A Quantum-Resistant Secure Data Transmission Authentication Method Based on SLH-DSA

The SLH-DSA algorithm addresses quantum vulnerabilities in identity authentication and data encryption by providing lightweight, efficient, and secure data transmission with dynamic key updates, suitable for resource-constrained devices in industrial IoT and edge computing.

CN120110810BActive Publication Date: 2025-07-15CHENGDU MOJIA INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510593697.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-07-15
Estimated Expiration
2045-05-09

AI Technical Summary

Technical Problem

The existing identity authentication and data encryption methods are insufficient in the face of quantum computing threats, have large computing overhead, and lack a flexible session key update mechanism, making it difficult to deploy efficiently on resource-constrained devices, especially in edge computing and low-power device scenarios, which are difficult to meet the security and efficiency requirements.

Method used

The anti-quantum-security data transmission authentication method based on SLH-DSA is adopted, and the system public parameters are issued through the certificate proxy CA, the terminal equipment obtains the anti-quantum-security identity certificate, builds a secure communication connection and generates a shared key, and data encryption is encrypted in combination with the National Secret SM4 algorithm, and dynamic session key update is supported.

Benefits of technology

It realizes high-security identity authentication and data transmission in a quantum computing environment, reduces computing overhead, supports fast identity authentication and key establishment of resource-constrained devices, reduces the risk of key leakage, and is suitable for scenarios such as industrial Internet of Things and Internet of Vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110810B_ABST
    Figure CN120110810B_ABST
Patent Text Reader

Abstract

The present invention discloses a quantum-resistant secure data transmission authentication method based on SLH-DSA, aiming to address the communication security challenges in the quantum computing environment. During the registration phase, the device locally generates a key pair and applies for a quantum-resistant identity certificate from the certificate proxy. In the authentication phase, users exchange identity certificates and key parameters to achieve identity verification and negotiate a shared key. In the data transmission phase, the shared key is used to dynamically derive a session key, and the national cryptographic symmetric encryption algorithm SM4 is combined to encrypt the data, and a quantum-resistant signature algorithm is used for integrity verification. This method takes into account security, lightweightness, and performance, has the ability to resist quantum attacks and forward security, is applicable to application scenarios with high requirements for data security such as industrial Internet of Things and smart grid, and has good application prospects and promotion value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular, to a quantum-resistant secure data transmission authentication method based on SLH-DSA. Background Art

[0002] In emerging application scenarios such as industrial Internet of Things, smart grid, Internet of Vehicles, and edge computing, a large number of users and devices need to frequently interact data through the network. Therefore, how to ensure the security of data and the credibility of identity information during the communication process has become a key issue to be solved urgently. Currently, traditional identity authentication and data encryption methods mostly rely on Elliptic Curve Digital Signature Algorithm (ECDSA) and symmetric encryption algorithms such as AES. Although these methods have certain security guarantees under the classical computing model, with the continuous evolution of quantum computing technology, traditional public key encryption and digital signature algorithms are facing the potential risk of being cracked. In addition, some existing security authentication protocols have problems such as large computational overhead and low certificate verification efficiency, and it is difficult to be efficiently deployed on resource-constrained terminal devices, further restricting their wide application in practical scenarios. On the other hand, existing data communication protocols generally lack a flexible session key update mechanism. Long-term use of static keys is likely to increase the risk of key leakage, thereby threatening the security of the entire communication system. At the same time, not only the security of communication needs to be ensured during the data transmission process, but also the efficiency and computational overhead need to be considered. Especially in scenarios such as edge computing and low-power devices, there are higher requirements for the lightweight design of encryption and decryption algorithms.

[0003] Existing studies have proposed various secure data transmission and authentication schemes in application scenarios such as smart grid, 5G network, edge computing, and industrial control, covering various cryptographic algorithms such as symmetric encryption, public key encryption, blockchain, and national cryptographic algorithms. These schemes have improved the authentication efficiency of the system and the security of data transmission to a certain extent. However, existing studies generally lack the ability to cope with future quantum threats, especially in the design of the public key system, they still rely on traditional signature algorithms such as ECDSA that are vulnerable to quantum algorithm attacks; in addition, existing studies have not introduced an effective dynamic key update mechanism, and the long-term use of static keys makes the system vulnerable to attacks such as key leakage and session replay; moreover, there are still problems such as relatively high computational overhead during the identity authentication process, making it difficult to meet the performance requirements of resource-constrained devices. Therefore, there is an urgent need to design a data security transmission authentication method that simultaneously has quantum-resistant security, efficient identity authentication, dynamic session key derivation, and lightweight data encryption to meet the higher requirements for communication security in complex environments. Summary of the Invention

[0004] The object of the present invention is to design a quantum-resistant secure data transmission authentication method based on SLH-DSA to solve the above problems.

[0005] The present invention realizes the above object through the following technical solutions:

[0006] A quantum-resistant secure data transmission authentication method based on SLH-DSA includes:

[0007] S1. The certificate proxy CA publishes system public parameters to the terminal devices that need to perform data transmission;

[0008] S2. Terminal device D i and terminal device D j both obtain quantum-resistant identity certificates from the certificate proxy CA through the system public parameters;

[0009] S3. Terminal device D i and terminal device D j build a secure communication connection through the quantum-resistant identity certificates and generate a shared key; specifically including:

[0010] S31. Terminal device D i sends an authentication request message to terminal device D j , and the authentication request message includes the quantum-resistant identity certificate, key information and related authentication parameters of terminal device D i ;

[0011] S32. Terminal device D j verifies the authentication request message of terminal device D i . If the verification fails, the communication connection is rejected and the process ends; otherwise, terminal device D j generates an authentication reply message and sends it to terminal device D i , and then enters S33; the authentication reply message includes the quantum-resistant identity certificate, key information and related authentication parameters of terminal device D j ;

[0012] S33. Terminal device D i verifies the authentication reply message of terminal device D j . If the verification fails, the communication connection is rejected and the process ends; otherwise, terminal device D i establishes a communication connection with terminal device D j , and terminal device D i and terminal device D j both generate a shared key using their own private keys and the public keys of the other party;

[0013] S4. Terminal device D i and terminal device D jDynamically generate a session key based on a shared key and perform data transmission, specifically including:

[0014] S41. The terminal device D i Sends a data communication request message to the terminal device D j ;

[0015] S42. The terminal device D j Verifies the data communication request message. If the verification fails, the session is rejected and ended; otherwise, the terminal device D j Updates the session key according to the data communication request message and sends a data communication reply message to the terminal device D i , and enters S43. The data communication reply message includes relevant information about the session key;

[0016] S43. The terminal device D i Verifies the data communication reply message. If the verification fails, data transmission is rejected and ended; if the verification passes, the terminal device D i Updates the session key according to the data communication request message, encrypts the data M to be transmitted according to the session key i to obtain the encrypted data C i , and generates a data integrity check signature. Sends the data C i and the data integrity check signature to the terminal device D j ;

[0017] S44. The terminal device D j Checks the data integrity check signature. If the check passes, the terminal device D j Decrypts the data C i to obtain the data M i ; otherwise, the encrypted data is not decrypted.

[0018] A quantum-resistant secure data transmission authentication system based on SLH-DSA, including:

[0019] A processor;

[0020] A storage; a computer program is stored in the storage. When the processor executes the computer program, it implements the above-mentioned quantum-resistant secure data transmission authentication method based on SLH-DSA. The quantum-resistant secure data transmission authentication system runs on computing devices such as desktop computers, laptop computers, palmtop computers, and cloud data centers.

[0021] The beneficial effects of the present invention are as follows:

[0022] This method constructs identity certificates with quantum resistance capabilities. Identity certificates constructed based on the post-quantum cryptographic algorithm SLH-DSA are introduced and issued by a trusted CA for communication users. While maintaining high-efficiency signature verification performance, these certificates possess excellent quantum attack resistance capabilities, effectively breaking through the bottlenecks in terms of security and verification efficiency of traditional digital certificates, and are applicable to high-security communication scenarios facing future quantum computing environments;

[0023] Lightweight and fast identity authentication and key negotiation. User identity legitimacy verification is achieved through quantum-resistant identity certificates, and the ECC algorithm is combined to complete the negotiation of shared keys. This mechanism combines security and computational efficiency. Certificate verification only requires a small number of hash operations, supports rapid identity authentication and key establishment between resource-constrained devices, effectively resists common security threats such as man-in-the-middle attacks and replay attacks, and enhances the security and real-time response capabilities of the overall authentication process;

[0024] Secure data communication supporting dynamic key updates. A mechanism for dynamically deriving session keys based on shared keys is designed. The national cryptographic SM4 symmetric encryption algorithm is combined to achieve efficient encryption and decryption of communication data, and the SLH-DSA algorithm is used to verify the integrity of messages. Through periodic or event-driven session key update strategies, the risk of long-term key leakage is effectively reduced. This mechanism has low computational overhead and high communication efficiency, and is applicable to application scenarios with high requirements for security and performance such as industrial Internet of Things and vehicle Internet of Things. Brief Description of the Drawings

[0025] Figure 1 It is a schematic diagram of a quantum-resistant secure data transmission authentication method based on SLH-DSA of the present invention;

[0026] Figure 2 It is a schematic diagram of the construction of a quantum-resistant identity certificate according to an embodiment of the present invention;

[0027] Figure 3 It is a schematic diagram of the identity authentication and shared key negotiation process according to an embodiment of the present invention;

[0028] Figure 4 It is a schematic diagram of the secure communication process according to an embodiment of the present invention. Detailed Embodiments

[0029] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Components of the embodiments of the present invention usually described and illustrated in the drawings here can be arranged and designed in various different configurations.

[0030] Accordingly, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0031] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0032] In the description of the present invention, it should be understood that the orientation or positional relationships indicated by the terms "upper", "lower", "inner", "outer", "left", "right", etc. are based on the orientation or positional relationships shown in the drawings, or the orientation or positional relationships in which the inventive product is customarily placed during use, or the orientation or positional relationships commonly understood by those skilled in the art. These are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present invention.

[0033] In addition, the terms "first", "second", etc. are only used for descriptive distinction and should not be construed as indicating or implying relative importance.

[0034] In the description of the present invention, it should also be noted that unless otherwise clearly specified and defined, terms such as "arrangement", "connection", etc. should be understood in a broad sense. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0035] The following specifically describes the embodiments of the present invention in conjunction with the accompanying drawings.

[0036] As Figure 1 , Figure 2 , Figure 3 , Figure 4 shown, a quantum-resistant secure data transmission authentication method based on SLH-DSA includes:

[0037] S1. The certificate authority CA issues system public parameters to the terminal device that needs to perform data transmission; specifically including:

[0038] S11. The certificate authority CA obtains security parameters ;

[0039] S12. The certificate proxy CA selects relevant parameters of the Elliptic Curve Cryptography (ECC) according to the security parameters The relevant parameters of the Elliptic Curve Cryptography (ECC) include the coefficients a and b of the elliptic curve, the base point G of the elliptic curve, and the finite field F p ;

[0040] S13. The certificate proxy CA sets the hash function , the key derivation function , and the public parameters of the quantum signature algorithm SLH-DSA. The public parameters of the quantum signature algorithm SLH-DSA include the Winternitz parameter w, the height s of the Merkle hash tree, and the number of layers d of the multi-layer structure, and generates the private key derivation seed sk seed , the pseudo-random function seed prf seed , and the address hash seed pub seed . The private key derivation seed sk seed is used for private key derivation, the pseudo-random function seed prf seed is used for the pseudo-random function, and the address hash seed pub seed is used for the address hash of the tree node; the hash function ; the key derivation function ;

[0041] S14. The certificate proxy CA constructs a Merkle tree according to the public parameters of the quantum signature algorithm SLH-DSA and obtains the root node root;

[0042] S15. The certificate proxy CA generates the private key sk seed and the public key PK seed according to the random private key derivation seed sk seed , the pseudo-random function seed prf CA , the address hash seed pub CA and the root node root; the private key sk CA is expressed as: sk CA = (sk seed , prf seed ), and the public key PK CA is expressed as: PK CA = (pub seed , root);

[0043] S16. The certificate proxy CA publishes the system public parameters .

[0044] The certificate proxy CA, as a trusted central entity in the system, is responsible for generating and distributing the global public parameters required for communication between terminal devices, including the parameters of the post-quantum signature algorithm SLH-DSA, the parameters related to the elliptic curve cryptosystem ECC, and the configuration specifications of the symmetric encryption algorithm SM4. The above parameters are sent to each industrial field terminal device through an open channel, providing a unified security foundation for subsequent key negotiation and identity authentication in the system; the certificate proxy CA sets an index counter N locally to index the signature parameter n, starting from 0, incrementing each time the quantum signature algorithm SLH-DSA is executed, and when the maximum value is reached, the signature parameters need to be re-initialized.

[0045] S2. Terminal device D i and terminal device D j both obtain quantum-resistant identity certificates from the certificate proxy CA through the system public parameters; specifically including:

[0046] S21. Terminal device D obtains the system public parameters;

[0047] S22. Terminal device D selects a random number sk, sk ∈ F p , and calculates the public key PK, expressed as: ;

[0048] S23. Terminal device D generates the signature key pair ssk and SPK of the quantum signature algorithm SLH-DSA;

[0049] S24. Terminal device D sends a registration request {ID, PK, SPK} to the certificate proxy CA, where ID represents the real identity information of terminal device D;

[0050] S25. The certificate proxy CA determines whether terminal device D has been registered. If so, it rejects the registration request; otherwise, the certificate proxy CA analyzes the pseudo-random value R according to the random prf seed and the indexed signature parameter n, and obtains the message digest h = H(R, root, n, ID, PK, SPK);

[0051] S26. The certificate proxy CA generates the private key of the enhanced weighted one-time signature algorithm WOTS+ through the random seed sk seed and the indexed signature parameter n, and signs the message digest h using the enhanced weighted one-time signature algorithm WOTS+ to obtain the signature value ; the certificate proxy CA finds the leaf node corresponding to the signature parameter n in the Merkle tree and obtains the path proof P Auth ;

[0052] S27. The certificate proxy CA sends the quantum-resistant identity certificate Cert to the terminal device, and the quantum-resistant identity certificate .

[0053] The following uses the terminal device D i as an example for registration:

[0054] The terminal device D i needs to complete registration with the certificate authority CA to obtain an identity certificate. The terminal device D i first obtains the system public parameters, selects a random number sk i , sk i ∈F p , and calculates the public key . In addition, the terminal device D i also needs the signature key pair ssk i and SPK i of the quantum signature algorithm SLH-DSA. After the calculation is completed, the terminal device D i initiates a registration request {ID i , PK i , SPK i} to the certificate authority CA through a secure channel, where ID i represents the real identity information of the terminal device D i ; after receiving this message, the certificate authority CA can first confirm through the registration list that ID i should not have been registered before, otherwise it rejects this request. The certificate authority CA uses prf seed and the signature parameter n of the index to calculate a pseudorandom value R i , and then obtains the message digest h i =H(R i , root, n, ID i , PK i , SPK i ); the certificate authority CA generates the corresponding WOTS+ private key through its private key information sk seed and the signature parameter n of the index, and uses the enhanced weighted one-time signature algorithm WOTS+ to sign h i to obtain the signature value . In addition, the certificate authority CA also needs to find the leaf node corresponding to the signature parameter n of the index from the Merkle tree and obtain the path proof P Auth of this node. Finally, the certificate authority CA returns its certificate information i to the terminal device D .

[0055] S3. The terminal device D i and the terminal device D j establish a secure communication connection through the anti-quantum identity certificate and generate a shared key; specifically including:

[0056] S31, terminal device D i To terminal device D j Send an authentication request message, which includes the terminal device D i Quantum-resistant identity certificate; specifically: terminal device D i Choose a random number r i , r i ∈F p , calculate the pseudo-random value R i , expressed as: , terminal device D i Record the current time T1, calculate the message verification h1 and signature , expressed as: h1=H(ID i ,ID j ,PK i ,SPK i ,Cert i ,R i ,T1), , terminal device D i The authentication request message sent is represented as , ID i and ID j They are terminal devices D i and terminal device D j The real identity information of PK i For terminal device D i The public key of Cert i For terminal device D i The quantum-resistant identity certificate, SLH.Sign is the signature function of the SLH-DSA algorithm, SPK i and ssk i For terminal device D i The signing key pair;

[0057] S32, terminal device D j Verify terminal device D i If the authentication request message fails, the communication connection is rejected and ends; otherwise, the terminal device D j Generate an authentication reply message and send it to terminal device D i , then enter S33; the authentication reply message includes the terminal device D j Quantum-resistant identity certificates; specifically including:

[0058] ①、Terminal device D j Analyze h according to the parameter information in the certificate i ' = H (R i ,root i ,n,ID i ,PK i,SPK i ), recover the signature public key PK of the terminal device D by using the enhanced weighted one-time signature algorithm WOTS+ i ; and calculate the hash of PK as the leaf node of the Merkle tree, where root WOTS is the root node of the terminal device D WOTS ; i for the terminal device D i ;

[0059] ②. The terminal device D j calculates the root node root' according to the leaf node and the path proof P in the certificate, and verifies whether root' is equal to root Auth ; if so, the quantum-resistant identity certificate provided by the terminal device D i is correct, and proceed to ③; otherwise, the terminal device D i rejects the communication connection and ends; j

[0060] ③. The terminal device D j records the current time T1', and verifies whether holds, where is the maximum tolerance time for message reply. If it does not hold, the terminal device D j rejects the communication connection and ends; if it holds, proceed to ④;

[0061] ④. The terminal device D j verifies the correctness of the signature ; if it is incorrect, the terminal device D j rejects the communication connection and ends; otherwise, proceed to ⑤;

[0062] ⑤. The terminal device D j selects a random number r j , r j ∈F p , calculates the pseudorandom value R j and the shared key K ij . The pseudorandom value R j is expressed as: , and the shared key K ji is expressed as: ; the terminal device D j records the current time T2 and generates a message check h2, expressed as: h2 = H(R j , PK j , Cert j , T2, K ji ), where sk j is the random number selected by the terminal device D j when calculating the public key, and PK j ​For the terminal device D j is the public key, Cert j For the terminal device D j is the quantum-resistant identity certificate;

[0063] ⑥. The terminal device D j generates an authentication reply message and sends it to the terminal device D i , and then enters S33. The authentication reply message is expressed as {R j , PK j , Cert j , T2, h2};

[0064] S33. The terminal device D i verifies the authentication reply message of the terminal device D j . If the verification fails, the communication connection is rejected and the process ends; otherwise, the terminal device D i establishes a communication connection with the terminal device D j . The terminal device D i and the terminal device D j both generate a shared key using their own private key and the other party's public key; specifically including:

[0065] (1). The terminal device D i verifies the correctness of the identity certificate Cert j (the verification steps are similar to S32); if it is incorrect, the communication connection is rejected and the process ends; otherwise, it enters (2);

[0066] (2). The terminal device D i records the current time T2', and verifies whether it holds. If it does not hold, the communication connection is rejected and the process ends; if it holds, it enters (3);

[0067] (3). Calculate the shared key K ij , expressed as: , where sk i is the random number selected by the terminal device D i when calculating the public key;

[0068] (4). Verify whether h2 = H(R j , PK j , Cert j , T2, K ij ) is satisfied. If it is not satisfied, the communication connection is rejected and the process ends; otherwise, the terminal device D i establishes a communication connection with the terminal device D j .

[0069] S4. The terminal device D i communicates with the terminal device D jDynamically generate a session key based on a shared key and perform data transmission, specifically including:

[0070] S41. The terminal device D i Sends a data communication request message to the terminal device D j Specifically: The terminal device D i Selects a random number r A , r A ∈F p , and calculates the check h3, expressed as: h3 = H(ID i , ID j , r A , K ij ); The terminal device D i Generates a data communication request message and sends it to the terminal device D j , and the data communication request message includes {ID i , ID j , r A , h3};

[0071] S42. The terminal device D j Verifies the data communication request message. If the verification fails, the session is rejected and ended; otherwise, the terminal device D j Updates the session key according to the data communication request message and sends a data communication reply message to the terminal device D i , and enters S43. The data communication reply message includes relevant information about the session key; Specifically: The terminal device D j Verifies whether the check h3 = H(ID i , ID j , r A , K ji ) holds. If it does not hold, the verification fails, the session is rejected, and ended; otherwise, the terminal device D j Selects a random number r B , r B ∈F p , calculates the check h4 and the session key sk ij , and the check h4 is expressed as: h4 = H(ID i , ID j , r B , K ji ); The session key sk ji Is expressed as: ; The terminal device D j Sends a data communication reply message to the terminal device D i , and the data communication reply message includes {r B , h4};

[0072] S43. The terminal device D iVerify the data communication reply message. If the verification fails, reject the data transmission and end; if the verification passes, the terminal device D i Update the session key according to the data communication request message, and encrypt the data M to be transmitted according to the session key i to obtain the encrypted data C i , and generate a data integrity check signature. Send the data C i and the data integrity check signature to the terminal device D j ; Specifically including:

[0073] 1). The terminal device D i verifies whether the check h4 = H(ID i , ID j , r B , K ij ) holds. If it does not hold, the verification fails, reject the session and end; otherwise, calculate the session key sk ij , expressed as: ;

[0074] 2). The terminal device D i uses the national cipher SM4 algorithm to encrypt the data M to be transmitted i to obtain the encrypted data C i , and generates the data integrity check using the quantum signature algorithm SLH-DSA. The data C i is expressed as: ; The data integrity check is expressed as: ;

[0075] 3). Send the data C i and the data integrity check signature to the terminal device D j .

[0076] S44. The terminal device D j checks the data integrity check signature. If the check passes, the terminal device D j decrypts the data C i to obtain the data M i , that is ; otherwise, do not decrypt the encrypted data C i , where SM4.Enc represents the national cipher symmetric encryption function.

[0077] A quantum-resistant secure data transmission authentication system based on SLH-DSA, including:

[0078] A processor;

[0079] A storage device; a computer program is stored in the storage device. When the processor executes the computer program, it implements a quantum-resistant secure data transmission authentication method based on SLH-DSA as described above. The quantum-resistant secure data transmission authentication system based on SLH-DSA runs on computing devices such as desktop computers, laptop computers, handheld computers, and cloud data centers.

[0080] The two communication parties are two terminal devices deployed in the industrial field, respectively used for the collection and response processing of industrial data, and have certain communication and computing capabilities. One party is terminal device D i , which undertakes the tasks of data collection or remote control and needs to actively request or transmit key business data to another terminal, and is regarded as the initiator of communication. The other party is terminal device D j , as the receiver, is responsible for processing the received data or instructions and providing response services. The two devices communicate point-to-point through the field network and have the requirements for security authentication and encrypted communication under actual deployment conditions. The quantum-resistant secure data transmission authentication method proposed by the present invention is applicable to the communication process between the above two terminal devices. First, in the device registration stage, terminal device D i and D j can respectively generate key pairs locally and apply for quantum-resistant identity certificates from a trusted certificate proxy CA. The obtained quantum-resistant identity certificates will be used for subsequent identity authentication. Subsequently, when establishing a connection, device D i and device D j exchange their respective identity identifiers, quantum-resistant identity certificates, and key negotiation parameters, complete two-way identity verification, and generate a shared key through a negotiation mechanism. This shared key will serve as the session basis to support subsequent encrypted communication. In the data transmission stage, both devices dynamically derive session keys based on the shared key, use the national cryptography SM4 encryption algorithm to encrypt the communication data, and at the same time use SLH-DSA to generate signatures for data messages to ensure message integrity and anti-tampering. The system supports a session key update mechanism driven by timing or events, which can significantly reduce the risk of key reuse and enhance forward security. The overall solution can achieve high-security and low-latency communication authentication and data protection between field devices without relying on heavy encryption computing modules, meeting the actual needs of the industrial Internet of Things environment for lightweight, secure, and quantum-resistant communication mechanisms.

[0081] The technical solution of the present invention is not limited to the limitations of the above specific embodiments. Any technical deformation made according to the technical solution of the present invention falls within the protection scope of the present invention.

Claims

1. A quantum-resistant secure data transmission authentication method based on SLH-DSA, characterized in that, include: S1. The certificate agent CA publishes system public parameters to the terminal devices that need to transmit data; S2, terminal device D i and the terminal device D j both obtain quantum-resistant identity certificates from the certificate proxy CA through the system public parameters; S3. Terminal device D i With terminal device D j Establish a secure communication connection through a quantum-resistant identity certificate and generate a shared key; specifically including: S31, terminal device D i To terminal device D j Send an authentication request message, which includes the terminal device D i The quantum-resistant identity certificate, key information and related authentication parameters of the terminal device D i Choose a random number r i , r i ∈F p , calculate the pseudo-random value R i , expressed as: , terminal device D i Record the current time T1, calculate the message verification h1 and signature , expressed as: h1=H(ID i ,ID j ,PK i ,SPK i ,Cert i ,R i ,T1), , terminal device D i The authentication request message sent is represented as , ID i and ID j They are terminal devices D i and terminal device D j The real identity information of PK i For terminal device D i The public key of Cert i For terminal device D i The quantum-resistant identity certificate, SLH.Sign is the signature function of the SLH-DSA algorithm, SPK i and ssk i For terminal device D i The signature key pair, F p is a finite field, G is the base point of the elliptic curve in the elliptic curve cryptography ECC, is a hash function; S32. Terminal device D j Verify the terminal device D i For the authentication request message, if the verification fails, reject the communication connection and end; otherwise, the terminal device D j Generates an authentication reply message and sends it to the terminal device D i , and then enters S33; the authentication reply message includes the anti-quantum identity certificate, key information, and related authentication parameters of the terminal device D j ; S33. Terminal device D i Verify the authentication reply message of terminal device D j If the verification fails, reject the communication connection and end; otherwise, terminal device D i Establish a communication connection with terminal device D j Once the communication connection is established, terminal device D i And terminal device D j Both generate a shared key using their own private key and the other party's public key; S4. Terminal device D i Based on a shared key with terminal device D j dynamically generate a session key and perform data transmission, specifically including: S41. Terminal device D i Send a data communication request message to terminal device D j ; S42. Terminal device D j Verify the data communication request message. If the verification fails, reject the session and end; otherwise, terminal device D j Update the session key according to the data communication request message and send a data communication reply message to terminal device D i , and enter S43. The data communication reply message includes information related to the session key; S43. Terminal device D i Verify the data communication reply message. If the verification fails, reject the data transmission and end; if the verification passes, then terminal device D i Update the session key according to the data communication request message, and encrypt the data M to be transmitted according to the session key i to obtain the encrypted data C i , and generate a data integrity check signature. Send the data C i and the data integrity check signature to terminal device D j ; specifically including: 1). Terminal device D i Verify check h4. If the verification fails, reject the session and end it; otherwise, calculate the session key sk ij , expressed as: , r A is for terminal device D i Select a random number, r B is for terminal device D j Select a random number, K ij is for terminal device D i Calculate the shared key between and terminal device D j ; is the key derivation function; 2), Terminal device D i Use the national cipher SM4 algorithm to encrypt the data M to be transmitted i to obtain the encrypted data C i , and generate data integrity verification using the quantum signature algorithm SLH-DSA , data C i is expressed as: ; Data integrity verification is expressed as: , where SM4.Enc represents the national cipher symmetric encryption function; 3), Send data C i and the data integrity verification signature to the terminal device D j ; S44. Terminal device D j Verify the integrity check signature of the data. If the verification passes, terminal device D j Decrypts data C i to obtain data M i ; otherwise, the encrypted data is not decrypted.

2. The anti-quantum secure data transmission authentication method based on SLH-DSA according to claim 1, characterized in that, S1 specifically includes: S11. The certificate proxy CA obtains security parameters ; S12. The certificate proxy CA selects relevant parameters of the Elliptic Curve Cryptography (ECC) based on security parameters The relevant parameters of the Elliptic Curve Cryptography (ECC) include the coefficients a and b of the elliptic curve, the base point G of the elliptic curve, and the finite field F p ; S13. Certificate Agent CA Sets Hash Function , Key Derivation Function , Public Parameters of Quantum Signature Algorithm SLH-DSA, where the public parameters of the quantum signature algorithm SLH-DSA include the Winternitz parameter w of Winternitz, the height s of the Merkle hash tree, and the number of layers d of the multi-layer structure, and generate a private key derivation seed sk seed , Pseudo-Random Function Seed prf seed and Address Hash Seed pub seed , The private key derivation seed sk seed is used for private key derivation, and the pseudo-random function seed prf seed is used for the pseudo-random function, and the address hash seed pub seed is used for the address hash of the tree node; S14, the certificate agent CA constructs a Merkle tree according to the public parameters of the quantum signature algorithm SLH-DSA and obtains the root node root; S15. The certificate proxy CA derives the seed sk from the random private key seed , the pseudo-random function seed prf seed and the address hash seed pub seed and generates the private key sk CA and the public key PK CA ; S16. Certificate proxy CA publishes system public parameters .

3. The anti-quantum secure data transmission authentication method based on SLH-DSA according to claim 2, wherein The certificate agent CA sets an index counter N locally for indexing the signature parameter n, starting from 0 and incrementing each time the quantum signature algorithm SLH-DSA is executed. When the maximum value is reached, the signature parameter needs to be reinitialized; specifically, S2 includes: S21, the terminal device D obtains the system common parameters; S22. The terminal device D selects a random number sk, where sk ∈ F p , and calculates the public key ; S23, the terminal device D generates a signature key pair ssk and SPK of the quantum signature algorithm SLH-DSA; S24, the terminal device D initiates a registration request {ID, PK, SPK} to the certificate agency CA, where ID represents the real identity information of the terminal device D; S25. The certificate proxy CA determines whether the terminal device D has been registered. If so, it rejects the registration request; otherwise, the certificate proxy CA analyzes the pseudo-random value R based on the random prf seed and the signature parameter n of the index, and obtains the message digest h = H(R, root, n, ID, PK, SPK); S26. The certificate proxy CA derives sk through a random private key seed and the signature parameter n of the index to generate the private key of the enhanced weighted one-time signature algorithm WOTS+. The enhanced weighted one-time signature algorithm WOTS+ is used to sign the message digest h to obtain the signature value ; The certificate proxy CA finds the leaf node corresponding to the signature parameter n in the Merkle tree and obtains the path proof P of this node Auth ; S27. The certificate proxy CA sends the quantum-resistant identity certificate Cert to the terminal device, and the quantum-resistant identity certificate .

4. A quantum-resistant secure data transmission authentication method based on SLH-DSA according to claim 3, characterized in that, S32 specifically includes: ①. Terminal device D j Analyze h according to the parameter information in the certificate i ’ = H(R i , root i , n, ID i , PK i , SPK i ), and use the enhanced weighted one-time signature algorithm WOTS+ signature to recover the signature public key PK of the terminal device D i , and calculate the hash of PK WOTS as the leaf node of the Merkle tree, where root WOTS is the root node of the terminal device D i ; i ​ ②. Terminal device D j Calculate the root node root’ based on the leaf node and the path proof P in the certificate Auth Verify whether root’ is equal to root i If so, the quantum-resistant identity certificate provided by the terminal device D i is correct and proceed to ③; otherwise, the terminal device D j rejects the communication connection and ends; ③. Terminal device D j Record the current moment T1', and verify whether it holds is the maximum tolerance time for message reply. If it does not hold, then the terminal device D j rejects the communication connection and ends; if it holds, proceed to ④; ④. Terminal device D j Verify the signature for correctness. If incorrect, terminal device D j rejects the communication connection and ends; otherwise, proceed to ⑤; ⑤. Terminal device D j Select a random number r j , r j ∈F p , and calculate the pseudorandom value R j and the shared key K ij . The pseudorandom value R j is expressed as: . The shared key K ji is expressed as: ; Terminal device D j records the current time T2 and generates a message authentication h2, expressed as: h2 = H(R j , PK j , Cert j , T2, K ji ), where sk j is the random number selected when calculating the public key of terminal device D j , PK j is the public key of terminal device D j , and Cert j is the quantum-resistant identity certificate of terminal device D j ; ⑥. Terminal device D j Generate an authentication reply message and send it to terminal device D i , and then enter S33. The authentication reply message is expressed as {R j , PK j , Cert j , T2, h2}.

5. A quantum-resistant secure data transmission authentication method based on SLH-DSA according to claim 4, characterized in that, S33 specifically includes: (1) Terminal device D i Verify the correctness of the identity certificate Cert j If it is incorrect, reject the communication connection and end; otherwise, proceed to (2); (2), Terminal device D i Record the current moment T2', and verify whether it holds. If not, reject the communication connection and end; if it holds, proceed to (3); (3), Calculate the shared key K ij , expressed as: , where sk i is the random number selected by the terminal device D i when calculating the public key; (4)Verify the check h2. If it fails, reject the communication connection and end; otherwise, the terminal device D i communicates with the terminal device D j establishes a communication connection.

6. The anti-quantum secure data transmission authentication method based on SLH-DSA according to claim 5, characterized in that, Specifically in S41: The terminal device D i selects a random number r A , r A ∈F p , and calculates the check h3, expressed as: h3 = H(ID i , ID j , r A , K ij ); The terminal device D i generates a data communication request message and sends it to the terminal device D j , and the data communication request message includes {ID i , ID j , r A , h3}.

7. A quantum-resistant secure data transmission authentication method based on SLH-DSA according to claim 6, characterized in that Specifically in S42: The terminal device D j Verifies the check h3. If the verification fails, the session is rejected and ended; otherwise, the terminal device D j Selects a random number r B , r B ∈F p , and calculates the check h4 and the session key sk ij . The check h4 is expressed as: h4 = H(ID i , ID j , r B , K ji ); The session key sk ji is expressed as: ; The terminal device D j Sends a data communication reply message to the terminal device D i , and the data communication reply message includes {r B , h4}.

8. An anti-quantum secure data transmission authentication system based on SLH-DSA, characterized in that, include: processor; Storage; A computer program is stored in the memory, and when the processor executes the computer program, an SLH-DSA-based quantum-resistant secure data transmission authentication method as described in any one of claims 1 to 7 is implemented. The SLH-DSA-based quantum-resistant secure data transmission authentication system runs in computing devices such as desktop computers, laptop computers, PDAs, and cloud data centers.

Citation Information

Patent Citations

  • Post-quantum and national secret hybrid dual-certificate IKE key negotiation method and device

    CN119135343A

  • Certificateless two-party authenticated key agreement method, device, and data storage medium

    WO2017202161A1