Encrypted communication method for client and server and related device

By using quantum key distribution equipment to distribute shared keys between the client and the server, and combining quantum cryptographic algorithms to perform identity authentication and key negotiation, the problem that the existing technology is difficult to resist quantum computer attacks is solved, and encrypted communications that take into account high security and take into account both cost and time are achieved.

CN119995859AInactive Publication Date: 2025-05-13ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Patent Information

Application Number
CN202510130232.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art is difficult to resist the attacks of quantum computers during the process of identity authentication and key negotiation, and the PQC algorithm is too large in key pairs and signatures/ciphertexts, which affects the transmission time.

Method used

Quantum key distribution (QKD) equipment is used to distribute shared keys to clients and servers, and identity authentication and session key negotiation are used to use quantum cryptography (PQC) algorithms. Before obtaining the negotiation session key, the shared key is used for encrypted communication, and after obtaining the negotiation session key is used for encrypted communication.

Benefits of technology

Through QKD and PQC protection of communication data, high-security encrypted communication is achieved that takes into account both cost and time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995859A_ABST
    Figure CN119995859A_ABST
Patent Text Reader

Abstract

The invention discloses an encrypted communication method for a client and a server and a related device. The method comprises the following steps: respectively configuring shared keys for the client and the server based on quantum key distribution equipment; performing key negotiation based on an anti-quantum cryptography algorithm between the client and the server based on the encrypted communication of the shared key to obtain a negotiation session key; and carrying out encrypted communication of service data information between the client and the server based on a shared key before the negotiation session key is obtained, and carrying out encrypted communication of the service data information between the client and the server based on the negotiation session key after the negotiation session key is obtained. Compared with the prior art, communication data are protected by using QKD (quantum key distribution) and PQC (quantum cryptography resisting), and both cost and time are taken into account.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum encryption communication technology, and in particular to an encryption communication method and related devices for a client and a server. Background Art

[0002] For security reasons, both parties in communication need to perform identity authentication and key negotiation before data transmission. Identity authentication is to confirm each other's identity, and key negotiation is to negotiate the key required for subsequent symmetric encryption. Currently, identity authentication and key negotiation are protected by classical algorithms, which will be difficult to resist attacks from quantum computers in the future. In order to protect the identity authentication and key negotiation process, the existing communication protocol needs to be upgraded to PQC.

[0003] Since the two processes of identity authentication and key negotiation generally occur in communication scenarios, not only security but also performance must be considered. Since the key pair and signature / ciphertext of the PQC algorithm are too large, the transmission time may be affected. Summary of the invention

[0004] The purpose of the present invention is to provide an encryption communication method and related devices for a client and a server to solve the technical problems in the prior art. It can use QKD and PQC to protect communication data and achieve a balance in cost and time.

[0005] In a first aspect, the present invention provides an encrypted communication method for a client and a server, comprising:

[0006] Based on a quantum key distribution device, a shared key is configured to the client and the server respectively;

[0007] Based on the encrypted communication with the shared key, a key negotiation based on the quantum-resistant cryptographic algorithm is performed between the client and the server to obtain a negotiated session key;

[0008] Before the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the shared key. After the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the negotiated session key.

[0009] A method as described above, wherein preferably, encrypted communication based on a shared key performs key negotiation based on a quantum-resistant cryptographic algorithm between the client and the server to obtain a negotiated session key;

[0010] The information used for key negotiation communicated between the client and the server is encrypted based on the shared key until a negotiated session key is obtained, wherein the information used for key negotiation sent to the second party by the first party between the client and the server is encrypted based on the built-in shared key and is decrypted within the second party based on the built-in shared key.

[0011] In the method as described above, preferably, performing key negotiation based on a quantum-resistant cryptographic algorithm between the client and the server to obtain a negotiated session key comprises:

[0012] The client generates a pre-key and sends the ciphertext obtained by encrypting the pre-key with the public key based on the first quantum-resistant cryptography algorithm to the server;

[0013] The client generates a first session key based on the pre-key, and performs a hash operation on the session key based on a hash operation to obtain a hash value, and the server generates a second session key based on the pre-key obtained by decrypting the ciphertext using the private key of the first quantum-resistant cryptographic algorithm, and performs a hash operation on the session key based on a hash operation to obtain a hash value;

[0014] The hash value of either the client or the server is encrypted and sent to the other party based on the shared key. When the hash values ​​of the two are consistent, the first session key and the second session key are determined to be the negotiated session keys.

[0015] A method as described above, wherein preferably, generating the first session key and the second session key based on the pre-key comprises:

[0016] Generate a first session key of the client based on the pre-secret key, a first random number generated by the client, and a second random number sent by the server; or,

[0017] A second session key of the server is generated based on a pre-key obtained by decrypting a ciphertext with a private key of a first quantum-resistant cryptographic algorithm, a first random number sent by the client, and a second random number generated by the server.

[0018] A method as described above, wherein preferably, performing a hash operation on the session key based on a hash operation to obtain a hash value comprises:

[0019] A hash value is obtained by performing a hash operation on the session key, the built-in fixed string, and the handshake information; wherein the built-in fixed string of the client is different from the built-in fixed string of the server.

[0020] In the method as described above, preferably, before the client generates the pre-key, the method includes:

[0021] The client verifies the server signature sent by the server and encrypted by the server's built-in shared key based on the public key and built-in shared key of the built-in second quantum-resistant cryptographic algorithm to confirm the server's identity, wherein the server signature is obtained by the server signing the server information using the private key of the second quantum-resistant cryptographic algorithm.

[0022] In the method as described above, preferably, before the server sends the server signature, the method further includes:

[0023] The client sends a first random number, a supported protocol version, and a supported algorithm type to the server;

[0024] The client receives a second random number, a selected protocol version, and a selected algorithm sent by the server to confirm that the client communicates with the server based on the same parameters, wherein the first quantum-resistant cryptographic algorithm and the second quantum-resistant cryptographic algorithm are selected algorithms.

[0025] A method as described above, wherein, preferably, the first quantum-resistant cryptographic algorithm is a quantum-resistant cryptographic encapsulation algorithm, and the second quantum-resistant cryptographic algorithm is a quantum-resistant cryptographic signature algorithm.

[0026] In the method as described above, preferably, the algorithm type is any one of the following:

[0027] Quantum-resistant cryptographic algorithms;

[0028] A first hybrid algorithm based on the quantum-resistant cryptographic algorithm and the national secret algorithm;

[0029] A second hybrid algorithm based on the quantum-resistant cryptographic algorithm and the international classical algorithm;

[0030] A third hybrid algorithm based on the quantum-resistant cryptographic algorithm, the national secret algorithm and the international classical algorithm.

[0031] In a second aspect, the present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the aforementioned method.

[0032] In a third aspect, the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions for executing the aforementioned method.

[0033] Compared with the prior art, the quantum key distribution device of the present invention first distributes a shared key to both communicating parties, and then both parties use the shared key distributed by the quantum key distribution device for encrypted communication, and both parties use quantum-resistant cryptographic algorithms for identity authentication and session key negotiation at the same time. Before the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the shared key, and after the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the negotiated session key. By using QKD (quantum key distribution) and PQC (quantum-resistant cryptography), communication data is protected, and a balance is achieved in terms of cost and time. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a flowchart of the encryption communication method provided by an embodiment of the present invention;

[0035] Figure 2 It is a schematic diagram of the structure of the encryption communication device provided by an embodiment of the present invention;

[0036] Figure 3 It is a schematic diagram of the process of session key negotiation provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0037] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, but should not be construed as limiting the present invention.

[0038] Reference Figure 1 As shown, in the first aspect, the present invention provides an encryption communication method for a client and a server, which is used to realize communication between the client and the server, including: configuring a shared key to the client and the server respectively based on a quantum key distribution device. Based on the encrypted communication with the shared key, a key negotiation based on a quantum-resistant cryptographic algorithm is performed between the client and the server to obtain a negotiated session key. Before the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the shared key, and after the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the negotiated session key.

[0039] Quantum key distribution (QKD) devices use quantum mechanics principles, such as quantum superposition or quantum entanglement, to generate and distribute shared keys. The device will distribute the generated keys to the communicating client and server. After obtaining the shared key, the client and server can use the shared key as the basis for negotiating the session key. Compared with traditional key exchange methods, quantum key distribution provides a theoretically unconditionally secure key distribution method that can effectively resist various eavesdropping attacks. It can provide a secure key foundation for the client and server, thereby achieving secure session key negotiation and encrypted communication.

[0040] The client and server use the preset key PSK for encrypted communication, and the content sent is communication data and key negotiation information. For example, the mobile terminal sends a data packet to the server, the size of this data packet is 1500 bytes, of which 750 bytes are communication data and the other 750 bytes are messages for key negotiation, so that both parties can transmit data and negotiation messages at the same time.

[0041] Compared with the prior art, the quantum key distribution device of the present invention first distributes a shared key to both communicating parties, and then both parties use the shared key distributed by the quantum key distribution device for encrypted communication, and both parties use quantum-resistant cryptographic algorithms for identity authentication and session key negotiation at the same time, and before the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the shared key, and after the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the negotiated session key. By using QKD (quantum key distribution) and PQC (quantum-resistant cryptography), communication data is protected, and a balance is achieved in terms of cost and time.

[0042] In the embodiment provided by the present invention, encrypted communication based on a shared key performs key negotiation based on a quantum-resistant cryptographic algorithm between a client and a server to obtain a negotiated session key, including the following steps:

[0043] Step S101: The client sends a first random number, supported protocol versions, and supported algorithm types to the server; the client receives a second random number, a selected protocol version, and a selected algorithm sent by the server to confirm that the client and the server communicate based on the same parameters.

[0044] The first random number is used in the subsequent key generation and verification process. Preferably, the first random number is a quantum random number, which is a random number generated based on the principle of quantum mechanics and is unpredictable and aperiodic to ensure security and reliability during the communication process.

[0045] The protocol version sent by the client determines the specification and rule framework that the two parties follow in subsequent communications. The protocol version defines the rules and steps that must be followed during the communication process, including how to establish a connection, how to exchange information, and how to handle errors. The type of algorithm is related to subsequent security-related operations such as encryption and signing to establish the initial parameters of communication.

[0046] After receiving the information from the client, the server starts to filter the protocol versions and algorithm types provided by the client, and determines a suitable option based on its own system configuration, pre-set security policies, and support capabilities for various protocols and algorithms. After determining the choice, the server will clearly inform the client which protocol version and algorithm type has been selected, so that the client knows that subsequent communications will proceed accordingly.

[0047] In addition, the server will also generate and transmit a second random number to the client. The second random number is similar to the first random number sent by the client and is also used for subsequent operations such as generating session keys. Preferably, the second random number is also a quantum random number. By providing random numbers by both parties, the randomness and confidentiality of key generation are further enhanced.

[0048] By exchanging random numbers and confirming the protocol version and algorithm, the client and server confirm that they use the same communication rules and security measures, thereby establishing a secure communication channel.

[0049] Step S102: Obtain the public key of the first quantum-resistant cryptographic algorithm and the server signature sent by the server, where the server signature is obtained by signing the server information using the private key of the second quantum-resistant cryptographic algorithm; the client uses the built-in public key of the second quantum-resistant cryptographic algorithm to verify the server signature and confirm the server identity.

[0050] In the embodiment provided by the present invention, the client has a built-in public key of the second quantum-resistant cryptographic algorithm, and the server has a built-in public and private key of the first quantum-resistant cryptographic algorithm and a private key of the second quantum-resistant cryptographic algorithm. In a feasible implementation, the first quantum-resistant cryptographic algorithm is a quantum-resistant cryptographic encapsulation algorithm, and the first quantum-resistant cryptographic encapsulation algorithm is exemplarily a Kyber algorithm, which is a lattice-based public key encryption scheme for key encapsulation and other operations. The second quantum-resistant cryptographic algorithm is a quantum-resistant cryptographic signature algorithm, and the second quantum-resistant cryptographic signature algorithm is exemplarily a Dilithium algorithm, which is a lattice-based digital signature scheme for identity authentication and other operations.

[0051] In this step, the server then sends two important elements to the client. One is the Kyber public key, which is used in subsequent key encapsulation and decryption operations to build a secure communication key system for both parties. The other is the server signature. This signature is obtained by the server using the built-in Dilithium private key to sign its own related information. The client has a built-in Dilithium public key. Through the private key-based signature method, the server proves the legitimacy of its identity to the client. Only the party with the corresponding Dilithium private key can generate the correct signature, and the client can verify it through the corresponding Dilithium public key. If the verification is successful, it means that the server currently communicating with it is legal and has the corresponding private key, thereby confirming the identity of the server and laying the foundation for subsequent secure and reliable communication. If the verification fails, it may mean that there is a security risk, such as encountering a man-in-the-middle attack, and the communication will be interrupted.

[0052] Through this step, the client can securely obtain the public key of the server's first quantum-resistant cryptographic algorithm and verify the server's signature to ensure the authenticity of the server's identity and the security of communication. At the same time, this process utilizes the characteristics of the quantum-resistant cryptographic algorithm to resist the threat of quantum computing.

[0053] Step S103: Generate a pre-key and a first session key, and use the public key of the first quantum-resistant cryptographic algorithm to encrypt the pre-key to obtain a ciphertext, and then send the ciphertext to the server.

[0054] After confirming the identity of the server, the client will use the Kyber public key sent by the server to perform key encapsulation. In this process, a specific key encapsulation algorithm is used to combine relevant parameters to generate a pre-key and the corresponding ciphertext form (i.e. Cipher).

[0055] The pre-key is usually a randomly generated random number, preferably a quantum random number, which is used for subsequent session encryption. Encrypting it into a Cipher is to ensure that it is not leaked during transmission to the server and to ensure its confidentiality. Subsequently, the client will generate a session key and send the Cipher to the server to enter the next round of interaction.

[0056] Step S104: After the ciphertext Cipher is decrypted by the server, the second session key is also generated by the server. The client and the server verify each other's session keys. After the first session key and the second session key are successfully verified, the first session key and the second session key are determined to be the negotiated session keys. The client uses the negotiated session key to perform encrypted communication with the server.

[0057] After receiving the Cipher sent by the client, the server uses its own Kyber private key to decrypt it. Since there is a specific mathematical correspondence between the Kyber public key and the private key, only the matching private key can correctly decrypt the ciphertext generated by the corresponding public key. Through this decryption process, the server can successfully obtain the plaintext content of the pre-key.

[0058] After the ciphertext is decrypted by the server, the server also has the necessary elements to generate a session key, namely the first random number, the second random number and the prekey. The server uses the same algorithm to combine the first random number, the second random number and the prekey to generate a second session key.

[0059] In order to ensure that the first session key and the second session key calculated by both parties are completely consistent and have not been tampered with, the two parties will send each other a Finished message encrypted with the session key. The client and the server each construct a Finished message, which includes the session key, a fixed string (such as "server finished" or "client finished"), and the hash value of all messages exchanged since the handshake began. This hash value includes the hash of all previous handshake messages to ensure the integrity of the message. The client and the server encrypt the Finished message using the session key, which was generated during the previous key exchange process, ensuring that only the two parties with the correct session key can decrypt the message.

[0060] The encrypted Finished message is sent to the other party. The receiver uses the session key to decrypt the received Finished message. The receiver calculates the hash value theoretically contained in the Finished message and compares it with the hash value in the decrypted Finished message. If the hash values ​​match, it means that the sender is using the correct session key and the handshake message has not been tampered with.

[0061] If the Finished message is successfully verified, the client and server use the session key for encrypted communication.

[0062] Taking the message sent by the client as an example, the plaintext structure of the message has a strict design. First, all the messages sent by both parties before are hashed to obtain a hash value, and then the hash value is integrated with the session key and the fixed string "client finished" and hashed again. The client uses the session key to encrypt the message and sends it to the server. After receiving it, the server decrypts it with the same session key and calculates the hash value according to the same rules. Then the two hash values ​​are compared. If the two are consistent, it means that the session key used by both parties is correct and the messages during the entire session have not been tampered with, ensuring the integrity and security of the communication. After that, the server will generate a message with a similar structure but with the fixed string replaced ("server finished") and encrypt it and send it to the client for the same verification operation. This method not only verifies that both parties have calculated the correct session key, but also ensures that the session messages of both parties have not been tampered with.

[0063] After the key verification step, the client and the server have determined a consistent, secure and reliable negotiated session key. On this basis, the client and the server can use this negotiated session key to encrypt the communication content to ensure that the communication data is confidential during network transmission. Only the two parties with the correct session key can decrypt and restore the encrypted content to achieve secure communication.

[0064] In a feasible implementation, the algorithm supported by the client is any of the following:

[0065] Quantum-resistant cryptographic algorithms provide quantum-resistant data protection to ensure data security in the era of quantum computing, including one or more algorithms in Kyber and Dilithum.

[0066] The first hybrid algorithm based on quantum-resistant cryptographic algorithms and national secret algorithms combines quantum-resistant cryptographic algorithms and national secret algorithms to provide a more flexible security solution. This hybrid approach can introduce quantum-resistant cryptographic algorithms to meet future security challenges while maintaining the compatibility of traditional algorithms.

[0067] The second hybrid algorithm based on quantum-resistant cryptographic algorithms and international classical algorithms combines quantum-resistant cryptographic algorithms and international classical algorithms to provide a more flexible security solution. This hybrid approach can introduce quantum-resistant cryptographic algorithms to meet future security challenges while maintaining the compatibility of traditional algorithms.

[0068] The third hybrid algorithm based on quantum-resistant cryptographic algorithms, national secret algorithms and international classical algorithms combines quantum-resistant cryptographic algorithms, national secret algorithms and international classical algorithms to provide a more flexible security solution. This hybrid approach can introduce quantum-resistant cryptographic algorithms to meet future security challenges while maintaining the compatibility of traditional algorithms.

[0069] In a second aspect, the present invention further provides an encryption communication method supporting a quantum-resistant cryptographic algorithm, which is applied to a server to implement communication between a client and a server, comprising the following steps:

[0070] Obtain the shared key, which is distributed to the client and server by the quantum key distribution device. The client and server use the shared key to achieve encrypted communication during the session key negotiation process.

[0071] Obtain a first random number, supported protocol version, and supported algorithm type sent by the client, determine the protocol version and algorithm supported by itself from the supported protocol version and supported algorithm type, and send the selection result and the second random number to the client.

[0072] The public key of the first quantum-resistant cryptographic algorithm and the server signature are sent to the client.

[0073] The ciphertext sent by the client is received and decrypted to generate a second session key. After the second session key is successfully verified, the client uses the negotiated session key to perform encrypted communication with the server.

[0074] Reference Figure 2 As shown, in a third aspect, the present invention further provides an encryption communication device, applied to a client, the device comprising:

[0075] The shared key acquisition module is used to obtain the shared key, and the client and the server use the shared key to achieve encrypted communication during the session key negotiation process.

[0076] The initialization module is used to send the first random number, the supported protocol version and the supported algorithm type to the server, and receive the second random number, the selected protocol version and the selected algorithm sent by the server. By exchanging random numbers and confirming the protocol version and algorithm, the client and server confirm that they use the same communication rules and security measures, thereby establishing a secure communication channel.

[0077] The identity authentication module is used to obtain the public key of the first quantum-resistant cryptographic algorithm and the server signature sent by the server, and use the built-in public key of the second quantum-resistant cryptographic algorithm to verify the server signature and confirm the server identity. The client can safely obtain the public key of the first quantum-resistant cryptographic algorithm of the server and verify the server signature to ensure the authenticity of the server identity and the security of communication. At the same time, this process utilizes the characteristics of the quantum-resistant cryptographic algorithm to resist the threat of quantum computing.

[0078] The pre-key generation module is used to generate a pre-key, encrypt the pre-key with the public key of the first quantum-resistant cryptographic algorithm to obtain a ciphertext, and then send the ciphertext to the server. After confirming the identity of the server, the client will use the Kyber public key sent by the server to perform a key encapsulation operation. In this process, a specific key encapsulation algorithm is used to combine relevant parameters to generate a pre-key and the corresponding ciphertext form (i.e. Cipher).

[0079] The negotiated session key generation and authentication module is used to generate a first session key on the client side after generating a pre-key, and to mutually verify the session keys of both parties with the server side. After the first session key and the second session key are successfully verified, the first session key and the second session key are determined to be the negotiated session keys, and the client uses the negotiated session key to perform encrypted communication with the server side.

[0080] In order to ensure that the session key calculated by both parties is completely consistent and has not been tampered with, the two parties will send each other a Finished message encrypted with the session key. The client and the server each construct a Finished message, which includes the session key, a fixed string (such as "server finished" or "client finished"), and the hash value of all messages exchanged since the handshake began. This hash value usually includes the hash of all previous handshake messages, ensuring the integrity of the message. The client and the server encrypt the Finished message using the session key, which was generated during the previous key exchange process, ensuring that only the two parties with the correct session key can decrypt the message.

[0081] If the Finished message is successfully verified, the client and server use the session key for encrypted communication.

[0082] In a fourth aspect, an embodiment of the present invention provides an encrypted communication system, including a quantum key distribution device, a client, and a server, wherein:

[0083] The client has a built-in public key of the second quantum-resistant cryptographic algorithm, and the server has a built-in public and private key of the first quantum-resistant cryptographic algorithm and a private key of the second quantum-resistant cryptographic algorithm.

[0084] The quantum key distribution device distributes shared keys to the client and the server, and the client and the server use the shared key to achieve encrypted communication during the session key negotiation process.

[0085] The client sends a first random number, supported protocol version, and supported algorithm type to the server, and receives a second random number, selected protocol version, and selected algorithm sent by the server; obtains the public key of the first quantum-resistant cryptographic algorithm and the server signature sent by the server, and verifies the server signature using the built-in public key of the second quantum-resistant cryptographic algorithm; generates a pre-key, and uses the public key of the first quantum-resistant cryptographic algorithm to encrypt the pre-key to obtain a ciphertext, and then sends the ciphertext to the server; generates a first session key using the first random number, the second random number, and the pre-key.

[0086] The server selects the protocol version and algorithm it supports from the protocol versions and algorithm types supported by the client, and sends the selection result and the second random number to the client; sends the public key of the first quantum-resistant cryptographic algorithm and the server signature to the client, the server receives the ciphertext sent by the client, and decrypts it using the first quantum-resistant cryptographic algorithm key to obtain the plaintext of the pre-key, uses the first random number, the second random number and the pre-key to generate the second session key, the server and the client jointly verify the first session key and the second session key, and determine that the first session key and the second session key are the negotiated session keys.

[0087] The encrypted communication system provided by the embodiment of the present invention embodies multiple security measures:

[0088] 1. Combine the PQC algorithm with session key negotiation and identity authentication. Considering that the time required for the negotiation process will be greatly increased after the PQC algorithm is added, a shared key mechanism is introduced. Both parties use the shared key to encrypt communication during the negotiation, and then use the negotiated session key after the negotiation is completed.

[0089] 2. Using QKD to distribute shared keys is relatively more secure and difficult for attackers to intercept during distribution. Considering that the cost of using QKD may be relatively high, only QKD is used to preset session keys, and other session keys are negotiated keys.

[0090] 3. Through the signature and verification mechanism based on Dilithium public and private keys, illegal server access is effectively prevented, and identity disguise attacks such as man-in-the-middle attacks are resisted.

[0091] 4. The session key is generated by using the random numbers and pre-keys provided by both parties in combination with a specific algorithm, which increases the randomness and confidentiality of the key and reduces the risk of being cracked.

[0092] 5. The Finished message is processed by hash operation and comparative verification, which ensures the integrity of the message during the conversation between the two parties, and can promptly detect whether the message has been tampered with, ensuring the reliability and security of communication.

[0093] In general, the encryption communication system provided by the embodiment of the present invention is a relatively rigorous and highly secure client-server encryption communication negotiation system.

[0094] In a fifth aspect, an embodiment of the present invention further provides an electronic device, comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to implement the steps in any one of the above method embodiments.

[0095] Specifically, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0096] Specifically, in this embodiment, the processor may be configured to implement the following steps through a computer program:

[0097] Step S101: Send a first random number, supported protocol versions, and supported algorithm types to the server; receive a second random number, a selected protocol version, and a selected algorithm sent by the server to confirm that the client and the server communicate based on the same parameters.

[0098] Step S102: Obtain the public key of the first quantum-resistant cryptographic algorithm and the server signature sent by the server, where the server signature is obtained by signing the server information using the private key of the second quantum-resistant cryptographic algorithm; the client uses the built-in public key of the second quantum-resistant cryptographic algorithm to verify the server signature and confirm the server identity.

[0099] Step S103: Generate a pre-key and a first session key, and use the public key of the first quantum-resistant cryptographic algorithm to encrypt the pre-key to obtain a ciphertext, and then send the ciphertext to the server.

[0100] Step S104: After the ciphertext is decrypted by the server, the second session key is also generated by the server. The client and the server verify each other's session keys. After the first session key and the second session key are successfully verified, the first session key and the second session key are determined to be the negotiated session keys. The client uses the negotiated session key to perform encrypted communication with the server.

[0101] In a sixth aspect, an embodiment of the present invention further provides a storage medium, in which a computer program is stored, wherein the computer program is configured to implement the steps of any of the above method embodiments when run.

[0102] Specifically, in this embodiment, the above storage medium may be configured to store a computer program for implementing the following steps:

[0103] Step S101: Send a first random number, supported protocol versions, and supported algorithm types to the server; receive a second random number, a selected protocol version, and a selected algorithm sent by the server to confirm that the client and the server communicate based on the same parameters.

[0104] Step S102: Obtain the public key of the first quantum-resistant cryptographic algorithm and the server signature sent by the server, where the server signature is obtained by signing the server information using the private key of the second quantum-resistant cryptographic algorithm; the client uses the built-in public key of the second quantum-resistant cryptographic algorithm to verify the server signature and confirm the server identity.

[0105] Step S103: Generate a pre-key and a first session key, and use the public key of the first quantum-resistant cryptographic algorithm to encrypt the pre-key to obtain a ciphertext, and then send the ciphertext to the server.

[0106] Step S104: After the ciphertext is decrypted by the server, the second session key is also generated by the server. The client and the server verify each other's session keys. After the first session key and the second session key are successfully verified, the first session key and the second session key are determined to be the negotiated session keys. The client uses the negotiated session key to perform encrypted communication with the server.

[0107] The above describes in detail the structure, features and effects of the present invention based on the embodiments shown in the drawings. The above are only preferred embodiments of the present invention, but the present invention is not limited to the scope of implementation shown in the drawings. Any changes made according to the concept of the present invention, or modifications to equivalent embodiments with equivalent changes, which still do not exceed the spirit covered by the description and drawings, should be within the protection scope of the present invention.

Claims

1. An encrypted communication method for a client and a server, characterized in that: include: Based on a quantum key distribution device, a shared key is configured to the client and the server respectively; Based on the encrypted communication with the shared key, a key negotiation based on the quantum-resistant cryptographic algorithm is performed between the client and the server to obtain a negotiated session key; Before the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the shared key. After the negotiated session key is obtained, encrypted communication of business data information is performed between the client and the server based on the negotiated session key.

2. The method according to claim 1, characterized in that: Based on the encrypted communication with the shared key, a key negotiation based on the quantum-resistant cryptographic algorithm is performed between the client and the server to obtain a negotiated session key; The information used for key negotiation communicated between the client and the server is encrypted based on the shared key until a negotiated session key is obtained, wherein the information used for key negotiation sent to the second party by the first party between the client and the server is encrypted based on the built-in shared key and is decrypted within the second party based on the built-in shared key.

3. The method according to claim 2, characterized in that: A key negotiation based on a quantum-resistant cryptographic algorithm is performed between the client and the server to obtain a negotiated session key, including: The client generates a pre-key and sends the ciphertext obtained by encrypting the pre-key with the public key based on the first quantum-resistant cryptography algorithm to the server; The client generates a first session key based on the pre-key, and performs a hash operation on the session key based on a hash operation to obtain a hash value, and the server generates a second session key based on the pre-key obtained by decrypting the ciphertext using the private key of the first quantum-resistant cryptographic algorithm, and performs a hash operation on the session key based on a hash operation to obtain a hash value; The hash value of either the client or the server is encrypted and sent to the other party based on the shared key. When the hash values ​​of the two are consistent, the first session key and the second session key are determined to be the negotiated session keys.

4. The method according to claim 3, characterized in that: Generating a first session key and a second session key based on the pre-key includes: Generate a first session key of the client based on the pre-secret key, a first random number generated by the client, and a second random number sent by the server; or, A second session key of the server is generated based on a pre-key obtained by decrypting a ciphertext with a private key of a first quantum-resistant cryptographic algorithm, a first random number sent by the client, and a second random number generated by the server.

5. The method according to claim 3, characterized in that: The session key is hashed based on the hash operation to obtain a hash value, including: A hash value is obtained by performing a hash operation on the session key, the built-in fixed string, and the handshake information; wherein the built-in fixed string of the client is different from the built-in fixed string of the server.

6. The method according to claim 3, characterized in that: Before the client generates a pre-key, the method includes: The client verifies the server signature sent by the server and encrypted by the server's built-in shared key based on the public key and built-in shared key of the built-in second quantum-resistant cryptographic algorithm to confirm the server's identity, wherein the server signature is obtained by the server signing the server information using the private key of the second quantum-resistant cryptographic algorithm.

7. The method according to claim 6, characterized in that: Before the server sends the server signature, the method further includes: The client sends a first random number, a supported protocol version, and a supported algorithm type to the server; The client receives a second random number, a selected protocol version, and a selected algorithm sent by the server to confirm that the client communicates with the server based on the same parameters, wherein the first quantum-resistant cryptographic algorithm and the second quantum-resistant cryptographic algorithm are selected algorithms.

8. The method according to claim 7, characterized in that: The first quantum-resistant cryptographic algorithm is a quantum-resistant cryptographic encapsulation algorithm, and the second quantum-resistant cryptographic algorithm is a quantum-resistant cryptographic signature algorithm.

9. The method according to claim 7, characterized in that: The algorithm type is any of the following: Quantum-resistant cryptographic algorithms; A first hybrid algorithm based on the quantum-resistant cryptographic algorithm and the national secret algorithm; A second hybrid algorithm based on the quantum-resistant cryptographic algorithm and the international classical algorithm; A third hybrid algorithm based on the quantum-resistant cryptographic algorithm, the national secret algorithm and the international classical algorithm.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 9 is implemented.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a method for executing any one of claims 1 to 9.

Citation Information

Patent Citations

  • Communication system and communication method for realizing information encryption and decryption transmission based on quantum network

    CN108540436A

  • Anti-quantum computing electronic official document transmission method and system based on secret sharing and quantum communication service station

    CN111526131A

  • Key negotiation method and device and computer readable storage medium

    CN116132033A

  • Anti-quantum security enhancement method for national secret SSL VPN protocol

    CN118540163A

  • Key negotiation method and device

    WO2018076365A1

Cited By

  • QUIC communication method and device oriented to satellite communication and based on data classification, and medium

    CN120614038A

  • Communication method and device based on password infrastructure system, equipment and medium

    CN120896694A

  • QKD remote key distribution method, system and device based on PQC channel and medium

    CN121923817A