Digital certificate issuing method based on post-quantum hybrid algorithm and related device

By using a digital certificate issuance method based on a post-quantum hybrid algorithm, hybrid key signature certificates and hybrid key encapsulation certificates are generated, solving the problem of easy cracking of traditional public key encryption algorithms in a quantum computing environment, and realizing information security and legitimate use of certificates in the quantum computing era.

CN120110677BActive Publication Date: 2026-05-12ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD
Filing Date
2025-02-28
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Traditional public-key encryption algorithms are easily cracked in quantum computing environments, and existing secure communication and digital signature protocols are at risk of being compromised. Furthermore, traditional public-key certificates cannot be verified in scenarios involving classical and quantum-resistant hybrid algorithms, making them vulnerable to man-in-the-middle attacks.

Method used

A digital certificate issuance method based on post-quantum hybrid algorithms is adopted to generate hybrid key signature certificates and hybrid key encapsulation certificates. Public and private keys are generated through asymmetric encryption algorithms, post-quantum key signature algorithms, and post-quantum key encapsulation algorithms. Certificate signing and key encapsulation are performed in conjunction with a certificate authority to ensure the legitimate use of certificates in quantum-resistant algorithm scenarios.

Benefits of technology

It achieves information security in the quantum computing era, ensures the legitimate use of certificates and information security, and provides quantum-resistant security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110677B_ABST
    Figure CN120110677B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a digital certificate issuing method based on a post-quantum hybrid algorithm and a related device, a user terminal generates three pairs of public and private keys according to an asymmetric encryption algorithm, a post-quantum key signature algorithm and a post-quantum key packaging algorithm; generates a certificate signature request according to a hybrid public key including a first and a second public key and user identification information; and sends the same to a CA terminal together with a third public key; the CA terminal generates a hybrid key signature and a packaging certificate, key packaging ciphertext and encrypted hybrid key packaging private key according to the two; the user terminal decrypts the key packaging ciphertext and the encrypted hybrid key packaging private key according to the first and the third private keys to obtain the hybrid key packaging private key; installs the hybrid key signature and the packaging certificate and binds the same with the corresponding private key, so that the issuing of the hybrid key signature and the packaging certificate can be realized, the legal use of the certificate in the anti-quantum algorithm scene is ensured, and the information security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of post-quantum cryptography, and in particular to a digital certificate issuance method and related apparatus based on a post-quantum hybrid algorithm. Background Technology

[0002] The development of quantum computing poses a significant potential threat to traditional encryption algorithms. The mathematical problems upon which traditional public-key encryption algorithms such as RSA (Rivest-Shamir-Adleman) and ECC (Elliptic Curve Cryptography) rely may become easily solvable in the face of quantum computers. Once quantum computers achieve sufficient computing power, currently widely used encryption systems based on these algorithms will be at risk of being cracked. For example, in a quantum computing environment, the encryption key of the RSA algorithm may be rapidly fragmented, causing encrypted data to lose its confidentiality. This means that many existing secure communication, digital signature, and key exchange protocols need to be re-examined and improved to meet the challenges of the quantum computing era.

[0003] Post-quantum cryptography (PQC) offers an effective solution to the threat posed by quantum computing to traditional encryption algorithms. PQC is based on novel mathematical problems that remain highly secure against quantum computers. Its main advantage lies in providing reliable encryption protection in the quantum computing era. Unlike traditional encryption algorithms, PQC's security does not rely on mathematical problems easily cracked by quantum computers. For example, lattice-based cryptography, encoding-based cryptography, and multivariate polynomial-based cryptography are important research directions in PQC. However, traditional public key certificates do not contain the PQC algorithm's public key. In scenarios using classical + quantum-resistant hybrid algorithms, the quantum-resistant public key cannot be verified, making it vulnerable to man-in-the-middle attacks. Summary of the Invention

[0004] This application provides a digital certificate issuance method and related apparatus based on a post-quantum hybrid algorithm, which can issue hybrid key signature certificates and hybrid key encapsulation certificates, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios and improving information security.

[0005] The first aspect of this application provides a digital certificate issuance method based on a post-quantum hybrid algorithm, applied to a user terminal, the method comprising:

[0006] A first public key and a first private key are generated according to an asymmetric encryption algorithm; a second public key and a second private key are generated according to a post-quantum key signature algorithm; and a third public key and a third private key are generated according to a post-quantum key encapsulation algorithm.

[0007] The first public key and the second public key are used as a hybrid public key, and a certificate signing request is generated based on the hybrid public key and user identification information;

[0008] Send the certificate signing request and the third public key to the certificate authority terminal;

[0009] Receive the hybrid key signature certificate, hybrid key encapsulation certificate, key encapsulation ciphertext, and encrypted hybrid key encapsulation private key generated by the certificate authorization center terminal based on the certificate signing request and the third public key;

[0010] Decrypt the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key using the first private key and the third private key to obtain the hybrid key-encapsulated private key.

[0011] Install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0012] Optionally, receiving the hybrid key signature certificate, hybrid key encapsulated certificate, key encapsulated ciphertext, and encrypted hybrid key encapsulated private key generated by the certificate authorization center terminal based on the certificate signing request and the third public key includes:

[0013] The system receives a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key from the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key and the user identification information using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The key encapsulation ciphertext and the symmetric key are obtained by the certificate authority terminal performing key encapsulation operations using the first public key and the third public key. The hybrid key encapsulation public key includes a fourth public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a fourth private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth private key generated according to the post-quantum key encapsulation algorithm.

[0014] Optionally, the step of decrypting the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key based on the first private key and the third private key to obtain the hybrid key-encapsulated private key includes:

[0015] The symmetric key is obtained by performing a key decapsulation operation on the key-encapsulated ciphertext based on the first private key and the third private key.

[0016] The symmetric key is used to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0017] Optionally, binding the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key includes:

[0018] The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the fourth private key and the fifth private key.

[0019] Optionally, the method further includes:

[0020] When installing an intermediate certificate, if the certificate authority terminal is a root certificate authority terminal, then the intermediate certificate is issued by the root certificate authority terminal; if the certificate authority terminal is not a root certificate authority terminal, then the intermediate certificate is issued by the next higher-level certificate authority terminal.

[0021] A second aspect of this application provides a digital certificate issuance method based on a post-quantum hybrid algorithm, applied to a certificate authority terminal, the method comprising:

[0022] The system receives a certificate signing request and a third public key sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The third public key is generated by the user terminal based on a post-quantum key encapsulation algorithm. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signing algorithm.

[0023] Based on the certificate signing request and the third public key, a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key are generated and sent to the user terminal. This allows the user terminal to decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key using the first private key corresponding to the first public key and the third private key corresponding to the third public key, thereby obtaining the hybrid key encapsulation private key. The user terminal also installs the hybrid key signing certificate and the hybrid key encapsulation certificate and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key corresponding to the second public key.

[0024] Optionally, the step of generating a hybrid key signature certificate, a hybrid key encapsulated certificate, a key encapsulated ciphertext, and an encrypted hybrid key encapsulated private key based on the certificate signing request and the third public key includes:

[0025] After successfully verifying the user identification information, the user uses their own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate.

[0026] A fourth public key and a fourth private key are generated according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key are generated according to the post-quantum key encapsulation algorithm;

[0027] The fourth public key and the fifth public key are used as a hybrid key to encapsulate the public key, and the fourth private key and the fifth private key are used as a hybrid key to encapsulate the private key;

[0028] Use your own hybrid signature private key to sign the hybrid key-encapsulated public key and the user identification information to generate a hybrid key-encapsulated certificate;

[0029] The first public key and the third public key are used to perform key encapsulation operations to obtain the key-encapsulated ciphertext and the symmetric key;

[0030] The symmetric key is used to encrypt the private key encapsulated in the hybrid key to obtain the encrypted private key encapsulated in the hybrid key.

[0031] Optionally, the user terminal performs a key decapsulation operation on the key-encapsulated ciphertext based on the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0032] Optionally, the user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the fourth private key and the fifth private key.

[0033] A third aspect of this application provides a digital certificate issuance device based on a post-quantum hybrid algorithm, applied to a user terminal, the device comprising:

[0034] The key generation unit is used to generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm.

[0035] A key processing unit is configured to use the first public key and the second public key as a hybrid public key, and to generate a certificate signing request based on the hybrid public key and user identification information;

[0036] The information generation unit is used to send the certificate signing request and the third public key to the certificate authorization center terminal;

[0037] The information receiving unit is used to receive the hybrid key signature certificate, hybrid key encapsulation certificate, key encapsulation ciphertext, and encrypted hybrid key encapsulation private key generated by the certificate authorization center terminal based on the certificate signing request and the third public key;

[0038] The information decryption unit is used to decrypt the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key according to the first private key and the third private key to obtain the hybrid key-encapsulated private key;

[0039] The certificate installation unit is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0040] A fourth aspect of this application provides a digital certificate issuance device based on a post-quantum hybrid algorithm, applied to a certificate authorization center terminal, the device comprising:

[0041] The information receiving unit is used to receive a certificate signing request and a third public key sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The third public key is generated by the user terminal based on a post-quantum key encapsulation algorithm. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signing algorithm.

[0042] The information generation unit is configured to generate a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key, and send them to the user terminal. This enables the user terminal to decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key based on the first private key corresponding to the first public key and the third private key corresponding to the third public key, thereby obtaining the hybrid key encapsulation private key. The user terminal also installs the hybrid key signature certificate and the hybrid key encapsulation certificate, and binds the hybrid key signature certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second public key corresponding to the second private key.

[0043] A fifth aspect of this application provides an electronic device, including: a processor and a memory;

[0044] The processor is connected to a memory, wherein the memory is used to store computer programs and the processor is used to invoke the computer programs to execute the methods as described in the first or second aspect of the embodiments of this application.

[0045] A sixth aspect of this application provides a computer-readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a processor, perform the methods described in the first or second aspect of this application.

[0046] In this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, a second public key and a second private key according to a post-quantum key signature algorithm, and a third public key and a third private key according to a post-quantum key encapsulation algorithm. The first and second public keys are used as a hybrid public key, and a certificate signing request is generated based on the hybrid public key and user identification information. The certificate signing request and the third public key are sent to a certificate authority terminal. The certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key, and sends these to the user terminal. The user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key using the first and third private keys to obtain the hybrid key encapsulation private key. The hybrid key signature certificate and the hybrid key encapsulation certificate are installed, and bound to the hybrid key encapsulation private key, the first private key, and the second private key. This enables the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant scenarios and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, providing quantum-resistant security protection for the private key distribution process. Attached Figure Description

[0047] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 A schematic diagram of the operating environment of a digital certificate issuance method based on a post-quantum hybrid algorithm provided in one embodiment of this application is shown.

[0049] Figure 2 A flowchart illustrating a digital certificate issuance method based on a post-quantum hybrid algorithm according to an embodiment of this application is shown.

[0050] Figure 3 A flowchart illustrating a digital certificate issuance method based on a post-quantum hybrid algorithm provided in another embodiment of this application is shown.

[0051] Figure 4 A flowchart illustrating a digital certificate issuance method based on a post-quantum hybrid algorithm provided in another embodiment of this application is shown.

[0052] Figure 5 This paper shows a schematic diagram of the structure of a digital certificate issuance device based on a post-quantum hybrid algorithm according to an embodiment of this application;

[0053] Figure 6 This illustration shows a schematic diagram of the structure of a digital certificate issuance device based on a post-quantum hybrid algorithm according to another embodiment of this application;

[0054] Figure 7 A schematic diagram of the structure of a computer device provided in one embodiment of this application is shown. Detailed Implementation

[0055] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0056] Please refer to Figure 1This diagram illustrates the operating environment of a digital certificate issuance method based on a post-quantum hybrid algorithm provided in one embodiment of this application. The operating environment may include a user terminal 10 and a Certificate Authority (CA) terminal 20.

[0057] User terminal 10 includes, but is not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, in-vehicle terminals, game consoles, e-book readers, multimedia playback devices, wearable devices, and other electronic devices. Application clients can be installed on terminal 10.

[0058] CA Terminal 20 is a third-party terminal responsible for managing and issuing certificates. It possesses sufficient authority and is trusted and recognized by all industries and the public. The functions of CA Terminal 20 include: verifying website trustworthiness (for HTTPS), generating and storing the root certificate file (ca.crt) and the corresponding private key file (ca.key).

[0059] The relationship between user terminal 10 and CA terminal 20 is as follows: User terminal 10 has a trust store containing the CAs it trusts. The certificate of user terminal 10 is signed by the CA at a leaf position in the certificate tree. The end-user's certificate is signed by the Certificate Authority at a leaf position in the tree; each Certificate Authority also has a certificate signed by its parent Certificate Authority.

[0060] Optionally, user terminal 10 and CA terminal 20 can communicate with each other via network 30. User terminal 10 and CA terminal 20 can be directly or indirectly connected via wired or wireless communication, which is not limited herein.

[0061] Please refer to Figure 2 This document illustrates a flowchart of a digital certificate issuance method based on a post-quantum hybrid algorithm according to an embodiment of this application. This method can be applied to computer devices, which refer to electronic devices with data computing and processing capabilities. For example, the executing entity for each step can be... Figure 1 The user terminal 10 shown. This method may include the following steps:

[0062] Step 201: Generate a first public key and a first private key according to the asymmetric encryption algorithm, generate a second public key and a second private key according to the post-quantum key signature algorithm, and generate a third public key and a third private key according to the post-quantum key encapsulation algorithm.

[0063] Asymmetric encryption algorithms are a type of encryption method that requires two keys: a public key (pk) and a private key (sk). These two keys are different but mathematically related. In asymmetric encryption, data is encrypted using the public key, and only the corresponding private key can decrypt it. Similarly, digital signatures are created using the private key, and only the corresponding public key can verify the validity of the signature. Common asymmetric encryption algorithms include RSA, ECC, and Chinese national cryptographic algorithms.

[0064] Post-quantum digital signatures are a type of modern public-key cryptographic digital signature that can resist known quantum computing attacks. Currently, NIST has selected several post-quantum digital signature algorithms, such as Dilithium, Falcon, SPHINCS+, and Rainbow.

[0065] Post-quantum key encapsulation algorithms are new encryption algorithms developed to defend against the threat posed by quantum computers to currently widely used public-key cryptosystems. For example, the Kyber algorithm is a key encapsulation mechanism that satisfies IND-CCA2 security; its security relies on the difficulty of the MLWE problem and is constructed using a two-phase approach. The SIKE algorithm is a PQC algorithm that implements post-quantum key encapsulation based on the Supersingular Isogeny Diffie-Hellman (SIDH) key exchange protocol.

[0066] Step 202: Use the first public key and the second public key as a hybrid public key, and generate a certificate signing request based on the hybrid public key and user identification information.

[0067] The Certificate Signing Request (CSR) is a file generated by the entity requesting the certificate (such as user terminal 10 in this application). It contains the applicant's public key and user identification information, such as country / region code, organization name, organizational unit, and common name, to identify the user. The CSR is primarily used to request a signature from the Certificate Authority (CA) during the digital certificate authentication process to obtain a trusted digital certificate.

[0068] Step 203: Send the certificate signing request and the third public key to the certificate authority terminal.

[0069] Step 204: Receive the hybrid key signature certificate, hybrid key encapsulation certificate, key encapsulation ciphertext, and encrypted hybrid key encapsulation private key generated by the certificate authorization center terminal based on the certificate signing request and the third public key.

[0070] Digital certificates can be categorized into signature certificates and encryption certificates. Signature certificates are used to sign user information, ensuring its validity and non-repudiation; examples include hybrid key signature certificates containing more than one key. Encryption certificates are used to encrypt user-transmitted information, ensuring its confidentiality and integrity; examples include hybrid key encapsulation certificates containing more than one key. A symmetric key is an encryption key used in symmetric encryption algorithms. In symmetric encryption, the same key is used for both encryption and decryption.

[0071] Specifically, receiving the hybrid key signature certificate, hybrid key encapsulation certificate, key encapsulation ciphertext, and encrypted hybrid key encapsulation private key generated by the certificate authorization center terminal based on the certificate signing request and the third public key includes:

[0072] The system receives a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key from the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key and the user identification information using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The key encapsulation ciphertext and the symmetric key are obtained by the certificate authority terminal performing key encapsulation operations using the first public key and the third public key. The hybrid key encapsulation public key includes a fourth public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a fourth private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth private key generated according to the post-quantum key encapsulation algorithm.

[0073] Step 205: Decrypt the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key according to the first private key and the third private key to obtain the hybrid key-encapsulated private key.

[0074] Specifically, the step of decrypting the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key based on the first private key and the third private key to obtain the hybrid key-encapsulated private key includes:

[0075] The symmetric key is obtained by performing a key decapsulation operation on the key-encapsulated ciphertext based on the first private key and the third private key.

[0076] The symmetric key is used to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0077] Step 206: Install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0078] Specifically, binding the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key includes:

[0079] The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the fourth private key and the fifth private key.

[0080] Furthermore, the method also includes:

[0081] When installing an intermediate certificate, if the certificate authority terminal is a root certificate authority terminal, then the intermediate certificate is issued by the root certificate authority terminal; if the certificate authority terminal is not a root certificate authority terminal, then the intermediate certificate is issued by the next higher-level certificate authority terminal.

[0082] The intermediate certificate may be sent to the user terminal by the certificate authority terminal, or it may be downloaded by the user terminal from the address provided by the certificate authority terminal; there is no limitation on this.

[0083] As can be seen, in this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, a second public key and a second private key according to a post-quantum key signature algorithm, and a third public key and a third private key according to a post-quantum key encapsulation algorithm; uses the first and second public keys as a hybrid public key, and generates a certificate signing request based on the hybrid public key and user identification information; sends the certificate signing request and the third public key to the certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key; and sends these to the user terminal; the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key based on the first and third private keys to obtain the hybrid key encapsulation private key; installs the hybrid key signature certificate and the hybrid key encapsulation certificate, and binds the hybrid key signature certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key, thereby enabling the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios, and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, providing quantum-resistant security protection for the private key distribution process.

[0084] Please refer to Figure 3 This illustration shows a flowchart of a digital certificate issuance method based on a post-quantum hybrid algorithm according to another embodiment of this application. This method can be applied to computer devices, which refer to electronic devices with data computing and processing capabilities. For example, the executing entity for each step can be... Figure 1 The certificate authority terminal 20 shown. This method may include the following steps:

[0085] Step 301: Receive a certificate signing request and a third public key sent by the user terminal. The certificate signing request is generated by the user terminal based on the hybrid public key and user identification information. The third public key is generated by the user terminal based on the post-quantum key encapsulation algorithm. The hybrid public key includes a first public key generated by the user terminal based on the asymmetric encryption algorithm and a second public key generated based on the post-quantum key signing algorithm.

[0086] Step 302: Generate a hybrid key signing certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key, and send them to the user terminal. This allows the user terminal to decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key using the first private key corresponding to the first public key and the third private key corresponding to the third public key, thereby obtaining the hybrid key encapsulation private key. The user terminal also installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key corresponding to the second public key.

[0087] Specifically, the step of generating a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key includes:

[0088] After successfully verifying the user identification information, the user uses their own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate.

[0089] A fourth public key and a fourth private key are generated according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key are generated according to the post-quantum key encapsulation algorithm;

[0090] The fourth public key and the fifth public key are used as a hybrid key to encapsulate the public key, and the fourth private key and the fifth private key are used as a hybrid key to encapsulate the private key;

[0091] Use your own hybrid signature private key to sign the hybrid key-encapsulated public key and the user identification information to generate a hybrid key-encapsulated certificate;

[0092] The first public key and the third public key are used to perform key encapsulation operations to obtain the key-encapsulated ciphertext and the symmetric key;

[0093] The symmetric key is used to encrypt the private key encapsulated in the hybrid key to obtain the encrypted private key encapsulated in the hybrid key.

[0094] Specifically, the user terminal performs key decapsulation operations on the key-encapsulated ciphertext based on the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0095] Specifically, the user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the fourth private key and the fifth private key.

[0096] It should be noted that the steps of the certificate authorization center terminal-side method embodiment are described in detail below. Figure 2 The user terminal-side method embodiment shown will not be described again here.

[0097] As can be seen, in this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, a second public key and a second private key according to a post-quantum key signature algorithm, and a third public key and a third private key according to a post-quantum key encapsulation algorithm; uses the first and second public keys as a hybrid public key, and generates a certificate signing request based on the hybrid public key and user identification information; sends the certificate signing request and the third public key to the certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key; and sends these to the user terminal; the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key based on the first and third private keys to obtain the hybrid key encapsulation private key; installs the hybrid key signature certificate and the hybrid key encapsulation certificate, and binds the hybrid key signature certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key, thereby enabling the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios, and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, providing quantum-resistant security protection for the private key distribution process.

[0098] Please refer to Figure 4 This illustration shows a flowchart of a digital certificate issuance method based on a post-quantum hybrid algorithm according to another embodiment of this application. The method may include the following steps:

[0099] Step 401: User terminal 10 generates a first public key and a first private key according to an asymmetric encryption algorithm, generates a second public key and a second private key according to a post-quantum key signature algorithm, and generates a third public key and a third private key according to a post-quantum key encapsulation algorithm.

[0100] Step 402: User terminal 10 uses the first public key and the second public key as a hybrid public key.

[0101] Step 403: User terminal 10 generates a certificate signing request based on the hybrid public key and user identification information.

[0102] Step 404: User terminal 10 sends the certificate signing request and the third public key to certificate authority terminal 20.

[0103] Step 405: The certificate authorization center terminal 20 verifies the user identification information.

[0104] Step 406: If the verification is successful, the Certificate Authority Terminal 20 uses its own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate.

[0105] Step 407: The certificate authorization center terminal 20 generates a fourth public key and a fourth private key according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key according to the post-quantum key encapsulation algorithm.

[0106] Step 408: The Certificate Authority Terminal 20 encapsulates the fourth public key and the fifth public key as a hybrid key to encapsulate the public key, and encapsulates the fourth private key and the fifth private key as a hybrid key to encapsulate the private key.

[0107] Step 409: The certificate authority terminal 20 uses its own hybrid signature private key to sign the hybrid key encapsulated public key and the user identification information to generate a hybrid key encapsulated certificate.

[0108] Step 410: The certificate authorization center terminal 20 uses the first public key and the third public key to perform key encapsulation operation to obtain the key encapsulation ciphertext and the symmetric key.

[0109] Step 411: The certificate authorization center terminal 20 uses the symmetric key to encrypt the hybrid key encapsulated private key to obtain the encrypted hybrid key encapsulated private key.

[0110] Step 412: The certificate authority terminal 20 sends the hybrid key signature certificate, hybrid key encapsulation certificate, key encapsulation ciphertext, and encrypted hybrid key encapsulation private key to the user terminal 10.

[0111] Step 413: User terminal 10 performs key decapsulation operation on the key-encapsulated ciphertext according to the first private key and the third private key to obtain the symmetric key.

[0112] Step 414: User terminal 10 uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0113] Step 415: User terminal 10 installs the hybrid key signing certificate and the hybrid key encapsulation certificate.

[0114] Step 416: User terminal 10 binds the hybrid key signing certificate to the first private key and the second private key, and binds the hybrid key encapsulation certificate to the fourth private key and the fifth private key.

[0115] It should be noted that the steps of this method embodiment are described in detail below. Figure 2 The user terminal side method embodiment shown and Figure 3 The certificate authorization center terminal-side method embodiment shown will not be described again here.

[0116] As can be seen, in this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, a second public key and a second private key according to a post-quantum key signature algorithm, and a third public key and a third private key according to a post-quantum key encapsulation algorithm; uses the first and second public keys as a hybrid public key, and generates a certificate signing request based on the hybrid public key and user identification information; sends the certificate signing request and the third public key to the certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key; and sends these to the user terminal; the user terminal decrypts the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key based on the first and third private keys to obtain the hybrid key encapsulation private key; installs the hybrid key signature certificate and the hybrid key encapsulation certificate, and binds the hybrid key signature certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key, thereby enabling the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios, and improving information security. In addition, the user terminal generates a third public key and a third private key according to the post-quantum key encapsulation algorithm, which are used for key encapsulation in the private key distribution process, providing quantum-resistant security protection for the private key distribution process.

[0117] Figure 5 A schematic diagram of a digital certificate issuance device based on a post-quantum hybrid algorithm according to an embodiment of this application is shown. Applied to a user terminal, the device includes:

[0118] The key generation unit 501 is used to generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm.

[0119] The key processing unit 502 is configured to use the first public key and the second public key as a hybrid public key, and to generate a certificate signing request based on the hybrid public key and user identification information.

[0120] Information generation unit 503 is used to send the certificate signing request and the third public key to the certificate authorization center terminal;

[0121] Information receiving unit 504 is used to receive the hybrid key signature certificate, hybrid key encapsulation certificate, key encapsulation ciphertext and encrypted hybrid key encapsulation private key generated by the certificate authorization center terminal according to the certificate signing request and the third public key;

[0122] The information decryption unit 505 is used to decrypt the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key according to the first private key and the third private key to obtain the hybrid key-encapsulated private key.

[0123] The certificate installation unit 506 is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0124] Figure 6 A schematic diagram of a digital certificate issuance device based on a post-quantum hybrid algorithm according to another embodiment of this application is shown. Applied to a certificate authority terminal, the device includes:

[0125] The information receiving unit 601 is used to receive a certificate signing request and a third public key sent by a user terminal. The certificate signing request is generated by the user terminal based on the hybrid public key and user identification information. The third public key is generated by the user terminal based on the post-quantum key encapsulation algorithm. The hybrid public key includes a first public key generated by the user terminal based on the asymmetric encryption algorithm and a second public key generated based on the post-quantum key signing algorithm.

[0126] The information generation unit 602 is configured to generate a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key based on the certificate signing request and the third public key, and send them to the user terminal. This enables the user terminal to decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key based on the first private key corresponding to the first public key and the third private key corresponding to the third public key, thereby obtaining the hybrid key encapsulation private key. The user terminal also installs the hybrid key signature certificate and the hybrid key encapsulation certificate, and binds the hybrid key signature certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key corresponding to the second public key.

[0127] Figure 7 The diagram illustrates the structure of a computer device according to an embodiment of this application, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the functions of the computer system based on the digital certificate issuance method of the post-quantum hybrid algorithm in any of the above embodiments.

[0128] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a computer, causes the computer to perform the functions of the computer system of the digital certificate issuance method based on the post-quantum hybrid algorithm in any of the above embodiments.

[0129] This application also provides a computer program product containing instructions that, when executed by a computer, cause the computer to perform the functions of the computer system of the digital certificate issuance method based on the post-quantum hybrid algorithm in any of the above embodiments.

[0130] It is understood that the specific examples in this application are only intended to help those skilled in the art better understand the implementation methods of this application, and are not intended to limit the scope of the invention.

[0131] It is understood that in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not limit the implementation process of the embodiments of this application in any way.

[0132] It is understood that the various implementation methods described in this application can be implemented individually or in combination, and the implementation methods in this application are not limited in this respect.

[0133] Unless otherwise stated, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The term "and / or" as used in this application includes any and all combinations of one or more of the associated listed items. The singular forms "a," "the," and "the" as used in the embodiments of this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0134] It is understood that the processor in the embodiments of this application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by the integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory; the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0135] It is understood that the memory in the embodiments of this application may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Specifically, non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM). It should be noted that the memory in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0136] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0137] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the aforementioned method implementations, and will not be repeated here.

[0138] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0139] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0140] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0141] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0142] The above are merely specific embodiments of this application, but the scope of protection of this invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this invention should be determined by the scope of the claims.

Claims

1. A digital certificate issuance method based on a post-quantum hybrid algorithm, characterized in that, Applied to a user terminal, the method includes: A first public key and a first private key are generated according to an asymmetric encryption algorithm; a second public key and a second private key are generated according to a post-quantum key signature algorithm; and a third public key and a third private key are generated according to a post-quantum key encapsulation algorithm. The first public key and the second public key are used as a hybrid public key, and a certificate signing request is generated based on the hybrid public key and user identification information; Send the certificate signing request and the third public key to the certificate authority terminal; The system receives a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key from the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key and the user identification information using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The key encapsulation ciphertext and the symmetric key are obtained by the certificate authority terminal performing key encapsulation operations using the first public key and the third public key. The hybrid key encapsulation public key includes a fourth public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a fourth private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth private key generated according to the post-quantum key encapsulation algorithm. Decrypt the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key using the first private key and the third private key to obtain the hybrid key-encapsulated private key. Install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

2. The method according to claim 1, characterized in that, The step of decrypting the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key based on the first private key and the third private key to obtain the hybrid key-encapsulated private key includes: The symmetric key is obtained by performing a key decapsulation operation on the key-encapsulated ciphertext based on the first private key and the third private key. The symmetric key is used to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

3. The method according to claim 1 or 2, characterized in that, The step of binding the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key, and the second private key includes: The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the fourth private key and the fifth private key.

4. The method according to claim 1, characterized in that, The method further includes: When installing an intermediate certificate, if the certificate authority terminal is a root certificate authority terminal, then the intermediate certificate is issued by the root certificate authority terminal; if the certificate authority terminal is not a root certificate authority terminal, then the intermediate certificate is issued by the next higher-level certificate authority terminal.

5. A digital certificate issuance method based on a post-quantum hybrid algorithm, characterized in that, Applied to a certificate authority terminal, the method includes: The system receives a certificate signing request and a third public key sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The third public key is generated by the user terminal based on a post-quantum key encapsulation algorithm. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signing algorithm. After successfully verifying the user identification information, the user uses their own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate. A fourth public key and a fourth private key are generated according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key are generated according to the post-quantum key encapsulation algorithm; The fourth public key and the fifth public key are used as a hybrid key to encapsulate the public key, and the fourth private key and the fifth private key are used as a hybrid key to encapsulate the private key; Use your own hybrid signature private key to sign the hybrid key-encapsulated public key and the user identification information to generate a hybrid key-encapsulated certificate; The first public key and the third public key are used to perform key encapsulation operations to obtain the key-encapsulated ciphertext and the symmetric key; The symmetric key is used to encrypt the private key encapsulated in the hybrid key to obtain the encrypted private key encapsulated in the hybrid key. The hybrid key signature certificate, hybrid key encapsulation certificate, key encapsulation ciphertext, and encrypted hybrid key encapsulation private key are sent to the user terminal, so that the user terminal can decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulation private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulation private key, and install the hybrid key signature certificate and the hybrid key encapsulation certificate, and bind the hybrid key signature certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the second private key corresponding to the first private key and the second public key.

6. The method according to claim 5, characterized in that, The user terminal performs key decapsulation operation on the key-encapsulated ciphertext based on the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

7. The method according to claim 5 or 6, characterized in that, The user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the fourth private key and the fifth private key.

8. A digital certificate issuance device based on a post-quantum hybrid algorithm, characterized in that, The device, applied to a user terminal, includes: The key generation unit is used to generate a first public key and a first private key according to an asymmetric encryption algorithm, generate a second public key and a second private key according to a post-quantum key signature algorithm, and generate a third public key and a third private key according to a post-quantum key encapsulation algorithm. A key processing unit is configured to use the first public key and the second public key as a hybrid public key, and to generate a certificate signing request based on the hybrid public key and user identification information; The information generation unit is used to send the certificate signing request and the third public key to the certificate authorization center terminal; The information receiving unit is configured to receive a hybrid key signature certificate, a hybrid key encapsulation certificate, a key encapsulation ciphertext, and an encrypted hybrid key encapsulation private key sent by the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key and the user identification information using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The key encapsulation ciphertext and the symmetric key are obtained by the certificate authority terminal performing key encapsulation operations using the first public key and the third public key. The hybrid key encapsulation public key includes a fourth public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a fourth private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fifth private key generated according to the post-quantum key encapsulation algorithm. The information decryption unit is used to decrypt the key-encapsulated ciphertext and the encrypted hybrid key-encapsulated private key according to the first private key and the third private key to obtain the hybrid key-encapsulated private key; The certificate installation unit is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

9. A digital certificate issuance device based on a post-quantum hybrid algorithm, characterized in that, The device is applied to a certificate authority terminal and includes: The information receiving unit is used to receive a certificate signing request and a third public key sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The third public key is generated by the user terminal based on a post-quantum key encapsulation algorithm. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signing algorithm. The information generation unit is configured to, after successfully verifying the user identification information, use its own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate; generate a fourth public key and a fourth private key according to the asymmetric encryption algorithm, and a fifth public key and a fifth private key according to the post-quantum key encapsulation algorithm; use the fourth public key and the fifth public key as hybrid key encapsulation public keys, and use the fourth private key and the fifth private key as hybrid key encapsulation private keys; use its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information to generate a hybrid key encapsulation certificate; use the first public key and the third public key to perform key encapsulation operations to obtain key encapsulation ciphertext and a symmetric key; and use... The symmetric key encrypts the hybrid key encapsulated private key to obtain an encrypted hybrid key encapsulated private key; the hybrid key signing certificate, hybrid key encapsulation certificate, key encapsulation ciphertext, and encrypted hybrid key encapsulated private key are sent to the user terminal, so that the user terminal can decrypt the key encapsulation ciphertext and the encrypted hybrid key encapsulated private key according to the first private key corresponding to the first public key and the third private key corresponding to the third public key to obtain the hybrid key encapsulated private key, and install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulated private key, the second private key corresponding to the first private key and the second public key.

10. An electronic device, characterized in that, include: Processor and memory; The processor is connected to a memory, wherein the memory is used to store a computer program, and the processor is used to invoke the computer program to perform the method as described in any one of claims 1-4 or 5-7.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions that, when executed by a processor, perform the method as described in any one of claims 1-4 or 5-7.