Hybrid encryption communication method applied to mobile communication network and IP bearer network hierarchical system
By adopting a hybrid encrypted communication method in the mobile communication network and the IP bearer network, and using the combination of SM2, SM3 and SM4 algorithms, the risks of leakage and tampering during data transmission are solved, data confidentiality and integrity are achieved, the identity verification of both parties of the communication is enhanced, and the security of the system is improved.
Patent Information
- Application Number
- CN202510304976.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-05-13
AI Technical Summary
The lack of encryption and authentication technology based on national standards in the mobile communication network and IP bearer network, resulting in the risk of data leakage and tampering during transmission, and the identity of both parties to the communication cannot be effectively verified.
The hybrid encryption communication method is adopted to realize the encrypted transmission and authentication of data through the combination of offline preset keys, SM2, SM3 and SM4 algorithms. Specific steps include offline key exchange of first-level systems and second-level systems, encryption and signature of service request and response messages, as well as message verification and key destruction.
It effectively protects the confidentiality and integrity of data during transmission, reduces the risk of man-in-the-middle attacks, enhances the identity verification of both parties in the communication, and improves the overall security of the system.
Smart Images

Figure CN119996053A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of broadband network construction, and is particularly suitable for a hybrid encryption communication method applied to a mobile communication network and an IP bearer network hierarchical system. Background Art
[0002] With the development of mobile communication technology, the data traffic carried by mobile communication networks and IP bearer networks is increasing, and the services and applications involved are becoming more and more complex. These services and applications contain a large amount of key information, such as user data, control information, business information, etc. The leakage or tampering of data may lead to serious security risks, especially for key information in enterprises, governments, finance and other industries.
[0003] At present, most encryption transmission solutions in mobile communication networks and IP bearer networks are based on international standards (such as AES, RSA, etc.), and there is no encryption and authentication technology based on national standards.
[0004] Compared with traditional international algorithms, national encryption algorithms can better meet national security standards and adapt to the diverse needs of local network environments. Therefore, how to integrate national encryption algorithms into the security framework of mobile communication networks and IP bearer networks to ensure that data can be effectively protected from generation, transmission to storage is an important topic in this field.
[0005] At the same time, in the existing technology, the mobile communication network and the IP bearer network do not involve verification of the identities of the communicating parties, which may lead to man-in-the-middle attacks, allowing attackers to impersonate one party to communicate with the other party and obtain sensitive information; and fail to verify data integrity, resulting in data being tampered with without being discovered during transmission. Summary of the invention
[0006] The present invention aims to provide a hybrid encryption communication method applied to mobile communication network and IP bearer network hierarchical system, aiming to solve the security protection problem of the whole process from generation, transmission to storage of data in mobile communication network and IP bearer network hierarchical system.
[0007] To achieve the above object, the present invention adopts the following technical solutions: The hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system of the present invention comprises the following steps: S1, offline pre-set key; the primary system generates SM2 key pairs and distributes public keys to each secondary system offline; each secondary system generates SM2 key pairs and reports public keys to the primary system offline; the primary and secondary systems use offline key exchange to distribute initial keys and establish trust. The offline key exchange method avoids the risk of transmitting keys through online channels and reduces the possibility of being attacked by a man-in-the-middle.
[0008] S2, the primary system sends a service request message to the secondary system; the service request message includes an SM4 key and an SM4 key digest randomly generated by the primary system; the SM4 key is encrypted by the secondary system SM2 public key; the SM4 key digest is signed by the primary system SM2 private key; S3, the primary system obtains a service response message from the secondary system; the service response message includes a service response message summary; the service response message summary uses the secondary system SM2 private key to sign the service response message summary, embeds the service response message tag, and uses the SM4 key to encrypt the service response message; S4, after the message is verified, the primary system and the secondary system clear the SM4 key. The communicating parties will immediately destroy the SM4 temporary key in the memory after completing this session. The temporary key is only valid during the session and is destroyed after the session ends to prevent key leakage and abuse.
[0009] Furthermore, in step S2, after receiving the service request message, the secondary system uses the secondary system SM2 private key to decrypt the SM4 key; uses the primary system SM2 public key to decrypt the SM4 key summary; and determines data security by verifying the integrity of the SM4 key summary.
[0010] Further, in step S2, the SM4 key is embedded in the service request message <seckey>Tag, the SM4 key digest is embedded in the service request message <signature>Label.
[0011] Furthermore, in step S3, after receiving the service response message, the primary system uses the SM4 key to decrypt the service response message; uses the secondary system SM2 public key to decrypt the service response message summary; and verifies the integrity of the service response message summary to determine data security. The message integrity during transmission can be verified through the digital signature mechanism. In key exchange, data transmission and response, all important information will be digitally signed with a private key, and the recipient will use the corresponding public key to verify the signature to ensure that the data has not been tampered with during transmission.
[0012] Furthermore, in step S2, the SM4 key summary is obtained by calculation using the SM3 algorithm.
[0013] Furthermore, the service response message summary is obtained by calculation using an SM3 algorithm.
[0014] Furthermore, the primary system provides feedback on business processing results to the secondary system managers, including the execution results of business requests, data verification status, and message transmission integrity, so that managers can take timely measures when transmission errors or potential security issues occur, and track and repair problems.
[0015] The advantages of the present invention include the following aspects: 1. The primary and secondary systems use offline key exchange to distribute the initial key and establish trust. This offline key exchange method avoids the risk of transmitting keys through online channels and reduces the possibility of being attacked by a man-in-the-middle.
[0016] 2. The introduction of a digital signature mechanism can verify the integrity of messages during transmission, ensure that data has not been tampered with during transmission, enhance the identity authentication of both parties in communication, and improve the overall security of the system.
[0017] 3. The primary system provides real-time feedback of business processing results to managers of the secondary system, allowing managers to take timely measures, track and repair problems when transmission errors or potential security issues occur.
[0018] 4. The present invention selects different encryption algorithms according to different security requirements, and uses SM2, SM3, and SM4 encryption in combination, which can simultaneously achieve data confidentiality, integrity, and authentication, significantly enhancing the performance and security of the entire data transmission process.
[0019] 5. The present invention will immediately destroy the SM4 temporary key in the memory after the communication parties complete the current session. The temporary key is only valid during the session and is destroyed after the session ends, effectively preventing the key from being leaked and abused. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 The present invention is a schematic diagram of the hybrid encryption communication method process applied to mobile communication networks and IP bearer network hierarchical systems.
[0021] Figure 2 This is a schematic diagram of the primary system encryption described in the present invention.
[0022] Figure 3 This is a schematic diagram of decryption of the secondary system of the present invention.
[0023] Figure 4 This is a schematic diagram of the secondary system encryption of the present invention.
[0024] Figure 5 This is a schematic diagram of the first-level system decryption of the present invention. DETAILED DESCRIPTION
[0025] The technical solutions in the embodiments of the present invention are described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0026] like Figure 1 As shown, the hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system of the present invention comprises the following steps: S1, offline pre-set key. The primary system and the secondary system exchange SM2 public keys offline. The primary system generates SM2 key pairs and distributes public keys to each secondary system offline. Each secondary system generates SM2 key pairs and reports public keys offline to the primary system for storage. Using offline key exchange to distribute initial keys and establish trust effectively avoids the risk of transmitting keys through online channels and reduces the possibility of being attacked by a man-in-the-middle.
[0027] S2, when the secondary system administrator sends a service request corresponding to the secondary system in the primary system, the primary system will send a service request message to the secondary system. The service request message includes the SM4 key and SM4 key summary randomly generated by the primary system; the SM4 key is encrypted by the secondary system SM2 public key; the SM4 key summary is signed by the primary system SM2 private key. The specific process is: The primary system randomly generates a 128-bit SM4 symmetric key (SM4Key), and obtains the digest value (SM4Digest) of the SM4 symmetric key through the SM3 encryption algorithm. The SM4 key is encrypted using the stored secondary platform SM2 public key (2_SM2PuKey) to obtain the encrypted SM4 key (SM4_SM2coding), and the SM4 symmetric key digest value is generated using the primary system's SM2 private key (1_SM2PrKey) to generate a digital signature (SM4_Signature). The encrypted SM4 key (SM4_SM2coding) and digital signature (SM4_Signature) are placed in the service request message's label. <seckey>Label, <signature>Tags are sent to secondary systems.
[0028] S3, after the secondary system receives the service request message, first, it uses the secondary system SM2 private key to decrypt the SM4 key; uses the primary system SM2 public key to decrypt the SM4 key summary; and verifies the integrity of the SM4 key summary to determine data security. That is, the SM4 key (SM4_SM2coding) is decrypted with the secondary system SM2 private key (2_SM2PrKey), and the digital signature (SM4_Signature) is decrypted with the primary system SM2 public key (1_SM2PuKey) to obtain the signature to be verified (SM4_Signature_V), and then the SM3 encryption algorithm is used to obtain the summary value (SM4Digest_V) of the SM4 symmetric key (SM4Key) and compare it with the signature to be verified (SM4_Signature_V) to verify the signature, confirming that the SM4 key has not been modified during the transmission process. Through the digital signature mechanism, the message integrity during the transmission process can be verified. In key exchange, data transmission and response, all important information (such as the summary value of the SM4 temporary key) will be digitally signed by the SM2 private key. The recipient uses the corresponding public key to verify the signature to ensure that the data has not been tampered with during transmission.
[0029] Then, the secondary system organizes the business response message and sends it to the primary system. The business response message includes a business response message summary; the business response message summary uses the secondary system SM2 private key to sign the business response message summary, embeds the business response message label, and uses the SM4 key to encrypt the business response message. That is, the secondary system generates a summary (2_Me_Digest) from the business response message (2_Message) through the SM3 encryption algorithm, and uses the secondary system SM2 private key (2_SM2PrKey) to encrypt the summary of the business response message to generate a digital signature (2_Me_Signature). The digital signature is stored in the label, and the content in the label is encrypted using the previous 128-bit SM4 key algorithm and sent to the primary system.
[0030] S4, after the message is verified, the primary system and the secondary system clear the SM4 key.
[0031] After receiving the service response message, the primary system uses the SM4 key to decrypt the service response message; uses the secondary system SM2 public key to decrypt the service response message digest; and verifies the integrity of the service response message digest to determine data security. That is, after receiving the service response message (2_Message_coding), the primary system uses the SM4 symmetric key (SM4Key) to parse the service response message content and obtain the service response message civilized text (2_Message_encoded). The secondary system SM2 public key (2_SM2PuKey) is used to decrypt the digital signature (2_Me_Signature) of the service response message digest to obtain the service response message digest (2_Me_Digest_V). The parsed service response message civilized text (2_Message_encoded) is calculated by the SM3 encryption algorithm to obtain the verification digest (2_Me_Signature_V) and compared with the parsed digest (2_Me_Digest_V) to confirm that the service response message has not been tampered with during transmission. After the communicating parties complete the conversation, the primary system and the secondary system will immediately clear the SM4 temporary key in the memory to eliminate the risk of key reuse.
[0032] During the entire process, the primary system returns the business request execution results and integrity verification status to the administrator interface, including business request execution results, data verification status, message transmission integrity and other information, completing the closed-loop business process. This mechanism ensures that administrators can take timely measures when transmission errors or potential security issues occur, and track and repair problems.
[0033] like Figure 2 As shown, the process of encrypting the service request message of the first-level system of the present invention is demonstrated. The first-level system generates a 128-bit SM4 symmetric key (SM4Key) through the SM4 random key generation module, and the SM4 key is stored in the SM4 key register and saved in the first-level system. At the same time, it enters the SM2 encryption module through the input interface, and uses the second-level platform SM2 public key (2_SM2PuKey) stored in the SM2 key register to encrypt the SM4 key to obtain the encrypted SM4 key (SM4_SM2coding); the summary value (SM4Digest) of the SM4 symmetric key obtained by the SM3 encryption algorithm enters the SM2 encryption module, and is signed with the first-level platform SM2 private key stored in the SM2 key register. Finally, the encrypted SM4 key (SM4_SM2coding) is put into the service request message together with the summary value of the SM4 symmetric key signed by the first-level platform SM2 private key. <seckey>Label, <signature>Label output.
[0034] like Figure 3 As shown, the process of decrypting the service request message and verifying the integrity of the service request message by the secondary system of the present invention is shown. After the secondary system receives the service request message, the service request message enters the SM2 decryption module, and takes out the secondary system SM2 private key from the SM2 key storage module to decrypt the SM4 key; at the same time, the primary system SM2 public key in the SM2 key storage module is taken out to decrypt the SM4 key summary. The decrypted SM4 key and the SM4 key summary are temporarily stored in the SM4 key temporary storage register. The decrypted SM4 key obtains the summary value (SM4Digest_V) of the SM4 symmetric key (SM4Key) in the SM3 decryption module. The summary value (SM4Digest_V) is compared with the SM4 key summary decrypted in the SM4 key temporary storage register. If they are not the same, an alarm prompt is issued. If the two are the same, the SM4 key in the SM4 key temporary storage register is stored in the SM4 key register, and a data message feedback signal is output. Then the secondary system organizes the service response message according to the data message feedback signal and sends it to the primary system.
[0035] like Figure 4 As shown, the process of encrypting and generating a business response message by the secondary system of the present invention is demonstrated. After receiving the data message feedback signal, the secondary system organizes the business response message. The business response message first enters the SM3 encryption module to generate a digest (2_Me_Digest) of the business response message (2_Message), and takes out the secondary system SM2 private key (2_SM2PrKey) from the SM2 key register to encrypt the digest of the business response message to generate a digital signature (2_Me_Signature). After the digest of the signed business response message is embedded in the business response message label, it enters the SM4 encryption module, and is encrypted as a whole using the SM4 key in the SM4 key register and then output.
[0036] like Figure 5 As shown, the process of decrypting the business response message and verifying its integrity by the first-level system of the present invention is demonstrated. After the business response message enters the first-level system, the SM4 decryption module uses the key in the SM4 key register to complete the parsing of the business response message. The civilized text (2_Message_encoded) of the business response message is stored in the data plaintext temporary storage register, and the decryption of the business response message digest (2_Me_Digest_V) is completed in the SM2 decryption module. The civilized text (2_Message_encoded) of the business response message is recalculated in the SM3 decryption module. The digest (2_Me_Signature_V) is compared with (2_Me_Digest_V). If they are not the same, an alarm prompt is issued. If the two are the same, the business response message in the data plaintext temporary storage register is stored in the data plaintext register and output. After the communicating parties complete this session, the first-level system and the second-level system will immediately clear the SM4 temporary key in the memory to eliminate the risk of key reuse.
[0037] In the hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system described in the present invention, a hybrid encryption method of SM2, SM3 and SM4 is adopted. Working together in a single session, different encryption algorithms are selected for different security requirements, and SM2, SM3 and SM4 are integrated and applied according to the load balancing strategy of first summary and then signature, first encryption and then encapsulation, and cryptographic service module. In the response data transmission stage, the response data double insurance mechanism of SM4 ciphertext protection + SM2 signature traceability is adopted, and in the key transmission stage, the double factor verification of SM2 decryption verification + SM3 summary comparison is adopted, and the positioning rules of the message SECKEY and SIGNATURE fields under the HEAD tag and the multiple protection of SM4 content encryption + SM3 summary nesting under the BODY tag are combined to realize the binding of the message label level and the encryption component, and the confidentiality, integrity and authentication security of the data. Compared with a single encryption method, the use of a hybrid encryption method can maximize the performance and security of the system, especially in critical information infrastructure systems, and can effectively prevent various potential security threats.< / signature> < / seckey> < / signature> < / seckey> < / signature> < / seckey>
Claims
1. A hybrid encryption communication method applied to a mobile communication network and an IP bearer network hierarchical system, characterized in that: The following steps are involved: S1, offline pre-set key; The primary system generates SM2 key pairs and distributes public keys offline to each secondary system; Each secondary system generates an SM2 key pair and reports the public key to the primary system offline; S2, the primary system sends a service request message to the secondary system; the service request message includes an SM4 key and an SM4 key digest randomly generated by the primary system; the SM4 key is encrypted by the secondary system SM2 public key; the SM4 key digest is signed by the primary system SM2 private key; S3, the primary system obtains a service response message from the secondary system; the service response message includes a service response message summary; the service response message summary uses the secondary system SM2 private key to sign the service response message summary, embeds the service response message tag, and uses the SM4 key to encrypt the service response message; S4, after the message is verified, the primary system and the secondary system clear the SM4 key.
2. According to claim 1, a hybrid encryption communication method applied to a mobile communication network and an IP bearer network hierarchical system, characterized in that: In step S2, after receiving the service request message, the secondary system uses the secondary system SM2 private key to decrypt the SM4 key; uses the primary system SM2 public key to decrypt the SM4 key summary; and determines data security by verifying the integrity of the SM4 key summary.
3. The hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system according to claim 1, characterized in that: In step S2, the SM4 key is embedded in the service request message. <seckey>Tag, the SM4 key digest is embedded in the service request message <signature> Label.< / signature> < / seckey> 4. The hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system according to claim 1, characterized in that: In step S3, after receiving the service response message, the primary system uses the SM4 key to decrypt the service response message; Use the secondary system SM2 public key to decrypt the business response message summary; determine data security by verifying the integrity of the business response message summary.
5. The hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system according to claim 1, characterized in that: In step S2, the SM4 key digest is calculated and obtained by the SM3 algorithm.
6. The hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system according to claim 4, characterized in that: The service response message summary is obtained by calculation using the SM3 algorithm.
7. The hybrid encryption communication method applied to the mobile communication network and IP bearer network hierarchical system according to claim 1, characterized in that: The primary system feeds back service processing results to the secondary system managers, including the execution results of business requests, data verification status, and integrity of message transmission.