card key generation method supporting the national cryptography SM9 algorithm has corresponding beneficial effects.
[0106] It should be understood that although the steps in the flowcharts of the embodiments of the present invention are displayed in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least a part of the steps in each embodiment may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.
[0107] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0108] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0109] The above embodiments only represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention should be subject to the appended claims.
[0110] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A super SIM card key generation system supporting the national secret SM9 algorithm, characterized in that: Specifically comprising a terminal device, a super SIM card installed in the terminal device, an Internet of Things platform and a key generation center, wherein the terminal device communicates with the key generation center through the Internet of Things platform; The terminal device is used to generate a key generation instruction; The super SIM card is used to generate an SM2 temporary key pair in response to the key generation instruction, generate a first key request including a public key of the SM2 temporary key pair and a preset chip unique serial number, and calculate a first authentication code for the first key request using a preset root key; The terminal device is used to generate a second key request including the first key request and a first authentication code in response to the first key request and send the second key request to the Internet of Things platform; The Internet of Things platform is used to send the second key request to the key generation center; The key generation center is used to respond to the second key request, obtain the corresponding salt value from the relationship table according to the chip unique serial number in the first key request, and generate a root key through a key derivation algorithm, and use the root key to calculate the second authentication code for the first key request. When the second authentication code matches the first authentication code, a user key is generated and the public key of the SM2 temporary key pair in the first key request is used to encrypt the user key to obtain a user key ciphertext, and then the root key is used to calculate a third authentication code for a key package consisting of the user key ciphertext and the key generation center identifier, and the key package and the third authentication code are sent to the Internet of Things platform; The Internet of Things platform is used to send the key package and the third authentication code to the terminal device; The terminal device is used to forward the key package and the third authentication code to the super SIM card; The super SIM card is used to use the root key to calculate the fourth identification code of the key package. When the fourth identification code matches the third identification code, the private key of the SM2 temporary key pair is used to decrypt the user key ciphertext in the key package to obtain the user key, and the user key and the key generation center identifier in the key package are stored in the memory.
2. The super SIM card key generation system supporting the national secret SM9 algorithm according to claim 1 is characterized in that: The terminal device includes an MCU and a communication module, and the MCU communicates with the super SIM card through the communication module; The MCU is used to generate a key generation instruction, and transparently transmit the key generation instruction to the super SIM card through the communication module; The communication module is used to transparently transmit the first key request and the first authentication code generated by the super SIM card to the MCU; The MCU is also used to generate a network request instruction in response to the first key request and send it to the communication module; The communication module is also used to generate a second key request including the first key request and the first authentication code in response to the network request instruction and send the second key request to the Internet of Things platform.
3. The super SIM card key generation system supporting the national secret SM9 algorithm according to claim 2 is characterized in that: The key generation center is used to respond to the second key request, obtain the corresponding salt value from the relationship table according to the chip unique serial number in the first key request, and generate a root key through a key derivation algorithm, and use the root key to calculate the second authentication code for the first key request. When the second authentication code matches the first authentication code, a user key is generated and the public key of the SM2 temporary key pair in the first key request is used to encrypt the user key to obtain a user key ciphertext, and then the root key is used to calculate a third authentication code for a key package consisting of the user key ciphertext and the key generation center identifier, and the key package and the third authentication code are sent to the Internet of Things platform; The Internet of Things platform is also used to send the key package and the third authentication code to the communication module.
4. The super SIM card key generation system supporting the national secret SM9 algorithm according to claim 3 is characterized in that: The communication module is also used to forward the key package and the third authentication code to the MCU; The MCU is also used to generate a parsing instruction including a key package and the third authentication code, and transparently transmit the parsing instruction to the super SIM card through the communication module; The super SIM card is also used to respond to the parsing instruction and use the root key to calculate the key package to obtain a fourth identification code, and when the fourth identification code matches the third identification code, use the private key of the SM2 temporary key pair to decrypt the user key ciphertext in the key package to obtain the user key, and store the user key and the key generation center identifier in the key package in the memory.
5. The super SIM card key generation system supporting the national secret SM9 algorithm according to any one of claims 1 to 4, characterized in that: The calculation algorithm of the first authentication code, the second authentication code, the third authentication code and the fourth authentication code is a hash algorithm using a root key.
6. The super SIM card key generation system supporting the national secret SM9 algorithm according to any one of claims 1 to 4, characterized in that: The Internet of Things platform communicates with the key generation center through a secure channel.
7. The super SIM card key generation system supporting the national secret SM9 algorithm according to claim 4, characterized in that: The super SIM card includes an application layer and a hardware layer, the hardware layer includes a non-volatile memory, and the application layer is used to store the user key and the key generation center identifier in the non-volatile memory.
8. The super SIM card key generation system supporting the national secret SM9 algorithm according to claim 7, characterized in that: The application layer is also used to store the key generation center identifier and key operation parameters in the non-volatile memory.
9. The super SIM card key generation system supporting the national secret SM9 algorithm according to claim 8, characterized in that: The hardware layer also includes a random access memory, and the application layer is further used for: The user key and the key operation parameters are loaded from the non-volatile memory into the random access memory according to the received key generation center identifier.
10. A super SIM card key generation method supporting the national secret SM9 algorithm, characterized in that: The super SIM card key generation system supporting the national secret SM9 algorithm as described in any one of claims 1 to 9 specifically comprises the following steps: The terminal device generates a key generation instruction; The super SIM card generates an SM2 temporary key pair in response to the key generation instruction, generates a first key request including a public key of the SM2 temporary key pair and a preset chip unique serial number, and calculates a first authentication code for the first key request using a preset root key; The terminal device generates, in response to the first key request, a second key request including the first key request and a first authentication code and sends the second key request to the Internet of Things platform; The Internet of Things platform sends the second key request to a key generation center; The key generation center responds to the second key request, obtains the corresponding salt value from the relationship table according to the chip unique serial number in the first key request, generates a root key through a key derivation algorithm, uses the root key to calculate the second authentication code for the first key request, and when the second authentication code matches the first authentication code, generates a user key and uses the public key of the SM2 temporary key pair in the first key request to encrypt the user key to obtain a user key ciphertext, and then uses the root key to calculate a third authentication code for a key package consisting of the user key ciphertext and the key generation center identifier, and sends the key package and the third authentication code to the Internet of Things platform; The Internet of Things platform sends the key package and the third authentication code to the terminal device; The terminal device forwards the key package and the third authentication code to the super SIM card; The super SIM card uses the root key to calculate the fourth identification code for the key package. When the fourth identification code matches the third identification code, the private key of the SM2 temporary key pair is used to decrypt the user key ciphertext in the key package to obtain the user key, and the user key and the key generation center identifier in the key package are stored in the memory.
Citation Information
Patent Citations
Method and system for generating SM9 identification public key of smart device
CN115065467A
Vehicle-mounted ECU identity authentication method through secret key
CN115883130A