Digital certificate processing method and device for anti-quantum cryptography algorithm

By establishing lightweight certificate files and excluding public key data, the problem of certificate files volume expansion after the introduction of quantum cryptography algorithm is solved, and the effect of reducing storage costs and expanding equipment functions is achieved.

CN120200748AActive Publication Date: 2025-06-24WATCHDATA SYST +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510677058.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-06-24
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

With the introduction of quantum cryptography algorithms, the public key and signature length of certificates have increased significantly, resulting in the expansion of certificate files in volume, increasing storage costs and limiting the functional expansion and application scope of the device.

Method used

By establishing a lightweight certificate file for excluding public key data, only the location and non-public key information of the public key data in the digital certificate to be stored, without storing the public key data, thereby significantly reducing the size of the certificate file.

Benefits of technology

It significantly reduces the size of the certificate file, reduces storage costs, and expands the functional expansion and application range of the device, and is suitable for resource-constrained devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200748A_ABST
    Figure CN120200748A_ABST
Patent Text Reader

Abstract

The invention discloses a digital certificate processing method and device for an anti-quantum cryptography algorithm, and a security authentication equipment method. The method comprises the following steps: receiving a to-be-stored digital certificate sent by an upper computer, wherein the to-be-stored digital certificate is generated based on the anti-quantum cryptography algorithm; establishing a lightweight certificate file for excluding the public key data, wherein the lightweight certificate file comprises a file header and a file body; an identifier of public key data in a to-be-stored digital certificate is written into a file header, the identifier comprises a public key file mark and public key offset of a public key in the digital certificate, data before the public key data and data after the public key data in the to-be-stored digital certificate are written into a file body, and the lightweight certificate file with the written data is stored. Therefore, by adopting the embodiment of the invention, the storage cost can be reduced, and meanwhile, the function extension and application range of the equipment can be expanded.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and particularly to a digital certificate processing method and device for quantum-resistant cryptographic algorithms. Background Art

[0002] In fields such as finance, government affairs, and the Internet of Things, security authentication devices are widely used. These devices are used to perform high-security identity authentication, and their core features include physical isolation, cryptographic operation capabilities, and anti-attack capabilities. These security capabilities rely on the physical security characteristics of the security chip.

[0003] In related technologies, when storing certificates, security authentication devices usually need to store complete public key and private key data. However, with the introduction of quantum-resistant cryptographic algorithms, the public key and signature lengths of certificates have increased significantly, resulting in the expansion of certificate file sizes. For example, an X.509 certificate embedded with a Dilithium5 public key and signature can reach 8KB in size, while traditional ECC certificates are usually only about 1KB. This not only increases the storage cost but also limits the function expansion and application scope of the device. Summary of the Invention

[0004] Embodiments of this application provide a digital certificate processing method and device for quantum-resistant cryptographic algorithms. To provide a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary section is not a general review nor is it intended to identify key / important constituent elements or delineate the protection scope of these embodiments. Its sole purpose is to present some concepts in a simple form as a prelude to the detailed description that follows.

[0005] In a first aspect, embodiments of this application provide a digital certificate processing method for quantum-resistant cryptographic algorithms, which is applied to a security authentication device. The method includes: Receiving a digital certificate to be stored sent by a host computer, where the digital certificate to be stored is generated based on a quantum-resistant cryptographic algorithm; Establishing a lightweight certificate file for excluding public key data, where the lightweight certificate file includes a file header and a file body; Writing the identifier of the public key data in the digital certificate to be stored into the file header, where the identifier includes a public key file marker and the public key offset in the digital certificate, and writing the data before the public key data and the data after the public key data in the digital certificate to be stored into the file body, and storing the lightweight certificate file with the written data.

[0006] Optionally, writing the identifier of the public key data in the digital certificate to be stored into the file header includes: Retrieving a public key file marker related to the digital certificate to be stored from the internal memory; Determine the start and end positions of the public key data in the digital certificate to be stored. The start and end positions include the public key offset, and the public key offset is the starting byte position of the public key data starting from 0. Write the file type of the lightweight certificate file, the public key file flag, and the public key offset into the file header.

[0007] Optionally, determine the data before the public key data and the data after the public key data in the digital certificate to be stored according to the following steps, including: Determine the public key length of the public key data according to the start and end positions. Obtain all the bytes of data before the public key offset in the digital certificate to be stored as the data before the public key data in the digital certificate to be stored. Accumulate the public key offset and the public key length to obtain the target position. Use the bytes of data at the target position and all the bytes of data after the target position as the data after the public key data in the digital certificate to be stored.

[0008] Optionally, determine the start and end positions of the public key data in the digital certificate to be stored, including: Obtain the certificate format of the digital certificate to be stored. Based on the certificate format, parse the digital certificate to be stored to obtain the certificate data structure. Analyze the start and end positions of the public key data according to the certificate data structure.

[0009] Optionally, determine the start and end positions of the public key data in the digital certificate to be stored, including: Read the public key data byte string related to the digital certificate to be stored from the internal memory based on the public key file flag related to the digital certificate to be stored. In the digital certificate to be stored, search for the string identical to the public key data byte string in the forward search method. In the case where the string identical to the public key data byte string is found, use the position of the first byte of the string identical to the public key data byte string found as the public key offset. Based on the public key offset, determine the start and end positions of the public key data in the digital certificate to be stored.

[0010] Optionally, the method further includes: In response to the digital certificate reading instruction sent by the host computer, determine whether the digital certificate reading instruction instructs the security authentication device to restore the digital certificate. If not, directly return the pre-stored digital certificate. If so, read the first file header of the pre-stored digital certificate. When the file type in the first file header indicates that the pre-stored digital certificate is of the file type of a lightweight certificate file, obtain the first public key file marker in the first file header; Read the internally stored first public key data according to the first public key file marker; Extract the first public key offset in the first file header and the first file body of the pre-stored digital certificate; Determine the position of the first public key offset in the first file body; Output the data of all bytes before the position of the first public key offset in the first file body; Output the first public key data; Output the data of the byte at the position of the first public key offset in the first file body and the data of all bytes after the position of the first public key offset.

[0011] Optionally, the method further includes: When the file type in the first file header indicates that the pre-stored digital certificate is not of the file type of a lightweight certificate file, return the pre-stored digital certificate.

[0012] In a second aspect, an embodiment of the present application provides a method for processing a digital certificate for a quantum-resistant cryptographic algorithm, which is applied to a host computer. The method includes: Based on the model or function of the security authentication device, determine whether the security authentication device supports the digital certificate restoration function; If so, generate a digital certificate reading instruction indicating that the security authentication device restores the digital certificate, and send it to the security authentication device to obtain the restored digital certificate from the security authentication device; If not, obtain the pre-stored digital certificate from the security authentication device; Read the second file header of the pre-stored digital certificate; When the file type in the second file header indicates that the pre-stored digital certificate is of the file type of a lightweight certificate file, obtain the second public key file marker in the second file header; Read the second public key data stored internally in the security authentication device according to the second public key file marker; Extract the second public key offset in the second file header and the second file body of the pre-stored digital certificate; the second file body includes the data before the public key data and the data after the public key data; Insert the second public key data into the position at the second public key offset of the second file body to obtain a digital certificate containing the public key data.

[0013] In a third aspect, a digital certificate processing device for a quantum-resistant cryptographic algorithm, the device includes: A receiving module, configured to receive a digital certificate to be stored sent by a host computer, where the digital certificate to be stored is generated based on a quantum-resistant cryptographic algorithm; A building module, configured to build a lightweight certificate file for excluding public key data, where the lightweight certificate file includes a file header and a file body; A writing module, configured to write an identifier of the public key data in the digital certificate to be stored into the file header, where the identifier includes a public key file flag and a public key offset in the digital certificate, and write the data before the public key data and the data after the public key data in the digital certificate to be stored into the file body, and store the lightweight certificate file with the written data.

[0014] Thirdly, a digital certificate processing device for a quantum-resistant cryptographic algorithm, the device includes: A judging module, configured to judge whether a security authentication device supports a digital certificate restoration function based on the model or function of the security authentication device; A generating module, if so, configured to generate a digital certificate reading instruction for instructing the security authentication device to restore the digital certificate, and send it to the security authentication device to obtain the restored digital certificate from the security authentication device; A first obtaining module, if not, configured to obtain a pre-stored digital certificate from the security authentication device; A first reading module, configured to read a second file header of the pre-stored digital certificate; A second obtaining module, configured to obtain a second public key file flag in the second file header when the file type in the second file header indicates the file type of the lightweight certificate file of the pre-stored digital certificate; A second reading module, configured to read second public key data stored inside the security authentication device according to the second public key file flag; An extracting module, configured to extract a second public key offset in the second file header and a second file body of the pre-stored digital certificate; the second file body includes the data before the public key data and the data after the public key data; An inserting module, configured to insert the second public key data into the position at the second public key offset in the second file body to obtain a digital certificate including the public key data.

[0015] Fifthly, an embodiment of the present application provides a computer storage medium, where the computer storage medium stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the above method steps.

[0016] Sixthly, an embodiment of the present application provides an electronic device, which may include: a processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the above method steps.

[0017] The technical solutions provided by the embodiments of the present application may include the following beneficial effects: In the embodiments of the present application, on the one hand, due to the large amount of public key data in the digital certificate generated based on the quantum-resistant cryptographic algorithm, the present application establishes a lightweight certificate file for excluding the public key data, and can write the public key offset of the public key data in the digital certificate to be stored, the data before the public key data, and the data after the public key data into the file body, so that the digital certificate only records the position of the public key data in the digital certificate to be stored and the non-public key information without storing the public key data. Therefore, the public key data with a large amount of data is excluded, significantly reducing the volume of the certificate file, thereby reducing the storage cost and at the same time expanding the function expansion and application scope of the device. On the other hand, when restoring the data of the pre-stored digital certificate, since it is not necessary to parse the entire certificate file, the amount of calculation is reduced, which is suitable for devices with limited resources.

[0018] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0020] Figure 1 is a schematic flowchart of a method for processing a digital certificate for a quantum-resistant cryptographic algorithm provided by an embodiment of the present application; Figure 2 is a schematic diagram of a comparison between an original digital certificate and the file body of a lightweight certificate file provided by the present application; Figure 3 is a schematic flowchart of another method for processing a digital certificate for a quantum-resistant cryptographic algorithm provided by an embodiment of the present application; Figure 4 is a schematic structural diagram of a device for processing a digital certificate for a quantum-resistant cryptographic algorithm provided by an embodiment of the present application; Figure 5 is a schematic structural diagram of another device for processing a digital certificate for a quantum-resistant cryptographic algorithm provided by an embodiment of the present application; Figure 6 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] The following description and the accompanying drawings fully illustrate the specific embodiments of the present application, enabling those skilled in the art to practice them.

[0022] It should be clear that the described embodiments are only a part of the embodiments of this application, rather than all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.

[0023] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are only examples of systems and methods consistent with some aspects of this application as detailed in the appended claims.

[0024] In the description of this application, it should be understood that terms such as "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances. In addition, in the description of this application, unless otherwise specified, "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0025] Currently, when a security authentication device stores a certificate, it usually needs to store the complete public key and private key data.

[0026] The applicant of this application has noticed that with the introduction of quantum-resistant cryptographic algorithms, the public key and signature lengths of certificates have increased significantly, resulting in the inflation of the certificate file size. For example, an X.509 certificate embedded with Dilithium5 public key and signature can reach 8KB in size, while traditional ECC certificates are usually only about 1KB. This not only increases the storage cost but also limits the function expansion and application scope of the device.

[0027] In order to solve the above problems, the applicant of this application has found through research that, on the one hand, by establishing a lightweight certificate file for excluding public key data, the public key offset of the public key data in the digital certificate to be stored, the data before the public key data, and the data after the public key data can be written into the file body, so that the digital certificate only records the position of the public key data in the digital certificate to be stored and the non-public key information without storing the public key data. Therefore, the large-volume public key data is excluded, significantly reducing the size of the certificate file, thereby reducing the storage cost and at the same time expanding the function expansion and application scope of the device. On the other hand, when restoring the data of the pre-stored digital certificate, since it is not necessary to parse the entire certificate file, the amount of calculation is reduced, which is suitable for devices with limited resources.

[0028] The present application provides a digital certificate processing method and apparatus for anti-quantum cryptographic algorithms to solve the problems existing in the above related technical problems. The digital certificate processing method provided by the embodiments of the present application will be introduced in detail below with reference to the accompanying drawings. This method can be implemented depending on a computer program and can run on a digital certificate processing apparatus for anti-quantum cryptographic algorithms based on the von Neumann architecture. This computer program can be integrated into an application or run as an independent tool-like application.

[0029] Please refer to Figure 1 , which is a schematic flowchart of a digital certificate processing method provided by an embodiment of the present application and is applied to a security authentication device. As Figure 1 shown, the method of the embodiment of the present application may include the following steps: S101, receiving a digital certificate to be stored sent by a host computer, where the digital certificate to be stored is generated based on an anti-quantum cryptographic algorithm; Among them, the host computer is a computer system used for management and monitoring in an automated control system. The digital certificate to be stored is a digital certificate that needs to be stored by the security authentication device. A digital certificate is an electronic document issued by a trusted third party (such as a certificate authority CA) to prove the identity of the certificate holder and contains public key information. Anti-quantum cryptographic algorithms (Post-Quantum Cryptography, PQC) are those cryptographic algorithms that can still maintain security even after the emergence of quantum computers.

[0030] In some embodiments of the present application, the security authentication device (such as a smart card or USBKey) initializes a communication connection with the host computer (such as a personal computer or a server), and the host computer sends a digital certificate generated based on an anti-quantum cryptographic algorithm to the security authentication device, and the security authentication device receives the digital certificate to be stored sent by the host computer.

[0031] S102, establishing a lightweight certificate file for excluding public key data, where the lightweight certificate file includes a file header and a file body; Among them, the lightweight certificate file is an optimized certificate file format, and its purpose is to reduce the demand for storage space.

[0032] Taking the X.509 certificate as an example, its data structure is briefly summarized as follows: a) Version number: Identifies the certificate version (v1 / v2 / v3).

[0033] b) Serial number: An integer that uniquely identifies the certificate.

[0034] c) Signature algorithm: The algorithm used by the CA for signing (such as SHA256-RSA).

[0035] d) Issuer: DN (Distinguished Name) of the CA.

[0036] e) Validity period: start and end times.

[0037] f) Subject: DN of the certificate holder.

[0038] g) Subject Public Key Info (SubjectPublicKeyInfo): 1. Algorithm identifier: public key algorithm (such as RSA, ECC).

[0039] 2. Public key data: DER-encoded public key bit string (such as modulus and exponent of RSA).

[0040] h) Extensions: such as key usage, subject alternative name, etc.

[0041] i) Signature: hash signature of the CA for the certificate content.

[0042] Taking the PGP certificate (OpenPGP) as an example, its data structure is briefly summarized as follows: a) Public-Key Packet: 1. Version number (v4 is the mainstream).

[0043] 2. Algorithm identifier (such as RSA = 1, ECDH = 18).

[0044] 3. Creation time.

[0045] 4. Public key parameters (dynamically defined according to the algorithm).

[0046] b) User ID Packet: identity identifier of the holder (such as email).

[0047] c) Signature Packet: self-signature or signature of other entities, binding the user ID to the public key.

[0048] d) Subkey Packet (optional): additional encryption subkeys.

[0049] It can be seen that the digital certificate must contain the public key data corresponding to the certificate. The position of the public key in the digital certificate is not fixed and is related to the certificate format and the length of other information in the certificate.

[0050] Therefore, the lightweight certificate file established in this application for excluding public key data includes a file header and a file body.

[0051] Among them, the file header includes: File type: Declare whether this file adopts the lightweight storage solution of this application; Public key identifier: Declare the ID / identifier / index / file name of the public key file (or key file containing the public key) stored in the device corresponding to this certificate; Public key offset: Declare the position of the first byte of the public key data in the entire certificate in this certificate (offset byte count, starting from 0).

[0052] Among them, the file body includes the certificate file data after deleting the public key data, that is: the result obtained by deleting the public key data from the complete certificate. A comparison diagram between the original digital certificate and the file body of the lightweight certificate file is shown in Figure 2 as follows.

[0053] Among them, the data structure of the lightweight certificate file is shown in Table 1, for example.

[0054] Table 1

[0055] Among them, type 01 represents that this file adopts the lightweight storage solution. The public key file ID 0002 represents the public key corresponding to this certificate, and the key file ID in the device is 0002; the public key offset 0220 represents that the offset position where the first byte of the public key data appears in the complete certificate is 0x0220 (decimal is 544).

[0056] In some embodiments of this application, the process of establishing a lightweight certificate file for excluding public key data includes: first obtaining the data structure of the lightweight certificate file, then establishing a file header and a file body based on this data structure, and finally combining the file header and the file body to obtain a lightweight certificate file for excluding public key data.

[0057] S103, write the identifier of the public key data in the digital certificate to be stored into the file header. The identifier includes the public key file mark and the public key offset in the digital certificate, and write the data before the public key data and the data after the public key data in the digital certificate to be stored into the file body, and store the lightweight certificate file with the written data.

[0058] In some embodiments of this application, the specific process of writing the identifier of the public key data in the digital certificate to be stored into the file header includes: retrieving the public key file mark related to the digital certificate to be stored from the internal memory; determining the start and end positions of the public key data in the digital certificate to be stored, and the start and end positions include the public key offset, and the public key offset is the starting byte position of the public key data starting from 0; using the public key file mark and the public key offset as the identifier of the public key data; writing the file type and identifier of the lightweight certificate file into the file header.

[0059] Among them, the internal memory can be the storage area of the security chip in the security authentication device, or it can be a flash memory independently set in the security authentication device.

[0060] In some embodiments of the present application, the data before the public key data and the data after the public key data in the digital certificate to be stored are determined according to the following steps, including: determining the public key length of the public key data according to the start and end positions; obtaining the data of all bytes before the public key offset in the digital certificate to be stored as the data before the public key data in the digital certificate to be stored; adding the public key offset and the public key length to obtain the target position; taking the data of the byte at the target position and all the data of the bytes after the target position as the data after the public key data in the digital certificate to be stored.

[0061] Specifically, the specific process of determining the start and end positions of the public key data in the digital certificate to be stored includes: obtaining the certificate format of the digital certificate to be stored; parsing the digital certificate to be stored based on the certificate format to obtain the certificate data structure; analyzing the start and end positions of the public key data according to the certificate data structure. Among them, this method requires the device to have the ability and operating resources to parse the certificate data structure.

[0062] Specifically, the specific process of determining the start and end positions of the public key data in the digital certificate to be stored includes: reading the byte string of the public key data related to the digital certificate to be stored from the internal memory based on the public key file mark related to the digital certificate to be stored; searching for the string identical to the byte string of the public key data in the digital certificate to be stored in the order of searching from front to back; in the case of finding the string identical to the byte string of the public key data, taking the position of the first byte of the found string identical to the byte string of the public key data as the public key offset; determining the start and end positions of the public key data in the digital certificate to be stored based on the public key offset. Among them, this method does not require the device to have the ability to parse the certificate data structure and is more suitable for resource-constrained devices.

[0063] Further, when the host computer reads the certificate from the security authentication device, the security authentication device restores and outputs the complete certificate. The specific method includes: in response to the digital certificate reading instruction sent by the host computer, determining whether the digital certificate reading instruction indicates that the security authentication device restores the digital certificate; if not, directly returning the pre-stored digital certificate; if so, reading the first file header of the pre-stored digital certificate; in the case where the file type in the first file header indicates the file type of the lightweight certificate file of the pre-stored digital certificate, obtaining the first public key file flag in the first file header; according to the first public key file flag, reading the first public key data stored internally; extracting the first public key offset in the first file header and the first file body of the pre-stored digital certificate; in the first file body, determining the position of the first public key offset; outputting the data of all bytes before the position of the first public key offset in the first file body; outputting the first public key data; outputting the data of the byte at the position of the first public key offset in the first file body and the data of all bytes after the position of the first public key offset.

[0064] Specifically, the method further includes: in the case where the file type in the first file header indicates that the pre-stored digital certificate is not of the file type of the lightweight certificate file, returning the pre-stored digital certificate.

[0065] In the embodiments of the present application, on the one hand, the public key data in the digital certificate generated based on the quantum-resistant cryptographic algorithm is large in amount. The present application can establish a lightweight certificate file for excluding the public key data, and write the public key offset, the data before the public key data, and the data after the public key data in the digital certificate to be stored into the file body, so that the digital certificate only records the position of the public key data in the digital certificate to be stored and the non-public key information without storing the public key data. Therefore, the large-volume public key data is excluded, significantly reducing the volume of the certificate file, thereby reducing the storage cost and at the same time expanding the function expansion and application scope of the device. On the other hand, when restoring the data of the pre-stored digital certificate, since it is not necessary to parse the entire certificate file, the amount of calculation is reduced, which is suitable for devices with limited resources.

[0066] Please refer to Figure 3 , which is a schematic flowchart of a method for processing digital certificates for quantum-resistant cryptographic algorithms provided by an embodiment of the present application and is applied to a host computer. As Figure 3 shown, the method of the embodiment of the present application may include the following steps: S201, based on the model or function of the security authentication device, determining whether the security authentication device supports the digital certificate restoration function; if so, generating a digital certificate reading instruction indicating that the security authentication device restores the digital certificate and sending it to the security authentication device to obtain the restored digital certificate from the security authentication device; if not, obtaining the pre-stored digital certificate from the security authentication device; S202, read the second file header of the pre-stored digital certificate; S203, when the file type in the second file header indicates the file type of the pre-stored digital certificate as a lightweight certificate file, obtain the second public key file flag in the second file header; S204, according to the second public key file flag, read the second public key data stored inside the security authentication device; S205, extract the second public key offset in the second file header and the second file body of the pre-stored digital certificate; the second file body includes the data before the public key data and the data after the public key data; S206, insert the second public key data into the position at the second public key offset of the second file body to obtain a digital certificate containing the public key data.

[0067] In the embodiments of the present application, on the one hand, the public key data in the digital certificate generated based on the quantum-resistant cryptographic algorithm has a large amount of data. The present application can write the public key offset of the public key data, the data before the public key data, and the data after the public key data in the digital certificate to be stored into the file body by establishing a lightweight certificate file for excluding the public key data, so that the digital certificate only records the position of the public key data in the digital certificate to be stored and the non-public key information without storing the public key data. Therefore, the public key data with a large amount of data is excluded, significantly reducing the volume of the certificate file, thereby reducing the storage cost and at the same time expanding the function expansion and application scope of the device. On the other hand, when restoring the data of the pre-stored digital certificate, since it is not necessary to parse the entire certificate file, the amount of calculation is reduced, which is suitable for devices with limited resources.

[0068] The following is an embodiment of the device of the present application, which can be used to execute the method embodiment of the present application. For the details not disclosed in the embodiment of the device of the present application, please refer to the method embodiment of the present application.

[0069] Please refer to Figure 4 , which shows a schematic structural diagram of a digital certificate processing device for a quantum-resistant cryptographic algorithm provided by an exemplary embodiment of the present application. The digital certificate processing device for the quantum-resistant cryptographic algorithm can be implemented as all or part of an electronic device through software, hardware, or a combination of both. The device 1 includes a receiving module 10, a establishing module 20, and a writing module 30.

[0070] The receiving module 10 is configured to receive the digital certificate to be stored sent by the host computer, and the digital certificate to be stored is generated based on the quantum-resistant cryptographic algorithm; The establishing module 20 is configured to establish a lightweight certificate file for excluding the public key data, and the lightweight certificate file includes a file header and a file body; A writing module 30 is configured to write an identifier of public key data in a digital certificate to be stored into a file header, where the identifier includes a public key file flag and a public key offset of the public key in the digital certificate, and write data before the public key data and data after the public key data in the digital certificate to be stored into a file body, so as to store a lightweight certificate file with the written data.

[0071] It should be noted that when the digital certificate processing device for the post-quantum cryptographic algorithm provided in the above embodiment executes the digital certificate processing method for the post-quantum cryptographic algorithm, only the above division of each functional module is used for illustration. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the digital certificate processing device for the post-quantum cryptographic algorithm provided in the above embodiment and the embodiment of the digital certificate processing method for the post-quantum cryptographic algorithm belong to the same concept. The implementation process thereof is detailed in the method embodiment and will not be elaborated here.

[0072] The serial numbers of the embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.

[0073] In the embodiment of the present application, on the one hand, since the amount of public key data in the digital certificate generated based on the post-quantum cryptographic algorithm is large, the present application establishes a lightweight certificate file for excluding the public key data, and can write the public key offset of the public key data in the digital certificate to be stored, the data before the public key data, and the data after the public key data into the file body, so that the digital certificate only records the position of the public key data in the digital certificate to be stored and the non-public key information without storing the public key data. Therefore, the public key data with a large amount of data is excluded, the volume of the certificate file is significantly reduced, thereby reducing the storage cost, and at the same time expanding the function expansion and application scope of the device. On the other hand, when restoring the data of the pre-stored digital certificate, since it is not necessary to parse the entire certificate file, the amount of calculation is reduced, which is suitable for devices with limited resources.

[0074] Please refer to Figure 5 , which shows a schematic structural diagram of a digital certificate processing device for a post-quantum cryptographic algorithm provided in an exemplary embodiment of the present application. The digital certificate processing device for the post-quantum cryptographic algorithm can be implemented as all or part of an electronic device through software, hardware, or a combination of both. The device 2 includes a judgment module 40, a generation module 50, a first acquisition module 60, a first reading module 70, a second acquisition module 80, a second reading module 90, an extraction module 100, and an insertion module 110.

[0075] The judgment module 40 is configured to judge whether the security authentication device supports the digital certificate restoration function based on the model or function of the security authentication device; A generation module 50, if so, is configured to generate a digital certificate reading instruction for instructing the security authentication device to restore a digital certificate, and send the instruction to the security authentication device to obtain the restored digital certificate from the security authentication device; A first obtaining module 60, if not, is configured to obtain a pre-stored digital certificate from the security authentication device; A first reading module 70 is configured to read a second file header of the pre-stored digital certificate; A second obtaining module 80 is configured to obtain a second public key file flag in the second file header when the file type in the second file header indicates the file type of the pre-stored digital certificate as a lightweight certificate file; A second reading module 90 is configured to read second public key data stored inside the security authentication device according to the second public key file flag; An extraction module 100 is configured to extract a second public key offset in the second file header and a second file body of the pre-stored digital certificate; the second file body includes data before the public key data and data after the public key data; An insertion module 110 is configured to insert the second public key data into the position at the second public key offset of the second file body to obtain a digital certificate including the public key data.

[0076] It should be noted that when the digital certificate processing device for the post-quantum cryptographic algorithm provided in the above embodiment executes the digital certificate processing method for the post-quantum cryptographic algorithm, only the above division of each functional module is used for illustration. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the digital certificate processing device for the post-quantum cryptographic algorithm provided in the above embodiment and the embodiment of the digital certificate processing method for the post-quantum cryptographic algorithm belong to the same concept. The implementation process is detailed in the method embodiment and will not be repeated here.

[0077] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0078] In an embodiment of the present application, on the one hand, since the amount of public key data in the digital certificate generated based on the quantum-resistant cryptographic algorithm is large, the present application can write the public key offset, the data before the public key data, and the data after the public key data in the digital certificate to be stored into the file body by establishing a lightweight certificate file for excluding the public key data, so that the digital certificate only records the position of the public key data in the digital certificate to be stored and the non-public key information without storing the public key data. Therefore, the public key data with a large amount of data is excluded, significantly reducing the volume of the certificate file, thereby reducing the storage cost and at the same time expanding the function expansion and application scope of the device. On the other hand, when restoring the data of the pre-stored digital certificate, since it is not necessary to parse the entire certificate file, the amount of calculation is reduced, which is suitable for devices with limited resources.

[0079] The present application also provides a computer-readable medium, on which program instructions are stored. When the program instructions are executed by a processor, the digital certificate processing method for the quantum-resistant cryptographic algorithm provided by each of the above method embodiments is implemented.

[0080] The present application also provides a computer program product containing instructions. When it runs on a computer, the computer is caused to execute the digital certificate processing method for the quantum-resistant cryptographic algorithm provided by each of the above method embodiments.

[0081] Please refer to Figure 6 , which is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 6 shown, the electronic device 1000 may include: at least one processor 1001, at least one network interface 1004, a user interface 1003, a memory 1005, and at least one communication bus 1002.

[0082] Among them, the communication bus 1002 is used to realize the connection and communication between these components.

[0083] Among them, the user interface 1003 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface.

[0084] Among them, the network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).

[0085] Among them, the processor 1001 may include one or more processing cores. The processor 1001 connects various parts within the entire electronic device 1000 through various interfaces and lines. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 1005, and by calling the data stored in the memory 1005, it executes various functions of the electronic device 1000 and processes data. Optionally, the processor 1001 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 1001 may integrate a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 1001 and may be implemented separately by a single chip.

[0086] Among them, the memory 1005 may include random access memory (RAM) and may also include read-only memory. Optionally, the memory 1005 includes a non-transitory computer-readable storage medium. The memory 1005 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 1005 may include a program storage area and a data storage area. Among them, the program storage area can store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area can store the data involved in the above-mentioned various method embodiments. Optionally, the memory 1005 may also be at least one storage system located far from the aforementioned processor 1001. As Figure 6 shown, the memory 1005, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a digital certificate processing application program for anti-quantum cryptographic algorithms.

[0087] In Figure 6In the electronic device 1000 shown, the user interface 1003 is mainly used to provide an interface for the user to input and obtain the data input by the user; while the processor 1001 can be used to call the digital certificate processing application program stored in the memory 1005 for the post-quantum cryptographic algorithm, and specifically perform the following operations: Receive the digital certificate to be stored sent by the host computer, and the digital certificate to be stored is generated based on the post-quantum cryptographic algorithm; Establish a lightweight certificate file for excluding public key data, and the lightweight certificate file includes a file header and a file body; Write the identifier of the public key data in the digital certificate to be stored into the file header, where the identifier includes a public key file mark and a public key offset in the digital certificate, and write the data before the public key data and the data after the public key data in the digital certificate to be stored into the file body, and store the lightweight certificate file with the written data.

[0088] In one embodiment, when the processor 1001 executes writing the identifier of the public key data in the digital certificate to be stored into the file header, it specifically performs the following operations: Retrieve the public key file mark related to the digital certificate to be stored from the internal memory; Determine the start and end positions of the public key data in the digital certificate to be stored, where the start and end positions include a public key offset, and the public key offset is the starting byte position of the public key data starting from 0; Use the public key file mark and the public key offset as the identifier of the public key data; Write the file type and identifier of the lightweight certificate file into the file header.

[0089] In one embodiment, when the processor 1001 executes determining the data before the public key data and the data after the public key data in the digital certificate to be stored, it specifically performs the following operations: Determine the public key length of the public key data according to the start and end positions; Obtain the data of all bytes before the public key offset in the digital certificate to be stored as the data before the public key data in the digital certificate to be stored; Accumulate the public key offset and the public key length to obtain a target position; Use the data of the byte at the target position and all the data after the target position as the data after the public key data in the digital certificate to be stored.

[0090] In one embodiment, when the processor 1001 executes determining the start and end positions of the public key data in the digital certificate to be stored, it specifically performs the following operations: Obtain the certificate format of the digital certificate to be stored; Parse the digital certificate to be stored based on the certificate format to obtain a certificate data structure; Analyze the start and end positions of the public key data according to the certificate data structure.

[0091] In one embodiment, when the processor 1001 executes to determine the start and end positions of the public key data in the digital certificate to be stored, the following operations are specifically performed: Read the byte string of the public key data related to the digital certificate to be stored from the internal memory based on the public key file marker related to the digital certificate to be stored; In the digital certificate to be stored, search for a string identical to the byte string of the public key data in a forward search manner; In the case where a string identical to the byte string of the public key data is found, use the position of the first byte of the found string identical to the byte string of the public key data as the public key offset; Based on the public key offset, determine the start and end positions of the public key data in the digital certificate to be stored.

[0092] In one embodiment, the processor 1001 also performs the following operations: In response to a digital certificate reading instruction sent by the host computer, determine whether the digital certificate reading instruction instructs the security authentication device to restore the digital certificate; If not, directly return the pre-stored digital certificate; If so, read the first file header of the pre-stored digital certificate; In the case where the file type in the first file header indicates the file type of the lightweight certificate file for the pre-stored digital certificate, obtain the first public key file marker in the first file header; According to the first public key file marker, read the first public key data stored internally; Extract the first public key offset in the first file header and the first file body of the pre-stored digital certificate; In the first file body, determine the position of the first public key offset; Output all the byte data before the position of the first public key offset in the first file body; Output the first public key data; Output the byte data at the position of the first public key offset in the first file body and all the byte data after the position of the first public key offset.

[0093] In one embodiment, the processor 1001 also performs the following operations: In the case where the file type in the first file header indicates that the pre-stored digital certificate is not of the file type of the lightweight certificate file, return the pre-stored digital certificate.

[0094] In the embodiments of the present application, on the one hand, since the amount of public key data in the digital certificate generated based on the quantum-resistant cryptographic algorithm is large, the present application can write the public key offset of the public key data, the data before the public key data, and the data after the public key data in the digital certificate to be stored into the file body by establishing a lightweight certificate file for excluding the public key data, so that the digital certificate only records the position of the public key data in the digital certificate to be stored and the non-public key information without storing the public key data. Therefore, the public key data with a large amount of data is excluded, significantly reducing the volume of the certificate file, thereby reducing the storage cost and at the same time expanding the function expansion and application scope of the device. On the other hand, when restoring the data of the pre-stored digital certificate, since it is not necessary to parse the entire certificate file, the amount of calculation is reduced, which is suitable for devices with limited resources.

[0095] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program for processing digital certificates for quantum-resistant cryptographic algorithms can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disc, a read-only memory, or a random access memory, etc.

[0096] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of the rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.

Claims

1. A digital certificate processing method for quantum-resistant cryptographic algorithms, characterized in that, Applied to a security authentication device, the method includes: Receiving a digital certificate to be stored sent by a host computer, where the digital certificate to be stored is generated based on a quantum-resistant cryptographic algorithm; Establishing a lightweight certificate file for excluding public key data, where the lightweight certificate file includes a file header and a file body; Writing an identifier of the public key data in the digital certificate to be stored into the file header, where the identifier includes a public key file marker and a public key offset in the digital certificate, and writing the data before the public key data and the data after the public key data in the digital certificate to be stored into the file body, and storing the lightweight certificate file with the written data.

2. The method according to claim 1, wherein The writing the identifier of the public key data in the digital certificate to be stored into the file header includes: Retrieving a public key file marker related to the digital certificate to be stored from an internal memory; Determining the start and end positions of the public key data in the digital certificate to be stored, where the start and end positions include a public key offset, and the public key offset is the starting byte position of the public key data starting from 0; Taking the public key file marker and the public key offset as an identifier of the public key data; Writing the file type of the lightweight certificate file and the identifier into the file header.

3. The method according to claim 2, wherein Determining the data before the public key data and the data after the public key data in the digital certificate to be stored according to the following steps includes: Determining the public key length of the public key data according to the start and end positions; Obtaining the data of all bytes before the public key offset in the digital certificate to be stored as the data before the public key data in the digital certificate to be stored; Adding the public key offset and the public key length to obtain a target position; Taking the data of the byte at the target position and the data of all bytes after the target position as the data after the public key data in the digital certificate to be stored.

4. The method according to claim 2, wherein The determining the start and end positions of the public key data in the digital certificate to be stored includes: Obtaining the certificate format of the digital certificate to be stored; Parsing the digital certificate to be stored based on the certificate format to obtain a certificate data structure; Analyzing the start and end positions of the public key data according to the certificate data structure.

5. The method according to claim 2, wherein The determining the start and end positions of the public key data in the digital certificate to be stored includes: Reading a public key data byte string related to the digital certificate to be stored from an internal memory based on a public key file marker related to the digital certificate to be stored; Searching for a string identical to the public key data byte string in the digital certificate to be stored in a forward search manner from front to back; In the case of finding a string identical to the public key data byte string, taking the position of the first byte of the found string identical to the public key data byte string as the public key offset; Determining the start and end positions of the public key data in the digital certificate to be stored based on the public key offset.

6. The method according to claim 1, wherein The method further includes: In response to a digital certificate reading instruction sent by a host computer, determining whether the digital certificate reading instruction instructs the security authentication device to restore a digital certificate; If not, directly returning a pre-stored digital certificate; If so, reading a first file header of a pre-stored digital certificate; In the case that the file type in the first file header indicates that the pre-stored digital certificate is of the file type of a lightweight certificate file, obtain the first public key file marker in the first file header; According to the first public key file marker, read the first public key data stored internally; Extract the first public key offset in the first file header and the first file body of the pre-stored digital certificate; In the first file body, determine the position of the first public key offset; Output the data of all bytes before the position of the first public key offset in the first file body; Output the first public key data; Output the data of the byte at the position of the first public key offset in the first file body and the data of all bytes after the position of the first public key offset.

7. The method according to claim 6, wherein The method further includes: In the case that the file type in the first file header indicates that the pre-stored digital certificate is not of the file type of a lightweight certificate file, return the pre-stored digital certificate.

8. A digital certificate processing method for quantum-resistant cryptographic algorithms, characterized in that, Applied to the host computer, the method includes: Based on the model or function of the security authentication device, determine whether the security authentication device supports the digital certificate restoration function; If so, generate a digital certificate reading instruction indicating that the security authentication device restores the digital certificate, and send it to the security authentication device to obtain the restored digital certificate from the security authentication device; If not, obtain the pre-stored digital certificate from the security authentication device; Read the second file header of the pre-stored digital certificate; In the case that the file type in the second file header indicates that the pre-stored digital certificate is of the file type of a lightweight certificate file, obtain the second public key file marker in the second file header; According to the second public key file marker, read the second public key data stored internally in the security authentication device; Extract the second public key offset in the second file header and the second file body of the pre-stored digital certificate; the second file body includes the data before the public key data and the data after the public key data; Insert the second public key data into the position at the second public key offset in the second file body to obtain a digital certificate containing the public key data.

9. A digital certificate processing device for anti-quantum cryptographic algorithms, characterized in that, The device includes: A receiving module, configured to receive a digital certificate to be stored sent by the host computer, where the digital certificate to be stored is generated based on a quantum-resistant cryptographic algorithm; A building module, configured to build a lightweight certificate file for excluding public key data, where the lightweight certificate file includes a file header and a file body; A writing module, configured to write the identifier of the public key data in the digital certificate to be stored into the file header, where the identifier includes a public key file marker and the public key offset in the digital certificate, and write the data before the public key data and the data after the public key data in the digital certificate to be stored into the file body, and store the lightweight certificate file with the written data.

10. A digital certificate processing device for a quantum-resistant cryptographic algorithm, characterized in that, The device includes: A judgment module, configured to determine whether the security authentication device supports the digital certificate restoration function based on the model or function of the security authentication device; A generation module, if so, is configured to generate a digital certificate reading instruction for instructing the security authentication device to restore the digital certificate, and send it to the security authentication device to obtain the restored digital certificate from the security authentication device; A first acquisition module, if not, is configured to obtain the pre-stored digital certificate from the security authentication device; A first reading module is configured to read a second file header of the pre-stored digital certificate; A second acquisition module is configured to obtain a second public key file marker in the second file header when the file type in the second file header indicates the file type of the pre-stored digital certificate as a lightweight certificate file; A second reading module is configured to read second public key data stored inside the security authentication device according to the second public key file marker; An extraction module is configured to extract a second public key offset in the second file header and a second file body of the pre-stored digital certificate; the second file body includes data before the public key data and data after the public key data; An insertion module is configured to insert the second public key data into the position at the second public key offset of the second file body to obtain a digital certificate containing the public key data.

Citation Information

Patent Citations

  • Compression method and device, electronic equipment and storage medium

    CN116962310A

  • Anti-quantum hybrid certificate combination method and system, and electronic equipment

    CN117650898A

  • Digital certificate signing and issuing method and device, digital certificate application method and device, storage medium and electronic equipment

    CN118157871A

  • Lightweight password application method and device and password application service system

    CN118432946A

  • Digital certificate authentication method and device based on post-quantum algorithm, equipment and medium

    CN119603065A