Security authentication method and system and electronic equipment

By using algorithm support lists, mixed key exchange parameters and random numbers to generate handshake keys during the identity authentication process, and combining classic national secret algorithms and anti-quantum key packaging algorithms to verify the certificate chain, the problem of the inability to defend against quantum computer attacks and reduced identity authentication efficiency is solved, and efficient and secure identity authentication is achieved.

CN119995964AActive Publication Date: 2025-05-13ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Patent Information

Application Number
CN202510102194.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-13
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

The prior art cannot defend against attacks from quantum computers, and there is too much plaintext information transmission during the identity authentication process, which increases the possibility of information leakage. At the same time, directly replacing it with a post-quantum algorithm will lead to a decrease in identity authentication efficiency.

Method used

A secure authentication method is adopted to generate a handshake key by sending algorithm support lists, mixed key exchange parameters and random numbers, and use these keys to verify the certificate chain to achieve identity authentication. This method combines classic national secret algorithm and quantum key resistant packaging algorithm to improve security and efficiency.

Benefits of technology

Effectively defend against attacks from quantum computers, reduces the transmission of plain text information during the identity authentication process, reduces the risk of information leakage, and improves the security and efficiency of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995964A_ABST
    Figure CN119995964A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication security, in particular to a security authentication method and system and electronic equipment, and the method comprises the steps: sending an algorithm support list, a mixed key exchange parameter, a first random number and a first certificate request to a second terminal, and enabling the second terminal to generate a second handshake key and a ciphertext; and determining the first handshake key and verifying the target first certificate chain sent by the second terminal by using the first handshake key to obtain an authentication result. Identity authentication is performed based on the mixed key exchange parameter, so that the terminal has the security of quantum attack resistance, and in the whole identity authentication process, the authentication efficiency of the terminal is improved. The leakage of plaintext parameters in the initial handshake message is reduced, and subsequent messages are subjected to different encryption processing, so that the risk of leakage of an identity authentication key is reduced, and the security of identity authentication is improved. Meanwhile, the algorithm selection list is sent in a combined algorithm mode, the algorithm selection matching time of the second terminal can be effectively shortened, and the identity authentication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security technology, and in particular to a security authentication method, system and electronic equipment. Background Art

[0002] Due to the rapid development of quantum computers, the current cryptographic system needs to quickly transition to post-quantum security, such as the convenience of mobile banking, which involves the safety of people's property. At present, mobile banking has the advantages of convenience and speed. When conducting financial services such as transfer and remittance, mobile banking needs to authenticate with the bank server to ensure the safe transmission of transaction data. In the process of identity authentication, the two communicating parties adopt the transport layer security protocol, but the transport layer security protocol in the prior art is threatened by the attack of quantum computers because it uses the encryption method of the classical public key cryptography system and cannot defend against the attack of quantum computers. The direct replacement of the classical public key cryptography system with the post-quantum algorithm will reduce the efficiency of identity authentication. Summary of the invention

[0003] The present invention provides a security authentication method, system and electronic device to solve the problems that the prior art cannot defend against attacks from quantum computers, and that in the prior art, a large amount of plaintext information is transmitted during identity authentication, which increases the possibility of information leakage, and that the efficiency of identity authentication is reduced due to direct replacement with a post-quantum algorithm.

[0004] This embodiment of the specification provides a security authentication method, which is applied to a first terminal, and the method includes:

[0005] Sending an algorithm support list, a hybrid key exchange parameter, a first random number, and a first certificate request to a second terminal, so that the second terminal generates a second handshake key and a ciphertext according to a target algorithm matching the hybrid key exchange parameter selected from the algorithm support list, the hybrid key exchange parameter, and the first random number;

[0006] After the second terminal generates the second handshake key, determine the first handshake key using the third public key provided by the second terminal and sent by the second terminal, the target algorithm selected by the second terminal, and the ciphertext;

[0007] The target first certificate chain sent by the second terminal is verified using the first handshake key to obtain an authentication result, wherein the target first certificate chain is a first certificate chain encrypted by the second handshake key and obtained by the second terminal from the second terminal according to the first certificate request.

[0008] Optionally, the hybrid key exchange parameters include a first public key generated using a first national secret algorithm and a second public key generated using a first quantum-resistant key encapsulation algorithm;

[0009] The second terminal generates a second handshake key and a ciphertext according to a target algorithm selected from the algorithm support list and matching the hybrid key exchange parameter, the hybrid key exchange parameter, and a first random number, including:

[0010] The second terminal uses the first public key, the third private key provided by the second terminal and a target national secret algorithm selected by the second terminal in the algorithm support list that matches the first public key to generate a classical pre-key, and uses the second public key and a target quantum-resistant key encapsulation algorithm selected by the second terminal in the algorithm support list that matches the second public key to generate a quantum-resistant pre-key and a ciphertext;

[0011] The second terminal generates a second handshake key according to the first random number, the classical pre-key, the quantum-resistant pre-key and a target key derivation algorithm selected by the second terminal in the algorithm support list.

[0012] Optionally, the determining the first handshake key by using the third public key provided by the second terminal and sent by the second terminal, the target algorithm selected by the second terminal, and the ciphertext includes:

[0013] The first terminal uses the third public key, the first private key generated by the first national secret algorithm and the target national secret algorithm to calculate to obtain the classical pre-key, and uses the second private key generated by the first quantum-resistant key encapsulation algorithm and the target quantum-resistant key encapsulation algorithm to decrypt the ciphertext to obtain the quantum-resistant pre-key;

[0014] The first terminal generates a first handshake key according to the first random number, the classical pre-key, the quantum-resistant pre-key and the target key derivation algorithm.

[0015] Optionally, the using the first handshake key to verify the target first certificate chain sent by the second terminal to obtain an authentication result includes:

[0016] The first terminal uses the first handshake key to decrypt the target first certificate chain to obtain the first certificate chain;

[0017] The first terminal verifies the first certificate chain using the root certificate in the CA organization to obtain an authentication result.

[0018] Optionally, each certificate in the first certificate chain uses a custom object identifier field to represent a signature algorithm of the certificate, and the signature algorithm includes a hybrid signature algorithm.

[0019] Optionally, the first terminal verifies the first certificate chain using a root certificate in a CA organization to obtain an authentication result, including:

[0020] The first terminal collects the object identifier of the current certificate to be verified in the first certificate chain;

[0021] The first terminal uses the object identifier to parse the current certificate to be verified to obtain a first hybrid signature algorithm; the first hybrid signature algorithm includes a second national secret algorithm and a first quantum-resistant key signature algorithm;

[0022] The first terminal separates the mixed signature in the current certificate to be verified according to the second national secret algorithm and the first quantum-resistant key signature algorithm to obtain a first national secret signature and a first quantum-resistant key signature;

[0023] The first terminal determines the public key of the second national secret algorithm and the public key of the first quantum-resistant key signature algorithm in the public key of the root certificate or the upper-level certificate of the CA organization according to the second national secret algorithm and the first quantum-resistant key signature algorithm;

[0024] The first terminal verifies the first national secret signature using the public key of the second national secret algorithm in combination with the second national secret algorithm, and verifies the first quantum-resistant key signature using the public key of the first quantum-resistant key signature algorithm in combination with the first quantum-resistant key signature algorithm, to obtain a signature authentication result of the current certificate to be verified;

[0025] After the signature authentication of the current certificate to be verified passes, the first terminal collects the object identifier of the next node certificate of the current certificate to be verified in the first certificate chain, and returns to execute the step of the first terminal using the object identifier to parse the current certificate to be verified to obtain the first hybrid signature algorithm, until all certificates in the first certificate chain pass the verification, the first certificate chain is legal, and the second terminal is trustworthy.

[0026] Optionally, after using the first handshake key to verify the target first certificate chain sent by the second terminal to obtain an authentication result, the method further includes:

[0027] The first terminal obtains, from the second terminal, a second certificate request encrypted by a second handshake key;

[0028] The first terminal uses the first handshake key to decrypt the encrypted second certificate request provided by the second terminal to obtain a second certificate request;

[0029] The first terminal determines a second certificate chain of the first terminal according to the second certificate request;

[0030] The first terminal uses the first handshake key to encrypt the second certificate chain to obtain a target second certificate chain, and sends the target second certificate chain to the second terminal; the second terminal uses the second handshake key to verify the target second certificate chain to obtain an authentication result.

[0031] Optionally, the second terminal verifies the target second certificate chain using the second handshake key to obtain an authentication result, including:

[0032] The second terminal uses the second handshake key to decrypt the target second certificate chain to obtain a second certificate chain;

[0033] The second terminal verifies the second certificate chain using the root certificate in the CA organization to obtain an authentication result.

[0034] Optionally, each certificate in the second certificate chain uses a custom object identifier field to represent a signature algorithm of the certificate, and the signature algorithm includes a hybrid signature algorithm.

[0035] Optionally, the second terminal verifies the second certificate chain using a root certificate in a CA organization to obtain an authentication result, including:

[0036] The second terminal collects the object identifier of the current certificate to be verified in the second certificate chain;

[0037] The second terminal uses the object identifier to parse the current certificate to be verified to obtain a second hybrid signature algorithm; the second hybrid signature algorithm includes a third national secret algorithm and a second quantum-resistant key signature algorithm;

[0038] The second terminal separates the mixed signature in the current certificate to be verified according to the third national secret algorithm and the second quantum-resistant key signature algorithm to obtain a second national secret signature and a second quantum-resistant key signature;

[0039] The second terminal determines the public key of the third country's secret algorithm and the public key of the second quantum-resistant key signature algorithm in the public key of the root certificate or the upper-level certificate of the CA organization according to the third country's secret algorithm and the second quantum-resistant key signature algorithm;

[0040] The second terminal verifies the second national secret signature using the public key of the third national secret algorithm in combination with the third national secret algorithm, and verifies the second quantum resistant key signature using the public key of the second quantum resistant key signature algorithm in combination with the second quantum resistant key signature algorithm, to obtain a signature authentication result of the current certificate to be verified;

[0041] After the signature authentication of the current certificate to be verified passes, the second terminal collects the object identifier of the next node certificate of the current certificate to be verified in the second certificate chain, and returns to execute the step of the second terminal using the object identifier to parse the current certificate to be verified to obtain a second hybrid signature algorithm, until all certificates in the second certificate chain pass the verification, the second certificate chain is legal, and the first terminal is trustworthy.

[0042] Optionally, the method further includes:

[0043] The second terminal obtains the first handshake message sent by the first terminal, and performs a hash operation on the received algorithm support list, the hybrid key exchange parameter, the first certificate request, and the first random number to obtain the second handshake message; the first handshake message is the algorithm support list, the hybrid key exchange parameter, the first certificate request, and the first random number provided by the first terminal, and the handshake message is obtained by performing a hash operation;

[0044] The second terminal compares the first handshake message with the second handshake message;

[0045] When the first handshake message is the same as the second handshake message, the second terminal performs a hash operation on the second certificate request, the target first certificate chain provided by the second terminal, the third public key provided by the second terminal, the target algorithm selected by the second terminal in the algorithm support list, the first encrypted random number provided by the second terminal, the second encrypted random number provided by the second terminal, and the ciphertext to obtain a third handshake message;

[0046] The second terminal signs the second handshake message and the third handshake message using the third private key to obtain a signed handshake message;

[0047] The second terminal uses the second handshake key to encrypt the signature handshake message and sends the encrypted signature handshake message to the first terminal; the first terminal uses the first handshake key to decrypt the encrypted signature handshake message, and uses the third public key provided by the second terminal to verify the signature of the decrypted signature handshake message.

[0048] Optionally, the method further includes:

[0049] The second terminal generates a first session key according to the second handshake key, a second random number provided by the second terminal and a target key derivation algorithm selected by the second terminal in the algorithm support list;

[0050] The second terminal generates a second session key according to the second handshake key, a third random number provided by the second terminal and the target key derivation algorithm.

[0051] Optionally, after the second terminal generates a second session key according to the second handshake key, a third random number provided by the second terminal and the target key derivation algorithm, the method further includes:

[0052] The first terminal obtains a first encrypted random number and a second encrypted random number provided by the second terminal; wherein the first encrypted random number is generated by the second terminal by encrypting the second random number provided by the second terminal according to the classical pre-key and the target national secret algorithm, and the second encrypted random number is generated by the second terminal by encrypting the third random number provided by the second terminal according to the quantum-resistant pre-key and the target quantum-resistant key encapsulation algorithm;

[0053] The first terminal decrypts the first encrypted random number using the classic pre-key and the target national secret algorithm to obtain the second random number;

[0054] The first terminal decrypts the second encrypted random number using the quantum-resistant pre-key and the target quantum-resistant key encapsulation algorithm to obtain the third random number;

[0055] The first terminal generates the first session key according to the first handshake key, the second random number and the target key derivation algorithm;

[0056] The first terminal generates the second session key according to the first handshake key, the third random number and the target key derivation algorithm.

[0057] The embodiment of this specification also provides a security authentication method, which is applied to a second terminal, and the method includes:

[0058] Receive an algorithm support list, a key exchange parameter, a first random number, and a first certificate request sent by the first terminal, and generate a second handshake key and ciphertext by selecting a target algorithm matching the key exchange parameter from the algorithm support list and combining the hybrid key exchange parameter and the first random number;

[0059] Sending a third public key provided by the second terminal, a target algorithm selected by the second terminal, and the ciphertext to the first terminal, so that the first terminal generates a first handshake key;

[0060] Sending a target first certificate chain to a first terminal enables the first terminal to verify the target first certificate chain based on a first handshake key, wherein the target first certificate chain is a first certificate chain encrypted by a second handshake key and obtained from a second terminal according to the first certificate request.

[0061] The embodiment of this specification also provides a security authentication system, which is applied to a first terminal and a second terminal, and the system includes:

[0062] The first terminal sends an algorithm support list, a hybrid key exchange parameter, a first random number, and a first certificate request to the second terminal;

[0063] The second terminal receives the algorithm support list, the key exchange parameters, the first random number, and the first certificate request sent by the first terminal, and generates a second handshake key and ciphertext by selecting a target algorithm matching the key exchange parameters from the algorithm support list in combination with the hybrid key exchange parameters and the first random number;

[0064] The second terminal sends a third public key provided by the second terminal, a target algorithm selected by the second terminal, and the ciphertext to the first terminal;

[0065] The first terminal obtains a first handshake key by using a third public key provided by the second terminal and sent by the second terminal, a target algorithm selected by the second terminal, and the ciphertext;

[0066] The first terminal verifies the target first certificate chain sent by the second terminal using the first handshake key, wherein the target first certificate chain is a first certificate chain encrypted by the second handshake key and obtained by the second terminal from the second terminal according to the first certificate request.

[0067] An electronic device comprises a memory and a processor, wherein the memory stores computer instructions, and the processor is configured to run the computer instructions to execute the method described above.

[0068] A storage medium stores computer instructions, wherein the computer instructions are configured to execute the above method when executed.

[0069] Its beneficial effects are:

[0070] This application uses hybrid key exchange parameters for identity authentication, which enables the terminal to be secure against quantum attacks. During the entire identity authentication process, the leakage of plaintext parameters in the initial handshake message is reduced, and subsequent messages are encrypted differently to reduce the risk of identity authentication key leakage and improve the security of identity authentication. At the same time, the algorithm selection list is sent in a combined algorithm manner, which can effectively reduce the algorithm selection and matching time of the second terminal and improve the efficiency of identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0071] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0072] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0073] Figure 1 A flow chart of a security authentication method applied to a first terminal provided in an embodiment of this specification;

[0074] Figure 2 A schematic diagram of certificate verification interaction of a target second certificate chain between a first terminal and a second terminal provided in an embodiment of this specification;

[0075] Figure 3 A schematic diagram of verification interaction of a handshake message between a first terminal and a second terminal provided in an embodiment of this specification;

[0076] Figure 4 A schematic diagram of generating a session key between a first terminal and a second terminal provided in an embodiment of this specification;

[0077] Figure 5 A flow chart of a security authentication method applied to a second terminal provided in an embodiment of this specification;

[0078] Figure 6 A schematic diagram of the structure of a security authentication system provided in an embodiment of this specification;

[0079] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of this specification;

[0080] Figure 8 A schematic diagram of a computer-readable medium provided for an embodiment of this specification. DETAILED DESCRIPTION

[0081] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, but should not be construed as limiting the present invention.

[0082] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, but should not be construed as limiting the present invention.

[0083] It should be noted that the relative arrangement of components and steps, numerical expressions and numerical values ​​set forth in these embodiments do not limit the scope of the present invention unless specifically stated otherwise.

[0084] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.

[0085] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered as part of the specification.

[0086] In all examples shown and discussed herein, any specific values ​​should be interpreted as merely exemplary and not as limiting. Therefore, other examples of the exemplary embodiments may have different values.

[0087] It should be noted that like reference numerals and letters refer to similar items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.

[0088] Reference Figure 1 A flow chart of a security authentication method applied to a first terminal is provided for an embodiment of the present specification, and the method is applied to the first terminal, comprising: S101: sending an algorithm support list, a hybrid key exchange parameter, a first random number, and a first certificate request to a second terminal, so that the second terminal generates a second handshake key and a ciphertext according to a target algorithm matching the hybrid key exchange parameter selected from the algorithm support list, the hybrid key exchange parameter, and the first random number; S102: after the second terminal generates the second handshake key, determine the first handshake key using a third public key provided by the second terminal and sent by the second terminal, the target algorithm selected by the second terminal, and the ciphertext.

[0089] In an optional embodiment, taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, first, the mobile banking app sends an algorithm support list, a hybrid key exchange parameter, a first random number 1, and a first certificate request to the bank server, wherein the hybrid key exchange parameter includes a first public key pkc0 generated by a first national secret algorithm and a second public key pke1 generated by a first quantum-resistant key encapsulation algorithm; then, the bank server selects a target algorithm that matches the hybrid key exchange parameter from the algorithm support list. For example, if the first national secret algorithm is the SM2 algorithm and the first quantum-resistant key encapsulation algorithm is the Kyber algorithm, the bank server will select any target national secret algorithm that the bank server wants to use from the algorithm support list based on the SM2 algorithm that generates the first public key pkc0 in the hybrid key exchange parameter, and select any target national secret algorithm that the bank server wants to use from the algorithm support list based on the Kyber algorithm that generates the second public key pke1 in the hybrid key exchange parameter. The target anti-quantum key encapsulation algorithm is selected from the list, and the target anti-quantum key encapsulation algorithm is the Kyber algorithm; then, the second handshake key key2 and the ciphertext CT1 are generated according to the target algorithm, the hybrid key exchange parameters and the first random number 1; specifically, the bank server uses the first public key pkc0, the third private key sks0 provided by the bank server, and the target national secret algorithm matching the first public key pkc0 selected by the bank server in the algorithm support list to generate the classical pre-key key10, and uses the second public key pke1 in combination with the target anti-quantum key encapsulation algorithm matching the second public key pke1 selected by the bank server in the algorithm support list to generate the anti-quantum pre-key key11 and the ciphertext CT1, and the bank server generates the second handshake key key2 according to the first random number 1, the classical pre-key key10, the anti-quantum pre-key key11, and the target key derivation algorithm selected by the bank server in the algorithm support list. Among them, the target national secret algorithm is illustrated by the SM2 algorithm, the target anti-quantum key encapsulation algorithm is illustrated by the Kyber algorithm, and the target key derivation algorithm is illustrated by the HKDF (HMAC-based Extract-and-Expand Key Derivation Function) algorithm, which will not be repeated later.

[0090] After the bank server generates the second handshake key key2, the bank server sends the third public key pks0 provided by the bank server, the target algorithm selected by the bank server, and the ciphertext ct1 to the mobile banking app. The mobile banking app uses the third public key pks0 and the first private key skc0 generated by the SM2 algorithm in combination with the SM2 algorithm to calculate the classical pre-key key10, and uses the second private key ske1 generated by the Kyber algorithm in combination with the Kyber algorithm to decrypt the ciphertext ct1 to obtain the anti-quantum pre-key key11; then, the mobile banking app generates the first handshake key key1 according to the first random number 1, the classical pre-key key10, and the anti-quantum pre-key key11 in combination with the HKDF algorithm, wherein the target algorithm is the above-mentioned SM2 algorithm, Kyber algorithm, and HKDF algorithm. Both the bank server and the mobile banking app use the elliptic curve encryption algorithm, thus ensuring that both the bank server and the mobile banking app can generate the same classical pre-key key10 and anti-quantum pre-key key11 according to the transmitted public key in combination with their own private key. By using the hybrid key exchange parameters to generate the handshake key, the bank server has the security to resist quantum attacks, which provides higher security for subsequent identity authentication. At the same time, the algorithm support list method can be used to send two or more algorithms in combination, avoiding the bank server from having to make multiple algorithm selections when selecting a hybrid algorithm, thereby improving the efficiency of identity authentication.

[0091] S103: Use the first handshake key to verify the target first certificate chain sent by the second terminal to obtain an authentication result, wherein the target first certificate chain is the first certificate chain encrypted by the second handshake key obtained by the second terminal from the second terminal according to the first certificate request. Specifically, the first terminal uses the first handshake key to decrypt the target first certificate chain to obtain the first certificate chain; the first terminal uses the root certificate in the CA (Certificate Authority) organization to verify the first certificate chain to obtain an authentication result.

[0092] In an optional embodiment, still taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, the mobile banking app uses the first handshake key key1 to decrypt the target first certificate chain to obtain the first certificate chain, and then the mobile banking app uses the root certificate in the CA organization to verify the certificates in the first certificate chain in turn. When each certificate in the first certificate chain is verified, it means that the first certificate chain is supported and recognized by the CA organization, that is, the mobile banking app successfully authenticates the bank server. The above method is used to realize the identity authentication of the first terminal to the second terminal. In the entire ID card authentication process, most of the information in the authentication process is encrypted, which greatly reduces the transmission of plaintext data, reduces the possibility of information leakage, and improves the security of identity authentication.

[0093] Optionally, each certificate in the first certificate chain uses a custom object identifier field to represent the signature algorithm of the certificate, and each certificate in the second certificate chain uses a custom object identifier field to represent the signature algorithm of the certificate, and the signature algorithm includes a hybrid signature algorithm.

[0094] In an optional embodiment, in order to make the first terminal and the second terminal have security against quantum attacks, the signature algorithm used by each certificate in the first certificate chain and each certificate in the second certificate chain is generally a hybrid signature algorithm, such as a hybrid signature algorithm combining the SM2 algorithm with the Dilithium algorithm. In order to subsequently implement the verification of the certificate chain, each certificate in the first certificate chain and each certificate in the second certificate chain uses a custom object identifier field to represent the signature algorithm of the certificate. The signature algorithm is quickly parsed through the custom object identifier, which facilitates the verification of the certificate chain.

[0095] Optionally, the first terminal uses the root certificate in the CA organization to verify the first certificate chain to obtain an authentication result, including: the first terminal collects the object identifier of the current certificate to be verified in the first certificate chain; the first terminal uses the object identifier to parse the current certificate to be verified to obtain a first hybrid signature algorithm; the first hybrid signature algorithm includes a second national secret algorithm and a first quantum-resistant key signature algorithm; the first terminal separates the hybrid signature in the current certificate to be verified according to the second national secret algorithm and the first quantum-resistant key signature algorithm to obtain a first national secret signature and a first quantum-resistant key signature; the first terminal determines the second national secret algorithm in the public key of the root certificate or the upper-level certificate of the CA organization according to the second national secret algorithm and the first quantum-resistant key signature algorithm. The first terminal verifies the first national secret signature by using the public key of the second national secret algorithm in combination with the second national secret algorithm, and verifies the first quantum resistant key signature by using the public key of the first quantum resistant key signature algorithm in combination with the first quantum resistant key signature algorithm, to obtain the signature authentication result of the current certificate to be verified; after the signature authentication of the current certificate to be verified passes, the first terminal collects the object identifier of the next node certificate of the current certificate to be verified in the first certificate chain, and returns to execute the step of the first terminal parsing the current certificate to be verified by using the object identifier to obtain the first hybrid signature algorithm, until all certificates in the first certificate chain pass the verification, the first certificate chain is legal, and the second terminal is credible.

[0096] In an optional embodiment, still taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, the mobile banking app collects the object identifier of the certificate to be verified located at the first position of the first certificate chain; then, the mobile banking app uses the object identifier to parse the certificate to be verified at the first position to obtain a first hybrid signature algorithm, wherein the first hybrid signature algorithm includes a second national secret algorithm and a first quantum-resistant key signature algorithm, and the first hybrid signature algorithm is described here by taking a hybrid signature algorithm of the SM2 algorithm combined with the Dilithium algorithm as an example; then, the mobile banking app separates the hybrid signature sig1 in the certificate to be verified at the first position according to the SM2 algorithm and the Dilithium algorithm to obtain the first national secret signature sig10 and the first quantum-resistant key signature sig11; then, the mobile banking app determines the public key of the SM2 algorithm and the public key of the Dilithium algorithm in the public key of the root certificate of the CA institution according to the SM2 algorithm and the Dilithium algorithm. key; the mobile banking app uses the public key of the SM2 algorithm in combination with the SM2 algorithm to verify the first national secret signature sig10, and uses the public key of the Dilithium algorithm in combination with the Dilithium algorithm to verify the first quantum-resistant key signature sig11. When the two signatures are successfully verified, it means that the first certificate in the first certificate chain is successfully verified; finally, the certificate to be verified at the second position of the first certificate chain is verified. At this time, the mobile banking app first collects the object identifier of the next node certificate of the certificate to be verified at the first position in the first certificate chain, and loops the verification process of the certificate to be verified at the first position above. It should be noted that at this time, the mobile banking app determines the public key of the SM2 algorithm and the public key of the Dilithium algorithm used by the current node certificate in the public key of the previous level certificate according to the SM2 algorithm and the Dilithium algorithm used by the current node certificate, until all certificates in the first certificate chain are verified, which means that the first certificate chain is legal, that is, the bank server is trustworthy. By utilizing object identifiers to quickly parse the signature algorithm, major changes to the national secret signatures of the original certificates in the certificate chain can be avoided. Only cascading quantum-resistant key signatures is required to achieve quantum-resistant security, adapting to the combination of security authentication of the classic national secret algorithm and post-quantum security authentication.

[0097] like Figure 2As shown, the first terminal obtains the second certificate request encrypted by the second handshake key from the second terminal; the first terminal uses the first handshake key to decrypt the encrypted second certificate request provided by the second terminal to obtain the second certificate request; the first terminal determines the second certificate chain of the first terminal according to the second certificate request; the first terminal uses the first handshake key to encrypt the second certificate chain to obtain the target second certificate chain, and sends the target second certificate chain to the second terminal; the second terminal uses the second handshake key to verify the target second certificate chain to obtain the authentication result. Specifically, the second terminal uses the second handshake key to decrypt the target second certificate chain to obtain the second certificate chain; the second terminal uses the root certificate in the CA organization to verify the second certificate chain to obtain the authentication result.

[0098] In an optional embodiment, still taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, the mobile banking app uses the first handshake key kye1 to decrypt the encrypted second certificate request provided by the bank server to obtain the second certificate request; the mobile banking app determines the second certificate chain of the mobile banking app according to the second certificate request, and then the mobile banking app uses the first handshake key kye1 to encrypt the second certificate chain to obtain the target second certificate chain, and sends the target second certificate chain to the bank server. The bank server uses the second handshake key key2 to decrypt the target second certificate chain to obtain the second certificate chain, and then the bank server uses the root certificate in the CA organization to verify the certificates in the second certificate chain in turn. When each certificate in the second certificate chain is verified, it means that the second certificate chain is supported and recognized by the CA organization, that is, the bank server successfully authenticates the mobile banking app. The identity authentication of the second terminal to the first terminal is realized by the above method. In the entire identity card authentication process, by encrypting most of the information in the authentication process, the transmission of plaintext data is greatly reduced, the possibility of information leakage is reduced, and the security of identity authentication is improved. Finally, the two-way authentication between the first terminal and the second terminal is completed, ensuring that the terminals are trustworthy, and providing security guarantees for the subsequent transmission of important information between terminals.

[0099] Optionally, the second terminal uses the root certificate in the CA organization to verify the second certificate chain to obtain an authentication result, including: the second terminal collects the object identifier of the current certificate to be verified in the second certificate chain; the second terminal uses the object identifier to parse the current certificate to be verified to obtain a second hybrid signature algorithm; the second hybrid signature algorithm includes a third national secret algorithm and a second quantum-resistant key signature algorithm; the second terminal separates the hybrid signature in the current certificate to be verified according to the third national secret algorithm and the second quantum-resistant key signature algorithm to obtain a second national secret signature and a second quantum-resistant key signature; the second terminal determines the third national secret algorithm in the public key of the root certificate or the upper-level certificate of the CA organization according to the third national secret algorithm and the second quantum-resistant key signature algorithm. The second terminal verifies the second national secret signature using the public key of the third national secret algorithm in combination with the third national secret algorithm, and verifies the second quantum resistant key signature using the public key of the second quantum resistant key signature algorithm in combination with the second quantum resistant key signature algorithm, to obtain the signature authentication result of the current certificate to be verified; after the signature authentication of the current certificate to be verified passes, the second terminal collects the object identifier of the next node certificate of the current certificate to be verified in the second certificate chain, and returns to execute the step of the second terminal parsing the current certificate to be verified using the object identifier to obtain the second hybrid signature algorithm, until all certificates in the second certificate chain pass the verification, the second certificate chain is legal, and the first terminal is credible.

[0100] In an optional embodiment, still taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, the bank server collects the object identifier of the certificate to be verified located at the first position of the second certificate chain; then, the bank server uses the object identifier to parse the certificate to be verified at the first position to obtain a second hybrid signature algorithm, wherein the second hybrid signature algorithm includes a third national secret algorithm and a second quantum-resistant key signature algorithm, and the second hybrid signature algorithm here is described by taking a hybrid signature algorithm of the SM2 algorithm combined with the Dilithium algorithm as an example; then, the bank server separates the hybrid signature sig2 in the certificate to be verified at the first position according to the SM2 algorithm and the Dilithium algorithm, and obtains the second national secret signature sig20 and the second quantum-resistant key signature sig21; then, the bank server determines the public key of the SM2 algorithm and the public key of the Dilithium algorithm in the public key of the root certificate of the CA institution according to the SM2 algorithm and the Dilithium algorithm; The bank server uses the public key of the SM2 algorithm in combination with the SM2 algorithm to verify the second national secret signature sig20, and uses the public key of the Dilithium algorithm in combination with the Dilithium algorithm to verify the second quantum-resistant key signature sig21. When the two signatures are successfully verified, it means that the first certificate in the second certificate chain is successfully verified; finally, the certificate to be verified at the second position of the second certificate chain is verified. At this time, the bank server first collects the object identifier of the next node certificate of the certificate to be verified at the first position in the first certificate chain, and loops the verification process of the certificate to be verified at the first position above. It should be noted that at this time, the bank server determines the public key of the SM2 algorithm and the public key of the Dilithium algorithm used by the current node certificate in the public key of the previous level certificate according to the SM2 algorithm and the Dilithium algorithm used by the current node certificate, until all certificates in the second certificate chain pass the verification, which means that the second certificate chain is legal, that is, the bank mobile app is trustworthy. By utilizing object identifiers to quickly parse the signature algorithm, major changes to the national secret signature of the original certificate in the certificate chain can be avoided. Only cascading quantum-resistant key signatures is required to achieve quantum-resistant security, adapting to the combination of security authentication of the classic national secret algorithm and post-quantum security authentication. At the same time, completing identity authentication between terminals provides better security guarantees for the subsequent transmission of important information between terminals.

[0101] like Figure 3As shown, the second terminal obtains the first handshake message sent by the first terminal, and performs a hash operation on the received algorithm support list, the hybrid key exchange parameter, the first certificate request and the first random number to obtain a second handshake message; the first handshake message is the algorithm support list, the hybrid key exchange parameter, the first certificate request and the first random number provided by the first terminal to obtain a handshake message by performing a hash operation; the second terminal compares the first handshake message with the second handshake message; when the first handshake message is the same as the second handshake message, the second terminal performs a hash operation on the second certificate request, the target first certificate chain provided by the second terminal, the third public key provided by the second terminal, the target algorithm selected by the second terminal in the algorithm support list, the first encrypted random number provided by the second terminal, the second encrypted random number provided by the second terminal, and the ciphertext to obtain a third handshake message; the second terminal signs the second handshake message and the third handshake message using the third private key to obtain a signature handshake message; the second terminal encrypts the signature handshake message using the second handshake key, and sends the encrypted signature handshake message to the first terminal; the first terminal decrypts the encrypted signature handshake message using the first handshake secret key, and performs signature verification on the decrypted signature handshake message using the third public key provided by the second terminal.

[0102] In an optional embodiment, still taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, the bank server first obtains a first handshake message sent by the mobile banking app, wherein the first handshake message is an algorithm support list, a hybrid key exchange parameter, a first certificate request and a first random number provided by the mobile banking app, and a hash operation is performed to obtain a handshake message; then, the bank server performs a hash operation on the received algorithm support list, hybrid key exchange parameter, first certificate request and first random number 1 to obtain a second handshake message; thereafter, the bank server compares the first handshake message and the second handshake message; when the first handshake message is the same as the second handshake message, it indicates that the information such as the algorithm support list, hybrid key exchange parameter, first certificate request and first random number 1 sent by the mobile banking app to the bank server has not been tampered with, and the information received by the bank server can be used for subsequent handshake key generation and identity authentication, thereby avoiding the risk of information tampering in advance. Afterwards, the bank server performs a hash operation on the second certificate request provided by the bank server, the target first certificate chain provided by the bank server, the third public key pks0 provided by the bank server, the target algorithm selected by the bank server in the algorithm support list, the first encrypted random number provided by the bank server, the second encrypted random number provided by the bank server, and the ciphertext ct1 to obtain a third handshake message, and uses the third private key sks0 to sign the second handshake message and the third handshake message to obtain a signature handshake message sig3; finally, the bank server uses the second handshake key key2 to encrypt the signature handshake message, and sends the encrypted signature handshake message to the mobile banking app, and the mobile banking app uses the first handshake key key1 to decrypt the encrypted signature handshake message, and uses the third private key sks0 provided by the bank server to sign the second handshake message and the third handshake message to obtain a signature handshake message sig3; finally, the bank server uses the second handshake key key2 to encrypt the signature handshake message, and sends the encrypted signature handshake message to the mobile banking app, and the mobile banking app uses the first handshake key key1 to decrypt the encrypted signature handshake message, and uses the The third public key pks0 is used to verify the signature of the decrypted signed handshake message. It should be noted that when the second terminal verifies the identity of the first terminal, the first terminal performs a hash operation on the second target certificate chain provided by the first terminal and sent by the first terminal to the second terminal to obtain a fourth handshake message, and uses the first private key skc0 to sign the second handshake message, the third handshake message, and the fourth handshake message to obtain a signed handshake message sig4, and uses the first handshake key key1 to encrypt the signed handshake message sig4 and transmit it to the second terminal; the second terminal uses the second handshake key key2 to decrypt the signed handshake message sig4, and uses the first public key pkc0 to verify the signature of the decrypted signed handshake message sig4. The above method ensures the integrity of the handshake process and prevents information from being tampered with during transmission.

[0103] In an optional embodiment, since each certificate in the first certificate chain and the second certificate chain may be signed using only one signature algorithm, when verifying the first certificate chain or the second certificate chain, for the certificates in the certificate chain that are signed using only one signature algorithm, there is no need to perform a signature separation operation, and only the signature value in the signature field of the certificate needs to be directly verified, thereby improving the verification flexibility of the certificate chain.

[0104] like Figure 4 As shown, the second terminal generates a first session key according to the second handshake key, the second random number provided by the second terminal and the target key derivation algorithm selected by the second terminal in the algorithm support list; the second terminal generates a second session key according to the second handshake key, the third random number provided by the second terminal and the target key derivation algorithm; the first terminal obtains the first encrypted random number and the second encrypted random number provided by the second terminal; wherein the first encrypted random number is generated by the second terminal encrypting the second random number provided by the second terminal according to the classical pre-key and the target national secret algorithm, and the second encrypted random number is generated by the second terminal encrypting the third random number provided by the second terminal according to the anti-quantum pre-key and the target anti-quantum key encapsulation algorithm; the first terminal uses the classical pre-key and the target national secret algorithm to decrypt the first encrypted random number to obtain the second random number; the first terminal uses the anti-quantum pre-key and the target anti-quantum key encapsulation algorithm to decrypt the second encrypted random number to obtain the third random number; the first terminal generates the first session key according to the first handshake key, the second random number and the target key derivation algorithm; the first terminal generates the second session key according to the first handshake key, the third random number and the target key derivation algorithm.

[0105] In an optional embodiment, still taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, in order to encrypt and transmit and decrypt the data of both parties after the mobile banking app and the bank server realize identity authentication, the mobile banking app needs to generate a session key for encrypting the data sent by the mobile banking app to the bank server, and the bank server also needs to generate the same session key to decrypt the data sent by the mobile banking app to the bank server; similarly, the bank server needs to generate a session key for encrypting the data sent by the bank server to the mobile banking app, and the mobile banking app also needs to generate the same session key to decrypt the data sent by the mobile banking app to the bank server, that is, the mobile banking app and the bank server realize the secure transmission of the data of both parties based on the above two session keys. Specifically, for the bank server, the bank server generates the first session key key3 according to the second handshake key key2, the second random number 2 provided by the bank server, and the HKDF algorithm selected by the bank server in the algorithm support list, and the bank server generates the second session key key4 according to the second handshake key key2, the third random number 3 provided by the bank server, and the HKDF algorithm; the generation of the two session keys of the bank server is realized in the above manner, providing security for the subsequent data interaction between the mobile banking app and the bank server. As for the mobile banking app, in order to ensure that the session key generated in the mobile banking app is consistent with the session key generated in the bank server, the mobile banking app first obtains the first encrypted random number and the second encrypted random number provided by the bank server; wherein, the first encrypted random number is generated by the bank server according to the classic pre-secret key10 and SM2 algorithm to encrypt the second random number 2 provided by the bank server, and the second encrypted random number is generated by the bank server according to the anti-quantum pre-secret key11 and Kyber algorithm to encrypt the third random number 3 provided by the bank server; then, the mobile banking app uses the classic pre-secret key10 and SM2 algorithm to decrypt the first encrypted random number to obtain the The second random number 2; the mobile banking app uses the quantum-resistant pre-key key11 and the Kyber algorithm to decrypt the second encrypted random number to obtain the third random number 3; the mobile banking app generates the first session key key3 according to the first handshake key key1, the second random number 2 and the HKDF algorithm, and generates the second session key key4 according to the first handshake key key1, the third random number 3 and the HKDF algorithm; the above method ensures that the session key generated in the mobile banking app is consistent with the session key generated in the bank server, thereby realizing secure data communication between the mobile banking app and the bank server and preventing data from being tampered with during the communication between the two parties.

[0106] Reference Figure 5 A flow chart of a security authentication method applied to a second terminal is provided for an embodiment of the present specification, the method comprising: S201: receiving an algorithm support list, key exchange parameters, a first random number, and a first certificate request sent by a first terminal, and generating a second handshake key and a ciphertext based on a target algorithm selected from the algorithm support list that matches the key exchange parameters in combination with the hybrid key exchange parameters and the first random number; S202: sending a third public key provided by the second terminal, the target algorithm selected by the second terminal, and the ciphertext to the first terminal, so that the first terminal generates a first handshake key; S203: sending a target first certificate chain to the first terminal so that the first terminal verifies the target first certificate chain based on the first handshake key, wherein the target first certificate chain is the first certificate chain encrypted by the second handshake key and obtained by the second terminal from the second terminal according to the first certificate request.

[0107] In an optional embodiment, taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, first, the bank server receives the algorithm support list, hybrid key exchange parameters and the first random number 1, and the first certificate request sent by the mobile banking app to the bank server, wherein the hybrid key exchange parameters include a first public key pkc0 generated by a first national secret algorithm and a second public key pke1 generated by a first quantum-resistant key encapsulation algorithm; then, the bank server selects a target algorithm that matches the hybrid key exchange parameters from the algorithm support list. For example, if the first national secret algorithm is the SM2 algorithm and the first quantum-resistant key encapsulation algorithm is the Kyber algorithm, the bank server will select any target national secret algorithm that the bank server wants to use from the algorithm support list based on the SM2 algorithm that generates the first public key pkc0 in the hybrid key exchange parameters, and select any target national secret algorithm that the bank server wants to use from the algorithm support list based on the Kyber algorithm that generates the second public key pke1 in the hybrid key exchange parameters. The algorithm support list selects a target quantum-resistant key encapsulation algorithm, which is the Kyber algorithm; then, a second handshake key key2 and a ciphertext CT1 are generated according to the target algorithm, the hybrid key exchange parameters and the first random number 1; specifically, the bank server uses the first public key PKC0, the third private key SKS0 provided by the bank server, and the target national secret algorithm selected by the bank server in the algorithm support list that matches the first public key PKC0 to generate a classical pre-key key10, and uses the second public key PKE1 in combination with the target quantum-resistant key encapsulation algorithm selected by the bank server in the algorithm support list that matches the second public key PKE1 to generate a quantum-resistant pre-key key11 and a ciphertext CT1, and the bank server generates a second handshake key key2 according to the first random number 1, the classical pre-key key10, the quantum-resistant pre-key key11, and the target key derivation algorithm selected by the bank server in the algorithm support list. Among them, the target national secret algorithm is illustrated by the SM2 algorithm, the target anti-quantum key encapsulation algorithm is illustrated by the Kyber algorithm, and the target key derivation algorithm is illustrated by the HKDF (HMAC-based Extract-and-ExpandKey Derivation Function) algorithm, which will not be repeated later.

[0108] After the bank server generates the second handshake key key2, the bank server sends the third public key pks0 provided by the bank server, the target algorithm selected by the bank server, and the ciphertext ct1 to the mobile banking app. The mobile banking app uses the third public key pks0, the first private key skc0 generated by the SM2 algorithm and the SM2 algorithm to calculate the classical pre-key key10, and uses the second private key ske1 generated by the Kyber algorithm and the Kyber algorithm to decrypt the ciphertext ct1 to obtain the anti-quantum pre-key key11; then, the mobile banking app generates the first handshake key key1 according to the first random number 1, the classical pre-key key10, and the anti-quantum pre-key key11 in combination with the HKDF algorithm, wherein the target algorithm is the above-mentioned SM2 algorithm, Kyber algorithm and HKDF algorithm. Both the bank server and the mobile banking app use the elliptic curve encryption algorithm, thus ensuring that both the bank server and the mobile banking app can generate the same classical pre-key key10 and anti-quantum pre-key key11 according to the transmitted public key in combination with their own private key. By using the hybrid key exchange parameters to generate the handshake key, the bank server has the security to resist quantum attacks, which provides higher security for subsequent identity authentication. At the same time, the algorithm support list method can be used to send two or more algorithms in combination, avoiding the bank server from having to make multiple algorithm selections when selecting a hybrid algorithm, thereby improving the efficiency of identity authentication.

[0109] Finally, the mobile banking app uses the first handshake key key1 to decrypt the target first certificate chain to obtain the first certificate chain. The mobile banking app uses the root certificate in the CA organization to verify the certificates in the first certificate chain in turn. When each certificate in the first certificate chain is verified, it means that the first certificate chain is supported and recognized by the CA organization, that is, the mobile banking app successfully authenticates the bank server. The above method is used to implement the identity authentication of the mobile banking app to the bank service. By encrypting the communication messages except the initial handshake message with different keys, the leakage of plaintext data is reduced, the risk of key leakage is reduced, and the security of identity authentication is guaranteed.

[0110] Regarding the security authentication method applied to the second terminal in the above embodiment, the process of executing the operation in each step is basically the same as that of the embodiment of the security authentication method applied to the first terminal, and will not be elaborated here.

[0111] Reference Figure 6A security authentication system provided for an embodiment of the present specification is applied to a first terminal and a second terminal, the system comprising: the first terminal sends an algorithm support list, a hybrid key exchange parameter, a first random number and a first certificate request to the second terminal; the second terminal receives the algorithm support list, the key exchange parameter, the first random number and the first certificate request sent by the first terminal, and generates a second handshake key and a ciphertext based on a target algorithm selected from the algorithm support list that matches the key exchange parameter in combination with the hybrid key exchange parameter and the first random number; the second terminal sends a third public key provided by the second terminal, the target algorithm selected by the second terminal, and the ciphertext to the first terminal; the first terminal obtains a first handshake key using the third public key provided by the second terminal, the target algorithm selected by the second terminal, and the ciphertext sent by the second terminal; the first terminal verifies the target first certificate chain sent by the second terminal using the first handshake key, wherein the target first certificate chain is the first certificate chain encrypted by the second handshake key and obtained from the second terminal by the second terminal according to the first certificate request.

[0112] In an optional embodiment, taking the first terminal as a mobile banking app and the second terminal as a bank server as an example, first, the mobile banking app sends an algorithm support list, a hybrid key exchange parameter first random number 1 and a first certificate request to the bank server, wherein the hybrid key exchange parameter includes a first public key pkc0 generated by a first national secret algorithm and a second public key pke1 generated by a first quantum-resistant key encapsulation algorithm; then, the bank server selects a target algorithm that matches the hybrid key exchange parameter from the algorithm support list, and then, the bank server generates a second handshake key key2 and a ciphertext ct1 according to the target algorithm, the hybrid key exchange parameter and the first random number 1; The bank server generates a classical pre-key key10 by using the first public key pkc0 and the third private key sks0 provided by the bank server in combination with the target national secret algorithm selected by the bank server in the algorithm support list that matches the first public key pkc0, and generates an anti-quantum pre-key key11 and a ciphertext ct1 by using the second public key pke1 in combination with the target anti-quantum key encapsulation algorithm selected by the bank server in the algorithm support list that matches the second public key pke1. The bank server generates a second handshake key key2 according to the first random number 1, the classical pre-key key10, the anti-quantum pre-key key11 in combination with the target key derivation algorithm selected by the bank server in the algorithm support list.

[0113] After the bank server generates the second handshake key key2, the bank server sends the third public key pks0 provided by the bank server, the target algorithm selected by the bank server, and the ciphertext ct1 to the mobile banking app. The mobile banking app uses the third public key pks0, the first private key skc0 generated by the SM2 algorithm and the SM2 algorithm to calculate the classical pre-key key10, and uses the second private key ske1 generated by the Kyber algorithm and the Kyber algorithm to decrypt the ciphertext ct1 to obtain the anti-quantum pre-key key11; then, the mobile banking app generates the first handshake key key1 according to the first random number 1, the classical pre-key key10, and the anti-quantum pre-key key11 in combination with the HKDF algorithm. By using the hybrid key exchange parameters to generate the handshake key, the bank server has the security of resisting quantum attacks, which improves the security of subsequent identity authentication. At the same time, the algorithm support list can be used to send two or more algorithms in a combined manner, avoiding the bank server from having to make multiple algorithm selections when selecting a hybrid algorithm, thereby improving the efficiency of identity authentication. Finally, the mobile banking app uses the first handshake key key1 to decrypt the target first certificate chain to obtain the first certificate chain. The mobile banking app uses the root certificate in the CA organization to verify the certificates in the first certificate chain in turn. When each certificate in the first certificate chain is verified, it means that the first certificate chain is supported and recognized by the CA organization, that is, the mobile banking app successfully authenticates the bank server. During the entire authentication process, by encrypting communication messages other than the initial handshake message with different keys, the leakage of plaintext data is reduced, the risk of key leakage is reduced, and the security of authentication is guaranteed; at the same time, the algorithm selection list is sent by a combined algorithm, which can effectively reduce the algorithm selection and matching time of the second terminal and improve the efficiency of authentication.

[0114] Regarding the system in the above embodiment, the process of executing the operation in each step has been described in detail in the embodiment of the method, and will not be elaborated here.

[0115] Based on the same inventive concept, an embodiment of this specification also provides an electronic device.

[0116] The following describes an electronic device embodiment of the present invention, which can be regarded as a specific physical implementation of the method and device embodiments of the present invention. The details described in the electronic device embodiment of the present invention should be regarded as a supplement to the above method or device embodiments; details not disclosed in the electronic device embodiment of the present invention can be implemented with reference to the above method or device embodiments.

[0117] Reference Figure 7This is a schematic diagram of the structure of an electronic device provided in an embodiment of this specification. Figure 7 The electronic device 300 according to the embodiment of the present invention is described. Figure 7 The electronic device 300 shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0118] like Figure 7 As shown, the electronic device 300 is in the form of a general computing device. The components of the electronic device 300 may include, but are not limited to: at least one processing unit 310, at least one storage unit 320, a bus 330 connecting different device components (including the storage unit 320 and the processing unit 310), a display unit 340, etc.

[0119] The storage unit stores program codes, which can be executed by the processing unit 310, so that the processing unit 310 performs the steps according to various exemplary embodiments of the present invention described in the above processing method section of this specification. For example, the processing unit 310 can perform the following steps: Figure 1 and / or Figure 5 Steps shown.

[0120] The storage unit 320 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 3201 and / or a cache memory unit 3202 , and may further include a read-only memory unit (ROM) 3203 .

[0121] The storage unit 320 may also include a program / utility 3204 having a set (at least one) of program modules 3205, such program modules 3205 including but not limited to: operating means, one or more application programs, other program modules and program data, each of which or some combination may include the implementation of a network environment.

[0122] Bus 330 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0123] The electronic device 300 may also communicate with one or more external devices 400 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), one or more devices that enable a user to interact with the electronic device 300, and / or any device that enables the electronic device 300 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed through an input / output (I / O) interface 350. Furthermore, the electronic device 300 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 360. The network adapter 360 may communicate with other modules of the electronic device 300 through the bus 330. It should be understood that although Figure 7 Not shown, other hardware and / or software modules may be used in conjunction with the electronic device 300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID devices, tape drives, and data backup storage devices.

[0124] Through the description of the above implementation methods, it is easy for those skilled in the art to understand that the exemplary embodiments described in the present invention can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation method of the present invention can be embodied in the form of a software product, which can be stored in a computer-readable storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.) or on a network, including a number of instructions to enable a computing device (which can be a personal computer, server, or network device, etc.) to execute the above method according to the present invention. When the computer instructions are executed by a data processing device, the computer-readable medium can implement the above method of the present invention, that is: Figure 1 and / or Figure 5 The method shown.

[0125] Reference Figure 8 A schematic diagram of a computer-readable medium provided for an embodiment of this specification.

[0126] Implementation Diagram Figure 1 and / or Figure 5The computer instructions of the method shown can be stored on one or more computer readable media. The computer readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor device, device or component, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0127] The computer readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a readable program code is carried. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable storage medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in combination with an instruction execution device, device, or device. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0128] Program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0129] In summary, the present invention can be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof. It should be understood by those skilled in the art that general data processing devices such as microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the embodiments of the present invention. The present invention can also be implemented as a device or apparatus program (e.g., a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0130] The specific embodiments described above further describe the purpose, technical solutions and beneficial effects of the present invention in detail. It should be understood that the present invention is not inherently related to any specific computer, virtual device or electronic device, and various general devices can also implement the present invention. The above description is only a specific embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

[0131] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.

[0132] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A security authentication method, characterized in that: Applied to a first terminal, the method includes: Sending an algorithm support list, a hybrid key exchange parameter, a first random number, and a first certificate request to a second terminal, so that the second terminal generates a second handshake key and a ciphertext according to a target algorithm matching the hybrid key exchange parameter selected from the algorithm support list, the hybrid key exchange parameter, and the first random number; After the second terminal generates the second handshake key, determine the first handshake key using the third public key provided by the second terminal and sent by the second terminal, the target algorithm selected by the second terminal, and the ciphertext; The target first certificate chain sent by the second terminal is verified using the first handshake key to obtain an authentication result, wherein the target first certificate chain is a first certificate chain encrypted by the second handshake key and obtained by the second terminal from the second terminal according to the first certificate request.

2. The method according to claim 1, characterized in that The hybrid key exchange parameters include a first public key generated using a first national secret algorithm and a second public key generated using a first quantum-resistant key encapsulation algorithm; The second terminal generates a second handshake key and a ciphertext according to a target algorithm selected from the algorithm support list and matching the hybrid key exchange parameter, the hybrid key exchange parameter, and a first random number, including: The second terminal uses the first public key, the third private key provided by the second terminal and a target national secret algorithm selected by the second terminal in the algorithm support list that matches the first public key to generate a classical pre-key, and uses the second public key and a target quantum-resistant key encapsulation algorithm selected by the second terminal in the algorithm support list that matches the second public key to generate a quantum-resistant pre-key and a ciphertext; The second terminal generates a second handshake key according to the first random number, the classical pre-key, the quantum-resistant pre-key and a target key derivation algorithm selected by the second terminal in the algorithm support list.

3. The method according to claim 2, characterized in that The determining the first handshake key by using the third public key provided by the second terminal and sent by the second terminal, the target algorithm selected by the second terminal, and the ciphertext includes: The first terminal uses the third public key, the first private key generated by the first national secret algorithm and the target national secret algorithm to calculate to obtain the classical pre-key, and uses the second private key generated by the first quantum-resistant key encapsulation algorithm and the target quantum-resistant key encapsulation algorithm to decrypt the ciphertext to obtain the quantum-resistant pre-key; The first terminal generates a first handshake key according to the first random number, the classical pre-key, the quantum-resistant pre-key and the target key derivation algorithm.

4. The method according to claim 3, characterized in that The using the first handshake key to verify the target first certificate chain sent by the second terminal to obtain an authentication result includes: The first terminal uses the first handshake key to decrypt the target first certificate chain to obtain the first certificate chain; The first terminal verifies the first certificate chain using the root certificate in the CA organization to obtain an authentication result.

5. The method according to claim 4, characterized in that Each certificate in the first certificate chain uses a custom object identifier field to represent the signature algorithm of the certificate, and the signature algorithm includes a hybrid signature algorithm.

6. The method according to claim 5, characterized in that The first terminal verifies the first certificate chain using the root certificate in the CA organization to obtain an authentication result, including: The first terminal collects the object identifier of the current certificate to be verified in the first certificate chain; The first terminal uses the object identifier to parse the current certificate to be verified to obtain a first hybrid signature algorithm; the first hybrid signature algorithm includes a second national secret algorithm and a first quantum-resistant key signature algorithm; The first terminal separates the mixed signature in the current certificate to be verified according to the second national secret algorithm and the first quantum-resistant key signature algorithm to obtain a first national secret signature and a first quantum-resistant key signature; The first terminal determines the public key of the second national secret algorithm and the public key of the first quantum-resistant key signature algorithm in the public key of the root certificate or the upper-level certificate of the CA organization according to the second national secret algorithm and the first quantum-resistant key signature algorithm; The first terminal verifies the first national secret signature using the public key of the second national secret algorithm in combination with the second national secret algorithm, and verifies the first quantum-resistant key signature using the public key of the first quantum-resistant key signature algorithm in combination with the first quantum-resistant key signature algorithm, to obtain a signature authentication result of the current certificate to be verified; After the signature authentication of the current certificate to be verified passes, the first terminal collects the object identifier of the next node certificate of the current certificate to be verified in the first certificate chain, and returns to execute the step of the first terminal using the object identifier to parse the current certificate to be verified to obtain the first hybrid signature algorithm, until all certificates in the first certificate chain pass the verification, the first certificate chain is legal, and the second terminal is trustworthy.

7. The method according to any one of claims 1 to 6, characterized in that: After verifying the target first certificate chain sent by the second terminal using the first handshake key to obtain an authentication result, the method further includes: The first terminal obtains, from the second terminal, a second certificate request encrypted by a second handshake key; The first terminal uses the first handshake key to decrypt the encrypted second certificate request provided by the second terminal to obtain a second certificate request; The first terminal determines a second certificate chain of the first terminal according to the second certificate request; The first terminal encrypts the second certificate chain using the first handshake key to obtain a target second certificate chain, and sends the target second certificate chain to the second terminal; The second terminal verifies the target second certificate chain using the second handshake key to obtain an authentication result.

8. The method according to claim 7, characterized in that The second terminal verifies the target second certificate chain using the second handshake key to obtain an authentication result, including: The second terminal uses the second handshake key to decrypt the target second certificate chain to obtain a second certificate chain; The second terminal verifies the second certificate chain using the root certificate in the CA organization to obtain an authentication result.

9. The method according to claim 8, characterized in that Each certificate in the second certificate chain uses a custom object identifier field to represent the signature algorithm of the certificate, and the signature algorithm includes a hybrid signature algorithm.

10. The method according to claim 9, characterized in that The second terminal verifies the second certificate chain using the root certificate in the CA organization to obtain an authentication result, including: The second terminal collects the object identifier of the current certificate to be verified in the second certificate chain; The second terminal uses the object identifier to parse the current certificate to be verified to obtain a second hybrid signature algorithm; the second hybrid signature algorithm includes a third national secret algorithm and a second quantum-resistant key signature algorithm; The second terminal separates the mixed signature in the current certificate to be verified according to the third national secret algorithm and the second quantum-resistant key signature algorithm to obtain a second national secret signature and a second quantum-resistant key signature; The second terminal determines the public key of the third country's secret algorithm and the public key of the second quantum-resistant key signature algorithm in the public key of the root certificate or the upper-level certificate of the CA organization according to the third country's secret algorithm and the second quantum-resistant key signature algorithm; The second terminal verifies the second national secret signature using the public key of the third national secret algorithm in combination with the third national secret algorithm, and verifies the second quantum resistant key signature using the public key of the second quantum resistant key signature algorithm in combination with the second quantum resistant key signature algorithm, to obtain a signature authentication result of the current certificate to be verified; After the signature authentication of the current certificate to be verified passes, the second terminal collects the object identifier of the next node certificate of the current certificate to be verified in the second certificate chain, and returns to execute the step of the second terminal using the object identifier to parse the current certificate to be verified to obtain a second hybrid signature algorithm, until all certificates in the second certificate chain pass the verification, the second certificate chain is legal, and the first terminal is trustworthy.

11. The method according to claim 7, characterized in that The method further comprises: The second terminal obtains the first handshake message sent by the first terminal, and performs a hash operation on the received algorithm support list, the hybrid key exchange parameter, the first certificate request, and the first random number to obtain the second handshake message; the first handshake message is the algorithm support list, the hybrid key exchange parameter, the first certificate request, and the first random number provided by the first terminal, and the handshake message is obtained by performing a hash operation; The second terminal compares the first handshake message with the second handshake message; When the first handshake message is the same as the second handshake message, the second terminal performs a hash operation on the second certificate request, the target first certificate chain provided by the second terminal, the third public key provided by the second terminal, the target algorithm selected by the second terminal in the algorithm support list, the first encrypted random number provided by the second terminal, the second encrypted random number provided by the second terminal, and the ciphertext to obtain a third handshake message; The second terminal signs the second handshake message and the third handshake message using the third private key to obtain a signed handshake message; The second terminal uses the second handshake key to encrypt the signature handshake message and sends the encrypted signature handshake message to the first terminal; the first terminal uses the first handshake key to decrypt the encrypted signature handshake message, and uses the third public key provided by the second terminal to verify the signature of the decrypted signature handshake message.

12. The method according to claim 11, characterized in that The method further comprises: The second terminal generates a first session key according to the second handshake key, a second random number provided by the second terminal and a target key derivation algorithm selected by the second terminal in the algorithm support list; The second terminal generates a second session key according to the second handshake key, a third random number provided by the second terminal and the target key derivation algorithm.

13. The method according to claim 12, characterized in that After the second terminal generates a second session key according to the second handshake key, a third random number provided by the second terminal and the target key derivation algorithm, the method further includes: The first terminal obtains a first encrypted random number and a second encrypted random number provided by the second terminal; wherein the first encrypted random number is generated by the second terminal by encrypting the second random number provided by the second terminal according to the classical pre-key and the target national secret algorithm, and the second encrypted random number is generated by the second terminal by encrypting the third random number provided by the second terminal according to the quantum-resistant pre-key and the target quantum-resistant key encapsulation algorithm; The first terminal decrypts the first encrypted random number using the classic pre-key and the target national secret algorithm to obtain the second random number; The first terminal decrypts the second encrypted random number using the quantum-resistant pre-key and the target quantum-resistant key encapsulation algorithm to obtain the third random number; The first terminal generates the first session key according to the first handshake key, the second random number and the target key derivation algorithm; The first terminal generates the second session key according to the first handshake key, the third random number and the target key derivation algorithm.

14. A security authentication method, characterized in that: Applied to the second terminal, the method includes: Receive an algorithm support list, a key exchange parameter, a first random number, and a first certificate request sent by the first terminal, and generate a second handshake key and ciphertext by selecting a target algorithm matching the key exchange parameter from the algorithm support list and combining the hybrid key exchange parameter and the first random number; Sending a third public key provided by the second terminal, a target algorithm selected by the second terminal, and the ciphertext to the first terminal, so that the first terminal generates a first handshake key; Sending a target first certificate chain to a first terminal enables the first terminal to verify the target first certificate chain based on a first handshake key, wherein the target first certificate chain is a first certificate chain encrypted by a second handshake key and obtained from a second terminal according to the first certificate request.

15. A security authentication system, characterized in that: Applied to a first terminal and a second terminal, the system includes: The first terminal sends an algorithm support list, a hybrid key exchange parameter, a first random number, and a first certificate request to the second terminal; The second terminal receives the algorithm support list, the key exchange parameters, the first random number, and the first certificate request sent by the first terminal, and generates a second handshake key and ciphertext by selecting a target algorithm matching the key exchange parameters from the algorithm support list in combination with the hybrid key exchange parameters and the first random number; The second terminal sends a third public key provided by the second terminal, a target algorithm selected by the second terminal, and the ciphertext to the first terminal; The first terminal obtains a first handshake key by using a third public key provided by the second terminal and sent by the second terminal, a target algorithm selected by the second terminal, and the ciphertext; The first terminal verifies the target first certificate chain sent by the second terminal using the first handshake key, wherein the target first certificate chain is a first certificate chain encrypted by the second handshake key and obtained by the second terminal from the second terminal according to the first certificate request.

16. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores computer instructions, and the processor is configured to execute the computer instructions to perform the method according to any one of claims 1 to 14.

17. A storage medium, characterized in that: The storage medium stores computer instructions, and the computer instructions are configured to execute the method according to any one of claims 1 to 14 when executed.

Citation Information

Patent Citations

  • SSL communication method and device based on national cryptographic algorithm of hardware

    CN111740844A

  • Low-cost Internet of Things data encryption communication system

    CN112751668A

  • Data transmission method and device, terminal, server and storage medium

    CN113037484A

  • Key generation method and device and authentication end equipment

    CN114785486A

  • Quantum computing resistant digital signature method and system based on quantum communication service station

    CN114978518A

Cited By

  • Intelligent terminal security authentication method based on traffic shaping and multi-stage handshake negotiation

    CN122160186A

  • Intelligent terminal security authentication method based on traffic shaping and multi-stage handshake negotiation

    CN122160186B