Digital certificate issuing method based on post-quantum hybrid algorithm and related device
By using post-quantum hybrid algorithm in the issuance of digital certificates, a hybrid public and private key is generated, and a hybrid key signature certificate and a hybrid key encapsulation certificate are issued, the easy-to-break problem of traditional encryption algorithms in front of quantum computers is solved, and the anti-quantum security and legality of certificates are realized.
Patent Information
- Application Number
- CN202510235699.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-02-28
AI Technical Summary
Traditional public key encryption algorithms are easily cracked in front of quantum computers, resulting in the risk of existing secure communication and digital signature protocols being cracked. In addition, traditional certificates do not contain post-quantum cryptography public keys, which cannot effectively verify the quantum algorithm-resistant public keys, and are easily attacked by man-in-the-middle.
The digital certificate issuance method based on post-quantum hybrid algorithm is adopted, and a hybrid public and private key is formed by generating the public and private keys of the asymmetric encryption algorithm, the public and private keys of the post-quantum key signature algorithm, and the public and private keys of the post-quantum key packaging algorithm, which is used to issue a hybrid key signature certificate and a hybrid key packaging certificate to ensure the legality and security of the certificate in quantum algorithm-resistant scenarios.
The legal use of certificates and the improvement of information security in quantum algorithm scenarios have been achieved, ensuring the anti-quantum cracking ability of certificates and reducing the risk of man-in-the-middle attacks.
Smart Images

Figure CN120110677A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of post-quantum cryptography technology, and in particular to a digital certificate issuance method based on a post-quantum hybrid algorithm and related devices. Background Art
[0002] The development of quantum computing poses a huge potential threat to traditional encryption algorithms. The mathematical problems that traditional public key encryption algorithms such as RSA (Rivest-Shamir-Adleman) and ECC (Elliptic Curve Cryptography) rely on may become easy to solve in the face of quantum computers. Once quantum computers reach sufficient computing power, the encryption systems based on these algorithms that are currently widely used will face the risk of being cracked. For example, the encryption key of the RSA algorithm may be quickly decomposed in a quantum computing environment, resulting in the loss of confidentiality of encrypted data. This means that many existing secure communications, digital signatures, and key exchange protocols need to be re-examined and improved to meet the challenges of the quantum computing era.
[0003] Post-Quantum Cryptography Post-Quantum Cryptography (PQC) provides an effective solution to the threat of quantum computing to traditional encryption algorithms. PQC is based on some new mathematical problems that still have high security in the face of quantum computers. The main advantage of PQC is that it can provide reliable encryption protection in the era of quantum computing. Unlike traditional encryption algorithms, the security of PQC algorithms does not rely on mathematical problems that are easily cracked under quantum computers. For example, lattice-based cryptography, coding-based cryptography, and multivariate polynomial-based cryptography are all important research directions in PQC. However, the traditional public key certificate does not contain the public key of the PQC algorithm. In the scenario of using a classical + anti-quantum hybrid algorithm, the public key of the anti-quantum algorithm used cannot be verified, which is vulnerable to man-in-the-middle attacks. Summary of the invention
[0004] The embodiments of the present application provide a digital certificate issuance method and related devices based on a post-quantum hybrid algorithm, which can realize the issuance of hybrid key signature certificates and hybrid key encapsulation certificates, ensure the legal use of certificates in anti-quantum algorithm scenarios, and improve information security.
[0005] A first aspect of an embodiment of the present application provides a method for issuing a digital certificate based on a post-quantum hybrid algorithm, which is applied to a user terminal. The method includes:
[0006] Generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm;
[0007] Using the first public key and the second public key as a mixed public key, and generating a certificate signing request according to the mixed public key and user identification information;
[0008] Sending the certificate signing request and the third public key to a certificate authority terminal;
[0009] Receive a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key;
[0010] Decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain a hybrid key encapsulation private key;
[0011] The hybrid key signing certificate and the hybrid key encapsulation certificate are installed, and the hybrid key signing certificate and the hybrid key encapsulation certificate are bound to the hybrid key encapsulation private key, the first private key, and the second private key.
[0012] Optionally, the receiving a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key includes:
[0013] Receive a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key sent by the certificate authority terminal; the hybrid key signature certificate is generated by the certificate authority terminal using its own hybrid signature private key to sign the certificate signing request after successfully verifying the user identification information; the hybrid key encapsulation certificate is generated by the certificate authority terminal using its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information; the encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal using a symmetric key to encrypt the hybrid key encapsulation private key, and the key encapsulation ciphertext and the symmetric key are obtained by the certificate authority terminal using the first public key and the third public key to perform a key encapsulation operation; the hybrid key encapsulation public key includes a fourth public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth public key generated according to the post-quantum key encapsulation algorithm, and the hybrid key encapsulation private key includes a fourth private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth private key generated according to the post-quantum key encapsulation algorithm.
[0014] Optionally, decrypting the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key includes:
[0015] Performing a key decapsulation operation on the key-encapsulation ciphertext according to the first private key and the third private key to obtain the symmetric key;
[0016] The encrypted hybrid key-encapsulated private key is decrypted using the symmetric key to obtain the hybrid key-encapsulated private key.
[0017] Optionally, binding the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key, and the second private key includes:
[0018] The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the fourth private key and the fifth private key.
[0019] Optionally, the method further includes:
[0020] Install the intermediate certificate. If the certificate authority terminal is a root certificate authority terminal, the intermediate certificate is issued by the root certificate authority terminal. If the certificate authority terminal is not a root certificate authority terminal, the intermediate certificate is issued by the upper-level certificate authority terminal.
[0021] A second aspect of an embodiment of the present application provides a method for issuing a digital certificate based on a post-quantum hybrid algorithm, which is applied to a certificate authority terminal, and the method includes:
[0022] Receiving a certificate signing request and a third public key sent by a user terminal, wherein the certificate signing request is generated by the user terminal according to a hybrid public key and user identification information, the third public key is generated by the user terminal according to a post-quantum key encapsulation algorithm, and the hybrid public key includes a first public key generated by the user terminal according to an asymmetric encryption algorithm and a second public key generated according to a post-quantum key signature algorithm;
[0023] A hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key are generated according to the certificate signing request and the third public key, and sent to the user terminal, so that the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulation private key, and installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key corresponding to the second public key.
[0024] Optionally, generating a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key includes:
[0025] After the user identification information is successfully verified, the certificate signing request is signed using its own hybrid signature private key to generate a hybrid key signature certificate;
[0026] Generate a fourth public key and a fourth private key according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key generated according to the post-quantum key encapsulation algorithm;
[0027] Using the fourth public key and the fifth public key as a mixed key to encapsulate a public key, and using the fourth private key and the fifth private key as a mixed key to encapsulate a private key;
[0028] Use its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information to generate a hybrid key encapsulation certificate;
[0029] Perform a key encapsulation operation using the first public key and the third public key to obtain a key encapsulation ciphertext and a symmetric key;
[0030] The hybrid key encapsulation private key is encrypted using the symmetric key to obtain an encrypted hybrid key encapsulation private key.
[0031] Optionally, the user terminal performs a key decapsulation operation on the key-encapsulation ciphertext according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key-encapsulation private key to obtain the hybrid key-encapsulation private key.
[0032] Optionally, the user terminal binds the hybrid key signing certificate to a second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the fourth private key and the fifth private key.
[0033] A third aspect of the embodiment of the present application provides a digital certificate issuance device based on a post-quantum hybrid algorithm, which is applied to a user terminal, and the device includes:
[0034] A key generation unit, configured to generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm;
[0035] a key processing unit, configured to use the first public key and the second public key as a hybrid public key, and to generate a certificate signing request according to the hybrid public key and user identification information;
[0036] An information generating unit, used for sending the certificate signing request and the third public key to a certificate authority terminal;
[0037] An information receiving unit is used to receive a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key;
[0038] an information decryption unit, configured to decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key;
[0039] The certificate installation unit is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key and the second private key.
[0040] A fourth aspect of the embodiments of the present application provides a digital certificate issuance device based on a post-quantum hybrid algorithm, which is applied to a certificate authority terminal, and the device includes:
[0041] an information receiving unit, configured to receive a certificate signing request and a third public key sent by a user terminal, wherein the certificate signing request is generated by the user terminal according to a hybrid public key and user identification information, the third public key is generated by the user terminal according to a post-quantum key encapsulation algorithm, and the hybrid public key includes a first public key generated by the user terminal according to an asymmetric encryption algorithm and a second public key generated according to a post-quantum key signature algorithm;
[0042] An information generation unit is used to generate a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key, and send them to the user terminal, so that the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulation private key, and install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key corresponding to the second public key.
[0043] A fifth aspect of the embodiments of the present application provides an electronic device, including: a processor and a memory;
[0044] The processor is connected to the memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program to execute the method in the first aspect or the second aspect of the embodiment of the present application.
[0045] A sixth aspect of an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. The computer program includes program instructions. When the program instructions are executed by a processor, the method in the first aspect or the second aspect of the embodiment of the present application is executed.
[0046] In an embodiment of the present application, a user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, generates a second public key and a second private key according to a post-quantum key signature algorithm, and generates a third public key and a third private key according to a post-quantum key encapsulation algorithm; uses the first public key and the second public key as a hybrid public key, and generates a certificate signing request according to the hybrid public key and user identification information; sends the certificate signing request and the third public key to a certificate authority terminal; the certificate authority terminal generates a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key; and sends them to the user terminal; the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key; installs a hybrid key signing certificate and a hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key, so that the issuance of the hybrid key signing certificate and the hybrid key encapsulation certificate can be realized, thereby ensuring the legal use of certificates in anti-quantum algorithm scenarios and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, and also provides anti-quantum level security protection for the private key distribution process. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0048] Figure 1 A schematic diagram of the operating environment of a digital certificate issuance method based on a post-quantum hybrid algorithm provided by an embodiment of the present application is shown;
[0049] Figure 2 A schematic diagram of a process for issuing a digital certificate based on a post-quantum hybrid algorithm provided by an embodiment of the present application is shown;
[0050] Figure 3 A schematic diagram of a process for issuing a digital certificate based on a post-quantum hybrid algorithm provided by another embodiment of the present application is shown;
[0051] Figure 4 A schematic diagram of a process for issuing a digital certificate based on a post-quantum hybrid algorithm provided by another embodiment of the present application is shown;
[0052] Figure 5 A schematic diagram of the structure of a digital certificate issuing device based on a post-quantum hybrid algorithm provided by an embodiment of the present application is shown;
[0053] Figure 6 A schematic diagram of the structure of a digital certificate issuing device based on a post-quantum hybrid algorithm provided by another embodiment of the present application is shown;
[0054] Figure 7 A schematic diagram of the structure of a computer device provided in one embodiment of the present application is shown. DETAILED DESCRIPTION
[0055] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0056] Please refer to Figure 1, which shows a schematic diagram of the operating environment of a digital certificate issuance method based on a post-quantum hybrid algorithm provided by an embodiment of the present application. The operating environment may include: a user terminal 10 and a certificate authority (CA) terminal 20.
[0057] The user terminal 10 includes but is not limited to electronic devices such as mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, game consoles, e-book readers, multimedia playback devices, wearable devices, etc. The terminal 10 may be installed with a client of an application program.
[0058] CA terminal 20 is a third-party terminal responsible for managing and issuing certificates. It has sufficient authority and is trusted and recognized by all industries and the public. The functions of CA terminal 20 include: verifying whether the website is credible (for HTTPS), generating and keeping the root certificate file (ca.crt) and the private key file (ca.key) corresponding to the root certificate.
[0059] The relationship between the user terminal 10 and the CA terminal 20 is as follows: the user terminal 10 will have a trust store, which stores the CAs trusted by the user terminal 10. The certificate of the user terminal 10 is signed by the CA on the leaf of the certificate tree. The end user's certificate is signed by the certificate authority on the leaf of the tree, and each certificate authority also has a certificate signed by the parent certificate authority.
[0060] Optionally, the user terminal 10 and the CA terminal 20 can communicate with each other via the network 30. The user terminal 10 and the CA terminal 20 can be directly or indirectly connected via wired or wireless communication, which is not limited in the present application.
[0061] Please refer to Figure 2 , which shows a flow chart of a method for issuing a digital certificate based on a post-quantum hybrid algorithm provided by an embodiment of the present application. The method can be applied to a computer device, which refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 The user terminal 10 shown. The method may include the following steps:
[0062] Step 201: Generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm.
[0063] Among them, asymmetric encryption algorithm is an encryption method that requires two keys: a public key (referred to as public key pk) and a private key (referred to as private key sk). These two keys are different, but mathematically related. In asymmetric encryption, the public key is used to encrypt data, and only the corresponding private key can decrypt it. Similarly, when a private key is used for digital signature, only the corresponding public key can verify the validity of the signature. Common asymmetric encryption algorithms include RSA algorithm, ECC algorithm, national secret algorithm, etc.
[0064] Among them, digital signatures in post-quantum algorithms are a type of modern public key cryptographic digital signatures that can resist known quantum computing attacks. Currently, NIST has selected a variety of post-quantum digital signature algorithms, such as Dilithium, Falcon, SPHINCS+, Rainbow, etc.
[0065] Among them, the post-quantum key encapsulation algorithm is a new encryption algorithm developed to resist the threat of quantum computers to the currently widely used public key cryptographic systems. For example, the Kyber algorithm is a key encapsulation mechanism that meets the security of IND-CCA2. Its security depends on the difficulty of the MLWE problem and is constructed using a two-stage method. The SIKE algorithm is a PQC algorithm that implements post-quantum key encapsulation based on the Supersingular Isogeny Diffie-Hellman (SIDH) key exchange protocol.
[0066] Step 202: Use the first public key and the second public key as a mixed public key, and generate a certificate signing request according to the mixed public key and user identification information.
[0067] Among them, the Certificate Signing Request (CSR) is a file generated by an entity applying for a certificate (such as the user terminal 10 in this application), which contains the applicant's public key and user identification information, and the user identification information is used to indicate the user's identity, such as country / region code, organization name, organizational unit, common name, etc. CSR is mainly used to request a signature from a certificate authority (CA) during the digital certificate authentication process in order to obtain a trusted digital certificate.
[0068] Step 203: Send the certificate signing request and the third public key to a certificate authority terminal.
[0069] Step 204: Receive the hybrid key signing certificate, hybrid key encapsulation certificate, key encapsulation ciphertext and encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key.
[0070] Among them, digital certificates can be divided into signature certificates and encryption certificates. Signature certificates are used to sign user information to ensure the validity and non-repudiation of information, such as mixed key signature certificates that include more than one key; encryption certificates are used to encrypt user transmitted information to ensure the confidentiality and integrity of information, such as mixed key encapsulation certificates that include more than one key. Symmetric keys are encryption keys used in symmetric encryption algorithms. In symmetric encryption, the same key is used for encryption and decryption.
[0071] Specifically, the receiving the hybrid key signing certificate, the hybrid key encapsulation certificate, the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key includes:
[0072] Receive a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key sent by the certificate authority terminal; the hybrid key signature certificate is generated by the certificate authority terminal using its own hybrid signature private key to sign the certificate signing request after successfully verifying the user identification information; the hybrid key encapsulation certificate is generated by the certificate authority terminal using its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information; the encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal using a symmetric key to encrypt the hybrid key encapsulation private key, and the key encapsulation ciphertext and the symmetric key are obtained by the certificate authority terminal using the first public key and the third public key to perform a key encapsulation operation; the hybrid key encapsulation public key includes a fourth public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth public key generated according to the post-quantum key encapsulation algorithm, and the hybrid key encapsulation private key includes a fourth private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth private key generated according to the post-quantum key encapsulation algorithm.
[0073] Step 205: decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key.
[0074] Specifically, decrypting the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key includes:
[0075] Performing a key decapsulation operation on the key-encapsulation ciphertext according to the first private key and the third private key to obtain the symmetric key;
[0076] The encrypted hybrid key-encapsulated private key is decrypted using the symmetric key to obtain the hybrid key-encapsulated private key.
[0077] Step 206: Install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key, and the second private key.
[0078] Specifically, binding the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key and the second private key includes:
[0079] The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the fourth private key and the fifth private key.
[0080] Furthermore, the method further comprises:
[0081] Install the intermediate certificate. If the certificate authority terminal is a root certificate authority terminal, the intermediate certificate is issued by the root certificate authority terminal. If the certificate authority terminal is not a root certificate authority terminal, the intermediate certificate is issued by the upper-level certificate authority terminal.
[0082] The intermediate certificate may be sent by the certificate authority terminal to the user terminal, or may be downloaded by the user terminal according to an address provided by the certificate authority terminal, which is not limited here.
[0083] It can be seen that in the embodiment of the present application, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, generates a second public key and a second private key according to a post-quantum key signature algorithm, and generates a third public key and a third private key according to a post-quantum key encapsulation algorithm; uses the first public key and the second public key as a hybrid public key, and generates a certificate signing request according to the hybrid public key and user identification information; sends the certificate signing request and the third public key to the certificate authority terminal; the certificate authority terminal generates a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key; and sends them to the user terminal; the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key; installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key, so that the issuance of the hybrid key signing certificate and the hybrid key encapsulation certificate can be realized, ensuring the legal use of certificates in anti-quantum algorithm scenarios and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, and also provides anti-quantum level security protection for the private key distribution process.
[0084] Please refer to Figure 3 , which shows a flow chart of a method for issuing a digital certificate based on a post-quantum hybrid algorithm provided by another embodiment of the present application. The method can be applied to a computer device, which refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 The certificate authority terminal 20 shown. The method may include the following steps:
[0085] Step 301: receiving a certificate signing request and a third public key sent by a user terminal, wherein the certificate signing request is generated by the user terminal according to a hybrid public key and user identification information, the third public key is generated by the user terminal according to a post-quantum key encapsulation algorithm, and the hybrid public key includes a first public key generated by the user terminal according to an asymmetric encryption algorithm and a second public key generated according to a post-quantum key signature algorithm;
[0086] Step 302: Generate a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key, and send them to the user terminal, so that the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulation private key, and installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key corresponding to the second public key.
[0087] Specifically, generating a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key includes:
[0088] After the user identification information is successfully verified, the certificate signing request is signed using its own hybrid signature private key to generate a hybrid key signature certificate;
[0089] Generate a fourth public key and a fourth private key according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key generated according to the post-quantum key encapsulation algorithm;
[0090] Using the fourth public key and the fifth public key as a mixed key to encapsulate a public key, and using the fourth private key and the fifth private key as a mixed key to encapsulate a private key;
[0091] Use its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information to generate a hybrid key encapsulation certificate;
[0092] Perform a key encapsulation operation using the first public key and the third public key to obtain a key encapsulation ciphertext and a symmetric key;
[0093] The hybrid key encapsulation private key is encrypted using the symmetric key to obtain an encrypted hybrid key encapsulation private key.
[0094] Among them, the user terminal performs a key decapsulation operation on the key encapsulation ciphertext according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key encapsulation private key to obtain the hybrid key encapsulation private key.
[0095] The user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the fourth private key and the fifth private key.
[0096] It should be noted that the steps of the method embodiment of the certificate authority terminal side refer to Figure 2 The user terminal side method embodiment shown is not described in detail here.
[0097] It can be seen that in the embodiment of the present application, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, generates a second public key and a second private key according to a post-quantum key signature algorithm, and generates a third public key and a third private key according to a post-quantum key encapsulation algorithm; uses the first public key and the second public key as a hybrid public key, and generates a certificate signing request according to the hybrid public key and user identification information; sends the certificate signing request and the third public key to the certificate authority terminal; the certificate authority terminal generates a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key; and sends them to the user terminal; the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key; installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key, so that the issuance of the hybrid key signing certificate and the hybrid key encapsulation certificate can be realized, ensuring the legal use of certificates in anti-quantum algorithm scenarios and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, and also provides anti-quantum level security protection for the private key distribution process.
[0098] Please refer to Figure 4 , which shows a flow chart of a method for issuing a digital certificate based on a post-quantum hybrid algorithm provided by another embodiment of the present application. The method may include the following steps:
[0099] Step 401: The user terminal 10 generates a first public key and a first private key according to an asymmetric encryption algorithm, generates a second public key and a second private key according to a post-quantum key signature algorithm, and generates a third public key and a third private key according to a post-quantum key encapsulation algorithm.
[0100] Step 402: The user terminal 10 uses the first public key and the second public key as a mixed public key.
[0101] Step 403: The user terminal 10 generates a certificate signing request according to the hybrid public key and user identification information.
[0102] Step 404 : the user terminal 10 sends the certificate signing request and the third public key to the certificate authority terminal 20 .
[0103] Step 405: The certificate authority terminal 20 verifies the user identification information.
[0104] Step 406: If the verification is successful, the certificate authority terminal 20 uses its own hybrid signature private key to sign the certificate signing request to generate a hybrid key signature certificate.
[0105] Step 407: The certificate authority terminal 20 generates a fourth public key and a fourth private key according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key according to the post-quantum key encapsulation algorithm.
[0106] Step 408: The certificate authority terminal 20 uses the fourth public key and the fifth public key as a hybrid key to encapsulate a public key, and uses the fourth private key and the fifth private key as a hybrid key to encapsulate a private key.
[0107] Step 409: The certificate authority terminal 20 uses its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information to generate a hybrid key encapsulation certificate.
[0108] Step 410: The certificate authority terminal 20 uses the first public key and the third public key to perform a key encapsulation operation to obtain a key encapsulation ciphertext and a symmetric key.
[0109] Step 411: The certificate authority terminal 20 uses the symmetric key to encrypt the hybrid key encapsulation private key to obtain an encrypted hybrid key encapsulation private key.
[0110] Step 412: The certificate authority terminal 20 sends the hybrid key signature certificate, the hybrid key encapsulation certificate, the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key to the user terminal 10.
[0111] Step 413: The user terminal 10 performs a key decapsulation operation on the key-encapsulation ciphertext according to the first private key and the third private key to obtain the symmetric key.
[0112] Step 414: The user terminal 10 uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.
[0113] Step 415: The user terminal 10 installs the hybrid key signing certificate and the hybrid key encapsulation certificate.
[0114] Step 416: The user terminal 10 binds the hybrid key signing certificate with the first private key and the second private key, and binds the hybrid key encapsulation certificate with the fourth private key and the fifth private key.
[0115] It should be noted that the steps of this method embodiment refer to Figure 2 The user terminal side method embodiment shown and Figure 3 The certificate authority terminal side method embodiment shown is not repeated here.
[0116] It can be seen that in the embodiment of the present application, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, generates a second public key and a second private key according to a post-quantum key signature algorithm, and generates a third public key and a third private key according to a post-quantum key encapsulation algorithm; uses the first public key and the second public key as a hybrid public key, and generates a certificate signing request according to the hybrid public key and user identification information; sends the certificate signing request and the third public key to the certificate authority terminal; the certificate authority terminal generates a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key; and sends them to the user terminal; the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key; installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key, so that the issuance of the hybrid key signing certificate and the hybrid key encapsulation certificate can be realized, ensuring the legal use of certificates in anti-quantum algorithm scenarios and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, and also provides anti-quantum level security protection for the private key distribution process.
[0117] Figure 5 A schematic diagram of the structure of a digital certificate issuance device based on a post-quantum hybrid algorithm provided by an embodiment of the present application is shown. Applied to a user terminal, the device includes:
[0118] A key generation unit 501 is used to generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm;
[0119] A key processing unit 502, configured to use the first public key and the second public key as a hybrid public key, and generate a certificate signing request according to the hybrid public key and user identification information;
[0120] The information generating unit 503 is used to send the certificate signing request and the third public key to a certificate authority terminal;
[0121] An information receiving unit 504 is used to receive a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key;
[0122] An information decryption unit 505 is used to decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key;
[0123] The certificate installation unit 506 is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key and the second private key.
[0124] Figure 6 A schematic diagram of the structure of a digital certificate issuing device based on a post-quantum hybrid algorithm provided by another embodiment of the present application is shown. Applied to a certificate authority terminal, the device includes:
[0125] An information receiving unit 601 is configured to receive a certificate signing request and a third public key sent by a user terminal, wherein the certificate signing request is generated by the user terminal according to a hybrid public key and user identification information, the third public key is generated by the user terminal according to a post-quantum key encapsulation algorithm, and the hybrid public key includes a first public key generated by the user terminal according to an asymmetric encryption algorithm and a second public key generated according to a post-quantum key signature algorithm;
[0126] The information generation unit 602 is used to generate a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key, and send them to the user terminal, so that the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulation private key, and install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key corresponding to the second public key.
[0127] Figure 7 A structural schematic diagram of a computer device provided by an embodiment of the present application is shown, including a memory and a processor, the memory stores a computer program, and the processor implements the functions of the computer system of the digital certificate issuance method based on the post-quantum hybrid algorithm in any of the above-mentioned embodiments when executing the computer program.
[0128] An embodiment of the present application also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a computer, the computer performs the functions of a computer system of the digital certificate issuance method based on a post-quantum hybrid algorithm in any of the above embodiments.
[0129] The embodiments of the present application also provide a computer program product comprising instructions, which, when executed by a computer, enables the computer to perform the functions of a computer system of a digital certificate issuance method based on a post-quantum hybrid algorithm in any of the above embodiments.
[0130] It should be understood that the specific examples in this application are only intended to help those skilled in the art to better understand the embodiments of the present application, rather than to limit the scope of the present invention.
[0131] It can be understood that in the various implementations of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the implementation methods of the present application.
[0132] It can be understood that the various embodiments described in this application can be implemented individually or in combination, and the embodiments of this application are not limited to this.
[0133] Unless otherwise stated, all technical and scientific terms used in the embodiments of the present application have the same meaning as those generally understood by those skilled in the art of the technical field of the present application. The terms used in the present application are only for the purpose of describing specific embodiments and are not intended to limit the scope of the present application. The term "and / or" used in the present application includes any and all combinations of one or more related listed items. The singular forms of "a kind of", "above" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0134] It can be understood that the processor of the embodiment of the present application can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method implementation can be completed by the hardware integrated logic circuit or software instructions in the processor. The above processor can be a general processor, a digital signal processor (DigitalSignal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiment of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to perform, or the hardware and software modules in the decoding processor are combined and executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0135] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (programmable ROM, PROM), an erasable programmable read-only memory (erasable PROM, EPROM), an electrically erasable programmable read-only memory (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0136] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0137] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method implementation methods and will not be repeated here.
[0138] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device implementation described above is only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0139] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0140] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0141] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of each implementation method of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., various media that can store program codes.
[0142] The above are only specific embodiments of the present application, but the protection scope of the present invention is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for issuing digital certificates based on a post-quantum hybrid algorithm, characterized in that: Applied to a user terminal, the method comprises: Generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm; Using the first public key and the second public key as a mixed public key, and generating a certificate signing request according to the mixed public key and user identification information; Sending the certificate signing request and the third public key to a certificate authority terminal; Receive a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key; Decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain a hybrid key encapsulation private key; The hybrid key signing certificate and the hybrid key encapsulation certificate are installed, and the hybrid key signing certificate and the hybrid key encapsulation certificate are bound to the hybrid key encapsulation private key, the first private key, and the second private key.
2. The method according to claim 1, characterized in that: The receiving the hybrid key signing certificate, the hybrid key encapsulation certificate, the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key includes: Receive a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key sent by the certificate authority terminal; the hybrid key signature certificate is generated by the certificate authority terminal using its own hybrid signature private key to sign the certificate signing request after successfully verifying the user identification information; the hybrid key encapsulation certificate is generated by the certificate authority terminal using its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information; the encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal using a symmetric key to encrypt the hybrid key encapsulation private key, and the key encapsulation ciphertext and the symmetric key are obtained by the certificate authority terminal using the first public key and the third public key to perform a key encapsulation operation; the hybrid key encapsulation public key includes a fourth public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth public key generated according to the post-quantum key encapsulation algorithm, and the hybrid key encapsulation private key includes a fourth private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth private key generated according to the post-quantum key encapsulation algorithm.
3. The method according to claim 2, characterized in that The decrypting the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key includes: Performing a key decapsulation operation on the key-encapsulation ciphertext according to the first private key and the third private key to obtain the symmetric key; The encrypted hybrid key-encapsulated private key is decrypted using the symmetric key to obtain the hybrid key-encapsulated private key.
4. The method according to claim 2 or 3, characterized in that: The step of binding the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key and the second private key comprises: The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the fourth private key and the fifth private key.
5. The method according to claim 1, characterized in that The method further comprises: Install the intermediate certificate. If the certificate authority terminal is a root certificate authority terminal, the intermediate certificate is issued by the root certificate authority terminal. If the certificate authority terminal is not a root certificate authority terminal, the intermediate certificate is issued by the upper-level certificate authority terminal.
6. A method for issuing digital certificates based on a post-quantum hybrid algorithm, characterized in that: Applied to a certificate authority terminal, the method comprises: Receiving a certificate signing request and a third public key sent by a user terminal, wherein the certificate signing request is generated by the user terminal according to a hybrid public key and user identification information, the third public key is generated by the user terminal according to a post-quantum key encapsulation algorithm, and the hybrid public key includes a first public key generated by the user terminal according to an asymmetric encryption algorithm and a second public key generated according to a post-quantum key signature algorithm; A hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key are generated according to the certificate signing request and the third public key, and sent to the user terminal, so that the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulation private key, and installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key corresponding to the second public key.
7. The method according to claim 6, characterized in that The generating, according to the certificate signing request and the third public key, a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key comprises: After the user identification information is successfully verified, the certificate signing request is signed using its own hybrid signature private key to generate a hybrid key signature certificate; Generate a fourth public key and a fourth private key according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key generated according to the post-quantum key encapsulation algorithm; Using the fourth public key and the fifth public key as a mixed key to encapsulate a public key, and using the fourth private key and the fifth private key as a mixed key to encapsulate a private key; Use its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information to generate a hybrid key encapsulation certificate; Perform a key encapsulation operation using the first public key and the third public key to obtain a key encapsulation ciphertext and a symmetric key; The hybrid key encapsulation private key is encrypted using the symmetric key to obtain an encrypted hybrid key encapsulation private key.
8. The method according to claim 7, characterized in that The user terminal performs a key decapsulation operation on the key encapsulation ciphertext according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key encapsulation private key to obtain the hybrid key encapsulation private key.
9. The method according to claim 7 or 8, characterized in that: The user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the fourth private key and the fifth private key.
10. A digital certificate issuing device based on a post-quantum hybrid algorithm, characterized in that: Applied to a user terminal, the device comprises: A key generation unit, configured to generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm; a key processing unit, configured to use the first public key and the second public key as a hybrid public key, and to generate a certificate signing request according to the hybrid public key and user identification information; An information generating unit, used for sending the certificate signing request and the third public key to a certificate authority terminal; An information receiving unit is used to receive a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key generated by the certificate authority terminal according to the certificate signing request and the third public key; an information decryption unit, configured to decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key and the third private key to obtain the hybrid key encapsulation private key; The certificate installation unit is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key and the second private key.
11. A digital certificate issuing device based on a post-quantum hybrid algorithm, characterized in that: Applied to a certificate authority terminal, the device comprises: an information receiving unit, configured to receive a certificate signing request and a third public key sent by a user terminal, wherein the certificate signing request is generated by the user terminal according to a hybrid public key and user identification information, the third public key is generated by the user terminal according to a post-quantum key encapsulation algorithm, and the hybrid public key includes a first public key generated by the user terminal according to an asymmetric encryption algorithm and a second public key generated according to a post-quantum key signature algorithm; An information generation unit is used to generate a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext and an encrypted hybrid key encapsulation private key according to the certificate signing request and the third public key, and send them to the user terminal, so that the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulation private key, and install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key corresponding to the second public key.
12. An electronic device, characterized in that: include: Processor and memory; The processor is connected to a memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program to execute the method according to any one of claims 1 to 5 or claims 6 to 9.
13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the method according to any one of claims 1 to 5 or claims 6 to 9 is executed.
Citation Information
Patent Citations
Signing and issuing method, device, system and equipment for post-quantum and national secret hybrid double certificates
CN118944894A
Implicit certificate public key processing method and system based on post-fusion quantum algorithm, and user side
CN119341742A
Secure Server Digital Signature Generation For Post-Quantum Cryptography Key Encapsulations
US20220209944A1
Cited By
Anti-quantum computing communication system based on post quantum cryptography
CN121077762A
Zero-trust quantum key remote secure injection method and system based on PQC
CN122027153A
Quantum key remote secure injection method and system based on pqc and zero trust
CN122027153B