Digital certificate issuing method based on double certificate system and related device

By using a digital certificate issuance method based on a dual-certificate system, a hybrid public key is generated using asymmetric and post-quantum key signature algorithms, and hybrid key signature certificates and hybrid key encapsulation certificates are issued. This solves the security problem of traditional encryption algorithms in quantum computing environments and enables the legitimate use of certificates and improves information security in quantum-resistant algorithm scenarios.

CN120110678BActive Publication Date: 2026-07-03ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD
Filing Date
2025-02-28
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Traditional public-key encryption algorithms are easily cracked in a quantum computing environment. Existing secure communication and digital signature protocols are at risk of being compromised, and traditional certificates cannot verify public keys resistant to quantum algorithms, making them vulnerable to man-in-the-middle attacks.

Method used

A digital certificate issuance method based on a dual-certificate system is adopted. An asymmetric encryption algorithm is used to generate a first public key and a private key, and a post-quantum key signature algorithm is combined to generate a second public key and a private key, generating a hybrid public key. A hybrid key signature certificate and a hybrid key encapsulation certificate are issued through a certificate authority to ensure the legitimate use of the certificate in quantum-resistant algorithm scenarios.

Benefits of technology

This enables the legitimate use of certificates in a quantum computing environment, improving information security and ensuring the confidentiality and integrity of communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110678B_ABST
    Figure CN120110678B_ABST
Patent Text Reader

Abstract

Embodiments of the application disclose a digital certificate issuing method and related device based on a double-certificate system, a user terminal generates a first and a second public-private key pair according to an asymmetric encryption algorithm and a post-quantum key signature algorithm respectively; the first and the second public key are taken as a hybrid public key to generate a certificate signature request together with user identification information, and the certificate signature request is sent to a certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key and an encrypted symmetric key according to the certificate signature request; the user terminal decrypts the encrypted hybrid key encapsulation private key and the symmetric key according to the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed and bound with the corresponding private key, so that the hybrid key signature certificate and the hybrid key encapsulation certificate are issued, the legal use of the certificate in a quantum algorithm resistant scenario is ensured, and the information security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of post-quantum cryptography, and in particular to a digital certificate issuance method and related apparatus based on a dual-certificate system. Background Technology

[0002] The development of quantum computing poses a significant potential threat to traditional encryption algorithms. The mathematical problems upon which traditional public-key encryption algorithms such as RSA (Rivest-Shamir-Adleman) and ECC (Elliptic Curve Cryptography) rely may become easily solvable in the face of quantum computers. Once quantum computers achieve sufficient computing power, currently widely used encryption systems based on these algorithms will be at risk of being cracked. For example, in a quantum computing environment, the encryption key of the RSA algorithm may be rapidly fragmented, causing encrypted data to lose its confidentiality. This means that many existing secure communication, digital signature, and key exchange protocols need to be re-examined and improved to meet the challenges of the quantum computing era.

[0003] Post-quantum cryptography (PQC) offers an effective solution to the threat posed by quantum computing to traditional encryption algorithms. PQC is based on novel mathematical problems that remain highly secure against quantum computers. Its main advantage lies in providing reliable encryption protection in the quantum computing era. Unlike traditional encryption algorithms, PQC's security does not rely on mathematical problems easily cracked by quantum computers. For example, lattice-based cryptography, encoding-based cryptography, and multivariate polynomial-based cryptography are important research directions in PQC. However, traditional public key certificates do not contain the PQC algorithm's public key. In scenarios using classical + quantum-resistant hybrid algorithms, the quantum-resistant public key cannot be verified, making it vulnerable to man-in-the-middle attacks. Summary of the Invention

[0004] This application provides a digital certificate issuance method and related apparatus based on a dual-certificate system, which can issue hybrid key signature certificates and hybrid key encapsulation certificates, ensuring the legitimate use of certificates in quantum algorithm-resistant scenarios and improving information security.

[0005] The first aspect of this application provides a digital certificate issuance method based on a dual-certificate system, applied to a user terminal, the method comprising:

[0006] A first public key and a first private key are generated according to an asymmetric encryption algorithm, and a second public key and a second private key are generated according to a post-quantum key signature algorithm;

[0007] Use the first public key and the second public key as a hybrid public key;

[0008] A certificate signing request is generated based on the hybrid public key and user identification information, and the certificate signing request is sent to the certificate authority terminal.

[0009] Receive the hybrid key signature certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key generated and sent by the certificate authorization center terminal according to the certificate signature request;

[0010] The encrypted hybrid key-encapsulated private key and the encrypted symmetric key are decrypted using the first private key to obtain the hybrid key-encapsulated private key.

[0011] Install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0012] Optionally, the step of receiving the hybrid key signing certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key generated and sent by the certificate authorization center terminal according to the certificate signing request includes:

[0013] The system receives a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key from the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The encrypted symmetric key is obtained by the certificate authority terminal encrypting the symmetric key using the first public key. The hybrid key encapsulation public key includes a third public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a third private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth private key generated according to the post-quantum key encapsulation algorithm.

[0014] Optionally, the step of decrypting the encrypted hybrid key-encapsulated private key and the encrypted symmetric key based on the first private key to obtain the hybrid key-encapsulated private key includes:

[0015] The encrypted symmetric key is decrypted using the first private key to obtain the symmetric key;

[0016] The symmetric key is used to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0017] Optionally, binding the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key includes:

[0018] The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the third private key and the fourth private key.

[0019] Optionally, the method further includes:

[0020] When installing an intermediate certificate, if the certificate authority terminal is a root certificate authority terminal, then the intermediate certificate is issued by the root certificate authority terminal; if the certificate authority terminal is not a root certificate authority terminal, then the intermediate certificate is issued by the next higher-level certificate authority terminal.

[0021] A second aspect of this application provides a digital certificate issuance method based on a dual-certificate system, applied to a certificate authority terminal, the method comprising:

[0022] The system receives a certificate signing request sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signature algorithm.

[0023] Based on the certificate signing request, a hybrid key signing certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key are generated and sent to the user terminal. This allows the user terminal to decrypt the encrypted hybrid key encapsulation private key and the encrypted symmetric key using the first private key corresponding to the first public key, thereby obtaining the hybrid key encapsulation private key. The user terminal also installs the hybrid key signing certificate and the hybrid key encapsulation certificate and binds them to the hybrid key encapsulation private key, the first private key, and the second public key corresponding to the second private key.

[0024] Optionally, generating a hybrid key signing certificate, a hybrid key encapsulated certificate, an encrypted hybrid key encapsulated private key, and an encrypted symmetric key based on the certificate signing request includes:

[0025] After successfully verifying the user identification information, the user uses their own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate.

[0026] A third public key and a third private key are generated according to the asymmetric encryption algorithm, and a fourth public key and a fourth private key are generated according to the post-quantum key encapsulation algorithm;

[0027] The third public key and the third public key are used as a hybrid key to encapsulate the public key, and the third private key and the fourth private key are used as a hybrid key to encapsulate the private key;

[0028] Use your own hybrid signature private key to sign the hybrid key-encapsulated public key and the user identification information to generate a hybrid key-encapsulated certificate;

[0029] The encrypted private key encapsulated in the hybrid key is obtained by encrypting the private key encapsulated in the hybrid key using a symmetric key.

[0030] The first public key is used to encrypt the symmetric key to obtain the encrypted symmetric key.

[0031] Optionally, the user terminal decrypts the encrypted symmetric key using the first private key corresponding to the first public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0032] Optionally, the user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the third private key and the fourth private key.

[0033] A third aspect of this application provides a digital certificate issuance device based on a dual-certificate system, applied to a user terminal, the device comprising:

[0034] A key generation unit is used to generate a first public key and a first private key according to an asymmetric encryption algorithm, and to generate a second public key and a second private key according to a post-quantum key signature algorithm.

[0035] A key processing unit is configured to use the first public key and the second public key as a hybrid public key;

[0036] The information generation unit is used to generate a certificate signing request based on the hybrid public key and user identification information, and send the certificate signing request to the certificate authorization center terminal;

[0037] The information receiving unit is used to receive the hybrid key signing certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key generated and sent by the certificate authorization center terminal according to the certificate signing request;

[0038] The information decryption unit is used to decrypt the encrypted hybrid key-encapsulated private key and the encrypted symmetric key according to the first private key to obtain the hybrid key-encapsulated private key.

[0039] The certificate installation unit is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0040] A fourth aspect of this application provides a digital certificate issuance device based on a dual-certificate system, applied to a certificate authorization center terminal, the device comprising:

[0041] The information receiving unit is used to receive a certificate signing request sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signature algorithm.

[0042] The information generation unit is configured to generate a hybrid key signing certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key according to the certificate signing request, and send them to the user terminal. This enables the user terminal to decrypt the encrypted hybrid key encapsulation private key and the encrypted symmetric key according to the first private key corresponding to the first public key, thereby obtaining the hybrid key encapsulation private key. The user terminal also installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second public key corresponding to the second private key.

[0043] A fifth aspect of this application provides an electronic device, including: a processor and a memory;

[0044] The processor is connected to a memory, wherein the memory is used to store computer programs and the processor is used to invoke the computer programs to execute the methods as described in the first or second aspect of the embodiments of this application.

[0045] A sixth aspect of this application provides a computer-readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a processor, perform the methods described in the first or second aspect of this application.

[0046] In this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, and generates a second public key and a second private key according to a post-quantum key signature algorithm; the first public key and the second public key are used as a hybrid public key; a certificate signing request is generated based on the hybrid public key and user identification information, and the certificate signing request is sent to the certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key based on the certificate signing request, and sends them to the user terminal; the user terminal decrypts the encrypted hybrid key encapsulation private key and the encrypted symmetric key based on the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed, and the hybrid key signature certificate and the hybrid key encapsulation certificate are bound to the hybrid key encapsulation private key, the first private key, and the second private key, thereby enabling the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios, and improving information security. Attached Figure Description

[0047] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 A schematic diagram of the operating environment of a digital certificate issuance method based on a dual-certificate system provided in an embodiment of this application is shown;

[0049] Figure 2 A flowchart illustrating a digital certificate issuance method based on a dual-certificate system according to an embodiment of this application is shown.

[0050] Figure 3 A flowchart illustrating a digital certificate issuance method based on a dual-certificate system provided in another embodiment of this application is shown.

[0051] Figure 4 A flowchart illustrating a digital certificate issuance method based on a dual-certificate system provided in another embodiment of this application is shown.

[0052] Figure 5 This illustration shows a schematic diagram of the structure of a digital certificate issuance device based on a dual-certificate system according to an embodiment of this application;

[0053] Figure 6This illustration shows a schematic diagram of a digital certificate issuance device based on a dual-certificate system according to another embodiment of this application;

[0054] Figure 7 A schematic diagram of the structure of a computer device provided in one embodiment of this application is shown. Detailed Implementation

[0055] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0056] Please refer to Figure 1 This diagram illustrates the operating environment of a digital certificate issuance method based on a dual-certificate system according to an embodiment of this application. The operating environment may include a user terminal 10 and a Certificate Authority (CA) terminal 20.

[0057] User terminal 10 includes, but is not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, in-vehicle terminals, game consoles, e-book readers, multimedia playback devices, wearable devices, and other electronic devices. Application clients can be installed on terminal 10.

[0058] CA Terminal 20 is a third-party terminal responsible for managing and issuing certificates. It possesses sufficient authority and is trusted and recognized by all industries and the public. The functions of CA Terminal 20 include: verifying website trustworthiness (for HTTPS), generating and storing the root certificate file (ca.crt) and the corresponding private key file (ca.key).

[0059] The relationship between user terminal 10 and CA terminal 20 is as follows: User terminal 10 has a trust store containing the CAs it trusts. The certificate of user terminal 10 is signed by the CA at a leaf position in the certificate tree. The end-user's certificate is signed by the Certificate Authority at a leaf position in the tree; each Certificate Authority also has a certificate signed by its parent Certificate Authority.

[0060] Optionally, user terminal 10 and CA terminal 20 can communicate with each other via network 30. User terminal 10 and CA terminal 20 can be directly or indirectly connected via wired or wireless communication, which is not limited herein.

[0061] Please refer to Figure 2This document illustrates a flowchart of a digital certificate issuance method based on a dual-certificate system according to an embodiment of this application. This method can be applied to computer devices, which refer to electronic devices with data computing and processing capabilities. For example, the executing entity for each step can be... Figure 1 The user terminal 10 shown. This method may include the following steps:

[0062] Step 201: Generate a first public key and a first private key according to the asymmetric encryption algorithm, and generate a second public key and a second private key according to the post-quantum key signature algorithm.

[0063] Asymmetric encryption algorithms are a type of encryption method that requires two keys: a public key (pk) and a private key (sk). These two keys are different but mathematically related. In asymmetric encryption, data is encrypted using the public key, and only the corresponding private key can decrypt it. Similarly, digital signatures are created using the private key, and only the corresponding public key can verify the validity of the signature. Common asymmetric encryption algorithms include RSA, ECC, and Chinese national cryptographic algorithms.

[0064] Post-quantum digital signatures are a type of modern public-key cryptographic digital signature that can resist known quantum computing attacks. Currently, NIST has selected several post-quantum digital signature algorithms, such as Dilithium, Falcon, SPHINCS+, and Rainbow.

[0065] In this process, the private key and public key are usually generated simultaneously and through an encryption algorithm. The public key cannot be derived from the private key, and the private key cannot be derived from the public key.

[0066] Step 202: Use the first public key and the second public key as a hybrid public key.

[0067] Step 203: Generate a certificate signing request based on the hybrid public key and user identification information, and send the certificate signing request to the certificate authority terminal.

[0068] The Certificate Signing Request (CSR) is a file generated by the entity requesting the certificate (such as user terminal 10 in this application). It contains the applicant's public key and user identification information, such as country / region code, organization name, organizational unit, and common name, to identify the user. The CSR is primarily used to request a signature from the Certificate Authority (CA) during the digital certificate authentication process to obtain a trusted digital certificate.

[0069] Step 204: Receive the hybrid key signing certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key generated and sent by the certificate authorization center terminal according to the certificate signing request.

[0070] Digital certificates can be categorized into signature certificates and encryption certificates. Signature certificates are used to sign user information, ensuring its validity and non-repudiation; examples include hybrid key signature certificates containing more than one key. Encryption certificates are used to encrypt user-transmitted information, ensuring its confidentiality and integrity; examples include hybrid key encapsulation certificates containing more than one key. A symmetric key is an encryption key used in symmetric encryption algorithms. In symmetric encryption, the same key is used for both encryption and decryption.

[0071] Specifically, receiving the hybrid key signature certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key generated and sent by the certificate authorization center terminal according to the certificate signature request includes:

[0072] The system receives a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key from the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The encrypted symmetric key is obtained by the certificate authority terminal encrypting the symmetric key using the first public key. The hybrid key encapsulation public key includes a third public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a third private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth private key generated according to the post-quantum key encapsulation algorithm.

[0073] Post-quantum key encapsulation algorithms are new encryption algorithms developed to defend against the threat posed by quantum computers to currently widely used public-key cryptosystems. For example, the Kyber algorithm is a key encapsulation mechanism that satisfies IND-CCA2 security; its security relies on the difficulty of the MLWE problem and is constructed using a two-phase approach. The SIKE algorithm is a PQC algorithm that implements post-quantum key encapsulation based on the Supersingular Isogeny Diffie-Hellman (SIDH) key exchange protocol.

[0074] Step 205: Decrypt the encrypted hybrid key-encapsulated private key and the encrypted symmetric key using the first private key to obtain the hybrid key-encapsulated private key.

[0075] Specifically, the step of decrypting the encrypted hybrid key-encapsulated private key and the encrypted symmetric key using the first private key to obtain the hybrid key-encapsulated private key includes:

[0076] The encrypted symmetric key is decrypted using the first private key to obtain the symmetric key;

[0077] The symmetric key is used to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0078] Step 206: Install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0079] Specifically, binding the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second private key includes:

[0080] The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the third private key and the fourth private key.

[0081] Furthermore, the method also includes:

[0082] When installing an intermediate certificate, if the certificate authority terminal is a root certificate authority terminal, then the intermediate certificate is issued by the root certificate authority terminal; if the certificate authority terminal is not a root certificate authority terminal, then the intermediate certificate is issued by the next higher-level certificate authority terminal.

[0083] The intermediate certificate may be sent to the user terminal by the certificate authority terminal, or it may be downloaded by the user terminal from the address provided by the certificate authority terminal; there is no limitation on this.

[0084] As can be seen, in this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, and generates a second public key and a second private key according to a post-quantum key signature algorithm; the first public key and the second public key are used as a hybrid public key; a certificate signing request is generated based on the hybrid public key and user identification information, and the certificate signing request is sent to the certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key based on the certificate signing request, and sends them to the user terminal; the user terminal decrypts the encrypted hybrid key encapsulation private key and the encrypted symmetric key based on the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed, and the hybrid key signature certificate and the hybrid key encapsulation certificate are bound to the hybrid key encapsulation private key, the first private key, and the second private key, thereby enabling the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios, and improving information security.

[0085] Please refer to Figure 3 This illustration shows a flowchart of a digital certificate issuance method based on a dual-certificate system according to another embodiment of this application. This method can be applied to computer devices, which refer to electronic devices with data computing and processing capabilities. For example, the executing entity for each step can be... Figure 1 The certificate authority terminal 20 shown. This method may include the following steps:

[0086] Step 301: Receive a certificate signing request sent by the user terminal. The certificate signing request is generated by the user terminal based on the hybrid public key and user identification information. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signature algorithm.

[0087] Step 302: Generate a hybrid key signing certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key according to the certificate signing request, and send them to the user terminal. This allows the user terminal to decrypt the encrypted hybrid key encapsulation private key and the encrypted symmetric key using the first private key corresponding to the first public key to obtain the hybrid key encapsulation private key. The user terminal also installs the hybrid key signing certificate and the hybrid key encapsulation certificate, and binds the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second public key corresponding to the second private key.

[0088] Specifically, the step of generating a hybrid key signing certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key based on the certificate signing request includes:

[0089] After successfully verifying the user identification information, the user uses their own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate.

[0090] A third public key and a third private key are generated according to the asymmetric encryption algorithm, and a fourth public key and a fourth private key are generated according to the post-quantum key encapsulation algorithm;

[0091] The third public key and the third public key are used as a hybrid key to encapsulate the public key, and the third private key and the fourth private key are used as a hybrid key to encapsulate the private key;

[0092] Use your own hybrid signature private key to sign the hybrid key-encapsulated public key and the user identification information to generate a hybrid key-encapsulated certificate;

[0093] The encrypted private key encapsulated in the hybrid key is obtained by encrypting the private key encapsulated in the hybrid key using a symmetric key.

[0094] The first public key is used to encrypt the symmetric key to obtain the encrypted symmetric key.

[0095] Specifically, the user terminal decrypts the encrypted symmetric key using the first private key corresponding to the first public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0096] Specifically, the user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the third private key and the fourth private key.

[0097] It should be noted that the steps of the certificate authorization center terminal-side method embodiment are described in detail below. Figure 2 The user terminal-side method embodiment shown will not be described again here.

[0098] In this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, and generates a second public key and a second private key according to a post-quantum key signature algorithm; the first public key and the second public key are used as a hybrid public key; a certificate signing request is generated based on the hybrid public key and user identification information, and the certificate signing request is sent to the certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key based on the certificate signing request, and sends them to the user terminal; the user terminal decrypts the encrypted hybrid key encapsulation private key and the encrypted symmetric key based on the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed, and the hybrid key signature certificate and the hybrid key encapsulation certificate are bound to the hybrid key encapsulation private key, the first private key, and the second private key, thereby enabling the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios, and improving information security.

[0099] Please refer to Figure 4 This illustration shows a flowchart of a digital certificate issuance method based on a dual-certificate system according to another embodiment of this application. The method may include the following steps:

[0100] Step 401: User terminal 10 generates a first public key and a first private key according to an asymmetric encryption algorithm, and generates a second public key and a second private key according to a post-quantum key signature algorithm.

[0101] Step 402: User terminal 10 uses the first public key and the second public key as a hybrid public key.

[0102] Step 403: User terminal 10 generates a certificate signing request based on the hybrid public key and user identification information.

[0103] Step 404: User terminal 10 sends the certificate signing request to certificate authority terminal 20.

[0104] Step 405: The authorization center terminal 20 verifies the user identification information.

[0105] Step 406: If the verification is successful, the authorization center terminal 20 uses its own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate.

[0106] Step 407: The authorization center terminal 20 generates a third public key and a third private key according to the asymmetric encryption algorithm, and a fourth public key and a fourth private key according to the post-quantum key encapsulation algorithm.

[0107] Step 408: The authorization center terminal 20 encapsulates the third public key and the third public key as a hybrid key to encapsulate the public key, and encapsulates the third private key and the fourth private key as a hybrid key to encapsulate the private key.

[0108] Step 409: The authorization center terminal 20 uses its own hybrid signature private key to sign the hybrid key encapsulated public key and the user identification information to generate a hybrid key encapsulated certificate.

[0109] Step 410: The authorization center terminal 20 uses a symmetric key to encrypt the private key encapsulated in the hybrid key to obtain the encrypted private key encapsulated in the hybrid key.

[0110] Step 411: The authorization center terminal 20 uses the first public key to encrypt the symmetric key to obtain the encrypted symmetric key.

[0111] Step 412: The authorization center terminal 20 sends the hybrid key signing certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key to the user terminal 10.

[0112] Step 413: User terminal 10 decrypts the encrypted symmetric key using the first private key to obtain the symmetric key.

[0113] Step 414: User terminal 10 uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

[0114] Step 415: User terminal 10 installs the hybrid key signing certificate and the hybrid key encapsulation certificate.

[0115] Step 416: User terminal 10 binds the hybrid key signing certificate to the first private key and the second private key, and binds the hybrid key encapsulation certificate to the third private key and the fourth private key.

[0116] It should be noted that the steps of this method embodiment are described in detail below. Figure 2 The user terminal side method embodiment shown and Figure 3 The certificate authorization center terminal-side method embodiment shown will not be described again here.

[0117] In this embodiment, the user terminal generates a first public key and a first private key according to an asymmetric encryption algorithm, and generates a second public key and a second private key according to a post-quantum key signature algorithm; the first public key and the second public key are used as a hybrid public key; a certificate signing request is generated based on the hybrid public key and user identification information, and the certificate signing request is sent to the certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key based on the certificate signing request, and sends them to the user terminal; the user terminal decrypts the encrypted hybrid key encapsulation private key and the encrypted symmetric key based on the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed, and the hybrid key signature certificate and the hybrid key encapsulation certificate are bound to the hybrid key encapsulation private key, the first private key, and the second private key, thereby enabling the issuance of the hybrid key signature certificate and the hybrid key encapsulation certificate, ensuring the legitimate use of certificates in quantum-resistant algorithm scenarios, and improving information security.

[0118] Figure 5 This illustration shows a schematic diagram of a digital certificate issuance device based on a dual-certificate system according to an embodiment of this application. Applied to a user terminal, the device includes:

[0119] The key generation unit 501 is used to generate a first public key and a first private key according to an asymmetric encryption algorithm, and to generate a second public key and a second private key according to a post-quantum key signature algorithm.

[0120] The key processing unit 502 is configured to use the first public key and the second public key as a hybrid public key;

[0121] The information generation unit 503 is used to generate a certificate signing request based on the hybrid public key and user identification information, and send the certificate signing request to the certificate authorization center terminal.

[0122] Information receiving unit 504 is used to receive the hybrid key signing certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key and encrypted symmetric key generated and sent by the certificate authorization center terminal according to the certificate signing request;

[0123] The information decryption unit 505 is used to decrypt the encrypted hybrid key-encapsulated private key and the encrypted symmetric key according to the first private key to obtain the hybrid key-encapsulated private key.

[0124] The certificate installation unit 506 is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

[0125] Figure 6 A schematic diagram of a digital certificate issuance device based on a dual-certificate system according to another embodiment of this application is shown. Applied to a certificate authority terminal, the device includes:

[0126] The information receiving unit 601 is used to receive a certificate signing request sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signature algorithm.

[0127] The information generation unit 602 is configured to generate a hybrid key signing certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key according to the certificate signing request, and send them to the user terminal. This enables the user terminal to decrypt the encrypted hybrid key encapsulation private key and the encrypted symmetric key according to the first private key corresponding to the first public key to obtain the hybrid key encapsulation private key, install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second public key corresponding to the second private key.

[0128] Figure 7 The diagram illustrates the structure of a computer device according to an embodiment of this application, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the functions of the computer system based on the dual-certificate system digital certificate issuance method in any of the above embodiments.

[0129] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a computer, causes the computer to perform the functions of the computer system of the digital certificate issuance method based on the dual-certificate system in any of the above embodiments.

[0130] This application also provides a computer program product containing instructions that, when executed by a computer, cause the computer to perform the functions of the computer system of the digital certificate issuance method based on the dual-certificate system in any of the above embodiments.

[0131] It is understood that the specific examples in this application are only intended to help those skilled in the art better understand the implementation methods of this application, and are not intended to limit the scope of the invention.

[0132] It is understood that in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not limit the implementation process of the embodiments of this application in any way.

[0133] It is understood that the various implementation methods described in this application can be implemented individually or in combination, and the implementation methods in this application are not limited in this respect.

[0134] Unless otherwise stated, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The term "and / or" as used in this application includes any and all combinations of one or more of the associated listed items. The singular forms "a," "the," and "the" as used in the embodiments of this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0135] It is understood that the processor in the embodiments of this application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by the integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory; the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0136] It is understood that the memory in the embodiments of this application may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Specifically, non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM). It should be noted that the memory in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0137] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0138] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the aforementioned method implementations, and will not be repeated here.

[0139] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0140] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0141] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0142] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0143] The above are merely specific embodiments of this application, but the scope of protection of this invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this invention should be determined by the scope of the claims.

Claims

1. A digital certificate issuing method based on a dual certificate system, characterized by, Applied to a user terminal, the method includes: A first public key and a first private key are generated according to an asymmetric encryption algorithm, and a second public key and a second private key are generated according to a post-quantum key signature algorithm; Use the first public key and the second public key as a hybrid public key; A certificate signing request is generated based on the hybrid public key and user identification information, and the certificate signing request is sent to the certificate authority terminal. The system receives a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key from the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The encrypted symmetric key is obtained by the certificate authority terminal encrypting the symmetric key using the first public key. The hybrid key encapsulation public key includes a third public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a third private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth private key generated according to the post-quantum key encapsulation algorithm. The encrypted hybrid key-encapsulated private key and the encrypted symmetric key are decrypted using the first private key to obtain the hybrid key-encapsulated private key. Install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

2. The method of claim 1, wherein, The step of decrypting the encrypted hybrid key-encapsulated private key and the encrypted symmetric key based on the first private key to obtain the hybrid key-encapsulated private key includes: The encrypted symmetric key is decrypted using the first private key to obtain the symmetric key; The symmetric key is used to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

3. The method according to claim 1 or 2, characterized in that, The step of binding the hybrid key signing certificate and the hybrid key encapsulation certificate with the hybrid key encapsulation private key, the first private key, and the second private key includes: The hybrid key signing certificate is bound to the first private key and the second private key, and the hybrid key encapsulation certificate is bound to the third private key and the fourth private key.

4. The method of claim 1, wherein, The method further includes: When installing an intermediate certificate, if the certificate authority terminal is a root certificate authority terminal, then the intermediate certificate is issued by the root certificate authority terminal; if the certificate authority terminal is not a root certificate authority terminal, then the intermediate certificate is issued by the next higher-level certificate authority terminal.

5. A digital certificate issuing method based on a dual certificate system, characterized by, Applied to a certificate authority terminal, the method includes: The system receives a certificate signing request sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signature algorithm. After successfully verifying the user identification information, the user uses their own hybrid signature private key to sign the certificate signing request and generate a hybrid key signature certificate. A third public key and a third private key are generated according to the asymmetric encryption algorithm, and a fourth public key and a fourth private key are generated according to the post-quantum key encapsulation algorithm; The third public key and the fourth public key are used as a hybrid key to encapsulate the public key, and the third private key and the fourth private key are used as a hybrid key to encapsulate the private key; Use your own hybrid signature private key to sign the hybrid key-encapsulated public key and the user identification information to generate a hybrid key-encapsulated certificate; The encrypted private key encapsulated in the hybrid key is obtained by encrypting the private key encapsulated in the hybrid key using a symmetric key. The first public key is used to encrypt the symmetric key to obtain the encrypted symmetric key; The hybrid key signing certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key are sent to the user terminal, so that the user terminal can decrypt the encrypted hybrid key encapsulation private key and the encrypted symmetric key according to the first private key corresponding to the first public key to obtain the hybrid key encapsulation private key, and install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second public key corresponding to the second private key.

6. The method of claim 5, wherein, The user terminal decrypts the encrypted symmetric key using the first private key corresponding to the first public key to obtain the symmetric key; and uses the symmetric key to decrypt the encrypted hybrid key-encapsulated private key to obtain the hybrid key-encapsulated private key.

7. The method according to claim 5 or 6, characterized in that, The user terminal binds the hybrid key signing certificate to the second private key corresponding to the first private key and the second public key, and binds the hybrid key encapsulation certificate to the third private key and the fourth private key.

8. A digital certificate issuance device based on a dual-certificate system, characterized in that, The device, applied to a user terminal, includes: A key generation unit is used to generate a first public key and a first private key according to an asymmetric encryption algorithm, and to generate a second public key and a second private key according to a post-quantum key signature algorithm. A key processing unit is configured to use the first public key and the second public key as a hybrid public key; The information generation unit is used to generate a certificate signing request based on the hybrid public key and user identification information, and send the certificate signing request to the certificate authorization center terminal; The information receiving unit is configured to receive a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key, and an encrypted symmetric key sent by the certificate authority terminal. The hybrid key signature certificate is generated by the certificate authority terminal signing the certificate signing request using its own hybrid signature private key after successfully verifying the user identification information. The hybrid key encapsulation certificate is generated by the certificate authority terminal signing the hybrid key encapsulation public key using its own hybrid signature private key. The encrypted hybrid key encapsulation private key is obtained by the certificate authority terminal encrypting the hybrid key encapsulation private key using a symmetric key. The encrypted symmetric key is obtained by the certificate authority terminal encrypting the symmetric key using the first public key. The hybrid key encapsulation public key includes a third public key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth public key generated according to the post-quantum key encapsulation algorithm. The hybrid key encapsulation private key includes a third private key generated by the certificate authority terminal according to the asymmetric encryption algorithm and a fourth private key generated according to the post-quantum key encapsulation algorithm. The information decryption unit is used to decrypt the encrypted hybrid key-encapsulated private key and the encrypted symmetric key according to the first private key to obtain the hybrid key-encapsulated private key. The certificate installation unit is used to install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key and the second private key.

9. A digital certificate issuing apparatus based on a two-certificate system, characterized by comprising: The device is applied to a certificate authority terminal and includes: The information receiving unit is used to receive a certificate signing request sent by a user terminal. The certificate signing request is generated by the user terminal based on a hybrid public key and user identification information. The hybrid public key includes a first public key generated by the user terminal based on an asymmetric encryption algorithm and a second public key generated based on a post-quantum key signature algorithm. The information generation unit is configured to, after successfully verifying the user identification information, use its own hybrid signature private key to sign the certificate signing request to generate a hybrid key signature certificate; generate a third public key and a third private key according to the asymmetric encryption algorithm, and generate a fourth public key and a fourth private key according to the post-quantum key encapsulation algorithm; use the third public key and the fourth public key as the hybrid key encapsulation public key, and use the third private key and the fourth private key as the hybrid key encapsulation private key; use its own hybrid signature private key to sign the hybrid key encapsulation public key and the user identification information to generate a hybrid key encapsulation certificate; and encrypt the hybrid key encapsulation private key using a symmetric key to obtain the encrypted hybrid key encapsulation certificate. Install the private key; encrypt the symmetric key using the first public key to obtain the encrypted symmetric key; send the hybrid key signing certificate, hybrid key encapsulation certificate, encrypted hybrid key encapsulation private key, and encrypted symmetric key to the user terminal, so that the user terminal can decrypt the encrypted hybrid key encapsulation private key and the encrypted symmetric key according to the first private key corresponding to the first public key to obtain the hybrid key encapsulation private key, and install the hybrid key signing certificate and the hybrid key encapsulation certificate, and bind the hybrid key signing certificate and the hybrid key encapsulation certificate to the hybrid key encapsulation private key, the first private key, and the second public key corresponding to the second private key.

10. An electronic device, comprising: include: Processor and memory; The processor is connected to a memory, wherein the memory is used to store a computer program, and the processor is used to invoke the computer program to perform the method as described in any one of claims 1-4 or 5-7.

11. A computer readable storage medium characterized by, The computer-readable storage medium stores a computer program, the computer program including program instructions that, when executed by a processor, perform the method as described in any one of claims 1-4 or 5-7.

Citation Information

Patent Citations

  • Signing and issuing method, device, system and equipment for post-quantum and national secret hybrid double certificates

    CN118944894A