A method, apparatus, device, medium, and product for key determination
By obtaining the public key polynomial and building the target key polynomial, and using sparse matrix processing of user identification, the problem of high computational calculation of key determination is solved, and fast and secure communication is achieved.
Patent Information
- Application Number
- CN202411995745.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2044-12-31
AI Technical Summary
The prior art has a large amount of calculation and low efficiency when determining keys, making it difficult to achieve fast and secure communication in a huge network.
By obtaining the public key polynomial from the key center, a target key polynomial is constructed, and the user identification is processed using sparse matrix to determine the shared key and reduce the calculation amount.
This improves the efficiency of key determination, reduces the amount of computing, and realizes fast and secure communication between nodes in a large-scale network.
Smart Images

Figure CN119853902B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of encryption technology and communication technology, and particularly to a method, apparatus, device, medium and product for determining a key. Background Art
[0002] With the development of Internet technology, it is extremely important for fast and secure communication between nodes to ensure that each node in a large-scale network can securely obtain the paired key for communicating with other nodes. In the prior art, there are problems of large computational amount and low efficiency in determining keys. Summary of the Invention
[0003] The present invention provides a method, apparatus, device, medium and product for determining a key to improve the key determination efficiency.
[0004] According to one aspect of the present invention, there is provided a method for determining a key, the method comprising:
[0005] Obtaining a public key polynomial from a key management center; wherein the public key polynomial includes public parameters and a key factor set; the key factor set includes a first key factor, a second key factor and a third key factor;
[0006] Constructing a target key polynomial according to a target identification matrix of a target user and the public key polynomial;
[0007] Obtaining an identification matrix of the other party of the other user;
[0008] Determining a shared key between the target user and the other user according to the identification matrix of the other party and the target key polynomial.
[0009] According to another aspect of the present invention, there is provided a key determination apparatus, the apparatus comprising:
[0010] A public key polynomial obtaining module, configured to obtain a public key polynomial from a key management center; wherein the public key polynomial includes public parameters and a key factor set; the key factor set includes a first key factor, a second key factor and a third key factor;
[0011] A target key polynomial constructing module, configured to construct a target key polynomial according to a target identification matrix of a target user and the public key polynomial;
[0012] An identification matrix obtaining module of the other party, configured to obtain an identification matrix of the other party of the other user;
[0013] A shared key determining module, configured to determine a shared key between the target user and the other user according to the identification matrix of the other party and the target key polynomial.
[0014] According to another aspect of the present invention, there is provided an electronic device, which includes:
[0015] at least one processor; and
[0016] a memory communicatively connected to the at least one processor; wherein,
[0017] the memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the key determination method according to any embodiment of the present invention.
[0018] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for enabling a processor to implement the key determination method according to any embodiment of the present invention when executed.
[0019] According to another aspect of the present invention, there is provided a computer program product including a computer program which, when executed by a processor, implements the key determination method according to any embodiment of the present invention.
[0020] In the technical solution of the embodiment of the present invention, a public key polynomial is obtained from a cipher management center; wherein, the public key polynomial includes public parameters and a key factor set; the key factor set includes a first key factor, a second key factor and a third key factor. Then, according to the target identification matrix of the target user and the public key polynomial, a target key polynomial is constructed, and then the identification matrix of the other user is obtained. Finally, according to the identification matrix of the other user and the target key polynomial, the shared key between the target user and the other user is determined. In the above technical solution, by performing matrix processing on the user identification to determine the shared key, the calculation amount during key determination can be reduced, thereby improving the key determination efficiency.
[0021] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.
[0023] Figure 1It is a flowchart of a key determination method provided according to an embodiment of the present invention;
[0024] Figure 2 It is a flowchart of a key determination method provided according to an embodiment of the present invention;
[0025] Figure 3 It is a schematic structural diagram of a key determination device provided according to an embodiment of the present invention;
[0026] Figure 4 It is a schematic structural diagram of an electronic device for implementing the key determination method according to an embodiment of the present invention. Detailed implementation manners
[0027] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data used in appropriate cases can be interchanged so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0029] In addition, it should also be noted that in the technical solution of the present invention, the collection, storage, use, processing, transmission, provision, and disclosure of relevant data such as user identifiers comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0030] Figure 1 It is a flowchart of a key determination method provided according to an embodiment of the present invention. This embodiment is applicable to the situation of how nodes in a large-scale network perform fast and secure communication. This method can be executed by a key determination device, which can be implemented in the form of hardware and / or software, and the device can be configured in an electronic device with a key determination function, such as a server. As Figure 1As shown in the figure, the key determination method of this embodiment may include:
[0031] S110. Obtain a public key polynomial from the key management center; wherein, the public key polynomial includes public parameters and a key factor set.
[0032] In this embodiment, the key center is used to determine the key function and distribute the public key polynomial to each node user in the network. It should be noted that if shared communication is carried out between two node users, the public key polynomial is a binary quadratic polynomial. Among them, the public key polynomial is used for each node user to determine the shared key. The key factor set includes the coefficients of each term in the public key polynomial, including the first key factor, the second key factor, and the third key factor. The first key factor, the second key factor, and the third key factor are randomly determined natural numbers, which may be the same or different; the key factor set is publicly available between the two node users for shared communication. The public parameter is a prime number and is publicly available to each node user in the network.
[0033] Specifically, the key management center sends the public key polynomial of the shared user to the corresponding user; correspondingly, for each target user, the public key polynomial can be obtained from the key management center.
[0034] S120. Construct a target key polynomial according to the target identification matrix of the target user and the public key polynomial.
[0035] In this embodiment, the target user refers to the user of any network node in the communication network. The so-called target identification matrix refers to the identification matrix obtained by performing sparse matrix processing on the target user identification of the target user; optionally, the non-zero elements in the target identification matrix can be stored using a triple node, which can save storage space. It should be noted that the matrix size of the target identification matrix is determined by the target user identification of the target user and the number of users of the other party. Among them, the other party user refers to the user of other network nodes in the network that communicates with the target user.
[0036] The so-called target key polynomial refers to a polynomial used to determine the shared key based on the user identification of the other party user, and it is a unary quadratic polynomial.
[0037] Specifically, substitute the target identification matrix of the target user into the public key polynomial for a self-variable substitution to obtain the target key polynomial.
[0038] S130. Obtain the other party identification matrix of the other party user.
[0039] Specifically, when it is necessary to conduct secure communication with the other party user, obtain the other party identification matrix sent by the other party user.
[0040] S140: Determine a shared key between the target user and the other user according to the other party's identification matrix and the target key polynomial.
[0041] The shared key is used for encrypted communication between the target user and the other user.
[0042] Specifically, the other party's identification matrix may be substituted into the target key polynomial for operation to obtain a shared key between the target user and the other party user.
[0043] The technical solution of an embodiment of the present invention obtains a public key polynomial from a key management center; the public key polynomial includes public parameters and a key factor set; the key factor set includes a first key factor, a second key factor, and a third key factor. A target key polynomial is then constructed based on the target user's target identification matrix and the public key polynomial. The other party identification matrix of the other party is then obtained. Finally, the shared key between the target user and the other party is determined based on the other party identification matrix and the target key polynomial. By matrixing the user identifications and then determining the shared key, the above technical solution can reduce the computational effort involved in key determination, thereby improving key determination efficiency.
[0044] Figure 2 This is a flow chart of a key determination method provided according to an embodiment of the present invention. Based on the above embodiment, this embodiment further optimizes "constructing a target key polynomial based on the target identification matrix and public key polynomial of the target user" and provides an optional implementation scheme. Figure 2 As shown, the key determination method of this embodiment may include:
[0045] S210. Obtain a public key polynomial from a key management center; wherein the public key polynomial includes a public parameter and a key factor set.
[0046] The key factor set includes a first key factor, a second key factor and a third key factor.
[0047] Specifically, a public key polynomial such as f(x, y) = (a+b(x+y)+cxy) mod p can be obtained from the key management center; where a, b, c are the first key factor, the second key factor, and the third key factor respectively; and p is a public parameter.
[0048] S220 : Map the target user identifier of the target user to a sparse matrix to obtain a target identifier matrix.
[0049] Specifically, the target user identification of the target user is mapped to a sparse matrix to obtain a target identification matrix. For example, the target identification matrix is r U .
[0050] S230. Construct a candidate key polynomial according to the target identity matrix and the public key polynomial.
[0051] In this embodiment, the candidate key polynomial refers to the key polynomial of the target user, that is, the polynomial introducing the target identity matrix. For example, the candidate key polynomial is g U (x) = f(x, r U ) mod p.
[0052] S240. Perform a linear transformation on the candidate key polynomial to obtain the target key polynomial.
[0053] Specifically, it includes: constructing the first key coefficient according to the first key factor, the second key factor, the public parameter, and the target identity matrix; constructing the second key coefficient according to the second key factor, the third key factor, the public parameter, and the target identity matrix; constructing the target key polynomial according to the first key coefficient, the second key coefficient, and the identity of the other party to be obtained. Specifically, it can be determined in the following way: perform a transformation on g U (x) to obtain a linear polynomial, g I (x) = a U +b U x, where a U = a + br U mod p, b Y = b + cr U mod p; where a U is the first key coefficient, b U is the second key coefficient, and x is the identity of the other party to be obtained.
[0054] S250. Obtain the identity matrix of the other user.
[0055] Obtain the identity matrix r V of the other user.
[0056] S260. Determine the shared key between the target user and the other user according to the identity matrix of the other party and the target key polynomial.
[0057] Specifically, substitute the identity matrix of the other party into the target key polynomial to replace the identity of the other party to be obtained for calculation, and obtain the shared key between the target user and the other user, that is, obtain the shared key KB = g U (r V ) = a U +b U r V .
[0058] The technical solution provided by the embodiments of the present invention is to obtain a public key polynomial from the secret management center; wherein the public key polynomial includes public parameters and a key factor set, and then map the target user identifier of the target user to a sparse matrix to obtain a target identifier matrix, construct a candidate key polynomial according to the target identifier matrix and the public key polynomial, perform a linear transformation on the candidate key polynomial to obtain a target key polynomial, and further obtain the other party identifier matrix of the other party user, and determine the shared key between the target user and the other party user according to the other party identifier matrix and the target key polynomial. The above technical solution can reduce the number of operations and improve the key determination efficiency by obtaining the shared key between users through a sparse matrix.
[0059] Figure 3 FIG. 4 is a schematic structural diagram of a key determination device provided by an embodiment of the present invention. This embodiment is applicable to the situation of how to perform fast and secure communication between nodes in a large-scale network. The device can be implemented in the form of hardware and / or software, and the device can be configured in an electronic device carrying the key determination function, such as a server. As Figure 3 shown, the key determination device of this embodiment may include:
[0060] A public key polynomial acquisition module 310, configured to obtain a public key polynomial from the secret management center; wherein the public key polynomial includes public parameters and a key factor set; the key factor set includes a first key factor, a second key factor, and a third key factor;
[0061] A target key polynomial construction module 320, configured to construct a target key polynomial according to the target identifier matrix of the target user and the public key polynomial;
[0062] An other party identifier matrix acquisition module 330, configured to obtain the other party identifier matrix of the other party user;
[0063] A shared key determination module 340, configured to determine the shared key between the target user and the other party user according to the other party identifier matrix and the target key polynomial.
[0064] The technical solution of the embodiments of the present invention is to obtain a public key polynomial from the secret management center; wherein the public key polynomial includes public parameters and a key factor set; the key factor set includes a first key factor, a second key factor, and a third key factor, and then construct a target key polynomial according to the target identifier matrix of the target user and the public key polynomial, and further obtain the other party identifier matrix of the other party user, and finally determine the shared key between the target user and the other party user according to the other party identifier matrix and the target key polynomial. The above technical solution can reduce the calculation amount during key determination by performing matrix processing on the user identifier, thereby improving the key determination efficiency.
[0065] Optionally, the target key polynomial construction module 320 includes:
[0066] A target identification matrix acquisition unit, configured to map the target user identification of the target user to a sparse matrix to obtain a target identification matrix;
[0067] A candidate key polynomial construction unit, configured to construct a candidate key polynomial according to the target identification matrix and the public key polynomial;
[0068] A target key polynomial construction unit, configured to perform a linear transformation on the candidate key polynomial to obtain a target key polynomial.
[0069] Optionally, the target key polynomial construction unit is specifically configured to:
[0070] Construct a first key coefficient according to a first key factor, a second key factor, a public parameter, and the target identification matrix;
[0071] Construct a second key coefficient according to the second key factor, a third key factor, the public parameter, and the target identification matrix;
[0072] Construct a target key polynomial according to the first key coefficient, the second key coefficient, and the identification of the other party to be obtained.
[0073] ]>Optionally, the shared key is used for encrypted communication between the target user and the other user.
[0074] Optionally, a triple node is used to store the non-zero elements in the target identification matrix.
[0075] Optionally, the matrix size of the target identification matrix is determined by the target user identification of the target user and the number of users of the other user.
[0076] The key determination device provided by the embodiments of the present invention can execute the key determination method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0077] According to an embodiment of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.
[0078] Figure 4 It is a schematic structural diagram of an electronic device for implementing the key determination method of the embodiments of the present invention. Figure 4The structural schematic diagram of an electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0079] As Figure 4 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0080] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0081] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the key determination method.
[0082] In some embodiments, the key determination method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the key determination method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the key determination method by any other suitable means (e.g., by means of firmware).
[0083] The various embodiments of the systems and techniques described above in this document may be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: implemented in one or more computer programs that may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0084] The computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs may be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.
[0085] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0086] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0087] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by any form or medium of digital data communication (e.g., a communication network). Examples of the communication network include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0088] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0089] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.
[0090] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A key determination method, characterized in that Comprising: Obtaining a public key polynomial from a secure management center; wherein, the public key polynomial includes public parameters and a set of key factors; The set of key factors includes a first key factor, a second key factor, and a third key factor; Constructing a target key polynomial according to the target identification matrix of the target user and the public key polynomial; Obtaining the other party identification matrix of the other party user; Determining a shared key between the target user and the other party user according to the other party identification matrix and the target key polynomial.
2. The method according to claim 1, characterized in that Constructing a target key polynomial according to the target identification matrix of the target user and the public key polynomial, including: Mapping the target user identification of the target user to a sparse matrix to obtain a target identification matrix; Constructing a candidate key polynomial according to the target identification matrix and the public key polynomial; Performing a linear transformation on the candidate key polynomial to obtain a target key polynomial.
3. The method according to claim 2, characterized in that, Performing a linear transformation on the candidate key polynomial to obtain a target key polynomial, including: Constructing a first key coefficient according to the first key factor, the second key factor, the public parameters, and the target identification matrix; Constructing a second key coefficient according to the second key factor, the third key factor, the public parameters, and the target identification matrix; Constructing a target key polynomial according to the first key coefficient, the second key coefficient, and the other party identification to be obtained.
4. The method according to any one of claims 1 to 3, characterized in that The shared key is used for encrypted communication between the target user and the other party user.
5. The method according to any one of claims 1-3, characterized in that, Using triple nodes to store non-zero elements in the target identification matrix.
6. The method according to any one of claims 1 to 3, characterized in that, The matrix size of the target identification matrix is determined by the target user identification of the target user and the number of users of the other party user.
7. A key determination device, characterized in that, Comprising: A public key polynomial obtaining module, configured to obtain a public key polynomial from a secure management center; wherein, the public key polynomial includes public parameters and a set of key factors; the set of key factors includes a first key factor, a second key factor, and a third key factor; A target key polynomial constructing module, configured to construct a target key polynomial according to the target identification matrix of the target user and the public key polynomial; An other party identification matrix obtaining module, configured to obtain the other party identification matrix of the other party user; A shared key determining module, configured to determine a shared key between the target user and the other party user according to the other party identification matrix and the target key polynomial.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the key determination method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the key determination method according to any one of claims 1-6 when executed.
10. A computer program product, characterized in that, The computer program product includes a computer program, and the computer program implements the key determination method according to any one of claims 1-6 when executed by a processor.
Citation Information
Patent Citations
Certificateless key negotiation method, system, device and medium
CN117394995A
Message storage and transfer system
US20130246787A1