Elliptic curve key secure storage method, terminal device and storage medium

By writing and expanding the elliptic curve key factor in the storage module of the vehicle terminal, the problems of high key storage cost and hardware dependence in the prior art are solved, and the security of the key is protected without increasing the hardware cost.

CN120110667APending Publication Date: 2025-06-06XIAMEN YAXON ZHILLAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311616693.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-28
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The prior art has high cost and hardware dependency in protecting secure storage of elliptic curve keys, especially in the absence of encryption chips or HSMs on the original devices.

Method used

By writing the symmetric key factor, random number and elliptic curve key factor in the storage module of the on-board terminal, and obtaining the extended public key and the extended private key through the key expansion function at startup, it is stored in the dynamic security calculation area for encryption and decryption operations.

Benefits of technology

It realizes the security of the key without increasing hardware costs, so that even if the key factor is acquired, the ciphertext data cannot be decrypted, and the original program and structure are not changed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110667A_ABST
    Figure CN120110667A_ABST
Patent Text Reader

Abstract

The invention relates to an elliptic curve secret key secure storage method, terminal equipment and a storage medium. The method comprises the following steps: programming a symmetric secret key factor, a random number and an elliptic curve secret key factor in a storage module of a vehicle-mounted terminal; when the vehicle-mounted terminal is started, the symmetric secret key factor, the random number and the elliptic curve secret key factor are extracted from the storage module, and a corresponding expansion public key and a corresponding expansion private key are obtained through a secret key expansion function and are stored in a dynamic security calculation area; and performing corresponding encryption and decryption operation in the dynamic security computing area by using the extended public key and the extended private key. According to the invention, even if the key factor stored locally is acquired, the corresponding ciphertext data cannot be decrypted, and meanwhile, the corresponding hardware cost does not need to be spent, so that the security of the key can be protected on the basis of not changing the original program and structure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle technology, and in particular to an elliptic curve key secure storage method, terminal equipment and storage medium. Background Art

[0002] In recent years, intelligent connected cars have opened a new chapter of rapid development. The general trend of intelligent and connected cars is irreversible. The security issues such as user data and privacy leakage and malicious attacks on intelligent systems have aroused widespread concern in society. Therefore, elliptic curve cryptographic algorithms are used to ensure the authenticity, integrity and confidentiality of user data and privacy data. However, the protection of elliptic curve keys should be taken seriously.

[0003] Today, the secure storage of keys is generally stored in encryption chips or HSM (hardware security module), but the use of encryption chips or HSM increases costs. At the same time, encryption chips or HSM may not exist on the original equipment, and modifying them will bring corresponding problems. Summary of the invention

[0004] In order to solve the above problems, the present invention proposes a method for securely storing an elliptic curve key, a terminal device and a storage medium.

[0005] The specific plan is as follows:

[0006] A method for securely storing an elliptic curve key comprises the following steps:

[0007] S1: Burn the symmetric key factor, random number and elliptic curve key factor into the storage module of the vehicle terminal;

[0008] S2: When the vehicle terminal is started, the symmetric key factor, random number and elliptic curve key factor are extracted from the storage module, and the corresponding extended public key and extended private key are obtained through the key extension function and stored in the dynamic security calculation area;

[0009] S3: Use the extended public key and extended private key to perform corresponding encryption and decryption operations in the dynamic security computing area.

[0010] Furthermore, the symmetric key factor and the random number are both 128 bits.

[0011] Furthermore, the public key factor in the elliptic curve key factor is the product of the base point of the elliptic curve and the private key factor in the elliptic curve key factor.

[0012] Furthermore, the storage module of the vehicle-mounted terminal adopts a flash memory.

[0013] Furthermore, the calculation formula for obtaining the corresponding extended public key B through the secret key extension function f is:

[0014] B=A+f(k,R INT )*G

[0015] Where A represents the public key factor in the elliptic curve key factor, k represents the symmetric key factor, and R INT Represents a random number in integer format, and G represents the base point of the elliptic curve.

[0016] Furthermore, the calculation formula for obtaining the corresponding extended private key b through the secret key extension function f is:

[0017] b=(a+f(k,R INT ))mod l

[0018] Where a represents the private key factor in the elliptic curve key factor, k represents the symmetric key factor, and R INT Represents a random number in integer format, l represents the order of the elliptic curve, and mod represents the modular operation.

[0019] Furthermore, the key expansion function f is expressed as:

[0020] f(k,R INT ) = y mod l

[0021] Among them, k represents the symmetric key factor corresponding to the symmetric encryption algorithm Symm, R INT Represents a random number in integer format, l represents the order of the elliptic curve, mod represents the modular operation; y represents temporary output, and its calculation formula is:

[0022] y=(Symm(k,1 128 ))||(Symm(k,R))||(Symm(k,0 128 ))

[0023] Among them, 1 128 Represents a bit string formed by repeating 1 128 times, 0 128 represents a bit string formed by repeating 0 128 times, and || represents a concatenated bit string.

[0024] An elliptic curve key secure storage terminal device comprises a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned method in an embodiment of the present invention when executing the computer program.

[0025] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method described above in an embodiment of the present invention are implemented.

[0026] The present invention adopts the above technical solution. Even if the key factor stored locally is obtained, the corresponding ciphertext data cannot be decrypted. At the same time, no corresponding hardware cost is required, and the security of the key can be protected without changing the original program and structure. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 Shown is a flow chart of Embodiment 1 of the present invention. DETAILED DESCRIPTION

[0028] To further illustrate various embodiments, the present invention provides drawings. These drawings are part of the disclosure of the present invention, which are mainly used to illustrate the embodiments and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these contents, ordinary technicians in this field should be able to understand other possible implementations and advantages of the present invention.

[0029] The present invention will now be further described with reference to the accompanying drawings and specific implementation methods.

[0030] Embodiment 1:

[0031] The embodiment of the present invention provides a method for securely storing elliptic curve keys. Figure 1 As shown, the method comprises the following steps:

[0032] S1: Burn the symmetric key factor k, random number R and elliptic curve key factor into the storage module of the vehicle terminal.

[0033] In this embodiment, the symmetric key factor k and the random number R are both 128-bit binary bit strings, which can be generated by a host computer. The storage module of the vehicle terminal uses a flash memory.

[0034] The elliptic curve key factors include a public key factor A and a private key factor a, where A=a*G, and G represents the base point of the elliptic curve.

[0035] By burning the secret key factor k, random number R and elliptic curve key factor into the storage module of the vehicle terminal, the attacker cannot crack the ciphertext data even if he obtains the data in the storage module.

[0036] S2: When the vehicle terminal is started, the symmetric key factor k, random number R and elliptic curve key factor are extracted from the storage module, and the corresponding extended public key B and extended private key b are obtained through the key extension function and stored in the dynamic security calculation area.

[0037] The dynamic security computing area is a computing area generated after the vehicle terminal is started, and the computing area is released after the vehicle terminal stops running, such as memory.

[0038] The key expansion function used in this embodiment is described as follows:

[0039] 1. The key expansion function is represented by f, and its parameters include three types: (1) Symmetric encryption algorithm

[0040] Symm, with 128-bit input and output and a 128-bit key, adopts a block cipher algorithm, and works in ECB / NoPadding mode; (2) a 128-bit key (called a secret key factor in this embodiment), used for encryption and decryption of the symmetric encryption algorithm Symm, represented as k of the function f; (3) a 256-bit integer l, representing the order of the base point of the elliptic curve for key derivation.

[0041] 2. The input of the function is a 128-bit integer R INT (In this embodiment, it is a random number) whose range is (0,2 128 -1).

[0042] 3. The output of the function is a 256-bit integer o in the range (0, l).

[0043] 4. The function process is as follows:

[0044] Create a temporary output y (for f) as follows: The output is a string of 3 x 128 = 384 bits.

[0045] y=(Symm(k,1 128 ))||(Symm(k,R))||(Symm(k,0 128 ))

[0046] The final output of f is as follows:

[0047] f(k,R INT ) = y mod l

[0048] The symbols are explained below:

[0049] (1) For a bit string a and a number n, a n represents the bit string formed by repeating the bit string a n times;

[0050] (2) For bit strings x and y, x||y represents the concatenated bit strings, for example, if x=0110 and y=1010, then x||y=01101010;

[0051] (3) For numbers m and n, m mod n represents the result of a modular operation on m with modulus n, for example: if m=11 and n=2, then m mod n=1.

[0052] Based on the above key extension function, the calculation formulas for setting the extended public key B and the extended private key b in this embodiment are respectively:

[0053] B=A+f(k,R INT )*G

[0054] b=(a+f(k,R INT ))mod l

[0055] Where A represents the public key factor in the elliptic curve key factor, k represents the symmetric key factor, and R INT Represents a random number in integer format, G represents the base point of the elliptic curve, and a represents the private key factor in the elliptic curve key factor.

[0056] S3: Use the extended public key and extended private key to perform corresponding encryption and decryption operations in the dynamic security computing area.

[0057] In actual use, the data that needs to be encrypted and decrypted can be transmitted to the dynamic security computing area, and after encryption and decryption using the extended public key and extended private key in the dynamic security computing area, the encryption and decryption results are output to the dynamic security computing area for use.

[0058] The embodiment of the present invention ensures the security of the key. Even if the key factor stored locally is obtained, the corresponding ciphertext data cannot be decrypted. At the same time, no corresponding hardware cost is required, and the security of the key can be protected without changing the original program and structure.

[0059] Embodiment 2:

[0060] The present invention also provides an elliptic curve key security storage terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps in the above-mentioned method embodiment of the first embodiment of the present invention when executing the computer program.

[0061] Further, as an executable solution, the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the elliptic curve key security storage terminal device, and uses various interfaces and lines to connect various parts of the entire elliptic curve key security storage terminal device.

[0062] The memory can be used to store the computer program and / or module, and the processor realizes various functions of the elliptic curve key security storage terminal device by running or executing the computer program and / or module stored in the memory, and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required for a function; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0063] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method in the embodiment of the present invention are implemented.

[0064] If the module / unit integrated in the elliptic curve key security storage terminal device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device that can carry the computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-OnlyMemory), random access memory (RAM, Random Access Memory) and software distribution medium, etc.

[0065] Although the present invention has been specifically shown and described in conjunction with the preferred embodiments, it should be understood by those skilled in the art that various changes may be made to the present invention in form and details without departing from the spirit and scope of the present invention as defined by the appended claims, all of which are within the scope of protection of the present invention.

Claims

1. A secure storage method for elliptic curve keys, It is characterized in that The following steps are involved: S1: Burn the symmetric key factor, random number and elliptic curve key factor into the storage module of the vehicle terminal; S2: When the vehicle terminal is started, the symmetric key factor, random number and elliptic curve key factor are extracted from the storage module, and the corresponding extended public key and extended private key are obtained through the key extension function and stored in the dynamic security calculation area; S3: Use the extended public key and extended private key to perform corresponding encryption and decryption operations in the dynamic security computing area.

2. The method for securely storing elliptic curve keys according to claim 1, Features: The symmetric key factor and random number are both 128 bits.

3. The method for securely storing elliptic curve keys according to claim 1, Features: The public key factor in the elliptic curve key factor is the product of the base point of the elliptic curve and the private key factor in the elliptic curve key factor.

4. The method for securely storing elliptic curve keys according to claim 1, Features: The storage module of the vehicle terminal adopts flash memory.

5. The method for securely storing elliptic curve keys according to claim 1, Features: The calculation formula for obtaining the corresponding extended public key B through the secret key extension function f is: B=A+f(k,R INT )*G Where A represents the public key factor in the elliptic curve key factor, k represents the symmetric key factor, and R INT Represents a random number in integer format, and G represents the base point of the elliptic curve.

6. The method for securely storing elliptic curve keys according to claim 1, Features: The calculation formula for obtaining the corresponding extended private key b through the secret key extension function f is: b=(a+f(k,R INT ))mod l Where a represents the private key factor in the elliptic curve key factor, k represents the symmetric key factor, and R INT Represents a random number in integer format, l represents the order of the elliptic curve, and mod represents the modular operation.

7. The method for securely storing elliptic curve keys according to claim 1, Features: The key expansion function f is expressed as: f(k,R INT )=y mod l Among them, k represents the symmetric key factor corresponding to the symmetric encryption algorithm Symm, R INT Represents a random number in integer format, l represents the order of the elliptic curve, mod represents the modular operation; y represents temporary output, and its calculation formula is: y=(Symm(k,1 128 ))||(Symm(k,R))||(Symm(k,0 128 )) Among them, 1 128 Represents a bit string formed by repeating 1 128 times, 0 128 represents a bit string formed by repeating 0 128 times, and || represents a concatenated bit string.

8. An elliptic curve key secure storage terminal device, Features: The method comprises a processor, a memory and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 7 when executing the computer program.

9. A computer-readable storage medium storing a computer program. Features: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.