Identity authentication method, data transmission method and system and electronic equipment

Through the two-way identity authentication and data transmission method based on quantum keys on mobile terminal devices, the problem of insufficient security in the face of quantum computer attacks is solved, and efficient and secure quantum key usage and data protection are achieved.

CN119945676APending Publication Date: 2025-05-06E SURFING VISION TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510138499.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Existing identity authentication and data encryption methods have insufficient security in the face of quantum computer attacks, especially in mobile terminal devices, which are difficult to achieve efficient and secure quantum key generation and use.

Method used

A two-way identity authentication method and data transmission method based on quantum key are proposed. By independently and flexibly selecting quantum keys on both terminals, generating authentication tokens, and using quantum keys for key derivation, extending the life cycle of quantum keys and improving data security.

Benefits of technology

It realizes efficient and secure identity authentication interaction process, effectively resists the cracking risks faced by traditional encryption algorithms, extends the service life of quantum keys, and significantly improves the practical scenario applicability of quantum encryption on mobile terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945676A_ABST
    Figure CN119945676A_ABST
Patent Text Reader

Abstract

The invention discloses an identity authentication method and a data transmission method based on a quantum key, the identity authentication method flexibly selects the quantum key to generate an authentication token, so that the authentication interaction process is efficient and safe, and as the quantum key is true randomness, identity authentication information is encrypted by using the quantum key, so that the authentication efficiency is improved. The cracking risk faced by a traditional encryption algorithm can be effectively resisted; according to the data transmission method, key derivation is carried out by using a quantum key instead of directly using the quantum key to carry out data encryption and decryption, so that the life cycle of the quantum key is prolonged, and the terminal does not need to update the key in a short time; according to the method provided by the invention, the quantum key can be safely stored in the local terminal, an online key distribution infrastructure is not needed, and the actual scene applicability during quantum encryption is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to network data security technology, and in particular relates to an identity authentication method, a data transmission method and device, and an electronic device. Background Art

[0002] Identity authentication and data encryption have become necessary requirements for security systems. Existing identity authentication with a higher level of security mostly uses methods based on digital certificates and digital signatures. In essence, it uses public key cryptography algorithms for signing and verifying signatures to achieve identity authentication. However, the most commonly used public key cryptography RSA and ECC have polynomial time efficient cracking algorithms under quantum computer attacks, and their security has caused people's concerns.

[0003] In terms of data encryption (mostly using symmetric cryptographic algorithms), according to the Kerckhoff principle, it is usually assumed that the cryptographic algorithm is public and the key is the core of confidentiality. However, in practice, the key generation method is mostly using a pseudo-random number generator or a traditional physical noise source method. These methods lack randomness and unpredictability of the key, resulting in the possibility that the key can be restored by an attacker.

[0004] In response to the above problems, there are currently some evolving solutions: (1) In terms of public key cryptography, research and design of post-quantum cryptographic algorithms to achieve resistance to quantum computer attacks; (2) In terms of symmetric cryptography, use quantum physics-based methods to generate information-theoretically secure quantum keys. Since quantum keys are truly random and unpredictable, the security of the keys is greatly enhanced.

[0005] However, there are still many problems with existing solutions. For example, it will take a long time for post-quantum public key cryptography algorithms to be applied, and the quantum cryptography distribution (QKD) method requires the support of optical quantum infrastructure. Currently, it can only be applied to platform-level systems at fixed locations and cannot support mobile terminal devices. In addition, it is costly to directly generate quantum keys on mobile terminals, making it difficult to apply them on a large scale. Summary of the invention

[0006] Based on this, the present invention aims to propose a two-way identity authentication method and data transmission method based on quantum keys. The two parties of identity authentication can independently and flexibly select quantum keys, and the data transmission based on quantum keys realizes one session and one key, thereby improving data security.

[0007] In a first aspect, the present invention provides an identity authentication method, comprising:

[0008] The first terminal determines a first quantum key for encrypting identity authentication information;

[0009] The first terminal uses the first quantum key to encrypt the identity authentication information to generate an authentication token, and sends the authentication token to the second terminal;

[0010] The second terminal determines, based on the authentication token, a second quantum key for decrypting the identity authentication information of the first terminal;

[0011] The second terminal uses the second quantum key to decrypt the authentication token to obtain the identity authentication information of the first terminal, and uses the decrypted identity authentication information of the first terminal to perform identity authentication on the first terminal.

[0012] Further, the first terminal determines the first quantum key for encrypting the identity authentication information including:

[0013] Obtaining a quantum key group, the quantum key group including a plurality of quantum keys;

[0014] A quantum key for encrypting identity authentication information is determined in the quantum key group as a first quantum key.

[0015] Further, determining a quantum key for encrypting identity authentication information in the quantum key group as a first quantum key includes:

[0016] A quantum key for encrypting identity authentication information is randomly selected from the quantum key group as the first quantum key.

[0017] Further, the first terminal uses the first quantum key to encrypt the identity authentication information to generate an authentication token, including:

[0018] The identity authentication information is encrypted using the first quantum key to generate an authentication ciphertext, and an authentication token is generated according to the terminal identifier of the first terminal and the authentication ciphertext, wherein the authentication token includes a key index of the first quantum key.

[0019] Further, the second terminal determines, according to the authentication token, a second quantum key for decrypting the identity authentication information of the first terminal, including:

[0020] Parsing the authentication token to determine a key index of the first quantum key;

[0021] The second quantum key is determined according to the key index of the first quantum key, and the second quantum key and the first quantum key are a pair of symmetric keys.

[0022] Further, the second terminal performs identity authentication on the first terminal using the decrypted identity authentication information of the first terminal, including:

[0023] The second terminal verifies the consistency between the identity authentication information carried in the authentication token and the identity authentication information obtained by decryption.

[0024] In a second aspect, the present invention further provides a data transmission method, comprising:

[0025] The first terminal determines a third quantum key for encrypting data, performs key derivation using the third quantum key, and generates a data encryption key for directly encrypting data;

[0026] The first terminal encrypts the transmission data using the data encryption key to generate data ciphertext, and transmits the data ciphertext to the second terminal;

[0027] The second terminal determines a fourth quantum key for decrypting the data according to the data ciphertext, performs key derivation using the fourth quantum key, and generates a data decryption key for decrypting the data ciphertext;

[0028] The second terminal uses the data decryption key to decrypt the data ciphertext to obtain the transmission data.

[0029] Further, the first terminal determines the third quantum key used to encrypt data including:

[0030] Obtaining a quantum key group, the quantum key group including a plurality of quantum keys;

[0031] A quantum key for encrypting data is determined as a third quantum key in the quantum key group.

[0032] Furthermore, the first terminal uses the third quantum key to perform key derivation to generate a data encryption key for directly encrypting data, including:

[0033] Obtaining the current session identifier and key usage with the second terminal;

[0034] A key is derived based on the third quantum key, the current session identifier and the key purpose to generate a data encryption key.

[0035] Furthermore, the second terminal determines the fourth quantum key for decrypting the data according to the data ciphertext, including:

[0036] The second terminal parses the data ciphertext to obtain a key index of the third quantum key;

[0037] The fourth quantum key is determined according to the key index of the third quantum key, and the third quantum key and the fourth quantum key are a pair of symmetric keys.

[0038] In a third aspect, the present invention provides an identity authentication system, including a first terminal and a second terminal;

[0039] The first terminal deployment includes:

[0040] A first key determination module, used to determine a first quantum key for encrypting identity authentication information;

[0041] An authentication information encryption module, used to encrypt the identity authentication information using the first quantum key to generate an authentication token, and send the authentication token to the second terminal;

[0042] The second terminal deployment includes:

[0043] A second key determination module, used to determine a second quantum key for decrypting the identity authentication information of the first terminal according to the authentication token;

[0044] The decryption and authentication module is used to use the second quantum key to decrypt the authentication token to obtain the identity authentication information of the first terminal, and use the decrypted identity authentication information of the first terminal to authenticate the first terminal.

[0045] In a fourth aspect, the present invention provides a data transmission system, comprising a first terminal and a second terminal;

[0046] The first terminal deployment includes:

[0047] A first key derivation module, used to determine a third quantum key for encrypting data, perform key derivation using the third quantum key, and generate a data encryption key for directly encrypting data;

[0048] A data encryption module, used to encrypt the transmission data using the data encryption key to generate data ciphertext, and transmit the data ciphertext to the second terminal;

[0049] The second terminal deployment includes:

[0050] A second key derivation module determines a fourth quantum key for decrypting the data according to the data ciphertext, performs key derivation using the fourth quantum key, and generates a data decryption key for decrypting the data ciphertext;

[0051] The data decryption module is used to decrypt the data ciphertext using the data decryption key to obtain the transmission data.

[0052] Another aspect of an embodiment of the present invention provides an electronic device, comprising a memory storing computer-executable instructions and a processor. When the computer-executable instructions are executed by the processor, the device executes the identity authentication method provided in the above-mentioned first aspect embodiment and / or any possible implementation method in combination with the first aspect embodiment, or executes the data transmission method provided in the above-mentioned second aspect embodiment.

[0053] Another aspect of an embodiment of the present invention provides a readable storage medium storing a computer executable program. When the program is executed, it can implement the identity authentication method provided by the above-mentioned first aspect embodiment and / or any possible implementation method combined with the first aspect embodiment, or execute the data transmission method provided by the above-mentioned second aspect embodiment.

[0054] The present invention has the following beneficial effects:

[0055] The present invention proposes an identity authentication method and a data transmission method based on quantum keys. Both parties of authentication or data transmission can independently implement the method proposed by the present invention. The identity authentication method flexibly selects quantum keys to generate authentication tokens, so that the authentication interaction process is efficient and safe. Since quantum keys are truly random, using quantum keys to encrypt identity authentication information can effectively resist the cracking risks faced by traditional encryption algorithms. In a further embodiment, the second terminal determines the second quantum key according to the key index of the quantum key selected by the first terminal, and the authentication process based on the symmetric key algorithm is not susceptible to quantum computing attacks; the proposed data transmission method uses quantum keys for key deriving rather than directly using quantum keys for data encryption and decryption, thereby extending the life cycle of quantum keys and the terminal does not need to update the key in a short time; the method proposed by the present invention enables quantum keys to be securely stored locally on the terminal without the need for online key distribution infrastructure, significantly improving the applicability of actual scenarios when quantum encryption is used. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0057] Figure 1 is an architecture diagram of an identity authentication system provided by an embodiment of the present invention;

[0058] Figure 2 is a flowchart of an identity authentication method provided by an embodiment of the present invention;

[0059] Figure 3 is a schematic diagram of a mobile terminal and an identity authentication platform performing two-way identity authentication according to an embodiment of the present invention;

[0060] Figure 4 is a diagram of the data transmission system architecture provided by an embodiment of the present invention;

[0061] Figure 5 is a flow chart of a data transmission method according to an embodiment of the present invention;

[0062] Figure 6 It is a schematic diagram of uplink and downlink data transmission between a mobile terminal and a data service platform provided by an embodiment of the present invention;

[0063] Figure 7 This is a diagram of the electronic device architecture provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0064] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0065] See also Figure 1 An embodiment of the present invention provides an identity authentication system 10, including a first terminal 11 and a second terminal 12; the first terminal 11 is deployed with a first key determination module 111 and an authentication information encryption module 112, and the second terminal 12 is deployed with a second key determination module 121 and a decryption authentication module 122.

[0066] Specifically, the first terminal and the second terminal may be terminal devices used by a user, such as a smart phone, a computer or other smart device, or terminal devices of a service provider, such as a server, a cloud platform or other authentication devices.

[0067] When it is a terminal device such as a smart phone, computer or other smart device, such user terminal includes smart phones, tablet computers, laptops, desktop computers, wearable devices, smart homes, head-mounted devices and other smart terminals with data processing functions; when it is a terminal device such as a server, cloud platform or other authentication device, it can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or it can be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms.

[0068] According to an implementation aspect of the present invention, the first terminal and the second terminal can complete one-way identity authentication or two-way identity authentication.

[0069] based on Figure 1 The illustrated identity authentication system, one implementation aspect of the present invention will provide a corresponding identity authentication method implementation process.

[0070] See also Figure 2 An embodiment of the present invention provides an identity authentication method, comprising the following steps:

[0071] Step S210: The first terminal determines a first quantum key for encrypting identity authentication information.

[0072] Specifically, in this embodiment, the first terminal does not need to generate the first quantum key by itself, but injects a quantum key with true randomness into the storage module of the first terminal through a quantum key injection machine with a quantum key preparation mechanism, and the first terminal accesses the quantum key group in the storage module through a secure access interface to determine one of them as the first quantum key.

[0073] The key pre-injection process can be during the device manufacturing stage or initialization stage, when a trusted key manager (such as a device manufacturer or a certification center) generates a set of quantum keys, which are then injected into the storage module of the first terminal in a secure manner. The storage module is usually a high-security hardware module (such as a TPM, HSM, or a dedicated encryption chip) to prevent the keys from being stolen or tampered with.

[0074] Optionally, when the first terminal needs to perform identity authentication, it randomly selects a quantum key from the set of pre-injected quantum keys as the first quantum key. In a more preferred implementation, the random selection process should be completed by a high-quality random number generator (such as a hardware-based true random number generator) to avoid the selection pattern being predicted by an attacker.

[0075] In some embodiments, when a symmetric key algorithm is used for encryption and decryption, the key manager injects the same set of quantum keys into the storage module of the second terminal, so that in the subsequent identity authentication process, the second terminal can generate a second quantum key symmetric to the first quantum key to complete the decryption and authentication of the authentication information.

[0076] Step S220. The first terminal uses the first quantum key to encrypt the identity authentication information to generate an authentication token, and sends the authentication token to the second terminal.

[0077] Specifically, the identity authentication information includes the first terminal identifier, the second terminal identifier, the key index of the first quantum key, and a timestamp. The first terminal concatenates various identity authentication information into an authentication plaintext, encrypts the authentication plaintext using the first quantum key to generate an authentication ciphertext, and further generates an authentication token based on the terminal identifier and the authentication ciphertext of the first terminal. The authentication token includes the key index of the first quantum key.

[0078] An authentication token is a credential used for identity authentication, which often includes an authentication ciphertext, a terminal identifier, and a key index. An optional implementation may carry more information in the authentication token, and a more preferred implementation may concatenate more strings in the authentication plaintext to represent richer authentication information, such as the terminal's username, password, etc.

[0079] Step S230: The second terminal determines a second quantum key for decrypting the identity authentication information of the first terminal according to the authentication token.

[0080] In this step, the second terminal parses the authentication token and determines the second quantum key for decrypting the identity authentication information of the first terminal according to the parsed content.

[0081] In a more preferred embodiment, the first terminal carries a key index in the authentication token to instruct the second terminal to use the corresponding quantum key for decryption. If the key management party injects the same set of quantum keys into both parties, the second terminal can parse the authentication token to determine the key index of the first quantum key, and determine the second quantum key according to the key index of the first quantum key. The second quantum key and the first quantum key are a pair of symmetric keys. Specifically, according to the key index in the authentication token, the corresponding key, i.e., the second quantum key, is found from the quantum key group stored by itself. The premise of this is that the first terminal and the second terminal must pre-share the same quantum key group in the initialization phase to ensure that the key corresponding to the key index is consistent.

[0082] The key index in the authentication token indicates the position of the currently used quantum key in the pre-shared key group, which simplifies the selection of keys during decryption. Therefore, the design of the key index should avoid leaking too much information while ensuring the accuracy of the index.

[0083] The key mechanism provided by some implementation aspects of the present invention adopts a symmetric key algorithm. The second quantum key corresponds to the first quantum key one-to-one, but is not directly transmitted. It is indirectly pointed to by an index. Due to the randomness and non-cloning of the quantum key, an attacker cannot infer the key content by intercepting the authentication token. The encrypted authentication ciphertext and quantum key index are both included in the authentication token and transmitted through an encrypted channel to prevent tampering or theft during transmission.

[0084] Step S240. The second terminal uses the second quantum key to decrypt the authentication token to obtain the identity authentication information of the first terminal, and uses the decrypted identity authentication information of the first terminal to authenticate the first terminal.

[0085] In this step, the second terminal uses the same symmetric algorithm as the first terminal for decryption. For example, if the first terminal uses the AES algorithm to encrypt the authentication plaintext, the second terminal also uses the AES algorithm to decrypt the authentication ciphertext. Due to the randomness and pre-sharing mechanism of the quantum key, only the second terminal with the correct key can decrypt and obtain the correct identity authentication information.

[0086] Specifically, the decrypted authentication information is the real authentication data of the first terminal, such as terminal identification, password, timestamp, etc. The second terminal needs to verify it. The verification method includes checking whether the authentication information includes the expected identity information, such as whether the user name is valid and whether the password matches; if the authentication information contains a timestamp or random number, verify whether it is within the validity period to prevent replay attacks.

[0087] In a further embodiment, the terminal identifiers of both parties are concatenated in the identity authentication information, and the authentication token is also concatenated with the first terminal identifier, then the identity authentication information and the first terminal identifier and the key index in the authentication token can be compared to see if they are consistent. A more preferred implementation can also verify whether the identity authentication information and the second terminal identifier of the second terminal itself are consistent. If these information are consistent, it is considered that the first terminal has been authenticated. In addition, for the identity authentication information that carries a timestamp, the timeliness of the timestamp obtained after decryption can also be verified.

[0088] In a more specific implementation, the first terminal and the second terminal can perform two-way authentication. Based on the true randomness pre-sharing mechanism of quantum keys, after the second terminal completes the identity authentication of the first terminal, it can also use the same method to generate an authentication token of the second terminal and send it to the first terminal for identity authentication. The process is similar to the identity authentication process described in the aforementioned embodiment and will not be repeated here. In this way, two-way authentication of the two terminals can be completed.

[0089] According to the implementation aspects of the present invention, after one party completes the identity authentication of the other party, an identity authentication result can be returned. In a more specific embodiment, if the identity authentication of a terminal fails, the identity authentication can be retried, and the authentication initiating terminal sends a retry message. More preferably, a threshold for the number of retries can be set in advance. When the authentication fails and the number of retries exceeds the threshold, the retry is abandoned and the authenticating party sends an authentication failure result.

[0090] In the example, the mobile terminal is the first terminal and the identity authentication platform is the second terminal. Figure 3 As shown, taking the two-way identity authentication process as an example, the identity authentication methods provided by the above embodiments are explained below through an embodiment.

[0091] The user of the first terminal can initiate an identity authentication request through a specific application or plug-in, and securely access the quantum key stored in the storage module through a specific SDK. Index_T represents the number of the quantum key accessed by the first terminal. For example, when 1000 quantum keys are charged, the value range of Index_T is [1, 1000], and the Index_T value is randomly selected within the value range each time the access is made. ID_T and ID_P are the identities of the first terminal and the second terminal respectively, and Time is the current timestamp. The accuracy can be set according to actual needs, such as accurate to seconds.

[0092] The authentication plaintext is , where the symbol Represents the concatenation of strings, in The purpose of embedding the identities of both parties is to prevent an attacker from impersonating one of the parties and replaying the authentication Token to the other party.

[0093] The first terminal uses the key index The corresponding quantum key Use the national encryption algorithm SM4 encryption , obtain the authentication ciphertext Cipher_T=SM4_Encrypt(Key_T, Message_T), set the value of the authentication token Token_T on the first terminal side to Token_T=ID_T||Index_T||Cipher_T, and finally the first terminal sends Token_T to the authentication platform.

[0094] After receiving the authentication Token_T from the terminal, the authentication platform first The number of the quantum key group stored in the first terminal can be obtained as This is because the terminal and the authentication platform inject the same key group when the quantum key is pre-injected. The second terminal can decrypt the corresponding authentication message plaintext. The decryption process can be expressed as , and according to The definition format is parsed into ID_T, ID_P, Index_T, Time_T, and the correctness of these parameters and the real-time performance of Time_T are verified in turn, wherein it is verified whether ID_T and Index_T are consistent with the ID_T and Index_T carried in Token_T, and whether ID_P is consistent with the local identity of the second terminal. If all are consistent, the authentication is passed.

[0095] After the first terminal passes the authentication, the second terminal similarly generates an authentication token on the platform side:

[0096] ,

[0097] in,

[0098]

[0099] .

[0100] The second terminal sends the authentication token Token_P to the first terminal. Similarly, the first terminal obtains the corresponding quantum key Key_P according to the key index Index_P, and then decrypts the authentication ciphertext Cipher_P to obtain the authentication plaintext , and parse out the parameters ID_P, ID_T, Index_P, Time_P, verify the consistency and real-time performance of these parameters, and if the verification is passed, the identity authentication is passed, thus completing the two-way identity authentication.

[0101] See also Figure 4An embodiment of the present invention provides a data transmission system 40, including a first terminal 41 and a second terminal 42; the first terminal 41 is deployed with a first key derivation module 411 and a data encryption module 412; the second terminal 42 is deployed with a second key derivation module 421 and a data decryption module 422.

[0102] Specifically, the first terminal and the second terminal may be terminal devices used by a user, such as a smart phone, a computer or other smart device, or terminal devices of a service provider, such as a server, a cloud platform or other authentication devices.

[0103] When it is a terminal device such as a smart phone, computer or other smart device, such user terminal includes smart phones, tablet computers, laptops, desktop computers, wearable devices, smart homes, head-mounted devices and other smart terminals with data processing functions; when it is a terminal device such as a server, cloud platform or other authentication device, it can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or it can be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms.

[0104] based on Figure 4 A data transmission system is provided, and one implementation aspect of the present invention is to provide a corresponding identity authentication method implementation process.

[0105] See also Figure 5 An embodiment of the present invention provides a data transmission method, comprising the following steps:

[0106] Step S510: The first terminal determines a third quantum key for encrypting data, uses the third quantum key to perform key derivation, and generates a data encryption key for directly encrypting data.

[0107] Specifically, the process of determining the third quantum key in this embodiment is similar to that described in the aforementioned identity authentication method, and the process of determining the quantum key is not repeated here. This step does not directly use the quantum key to encrypt data, but calculates the session key for each session through a key derivation function. Such a design can provide high security of one key per session and extend the life cycle of the quantum key.

[0108] Optionally, the input required by the key derivation function includes the current session identifier of both parties, the key purpose and the third quantum key. The third quantum key provides basic security. The current session identifier and the key purpose are used as context information to ensure that the derived key is unique in different scenarios. A more preferred implementation may also add the terminal identifier as context information. The key derivation function may be HKDF, PBKDF2, etc.

[0109] In a further embodiment, the first terminal may also generate an integrity key through a key derivation function to perform integrity verification on the transmitted data.

[0110] Step S520: The first terminal uses the data encryption key to encrypt the transmission data to generate data ciphertext, and transmits the data ciphertext to the second terminal.

[0111] Step S530. The second terminal determines a fourth quantum key for decrypting the data based on the data ciphertext, uses the fourth quantum key to perform key derivation, and generates a data decryption key for decrypting the data ciphertext.

[0112] Step S540: The second terminal uses the data decryption key to decrypt the data ciphertext to obtain the transmission data.

[0113] Specifically, the second terminal can parse the data ciphertext to obtain the key index of the third quantum key, and then use the key index to determine the fourth quantum key. More specifically, based on the true randomness and pre-sharing mechanism of the quantum key, the second terminal and the first terminal simultaneously pre-inject the same set of quantum keys. Therefore, when the second terminal parses the key index of the third quantum key, it can determine the fourth quantum key for decrypting the data in the quantum key group stored in itself, and use the fourth quantum key to perform the same key derivation process to generate a data decryption key. A further implementation method can also use the fourth quantum key to perform key derivation to obtain an integrity key, and perform integrity verification on the data sent by the first terminal.

[0114] It is foreseeable that the third quantum key and the fourth quantum key are a pair of symmetric keys. When the two parties of data interaction inject the same set of quantum key groups, as long as the transmission process is legal and valid, both terminals can determine the data decryption key used for data decryption based on the key index transmitted by the other party.

[0115] In a further embodiment, for the key index of the third quantum key, the first terminal can transmit the key index to the second terminal separately through a secure channel in advance, and then encrypt and generate a data ciphertext that does not include the key index and send it to the second terminal. The second terminal can derive a data decryption key for decrypting data based on the key index.

[0116] In a more preferred embodiment, the first terminal transmits data to the second terminal as uplink transmission, and the second terminal can also transmit data to the first terminal in the same data encryption method as downlink transmission. In the downlink transmission, the first terminal can similarly derive a data decryption key based on the key index of the second terminal.

[0117] Another aspect of the embodiments of the present invention can also be applied to multi-terminal authentication and data encryption scenarios. For example, multiple first terminals share the same set of pre-injected quantum key groups, and send authentication tokens and encrypted data to the second terminals respectively. The second terminals independently complete the decryption and authentication process according to the key index in each authentication token or encrypted data.

[0118] In the example, the mobile terminal is the first terminal and the data service platform is the second terminal. Figure 6 As shown, taking the uplink and downlink data transmission process as an example, the data transmission methods provided by the above embodiments are described below through an embodiment.

[0119] This embodiment does not directly use quantum keys for data encryption, but instead calculates the session key for each session through a key derivation function. The key-derived data encryption mechanism can not only provide the high security of one key per session, but also extend the life cycle of the quantum key.

[0120] Taking the uplink data transmission from the first terminal to the second terminal as an example, the derivation design of the data encryption key CK_0 and the integrity key IK_0 is expressed as follows:

[0121] CK_0=SM3(Key_T||Encryption||Session_ID),

[0122] IK_0=SM3(Key_T||Integrity||Session_ID),

[0123] Among them, Session_ID is the session ID, and Key_T||Encryption||Session_ID means concatenating the quantum key Key_T, key purpose Encryption, and session ID in a string format. The parameter function for deriving the integrity key is similar, except that the key purpose is changed to Integrity.

[0124] This embodiment uses the national secret hash algorithm SM3 as the key derivation KDF algorithm.

[0125] After the key is derived, the first terminal can use the encryption key CK_0 and the integrity key IK_0 to encrypt and verify the integrity of the uplink data. The data service platform of the second terminal, as the data receiver, can determine the corresponding decryption key Key_T according to the key index Index_T, and derive CK_0 and IK_0 in the same way, so as to decrypt the plaintext data and perform integrity verification on the sent data.

[0126] Similarly, the second terminal can also independently derive the encryption key and integrity key of the downlink transmission data as follows:

[0127] CK_1=SM3(Key_P||Encryption||Session_ID),

[0128] IK_1=SM3(Key_P||Integrity||Session_ID).

[0129] After the first terminal receives the data ciphertext sent by the second terminal, it can also derive two keys CK_1 and IK_1 according to the key index Index_P, and then decrypt the plaintext data and verify the integrity of the data. This design very simply realizes that the uplink and downlink keys are unrelated, provides the independence of uplink and downlink data encryption, and further improves data security.

[0130] As a more specific example, the identity authentication method and data transmission method proposed in the present invention are introduced below by taking the identity authentication and data transmission performed by a SIM card with an identity authentication platform and a data service platform as an example.

[0131] First, set the identity of the SIM card and the identity authentication platform as follows:

[0132] ID_T=Terminal_000001;

[0133] ID_P=Platform_000001.

[0134] In this example, 10 truly random quantum keys are injected into both terminals, so the value range of the key index Index_T is 1 to 10. These 10 quantum keys are expressed in hexadecimal as follows:

[0135] Index_1:8d543acf70cf90a2eede3f7dff1d038f42630516e3cfa7e068059d18ebfa899b

[0136] Index_2:b88f2c720593f8bd660a5842a88cad25db2988b7bbaf87f0bf52d4251fbb9c6e

[0137] Index_3:873de4a086e70cb00403c30fde2945d3d9aa0b42b3f56c8806e6e291b0743d3a

[0138] Index_4:eeeb33646044a08d0927b19e57879c35da33bda830067eb0918dd0672e74dde0

[0139] Index_5:7fb1090474ac42aa450f14259e0adbaf65ed37099a8385a0e16a5fcd7d8eeb06

[0140] Index_6:66e014ba5fbc281cead18acc876b7d7d17199661262556a6bd678ccb35c42958

[0141] Index_7:960e8913ad3f927631d6b7bad9e688e16e50d402b1f9f9619ab1ba8ad604e43a

[0142] Index_8:7cfe6891edfa814c293de99f8e226fe844e1ac2b83466d24c7f3ece90a7c42a2

[0143] Index_9:c7319bb5bcd26f9e658418b92d3f1d85ce16c6dee0510e9f12997bc40f34399e

[0144] Index_10: c831bf3087e2229a0c149ac6e9c0e8d359924fe9cffa993552cd2d90c4e4e6ba

[0145] The user selects a mobile terminal equipped with the above SIM card, and randomly selects a quantum key index Index_6 through a specific terminal application, and its corresponding key value is:

[0146]

[0147] The plain text data sent by the mobile terminal to the identity authentication platform is

[0148] Message_T=ID_T||ID_P||Index_T||Time_T

[0149] Among them, ID_T=Terminal_000001, ID_P=Platform_000001, Index_T=Index_6, Time_T=2024_11_20_09_30_10, Message_T is encrypted using the CTR working mode of SM4 and the key Key_6, and the cascade symbol "||" is specifically represented by a hyphen "-", so the specific data plaintext Message_T is represented as:

[0150] Terminal_000001-Platform_000001-Index_6-2024_11_20_09_30_10

[0151] The string is 59 bytes long. After encryption with the key Key_6, the ciphertext Cipher_T with the same byte length is expressed as:

[0152] 4578697863d72e3db5dcd2bb56c8750f0a5929c6c82d88394445775b88472284d2d95724b5baab524d69767579604a5ff95ae76575c8c017efd4a6,

[0153] The Token_T finally sent by the mobile terminal is ID_T||Index_T||Cipher_T, and the specific value is: Terminal_000001-Index_6-4578697863d72e3db5dcd2bb56c8750f0a5 929c6c82d88394445775b88472284d2d95724b5baab524d69767579604a5ff95ae76575c8c017efd4a6.

[0154] The identity authentication platform receives Token_T and parses it to obtain Terminal_000001 and Index_6, and locally determines the same pre-injected quantum key:

[0155]

[0156] Then decrypt and restore the corresponding plaintext Message_T as:

[0157] Terminal_000001-Platform_000001-Index_6-2024_11_20_09_30_10,

[0158] The ID_T=Terminal_000001, ID_P=Platform_000001, Index_T=Index_6, Time_T=2024_11_20_09_30_10 are parsed in sequence. The identity authentication platform compares the parsed ID_T and Index_T with the ID_T and Index_T in Token_T. If they are consistent, the identity authentication platform verifies that Time_T is real-time. The specific mechanism for real-time verification is that the difference with the current time is within a certain threshold. If the comparison and verification are correct, the authentication platform passes the identity authentication of the terminal.

[0159] Conversely, the identity authentication platform can also similarly send an authentication token Token_P to the mobile terminal, and the mobile terminal can authenticate the identity authentication platform. This process is similar to the identity authentication process of the aforementioned platform for the mobile terminal, and will not be repeated here. The identity authentication platform selects the key Key_P for encrypting the identity authentication information independently and does not need to be the same as Key_T. After the above two-way identity authentication is completed, subsequent data encryption interaction can be carried out.

[0160] The user terminal randomly generates a session Session_ID = cd9d8f854016df16. The message used by the mobile terminal to derive the data encryption key is Key_6||Encryption||Session_ID. The key derivation calculation method is:

[0161] CK_0=SM3(Key_6||Encryption||Session_ID),

[0162] IK_0=SM3(Key_6||Integrity||Session_ID),

[0163] At this time, the uplink encryption key CK_0 and integrity key IK_0 are calculated as:

[0164]

[0165] The mobile terminal sends data encrypted by key CK_0 to the data service platform during uplink transmission. The data service platform determines the specific quantum key Key_6 based on the key index Index_6, thereby deriving the encryption key CK_0 and the integrity verification key IK_0 to decrypt and verify the uplink transmission data.

[0166] Similarly, the data service platform can independently select another quantum key Key_8 and derive the encryption key CK_1 and integrity key IK_1 for downlink transmission as follows:

[0167]

[0168] Therefore, uplink data and downlink data can be encrypted and verified using corresponding encryption keys and integrity verification keys to provide data confidentiality and integrity protection.

[0169] The methods and related devices mentioned in the above embodiments are described with reference to the method flow charts and / or structural diagrams provided in the embodiments of the present application. Specifically, each process and / or block in the method flow charts and / or structural diagrams, as well as the combination of processes and / or blocks in the flow charts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the process in the process. Figure 1 Schematic diagram of one or more processes and / or structures Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the functions specified in the process. Figure 1 Schematic diagram of one or more processes and / or structures Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide for implementing the process in the process. Figure 1 A flow or multiple flows and / or structures illustrate the steps of the functions specified in one block or multiple blocks.

[0170] The following embodiments are described by taking the method applied to a computer device as an example. It can be understood that the computer device can be any device with computing and processing functions, and can be but not limited to a server or a personal laptop computer, etc. In one embodiment, the computer device can be an application server, and the application server can be a server for running an application to be tested.

[0171] See also Figure 7, which shows a hardware block diagram of an electronic device, the electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or required herein.

[0172] like Figure 7 As shown, the electronic device includes: at least one processor 1, at least one communication interface 2, at least one memory 3 and at least one communication bus 4;

[0173] In the embodiment of the present application, the number of the processor 1, the communication interface 2, the memory 3, and the communication bus 4 is at least one, and the processor 1, the communication interface 2, and the memory 3 communicate with each other through the communication bus 4;

[0174] The processor 1 may be a central processing unit CPU, or an application-specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention, etc.;

[0175] The memory 3 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), etc., such as at least one disk memory;

[0176] The memory stores a program, and the processor can call the program stored in the memory, and the program is used to: implement the aforementioned identity authentication method, or each processing flow of the data transmission method.

[0177] An embodiment of the present invention also provides a readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements the identity authentication method provided in the above embodiment and / or any possible implementation method in combination with the embodiment, or the various processing flows of the data transmission method.

[0178] The above-mentioned embodiments have described the present invention in particular detail with respect to possible scenarios, and those skilled in the art will recognize that the present invention can be practiced through other embodiments. The specific naming of components, the capitalization of terms, attributes, data structures, or any other programming or structural aspects are not mandatory or important, and the mechanisms or features of the present invention may have different names, forms, or procedures. The system may be implemented by a combination of hardware and software (as described), entirely by hardware elements, or entirely by software elements. The specific division of functions between the various system components described herein is exemplary only and not mandatory; on the contrary, the functions performed by a single system component may be performed by multiple components, or the functions performed by multiple components may be performed by a single component.

[0179] Those skilled in the art should understand that the various steps of the above disclosed method can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, optionally, they can be implemented with program codes executable by the computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the embodiments of the present invention are not limited to any specific combination of hardware and software.

[0180] These computing device executable programs (also referred to as programs, software, software applications, or code) include machine instructions for programmable processors, and these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or device (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0181] Certain aspects of the present invention include process steps and instructions described herein in the form of algorithms. It should be noted that the process steps and instructions of the present invention can be implemented in software, firmware and / or hardware, and when implemented by software, it can be downloaded, stored on different platforms used by various operating systems and operated from the platforms.

[0182] Those skilled in the art will understand that the structures shown in the accompanying drawings are merely block diagrams of partial structures related to the scheme of the present application, and do not constitute a limitation on the terminal device to which the scheme of the present application is applied. The specific terminal device may include more or fewer components than shown in the figures, or combine certain components, or have a different arrangement of components.

[0183] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "possible design" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0184] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0185] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An identity authentication method, characterized in that: include: The first terminal determines a first quantum key for encrypting identity authentication information; The first terminal uses the first quantum key to encrypt the identity authentication information to generate an authentication token, and sends the authentication token to the second terminal; The second terminal determines a second quantum key for decrypting the identity authentication information of the first terminal according to the authentication token; The second terminal uses the second quantum key to decrypt the authentication token to obtain the identity authentication information of the first terminal, and uses the decrypted identity authentication information of the first terminal to perform identity authentication on the first terminal.

2. The method according to claim 1, characterized in that The first terminal determines the first quantum key used to encrypt the identity authentication information including: Obtaining a quantum key group, the quantum key group including a plurality of quantum keys; A quantum key for encrypting identity authentication information is determined in the quantum key group as the first quantum key.

3. The method according to claim 1, characterized in that The first terminal uses the first quantum key to encrypt the identity authentication information to generate an authentication token, including: The identity authentication information is encrypted using the first quantum key to generate an authentication ciphertext, and an authentication token is generated according to the terminal identifier of the first terminal and the authentication ciphertext, wherein the authentication token includes a key index of the first quantum key.

4. The method according to claim 3, characterized in that: The second terminal determines, according to the authentication token, a second quantum key for decrypting the identity authentication information of the first terminal, including: Parsing the authentication token to determine a key index of the first quantum key; The second quantum key is determined according to the key index of the first quantum key, and the second quantum key and the first quantum key are a pair of symmetric keys.

5. A data transmission method, characterized in that: include: The first terminal determines a third quantum key for encrypting data, and uses the third quantum key to perform key derivation to generate a data encryption key for directly encrypting data; The first terminal uses the data encryption key to encrypt the transmission data to generate data ciphertext, and transmits the data ciphertext to the second terminal; The second terminal determines a fourth quantum key for decrypting the data according to the data ciphertext, and uses the fourth quantum key to perform key derivation to generate a data decryption key for decrypting the data ciphertext; The second terminal uses the data decryption key to decrypt the data ciphertext to obtain the transmission data.

6. The method according to claim 5, characterized in that The first terminal determines the third quantum key used to encrypt data including: Acquire a quantum key group, wherein the quantum key group includes a plurality of quantum keys; A quantum key for encrypting data is determined in the quantum key group as the third quantum key.

7. The method according to claim 5, characterized in that The first terminal uses the third quantum key to perform key derivation to generate a data encryption key for directly encrypting data, including: Obtaining the current session identifier and key usage with the second terminal; A key is derived according to the third quantum key, the current session identifier and the key purpose to generate the data encryption key.

8. An identity authentication system, characterized in that: comprising a first terminal and a second terminal; The first terminal is deployed with: A first key determination module, used to determine a first quantum key for encrypting identity authentication information; An authentication information encryption module, used to encrypt the identity authentication information using the first quantum key to generate an authentication token, and send the authentication token to the second terminal; The second terminal is deployed with: A second key determination module, used to determine a second quantum key for decrypting the identity authentication information of the first terminal according to the authentication token; The decryption and authentication module is used to decrypt the authentication token using the second quantum key to obtain the identity authentication information of the first terminal, and perform identity authentication on the first terminal using the decrypted identity authentication information of the first terminal.

9. A data transmission system, characterized in that: comprising a first terminal and a second terminal; The first terminal is deployed with: A first key derivation module, used to determine a third quantum key for encrypting data, perform key derivation using the third quantum key, and generate a data encryption key for directly encrypting data; A data encryption module, used to encrypt the transmission data using the data encryption key to generate data ciphertext, and transmit the data ciphertext to the second terminal; The second terminal is deployed with: A second key derivation module determines a fourth quantum key for decrypting the data according to the data ciphertext, performs key derivation using the fourth quantum key, and generates a data decryption key for decrypting the data ciphertext; The data decryption module is used to decrypt the data ciphertext using the data decryption key to obtain the transmission data.

10. An electronic device, characterized in that: It includes a memory and a processor storing computer executable instructions. When the computer executable instructions are executed by the processor, the device executes the identity authentication method as described in any one of claims 1 to 4, and / or the data transmission method as described in any one of claims 5 to 7.

Citation Information

Cited By

  • Symmetric key synchronization method and symmetric key synchronization system

    CN121485917A