Security certificate issuing method, device, equipment, medium and product
By using post-quantum algorithms for key expansion and signature processing in V2X SCMS, the problem of traditional algorithm failure in the quantum computing environment is solved, and the efficiency and security of certificate issuance and management are achieved, ensuring the reliability of V2X communication.
Patent Information
- Application Number
- CN202510677103.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional signature and encryption methods based on algorithms such as ECC and SM2 have lost security in the quantum computing environment and cannot effectively resist quantum computing attacks, resulting in the loss of reliability of certificate issuance and management of V2X SCMS.
Post-quantum algorithms, such as RLWE-based key expansion method, generate an extended key set, including multiple butterfly sub-public keys and corresponding private keys, and configure a new public and private key pair in the pseudonym certificate processing unit to sign and encrypt, ensuring the secure issuance and use of certificates.
Through the use of post-quantum algorithms, the certificate issuance and management are efficient and secure, and can resist quantum computing attacks and ensure the integrity and privacy of V2X communication.
Smart Images

Figure CN120201426A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and in particular, to a method, device, equipment, medium and product for issuing security certificates. Background Art
[0002] With the rapid development of vehicle-to-vehicle (V2V) communication technology, the vehicle-to-everything (V2X) communication system is the technical cornerstone for its realization. The intelligent transportation system (ITS) has increasingly higher requirements for security and efficiency. As an important part of ITS, the V2X SCMS (Security Credential Management System) is responsible for issuing and managing digital certificates for vehicles to ensure the reliability and privacy of vehicle communication. Digital certificates are issued by a certificate authority (CA) and contain the public key, identity information, etc. of the vehicle, and are the basis for secure communication of the vehicle.
[0003] In the traditional V2X SCMS, signature and encryption methods based on algorithms such as elliptic curve cryptography (ECC) and SM2 are mainly used to implement the issuance and management of digital certificates. These methods have high security and efficiency in the classical computing environment and are widely used in the security guarantee of vehicle communication.
[0004] However, with the rapid development of quantum computing, the traditional signature and encryption methods based on algorithms such as ECC and SM2 are facing severe security challenges. The powerful computing power of quantum computers can crack these algorithms, making the traditional V2X SCMS lose its security guarantee in the quantum computing environment. In addition, although the traditional V2X SCMS adopts a butterfly key expansion algorithm based on ECC to improve the efficiency of certificate issuance, this algorithm is also threatened by quantum computing. Once quantum computers can crack the ECC algorithm, the butterfly key expansion algorithm will also lose its security, resulting in the generation and management of pseudonym certificates becoming unreliable. Summary of the Invention
[0005] The purpose of the present application is to provide a method, device, equipment, medium and product for issuing security certificates, which can improve the efficiency and security of certificate issuance.
[0006] To achieve the above object, the present application provides the following solutions: In a first aspect, the present application provides a method for issuing a security certificate, which is implemented by a V2X digital certificate issuance system; the V2X digital certificate issuance system includes: a certificate authentication unit, a pseudonym certificate processing unit, and a vehicle communication entity; wherein, the vehicle communication entity is connected to the certificate authentication unit; the certificate authentication unit is connected to the pseudonym certificate processing unit; The method includes: Obtain certificate request data; Generate a seed public-private key pair within the vehicle communication entity based on the certificate request data; Perform key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an extended key set; the extended key set includes multiple butterfly sub-public keys and corresponding private keys; Configure a new pair of public and private keys for each of the butterfly sub-public keys based on the pseudonym certificate processing unit, and sign the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate; the certificate to be signed is determined based on the new public and private keys; Encrypt the pseudonym certificate based on the encryption key corresponding to the pseudonym certificate processing unit to obtain an encrypted certificate; Based on the vehicle communication entity, use the seed public-private key pair to perform key reconstruction on the encrypted certificate to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate.
[0007] Optionally, the seed public-private key pair is generated by the vehicle communication entity according to preset standards based on the certificate request data; the seed public-private key pair includes: a signature key pair, an encryption key pair, and a symmetric key.
[0008] Optionally, performing key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an extended key set specifically includes: Perform key expansion on the seed public-private key pair using a key derivation function to obtain multiple butterfly sub-public keys; Configure and generate a corresponding private key for each of the butterfly sub-public keys, and store the butterfly sub-public keys and the corresponding private keys in association to obtain the extended key set.
[0009] Optionally, configuring a new pair of public and private keys for each of the butterfly sub-public keys based on the pseudonym certificate processing unit, and signing the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate specifically includes: Configure a new pair of public and private keys for each of the butterfly sub-public keys based on the pseudonym certificate processing unit; Construct a certificate to be signed according to the new public and private keys; Sign the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate.
[0010] Optionally, based on the vehicle communication entity using a seed public-private key pair, key reconstruction is performed on the encrypted certificate to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate, specifically including: Based on the vehicle communication entity using a seed public-private key pair, key reconstruction is performed on the encrypted certificate to obtain the complete private key corresponding to the initial pseudonym certificate; Verification processing is performed on the complete private key corresponding to the initial pseudonym certificate to obtain the complete private key corresponding to the pseudonym certificate.
[0011] Optionally, the secure certificate issuance method further includes: Based on the certificate authentication unit, the encrypted certificate is packaged and transmitted to the vehicle communication entity.
[0012] In a second aspect, the present application provides a secure certificate issuance device, including: A data acquisition module, configured to acquire certificate request data; A seed public-private key pair generation module, configured to generate a seed public-private key pair in the vehicle communication entity based on the certificate request data; A key expansion module, configured to perform key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an expanded key set; the expanded key set includes a plurality of butterfly sub-public keys and corresponding private keys; A signature module, configured to configure a new pair of public and private keys for each of the butterfly sub-public keys based on the pseudonym certificate processing unit, and perform signature on the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate; the certificate to be signed is determined according to the new public and private keys; An encryption module, configured to encrypt the pseudonym certificate based on the encryption key corresponding to the pseudonym certificate processing unit to obtain an encrypted certificate; A key reconstruction module, configured to perform key reconstruction on the encrypted certificate based on the vehicle communication entity using a seed public-private key pair to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate.
[0013] In a third aspect, the present application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the computer program to implement the above-mentioned secure certificate issuance method.
[0014] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned secure certificate issuance method is implemented.
[0015] Fifth aspect, the present application provides a computer program product, including a computer program which, when executed by a processor, implements the above-mentioned security certificate issuance method.
[0016] According to the specific embodiments provided by the present application, the present application has the following technical effects: The present application provides a security certificate issuance method, device, equipment, medium and product. A seed public-private key pair is generated in a vehicle communication entity based on certificate request data; the seed public-private key pair is key-expanded using a post-quantum algorithm to obtain an expanded key set; the expanded key set includes multiple butterfly sub-public keys and corresponding private keys; a new pair of public and private keys is configured for each butterfly sub-public key based on a pseudonym certificate processing unit, and the certificate to be signed is signed using a post-quantum algorithm to obtain a pseudonym certificate; the pseudonym certificate is encrypted based on the encryption key corresponding to the pseudonym certificate processing unit to obtain an encrypted certificate; based on the vehicle communication entity, the encrypted certificate is key-reconstructed using the seed public-private key pair to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate. The present application uses a post-quantum algorithm, which can realize the efficient and secure issuance and management of pseudonym certificates. The seed public-private key pair is key-expanded using a post-quantum algorithm, and then new public and private key pairs are continuously generated for the vehicle, thereby continuously issuing new certificates, greatly reducing the interaction volume between the device side and the cloud. At the same time, using the characteristics of the post-quantum algorithm, the anti-quantum attack ability of key generation and certificate issuance can be guaranteed, providing a more reliable security guarantee for vehicle communication. Thus, the present application can improve the efficiency and security of certificate issuance. Description of the Drawings
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0018] Figure 1 It is a flowchart of the security certificate issuance method; Figure 2 It is a flowchart of the operation steps of the security certificate issuance method in practical applications; Figure 3 It is a schematic structural diagram of a V2X security certificate issuance device based on a post-quantum algorithm; Figure 4 It is a schematic structural diagram of a computer device. Detailed Embodiments
[0019] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.
[0020] To achieve the key generation of batch pseudonym certificates, V2X SCMS adopts a butterfly key expansion algorithm based on ECC. This algorithm continuously generates new public-private key pairs for vehicles in a key derivation manner, thereby continuously issuing new certificates. This method reduces the interaction volume between the device side and the cloud and improves the efficiency of certificate issuance.
[0021] To make the above objects, features, and advantages of the present application more obvious and understandable, the following further details the present application in conjunction with the accompanying drawings and specific embodiments.
[0022] In an exemplary embodiment, as Figure 1 shown, a method for issuing a security certificate is provided. This method is implemented by a V2X digital certificate issuance system; the V2X digital certificate issuance system includes: a certificate authentication unit, a pseudonym certificate processing unit, and a vehicle communication entity; wherein, the vehicle communication entity is connected to the certificate authentication unit; the certificate authentication unit is connected to the pseudonym certificate processing unit.
[0023] As Figure 1 shown, the method includes: Step 100: Obtain certificate request data.
[0024] Step 200: Generate a seed public-private key pair in the vehicle communication entity based on the certificate request data.
[0025] The seed public-private key pair is generated by the vehicle communication entity according to preset standards based on the certificate request data; the seed public-private key pair includes: a signature key pair, an encryption key pair, and a symmetric key.
[0026] Step 300: Perform key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an extended key set. The extended key set includes multiple butterfly sub-public keys and corresponding private keys.
[0027] In one embodiment, performing key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an extended key set specifically includes: Performing key expansion on the seed public-private key pair using a key derivation function to obtain multiple butterfly sub-public keys. Among them, the processing process of the key derivation function is as follows.
[0028] The vehicle uses RLWE (Ring Learning with Errors) keys to generate a seed private key / public key pair. The seed private key consists of short ring elements ( and ) and is obtained by randomly sampling a zero-centered discrete Gaussian distribution with a standard deviation of σ. Then the corresponding seed public key Y = s·G + e is calculated, where e is a ring element following the LWE distribution. Here, G is a fixed basis matrix or generating matrix.
[0029] Then this seed public key Y is sent to the RA together with two random functions, namely the first random function and the second random function . The RA is a role or mechanism related to key management or authentication.
[0030] The RA uses Y and the first random function and the second random function to generate b sub-keys . is the index number. Among them, 0 ≤ < b.
[0031] The RA sends a batch of sub-keys to the PCA.
[0032] After receiving the sub-keys , the PCA calculates the public key of the vehicle .
[0033] Among them, is the private key polynomial or vector; is the noise polynomial or vector. is the assignment symbol.
[0034] Finally, the vehicle uses the private key = { + , + } to decrypt the response of the RA, thereby recovering the set ( seed i , meta i , sig i ).
[0035] seed i is a randomly generated seed value, usually used to generate pseudo-random numbers or key materials. meta i is the metadata related to the seed value, usually containing some additional information used to describe the purpose, generation time, generation method, etc. of the seed value. sigi The digital signature for the seed value and metadata is used to ensure data integrity and authentication.
[0036] Therefore, the vehicle first calculates: .
[0037] .
[0038] Where, is a discrete Gaussian distribution.
[0039] Check the signature of the PCA, that is sig i , if the verification is successful, set the th pseudonym certificate cert i to: cert i ←( , meta i , sig i ).
[0040] The corresponding private key .
[0041] Where, is the polynomial or vector in the private key ; is the noise in the private key ; is the initial private key part; is the initial noise part.
[0042] To ensure that this private key is correct, the vehicle also needs to verify .
[0043] Generate a corresponding private key for each butterfly sub-public key configuration, and store the butterfly sub-public key and the corresponding private key in association to obtain an extended key set.
[0044] Step 400: Based on the pseudonym certificate processing unit, configure a new pair of public and private keys for each butterfly sub-public key, and sign the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate. The certificate to be signed is determined according to the new public and private keys.
[0045] In one embodiment, based on the pseudonym certificate processing unit, configuring a new pair of public and private keys for each butterfly sub-public key, and signing the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate specifically includes: Based on the pseudonym certificate processing unit, configure a new pair of public and private keys for each butterfly sub-public key.
[0046] Construct a certificate to be signed according to the new public and private keys; sign the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate.
[0047] Step 500: Based on the encryption key corresponding to the pseudonym certificate processing unit, encrypt the pseudonym certificate to obtain an encrypted certificate.
[0048] Step 600: Based on the vehicle communication entity, use the seed public and private key pair to reconstruct the key of the encrypted certificate to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate.
[0049] As an optional implementation manner, based on the vehicle communication entity, use the seed public and private key pair to reconstruct the key of the encrypted certificate to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate, specifically including: Based on the vehicle communication entity, use the seed public and private key pair to reconstruct the key of the encrypted certificate to obtain the complete private key corresponding to the initial pseudonym certificate.
[0050] Perform verification processing on the complete private key corresponding to the initial pseudonym certificate to obtain the complete private key corresponding to the pseudonym certificate.
[0051] In one embodiment, the secure certificate issuance method further includes: based on the certificate authentication unit, perform packaging processing on the encrypted certificate and transmit it to the vehicle communication entity.
[0052] The post-quantum algorithm is a class of encryption algorithms designed to resist quantum computer attacks.
[0053] This application effectively solves the vulnerability problem of the traditional V2X secure certificate issuance system in the face of quantum computing attacks. Traditional signature and encryption methods based on algorithms such as elliptic curve cryptography (ECC) and SM2 will lose security protection in the face of quantum computers. However, the post-quantum algorithms adopted in this application, such as those based on RLWE (learning with errors over rings of integers), can maintain a high level of security in a quantum computing environment, thus ensuring the integrity and privacy of V2X communication.
[0054] The butterfly key generation method based on the post-quantum algorithm in this application realizes the efficient and secure issuance and management of pseudonym certificates. This method continuously generates new public and private key pairs for vehicles through a key derivation function, thereby continuously issuing new certificates, greatly reducing the interaction volume between the device side and the cloud. At the same time, using the characteristics of the post-quantum algorithm, it ensures the anti-quantum attack ability of key generation and certificate issuance, providing a more reliable security guarantee for vehicle communication.
[0055] This application also realizes the flexibility and scalability of the V2X security certificate issuance system through the design of modular devices. Each module works in coordination to complete the whole process from key generation, certificate issuance to certificate distribution and verification, providing strong support for the secure operation of the intelligent transportation system.
[0056] As Figure 2 shown, in practical applications, the method mentioned in this application includes the following steps.
[0057] Step 101: Construct a V2X digital certificate issuance system based on a post-quantum algorithm. The system includes a certificate authority ECA (i.e., the certificate authentication unit), a pseudonym certificate authority PCA (i.e., the pseudonym certificate processing unit), and a vehicle communication entity.
[0058] Specifically, step 101 includes: Step 1011: Build a network communication architecture including the ECA, the PCA, and the vehicle communication entity.
[0059] Step 1012: Deploy a post-quantum algorithm module in the ECA and the PCA to implement functions such as key generation, expansion, signature, and verification.
[0060] Step 1013: Register the vehicle communication entity and establish a communication link between it and the ECA and the PCA.
[0061] Step 102: The vehicle communication entity generates a pair of seed public and private key pairs and submits the pair to the ECA.
[0062] Step 102 specifically includes: Step 1021: The vehicle communication entity generates a pair of signature key pairs, a pair of encryption key pairs, and two symmetric keys according to preset standards.
[0063] Step 1022: Store and protect the signature key pairs, encryption key pairs, and symmetric keys as seed public and private key pairs.
[0064] Step 103: The ECA receives the seed public and private key pairs, performs key expansion using a post-quantum algorithm to generate a series of butterfly sub-public keys and corresponding private keys, and sends the butterfly sub-public keys to the PCA.
[0065] Step 103 specifically includes: Step 1031: After receiving the seed public and private key pairs submitted by the vehicle communication entity, the ECA performs multiple rounds of expansion operations using a key derivation function to generate a series of butterfly sub-public keys.
[0066] Step 1032: Generate a corresponding private key for each butterfly sub-public key, and store the butterfly sub-public key and the private key in an associated manner.
[0067] Step 104: The PCA receives the butterfly sub-public key, randomly generates a new pair of public and private keys for each butterfly sub-public key, constructs a certificate to be signed, signs it using a post-quantum algorithm to obtain a pseudonym certificate, and encrypts the certificate and the random number using the corresponding encryption key.
[0068] Step 104 specifically includes: Step 1041: After the PCA receives the butterfly sub-public key sent by the ECA, randomly generate a new pair of public and private keys for each butterfly sub-public key.
[0069] Step 1042: Construct a certificate to be signed based on the new public and private keys and other certificate information.
[0070] Step 1043: Sign the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate.
[0071] Step 105: The PCA sends the encrypted certificate back to the ECA, and the ECA then forwards the encrypted certificate to the vehicle communication entity requesting the certificate.
[0072] Step 105 specifically includes: Step 1051: The PCA encrypts the certificate and the random number using the corresponding encryption key.
[0073] Step 1052: Send the encrypted certificate back to the ECA.
[0074] Step 1053: After the ECA receives the encrypted certificate, perform a packaging process on the certificate.
[0075] Step 1054: Forward the packaged certificate to the vehicle communication entity requesting the certificate.
[0076] Step 106: After the vehicle communication entity receives the encrypted certificate, perform key reconstruction using the initially generated seed key (i.e., the seed public and private key pair) to obtain the complete private key corresponding to each pseudonym certificate, thereby realizing the secure issuance and use of the certificate.
[0077] Step 106 specifically includes: Step 1061: After the vehicle communication entity receives the encrypted certificate, perform multiple rounds of calculations using the initially generated seed key.
[0078] Step 1062: Obtain the complete private key corresponding to each pseudonym certificate through calculation.
[0079] Step 1063: Verify the correctness of the private key to ensure that the certificate can be correctly decrypted and verified.
[0080] Based on the same inventive concept, an embodiment of the present application further provides a security certificate issuance device for implementing the security certificate issuance method involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the security certificate issuance device provided below can refer to the limitations on the security certificate issuance method in the above text and will not be repeated here.
[0081] In an exemplary embodiment, a security certificate issuance device is provided, including: A data acquisition module, configured to acquire certificate request data.
[0082] A seed public-private key pair generation module, configured to generate a seed public-private key pair within the vehicle communication entity based on the certificate request data.
[0083] A key expansion module, configured to perform key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an extended key set; the extended key set includes multiple butterfly sub-public keys and corresponding private keys.
[0084] A signature module, configured to configure a new pair of public and private keys for each butterfly sub-public key based on the pseudonym certificate processing unit, and sign the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate; the certificate to be signed is determined according to the new public and private keys.
[0085] An encryption module, configured to perform encryption processing on the pseudonym certificate based on the encryption key corresponding to the pseudonym certificate processing unit to obtain an encrypted certificate.
[0086] A key reconstruction module, configured to perform key reconstruction on the encrypted certificate based on the vehicle communication entity using the seed public-private key pair to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate.
[0087] In an exemplary embodiment in practical applications, as Figure 3 shown, a V2X security certificate issuance device 20 based on a post-quantum algorithm is provided, including: A construction module 201, configured to construct a V2X digital certificate issuance system based on a post-quantum algorithm, and the system includes a certificate certification authority ECA, a pseudonym certificate authority PCA, and a vehicle communication entity.
[0088] An issuance module 202, configured to generate a pair of seed public-private key pairs for the vehicle communication entity and submit the seed public-private key pairs to the ECA.
[0089] The ECA receives the seed public-private key pair, performs key expansion using a post-quantum algorithm, generates a series of butterfly sub-public keys and corresponding private keys, and sends the butterfly sub-public keys to the PCA.
[0090] The PCA receives the butterfly sub-public keys, randomly generates a new pair of public-private keys for each butterfly sub-public key, constructs a certificate to be signed, performs signing using a post-quantum algorithm to obtain a pseudonym certificate, and encrypts the certificate and a random number using the corresponding encryption key.
[0091] The PCA sends the encrypted certificate back to the ECA, and the ECA then forwards the encrypted certificate to the vehicle communication entity requesting the certificate.
[0092] After receiving the encrypted certificate, the vehicle communication entity performs key reconstruction using the initially generated seed key to obtain the complete private key corresponding to each pseudonym certificate, thus realizing the secure issuance and use of the certificate.
[0093] The construction module 201 is further configured to: Build a network communication architecture including the ECA, the PCA, and the vehicle communication entity; deploy a post-quantum algorithm module in the ECA and the PCA to implement functions such as key generation, expansion, signing, and verification; register the vehicle communication entity and establish a communication link between it and the ECA and the PCA.
[0094] The signing module 202 is further configured to: The vehicle communication entity generates a pair of signature key pairs, a pair of encryption key pairs, and two symmetric keys according to preset standards; stores and protects the signature key pairs, encryption key pairs, and symmetric keys as the seed public-private key pair.
[0095] The signing module 202 is further configured to: After receiving the seed public-private key pair submitted by the vehicle communication entity, the ECA performs multiple rounds of expansion operations using a key derivation function to generate a series of butterfly sub-public keys; generates a corresponding private key for each butterfly sub-public key, and stores the butterfly sub-public keys and private keys in an associated manner.
[0096] The signing module 202 is further configured to: After the PCA receives the butterfly sub-public keys sent by the ECA, it randomly generates a new pair of public-private keys for each butterfly sub-public key; constructs a certificate to be signed using the new public key and other certificate information; signs the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate.
[0097] The PCA encrypts the certificate and the random number using the corresponding encryption key; sends the encrypted certificate back to the ECA; after receiving the encrypted certificate, the ECA performs a packaging process on the certificate; and forwards the packaged certificate to the vehicle communication entity that requests the certificate.
[0098] After receiving the encrypted certificate, the vehicle communication entity performs multiple rounds of calculations using the initially generated seed key; obtains the complete private key corresponding to each pseudonym certificate through the calculations; and verifies the correctness of the private key to ensure that the certificate can be correctly decrypted and verified.
[0099] In an exemplary embodiment, a computer device is provided. The computer device can be a server or a terminal, and its internal structural diagram can be as Figure 4 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store V2X security certificate issuance data based on the post-quantum algorithm. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a security certificate issuance method.
[0100] Those skilled in the art can understand that Figure 4 the structure shown in
[0101] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0102] In an exemplary embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, it implements the steps in the above method embodiments.
[0103] In an exemplary embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the steps in the above method embodiments.
[0104] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0105] Those of ordinary skill in the art can understand that all or part of the processes in the above method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0106] The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0107] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0108] In this article, specific examples are used to elaborate on the principles and implementation manners of the present application. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A method for issuing a security certificate, characterized in that, Implemented by a V2X digital certificate issuance system; The V2X digital certificate issuance system includes: a certificate authentication unit, a pseudonym certificate processing unit, and a vehicle communication entity; wherein, the vehicle communication entity is connected to the certificate authentication unit; the certificate authentication unit is connected to the pseudonym certificate processing unit; The method includes: Obtaining certificate request data; Generating a seed public-private key pair within the vehicle communication entity based on the certificate request data; Performing key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an extended key set; the extended key set includes multiple butterfly sub-public keys and corresponding private keys; Configuring a new pair of public and private keys for each of the butterfly sub-public keys based on the pseudonym certificate processing unit, and signing the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate; the certificate to be signed is determined based on the new public and private keys; Encrypting the pseudonym certificate based on the encryption key corresponding to the pseudonym certificate processing unit to obtain an encrypted certificate; Based on the vehicle communication entity, using the seed public-private key pair, performing key reconstruction on the encrypted certificate to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate.
2. The security certificate issuing method according to claim 1, wherein The seed public-private key pair is generated by the vehicle communication entity according to preset standards based on the certificate request data; The seed public-private key pair includes: a signature key pair, an encryption key pair, and a symmetric key.
3. The security certificate issuing method according to claim 1, characterized in that Performing key expansion on the seed public-private key pair using a post-quantum algorithm to obtain an extended key set, specifically including: Performing key expansion on the seed public-private key pair using a key derivation function to obtain multiple butterfly sub-public keys; Configuring and generating a corresponding private key for each of the butterfly sub-public keys, and storing the butterfly sub-public keys and the corresponding private keys in an associated manner to obtain the extended key set.
4. The security certificate issuing method according to claim 1, characterized in that, Configuring a new pair of public and private keys for each of the butterfly sub-public keys based on the pseudonym certificate processing unit, and signing the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate, specifically including: Configuring a new pair of public and private keys for each of the butterfly sub-public keys based on the pseudonym certificate processing unit; Constructing a certificate to be signed according to the new public and private keys; Signing the certificate to be signed using a post-quantum algorithm to obtain a pseudonym certificate.
5. The security certificate issuing method according to claim 1, characterized in that Based on the vehicle communication entity using the seed public-private key pair, performing key reconstruction on the encrypted certificate to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate, specifically including: Based on the vehicle communication entity using the seed public-private key pair, performing key reconstruction on the encrypted certificate to obtain the complete private key corresponding to the initial pseudonym certificate; Performing verification processing on the complete private key corresponding to the initial pseudonym certificate to obtain the complete private key corresponding to the pseudonym certificate.
6. The security certificate issuing method according to claim 1, characterized in that The secure certificate issuance method further includes: Packaging the encrypted certificate based on the certificate authentication unit and transmitting it to the vehicle communication entity.
7. A security certificate issuing device, characterized in that, The secure certificate issuance device includes: A data acquisition module for acquiring certificate request data; A seed public-private key pair generation module for generating a seed public-private key pair within the vehicle communication entity based on the certificate request data; A key expansion module, which is used to expand the seed public-private key pair by using a post-quantum algorithm to obtain an expanded key set; the expanded key set includes a plurality of butterfly sub-public keys and corresponding private keys; A signature module, which is used to configure a new pair of public and private keys for each of the butterfly sub-public keys based on a pseudonym certificate processing unit, and sign the certificate to be signed by using a post-quantum algorithm to obtain a pseudonym certificate; the certificate to be signed is determined according to the new public and private keys; An encryption module, which is used to encrypt the pseudonym certificate based on the encryption key corresponding to the pseudonym certificate processing unit to obtain an encrypted certificate; A key reconstruction module, which is used to reconstruct the key of the encrypted certificate based on a vehicle communication entity by using the seed public-private key pair to obtain the complete private key corresponding to the pseudonym certificate, so as to realize the secure issuance and use of the certificate.
8. A computer device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the secure certificate issuance method according to any one of claims 1-6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the secure certificate issuance method according to any one of claims 1-6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the secure certificate issuance method according to any one of claims 1-6.
Citation Information
Patent Citations
V2X communication system, communication key distribution method and implicit authentication method
CN113766452A
Implementation of butterfly key expansion scheme
CN113841360A
Method and device for processing pseudonym certificate of vehicle-mounted equipment and vehicle-mounted equipment
CN116156461A
Cryptographic methods and systems for managing digital certificates
US20190123915A1
Systems and methods for a butterfly key exchange program
US20210211306A1