Data processing method and system, electronic equipment and computer program product

By generating hybrid digital certificates and combining target and post-quantum algorithms, the problem of insufficient encryption security in the existing technology is solved, data protection against quantum computing is achieved, and the security of data transmission and storage is improved.

CN120281510APending Publication Date: 2025-07-08CHINA FINANCIAL CERTIFICATION AUTHORITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510311200.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing technology has failed to effectively combine the characteristics of post-quantum cryptography algorithm (PQC), resulting in the impact of encryption security and the inability to effectively resist attacks from quantum computers, and the reliability of digital certificates is threatened.

Method used

The hybrid digital certificate mechanism is adopted, and the target algorithm and post-quantum algorithm are combined to generate hybrid encryption results. Through the key identification, ciphertext and encrypted data of the target public key and post-quantum public key, the hybrid digital certificate is used for decryption to achieve secure transmission and protection of data.

Benefits of technology

Improve the security of data in the storage and transmission links, effectively resist traditional computing and quantum computing attacks, and protect plaintext data from malicious acquisition and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281510A_ABST
    Figure CN120281510A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method and system, electronic equipment and a computer program product, and relates to the technical field of data processing.The method comprises the steps that a mixed encryption result sent by a data encryption party is received; wherein the hybrid encryption result is obtained by encrypting to-be-encrypted data based on a previously obtained hybrid digital certificate by the data encryption party, and the hybrid digital certificate is obtained by requesting a certificate authority (CA) based on a certificate obtaining request and is sent to the data encryption party; and according to the hybrid encryption result, searching a corresponding hybrid digital certificate, and decrypting the hybrid encryption result by using a target private key corresponding to the hybrid digital certificate to obtain plaintext data. According to the method, the security of data in links such as storage and transmission is greatly improved, and plaintext data is effectively protected from being maliciously acquired and tampered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular, to a data processing method, system, electronic device, and computer program product. Background Art

[0002] A digital certificate is an electronic document issued by a Certificate Authority (CA for short), which is used to prove the authenticity of a public key and the identity of the owner. Digital certificates play a crucial role in the Public Key Infrastructure (PKI for short). By providing a secure and reliable way to verify identities and encrypt data, they ensure the security of information transmission. With the continuous development of quantum computer technology, it can break algorithms such as RSA, SM2, and ECC through the Shor algorithm, making the existing PKI technology no longer secure. After a quantum computer breaks the CA key, it can forge the signature made by the CA on the digital certificate, and then can arbitrarily replace the owner information in the certificate, making the digital certificate no longer reliable.

[0003] To resist the attacks of quantum computers, the technology of Post-Quantum Cryptography (PQC for short) has been deeply studied. PQC algorithms are a class of cryptographic algorithms designed to resist the attacks of quantum computers. PQC algorithms are mainly based on several types of mathematical problems, which are considered difficult to crack even in the face of quantum computers. Among them, methods based on problems such as Lattice-based, Code-based, Multivariate quadratic equations, Hash-based, and Isogeny-based have received greater attention. Different types of post-quantum cryptographic algorithms have different characteristics (key and ciphertext sizes, running times, etc.) and different security levels due to the different mathematical problems they are based on.

[0004] However, the development time of PQC algorithms is relatively short at present, and there is no PQC algorithm whose performance and security are simultaneously accepted by everyone. In addition, there are also difficulties in integrating PQC algorithms with existing security standards and protocols. Many traditional security protocols were not designed considering the characteristics of PQC algorithms. To achieve seamless docking, a large number of specifications and processes need to be re-established and revised, which is extremely challenging for the coordinated and unified work globally. Summary of the Invention

[0005] The present invention provides a data processing method, system, electronic device and computer program product, which are used to solve the defect that the characteristics of the PQC algorithm are not effectively combined in the prior art, resulting in the influence on encryption security, improve the security of data in storage, transmission and other links, and effectively protect the plaintext data from being maliciously obtained and tampered with.

[0006] The present invention provides a data processing method, including: receiving a hybrid encryption result sent by a data encryptor; wherein, the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on a previously obtained hybrid digital certificate, and the hybrid digital certificate is obtained by requesting from a certificate authority (CA) based on a certificate acquisition request and sent to the data encryptor; according to the hybrid encryption result, searching for the corresponding hybrid digital certificate, and using the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data; the hybrid encryption result is obtained by the data encryptor based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each post-quantum public key, a preset encryption algorithm, a first ciphertext, the second ciphertext corresponding to each post-quantum public key, and the encrypted data; the target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of each post-quantum public key are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; the hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and the certificate holder information in the certificate acquisition request; the first ciphertext is obtained by the data encryptor encrypting the first random number in a previously generated random number set using the target public key; the second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the random number set except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to each other random number one by one; the encrypted data is obtained by the data encryptor encrypting the previously obtained data to be encrypted using an encryption key and an encryption algorithm, and the encryption key is derived by the data encryptor based on the random number set using a previously obtained key derivation algorithm.

[0007] According to the data processing method provided by the present invention, the hybrid encryption result is obtained by the data encryptor encapsulating the target public key, the key identifier of the target public key, and the first ciphertext into a receiver information storage structure for the first key transmission, encapsulating each post-quantum public key, the key identifier corresponding to the post-quantum public key, and the second ciphertext into a receiver information storage structure for the second key transmission corresponding to each post-quantum public key, and encapsulating the encryption algorithm and the encrypted data into an encrypted content storage structure.

[0008] A data processing method provided by the present invention, according to the hybrid encryption result, searches for the corresponding hybrid digital certificate, and uses the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data, including: obtaining the receiver information storage structure of the first key transmission, the receiver information storage structure of each second key transmission, and the encrypted content storage structure according to the hybrid encryption result; determining the target private key of the corresponding hybrid digital certificate according to the key identifier of the target public key in the receiver information storage structure of the first key transmission, and using the target private key to decrypt the first ciphertext to obtain the first plaintext; determining the post-quantum private keys corresponding to the respective post-quantum public keys according to the post-quantum algorithms of the post-quantum public keys in the receiver information storage structures of the respective second key transmissions, in combination with the hybrid digital certificate, and using the respective post-quantum private keys to decrypt the corresponding second ciphertexts to obtain the corresponding second plaintexts; parsing the encrypted content storage structure to obtain the encryption algorithm and the encrypted data; obtaining the corresponding key derivation algorithm according to the encryption algorithm, and obtaining the decryption key by using the key derivation algorithm according to the first plaintext and the second plaintext; using the decryption key to decrypt the encrypted data to obtain the plaintext data.

[0009] A data processing method provided by the present invention, the hybrid encryption result is obtained by the data encryptor after parsing the hybrid digital certificate, based on the successful validation of the validity of the parsed hybrid digital certificate, based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of the respective post-quantum public keys, a preset encryption algorithm, the first ciphertext, the second ciphertexts corresponding to the respective post-quantum public keys, and the encrypted data; the validity verification is that the data encryptor uses the target public key according to the target algorithm, the target signature value, the target public key, the respective post-quantum algorithms, the respective post-quantum signature values, and the respective post-quantum public keys in the parsed hybrid digital certificate, and according to the verification rules corresponding to the target algorithm, validates the validity of the target signature value and the hybrid digital certificate other than the target signature value; and, using the respective post-quantum public keys, according to the verification rules corresponding to the respective post-quantum algorithms, validates the validity of the corresponding post-quantum signature value and the hybrid digital certificate after setting the corresponding post-quantum signature value to zero.

[0010] A data processing method provided by the present invention further includes, before sending a hybrid digital certificate to a data encryptor based on a certificate acquisition request: sending a certificate acquisition request to a CA based on a target public key, at least one post-quantum public key, and certificate holder information, where the certificate acquisition request includes the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of the respective post-quantum public keys, and certificate holder information; receiving the hybrid digital certificate returned by the CA based on the certificate acquisition request; where the hybrid digital certificate is obtained by the CA determining data to be signed based on the target public key, all post-quantum public keys, and certificate holder information parsed from the certificate acquisition request, signing the data to be signed using the post-quantum private keys corresponding to the respective post-quantum public keys based on the key identifiers of the respective post-quantum public keys, and signing the signed data to be signed using the target private key corresponding to the target public key based on the key identifier of the target public key.

[0011] A data processing method provided by the present invention, the hybrid digital certificate is obtained by the CA signing the data to be signed certificate data with a post-quantum signature value using the corresponding target private key based on the key identifier of the target public key; the data to be signed certificate data with a post-quantum signature value is obtained by the CA signing the data to be signed certificate data with a zero post-quantum signature value using the corresponding post-quantum private key based on the key identifier of each post-quantum public key; the data to be signed certificate data with a zero post-quantum signature value is obtained by the CA encapsulating the target public key, all post-quantum public keys, certificate holder information received from the certificate acquisition request, and the zeroed post-quantum signature value; the zeroed post-quantum signature value is obtained by the CA determining the storage space size corresponding to the post-quantum signature based on each post-quantum algorithm, allocating space for the corresponding post-quantum signature value and zeroing the content of the allocated space.

[0012] A data processing method provided by the present invention, before sending a certificate acquisition request to the CA, includes: obtaining certificate request data according to the certificate holder information, the pre-generated post-quantum public key, and the target public key; signing the certificate request data using the pre-generated post-quantum private key to obtain a signature result; generating a certificate acquisition request according to the signature result and the certificate request data.

[0013] The present invention also provides a data processing system, including: a result receiving module, which receives the hybrid encryption result sent by the data encryptor; wherein, the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on the previously obtained hybrid digital certificate, and the hybrid digital certificate is obtained by requesting from a certificate authority CA based on a certificate acquisition request and sent to the data encryptor; a decryption module, which, according to the hybrid encryption result, searches for the corresponding hybrid digital certificate and uses the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data; the hybrid encryption result is obtained by the data encryptor based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of the respective post-quantum public keys, a preset encryption algorithm, a first ciphertext, the second ciphertexts corresponding to the respective post-quantum public keys, and the data to be encrypted; the target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of the respective post-quantum public keys are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; the hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and the certificate holder information in the certificate acquisition request; the first ciphertext is obtained by the data encryptor encrypting the first random number in the previously generated random number set using the target public key; the second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the random number set except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to one of the other random numbers; the data to be encrypted is obtained by the data encryptor encrypting the previously obtained data to be encrypted using an encryption key and an encryption algorithm, and the encryption key is derived by the data encryptor based on the random number set using a pre-obtained key derivation algorithm.

[0014] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the data processing method as described in any one of the above is implemented.

[0015] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the data processing method as described in any one of the above is implemented.

[0016] The present invention also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the data processing method as described in any one of the above is implemented.

[0017] The data processing method, system, electronic device and computer program product provided by the present invention generate a hybrid digital certificate by combining a target algorithm and a post-quantum algorithm, so as to utilize the protection capabilities of two different types of algorithms to resist traditional computing attacks and potential future quantum computing attacks, greatly enhancing the security of data in storage, transmission and other links, and effectively protecting the plaintext data from being maliciously obtained and tampered with. Brief Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 is one of the flow diagrams of the data processing method provided by the present invention; Figure 2 is the second flow diagram of the data processing method provided by the present invention; Figure 3 is the structural diagram of the data processing device provided by the present invention; Figure 4 is the structural diagram of the electronic device provided by the present invention. Detailed Embodiments

[0020] To make the objectives, technical solutions and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.

[0021] Figure 1 is the flow diagram of the data processing method provided by the present invention. As Figure 1 shown, the execution subject of this method is the certificate holder, and the method includes: S11. Receive the hybrid encryption result sent by the data encryptor; the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on the previously obtained hybrid digital certificate, and the hybrid digital certificate is requested from the certificate authority CA based on the certificate acquisition request and sent to the data encryptor; S12. According to the hybrid encryption result, find the corresponding hybrid digital certificate, and use the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data.

[0022] It should be noted that the certificate holder can be the user side or the device side, and no further limitation is made here. In addition, the step number "S1N" in this specification does not represent the sequence of the data processing method. The data processing method of the present invention will be specifically described below in combination with Figure 2 Describe the data processing method of the present invention.

[0023] Step S11, receiving the hybrid encryption result sent by the data encryptor; wherein, the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on the previously obtained hybrid digital certificate, and the hybrid digital certificate is obtained by requesting from the certificate authority CA based on the certificate acquisition request and sent to the data encryptor. It should be noted that the data encryptor can be the user side or the device side, and no further limitation is made here.

[0024] Specifically, referring to Figure 2 , before the certificate holder receives the hybrid encryption result sent by the data encryptor, it includes: the data encryptor receives the hybrid digital certificate forwarded by the certificate holder; the data encryptor encrypts the previously obtained data to be encrypted based on the hybrid digital certificate to obtain the hybrid encryption result, and sends the hybrid encryption result to the certificate holder for decryption to obtain the decrypted plaintext data, so as to realize the secure transmission of data and improve the security of data transmission.

[0025] It should be added that the hybrid digital certificate sent by the certificate holder to the data encryptor can be actively forwarded by the certificate holder or sent based on the request of the data encryptor, which can be specifically set according to actual design requirements, and no further limitation is made here.

[0026] Furthermore, the hybrid encryption result is obtained by the data encryptor based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each post-quantum public key, a preset encryption algorithm, the first ciphertext, the second ciphertext corresponding to each post-quantum public key, and the encrypted data; the target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of each post-quantum public key are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; the hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and the certificate holder information in the certificate acquisition request; the first ciphertext is obtained by the data encryptor encrypting the first random number in the previously generated random number set using the target public key; the second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the random number set except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to each other random number one by one; the encrypted data is obtained by the data encryptor encrypting the previously obtained data to be encrypted using the encryption key and the encryption algorithm, and the encryption key is derived by the data encryptor according to the random number set using the pre-obtained key derivation algorithm.

[0027] It should be noted that the random numbers in the random number set are generated simultaneously, and for the convenience of representation, each generated random number is numbered. For example, the first random number is numbered 0, and the other random numbers are numbered 1 to N, etc. No further limitation is made here.

[0028] In an alternative embodiment, the encryption algorithm can be selected by the data encryption party based on the data encryption requirements. The encryption algorithm can be the symmetric encryption algorithm SymAlgm, and the key derivation algorithm can select the hash-based KDF algorithm to hash the first random number and each other random number, so as to obtain an encryption key with a fixed length and uniqueness.

[0029] Specifically, the data encryption party encrypts the previously obtained data to be encrypted based on the hybrid digital certificate to obtain a hybrid encryption result, including: receiving the hybrid digital certificate sent by the certificate holder, where the hybrid digital certificate includes the target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of each post-quantum public key; generating a random number set, where the random number set includes a preset number of random numbers; using the target public key to encrypt the first random number in the random number set to obtain a first ciphertext, and for each post-quantum public key, using the post-quantum public key to encrypt the other random numbers in the random number set except the first random number to obtain a second ciphertext corresponding to the post-quantum public key; where each post-quantum public key corresponds to one of the other random numbers; obtaining an encryption key according to the random number set using a preset key derivation algorithm; using the encryption key and a preset encryption algorithm to encrypt the previously obtained data to be encrypted to obtain encrypted data; obtaining a hybrid encryption result according to the target public key, the first ciphertext, the key identifier of the target public key, each post-quantum public key, the second ciphertext corresponding to each post-quantum public key, the key identifier of each post-quantum public key, the encryption algorithm, and the encrypted data, so as to adaptively introduce the required number of post-quantum keys to complete the encryption of the data based on the needs of the application security level on the basis of the target public key encryption.

[0030] Furthermore, the hybrid encryption result is obtained by the data encryption party encapsulating the target public key, the key identifier of the target public key, and the first ciphertext into the receiver information storage structure of the first key transmission, encapsulating each post-quantum public key, the key identifier corresponding to the post-quantum public key, and the second ciphertext into the receiver information storage structure of the second key transmission corresponding to each post-quantum public key, and encapsulating the encryption algorithm and the encrypted data into the encrypted content storage structure.

[0031] In other words, the data encryption party obtains a hybrid encryption result based on the target public key, the first ciphertext, the key identifier of the target public key, each post-quantum public key, the second ciphertext corresponding to each post-quantum public key, the key identifier of each post-quantum public key, the encryption algorithm, and the encrypted data, including: encapsulating the target public key, the key identifier of the target public key, and the first ciphertext into a recipient information storage structure for the first key transmission; encapsulating each post-quantum public key, the key identifier corresponding to the post-quantum public key, and the second ciphertext into a recipient information storage structure for the second key transmission corresponding to each post-quantum public key; encapsulating the encryption algorithm and the encrypted data into an encrypted content storage structure; and obtaining the hybrid encryption result based on the recipient information storage structure for the first key transmission, the recipient information storage structures for the second key transmissions, and the encrypted content storage structure.

[0032] It should be noted that the encrypted content storage structure includes a first storage part contentEncryptionAlgorithm for storing the encryption algorithm and a second storage part encryptedContent for storing the encrypted data. Additionally, contentEncryptionAlgorithm further includes a first tag and a second tag. The first tag is used to mark key derivation, and the second tag is used to mark the encryption algorithm. The priority of the first tag is higher than that of the second tag to implement the marking of the data encryption process, thereby facilitating subsequent decryption.

[0033] For example, the structure of the hybrid encryption result is represented as: EnvelopedData ::= SEQUENCE { version CMSVersion, originatorInfo [0] IMPLICIT OriginatorInfo OPTIONAL, recipientInfos RecipientInfos, encryptedContentInfo EncryptedContentInfo, unprotectedAttrs [1] IMPLICIT UnprotectedAttributes OPTIONAL} Among them, recipientInfos is used to store the recipient information storage structure for the first key transmission and the recipient information storage structures for the second key transmissions, and is specifically represented as: RecipientInfos ::= SET SIZE (1..MAX) OF RecipientInfo RecipientInfo ::= CHOICE { ktri KeyTransRecipientInfo, kari [1] KeyAgreeRecipientInfo, kekri [2] KEKRecipientInfo, pwri [3] PasswordRecipientinfo, ori [4] OtherRecipientInfo} KeyTransRecipientInfo ::= SEQUENCE { version CMSVersion, -- always set to 0 or 2 rid RecipientIdentifier, keyEncryptionAlgorithm KeyEncryptionAlgorithmIdentifier, encryptedKey EncryptedKey} Among them, RecipientInfos can be selected based on structural types such as KeyTransRecipientInfo, KeyAgreeRecipientInfo, KEKRecipientInfo, PasswordRecipientinfo, and OtherRecipientInfo, which will not be further described here. For example, when RecipientInfos selects the KeyTransRecipientInfo structure, the storage structure of the recipient information for the first key transmission is represented as KeyTransRecipientInfo0, and the storage structure of the recipient information for the second key transmission of each post-quantum public key is represented as KeyTransRecipientInfoi, where i ∈ [1, N], and N represents the number of post-quantum public keys, so as to store each ciphertext component into different RecipientInfos of the digital envelope respectively.

[0034] In an alternative embodiment, before the certificate holder sends the hybrid digital certificate to the data encryptor, it includes: parsing the hybrid digital certificate, and based on the parsed hybrid digital certificate, extracting the corresponding target algorithm, target signature value, and target public key; using the target public key, according to the verification rules corresponding to the target algorithm, verifying the validity of the target signature value and the hybrid digital certificate except the target signature value; and preprocessing each post-quantum signature value in the hybrid digital certificate to set each post-quantum signature value to zero; extracting each post-quantum algorithm, each post-quantum signature value, and each post-quantum public key according to the parsed hybrid digital certificate; using each post-quantum public key, according to the verification rules corresponding to each post-quantum algorithm, verifying the validity of the corresponding post-quantum signature value and the hybrid digital certificate after the corresponding post-quantum signature value is set to zero.

[0035] It should be added that the target algorithm can be algorithms such as RSA, SM2, and ECC, and can be specifically selected according to actual design requirements. The target public key and target private key are generated corresponding to the specific target algorithm, and the post-quantum public key and the corresponding post-quantum private key are generated based on the corresponding post-quantum algorithm, which will not be further elaborated here. In addition, when verifying the validity of the hybrid digital certificate, the validity of the traditional signature value and the post-quantum signature value are respectively verified through a dual verification mechanism to increase the difficulty of the hybrid digital certificate being forged or misused. Only when both signature values pass the verification can it be confirmed that the certificate is legal and used for encryption, providing a reliable trust basis for the entire encryption process and avoiding the risk of data leakage caused by possible security vulnerabilities in a single signature mechanism.

[0036] In an alternative embodiment, before receiving the hybrid encryption result sent by the data encryptor, it further includes: sending a certificate acquisition request to the CA, where the certificate acquisition request is generated based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each post-quantum public key, and the certificate holder information; receiving the hybrid digital certificate returned by the CA based on the certificate acquisition request; where the hybrid digital certificate is the certificate data to be signed determined by the CA based on the target public key, all post-quantum public keys, and the certificate holder information with the post-quantum signature value being zero, and is signed based on the key identifiers of each post-quantum public key using the post-quantum private key corresponding to each post-quantum public key to obtain the certificate data to be signed with the post-quantum signature value, and is signed based on the key identifier of the target public key using the target private key corresponding to the target public key for the certificate data to be signed with the post-quantum signature value.

[0037] Specifically, before sending the certificate acquisition request to the CA, it includes: generating a post-quantum public-private key pair and a target public-private key pair; generating a certificate acquisition request according to the post-quantum public-private key pair, the target public key, and the certificate holder information.

[0038] Furthermore, a certificate acquisition request is generated based on the post-quantum public-private key pair and the certificate holder information, including: obtaining certificate request data according to the target public key, the post-quantum public key, and the certificate holder information; signing the certificate request data with the post-quantum private key to obtain a signature result; and generating a certificate acquisition request based on the signature result and the certificate request data.

[0039] It should be noted that since there are many post-quantum cryptographic algorithms, the algorithm used by the certificate holder should be the same as the algorithm used by the CA when issuing the certificate. For example, if the post-quantum public key is based on a lattice algorithm, then the post-quantum private key used by the CA when issuing the certificate should also be a lattice-based algorithm; if the post-quantum public key is based on a hash algorithm, then the post-quantum private key used by the CA when issuing the certificate should also be a hash-based algorithm.

[0040] In addition, the hybrid digital certificate is obtained by the CA signing the certificate data to be signed with the post-quantum signature value based on the key identifier of the target public key using the corresponding target private key; the certificate data to be signed with the post-quantum signature value is obtained by the CA signing the certificate data to be signed with a post-quantum signature value of zero based on the key identifier of each post-quantum public key using the corresponding post-quantum private key; the certificate data to be signed with a post-quantum signature value of zero is obtained by the CA encapsulating the target public key, all post-quantum public keys, the certificate holder information, and the post-quantum signature value set to zero received based on the certificate acquisition request; the post-quantum signature value set to zero is obtained by the CA determining the storage space for the corresponding post-quantum signature according to each post-quantum algorithm, and allocating space for the corresponding post-quantum signature value and setting the content of the allocated space to zero.

[0041] In other words, after the certificate holder sends a certificate acquisition request to the CA, including: the CA receives and parses the certificate acquisition request to obtain the target public key, all post-quantum public keys, and the certificate holder information; the CA determines the storage space for the corresponding post-quantum signature pqcSignatureValue according to the post-quantum algorithm; the CA allocates space for the corresponding post-quantum signature value according to the storage space of the corresponding post-quantum signature and sets its content to zero to obtain the post-quantum signature value set to zero; the CA encapsulates the target public key, all post-quantum public keys, the certificate holder information, and the post-quantum signature value set to zero into the certificate data to be signed with a post-quantum signature value of zero TBSCertificate; the CA signs the certificate data to be signed with a post-quantum signature value of zero based on the key identifier of each post-quantum public key using the corresponding post-quantum private key and fills the signature result value into the corresponding position in the TBSCertificate to obtain the certificate data to be signed with the post-quantum signature value; the CA signs the certificate data to be signed with the post-quantum signature value based on the key identifier of the target public key using the corresponding target private key to obtain the hybrid digital certificate.

[0042] Further, after signing the certificate data to be signed with a post-quantum signature value of zero using the corresponding post-quantum private key, write the corresponding post-quantum signature value into the pre-allocated space to obtain the certificate data to be signed with a post-quantum signature value, and after signing the certificate data to be signed with a post-quantum signature value using the corresponding target private key, write the target signature value into the hybrid digital certificate. Additionally, after obtaining the to-be-signed data TBSCertificate, perform DER encoding on the TBSCertificate structure.

[0043] In addition, after the CA receives and parses the certificate acquisition request to obtain the target public key, all post-quantum public keys, and the certificate holder information, it further includes: the CA validates the validity of the signature result in the certificate acquisition request, and after the validity verification passes, signs the request data using the post-quantum private key. The specific method is as described above and will not be repeated here.

[0044] It should be noted that the post-quantum signature value needs to be dynamically allocated after first determining the space required for the corresponding signature value based on each post-quantum algorithm, so as to facilitate adaptively adding any number of post-quantum key pairs according to the needs of the business system.

[0045] In addition, the hybrid digital certificate also includes version content, serial number, target algorithm, issuing authority, certificate validity period, subject object for characterizing the certificate holder associated with the certificate, target public key, and extension content. The extension content is used to store the post-quantum public key and the corresponding signature value, specifically including the post-quantum public key pqcSubjectPublicKeyInfo, the key identifier pqcKeyIdentifier of the post-quantum public key, the post-quantum algorithm pqcSignatureAlgorithm, the post-quantum signature value pqcSignatureValue, and the key identifier pqcAuthorityKeyIdentifier used for signing. It should be noted that the key identifier pqcKeyIdentifier of the post-quantum public key is determined based on the hash value of the post-quantum public key to uniquely identify it without directly exposing the complete public key, facilitating quick positioning and differentiation of different post-quantum public keys in some scenarios (such as searching, verification, etc.), and also enhancing security to a certain extent; pqcSignatureAlgorithm is the object identifier (OID) of the signature algorithm used by the certificate authority (CA) to generate the post-quantum signature value, so that during the signature verification process, the same post-quantum algorithm can be accurately found and used based on the OID to check the validity of the signature, ensuring that the signature is generated by a legitimate CA using the correct algorithm, and when allocating space for the post-quantum signature value, the corresponding post-quantum algorithm can be accurately found based on the OID to determine the corresponding space to be allocated; pqcAuthorityKeyIdentifier is the KeyID of the key used by the CA during the post-quantum signature operation. In the case where a CA may have multiple different keys for different signature operations, the KeyID is used to clearly identify which specific key is used to generate the current post-quantum signature value, facilitating accurate finding of the corresponding key for verification during signature verification to ensure that the signature is generated by the correct CA key, thereby improving the accuracy and reliability of certificate verification.

[0046] It should be noted that the hybrid digital certificate retains traditional content such as the target public key information, which means that it can be better compatible with many existing systems, applications, and network infrastructures built based on traditional cryptography. In the current situation where a large number of traditional systems are still widely used, it is possible to smoothly introduce post-quantum cryptography-related content without large-scale system transformation, facilitating data interaction and collaborative work between different systems, and reducing the resistance faced by enterprises, institutions, etc. when gradually transitioning to quantum-resistant security protection.

[0047] In addition, for various deployed applications and services, using hybrid digital certificates to process hybrid encryption results facilitates their phased upgrading of security protection mechanisms according to their own rhythm and actual needs. The traditional part can be utilized first to maintain the normal operation of existing services, while gradually improving and enabling post-quantum related functions to achieve a stable transition from the traditional cryptographic system to the quantum-resistant cryptographic system, minimizing the impact on business continuity to the greatest extent possible.

[0048] Furthermore, hybrid digital certificates involve multiple encryption algorithms and keys, can be adapted to the encryption process corresponding to the hybrid encryption results, and flexibly support data decryption requirements in different encryption scenarios. The framework of hybrid digital certificates is relatively easy to expand and update. Whether it is the combination of traditional symmetric encryption and asymmetric encryption or complex encryption scenarios after integrating post-quantum encryption algorithms, the content and functions of the certificates can be further enriched on this basis to continue to ensure the decryption ability of various encryption results and data security, enabling the entire encryption and decryption system to keep pace with the times, adapt to the changing security situation, meet the data processing requirements under different business scenarios and different security level requirements, and has strong versatility.

[0049] For example, the extended content can be expressed as: Extensions ::= SEQUENCE SIZE (1..MAX) OF Extension Extension ::= SEQUENCE { extnID OBJECT IDENTIFIER, critical BOOLEAN DEFAULT FALSE, extnValue OCTET STRING -- contains the DER encoding of an ASN.1 value -- corresponding to the extension type identified -- by extnID The definition of PQCPubKeyAndSignatures can be as follows: PQCPubKeyAndSignatures ::= SEQUENCE SIZE (1..MAX) OFPQCPubKeyAndSignature Step S12: Based on the hybrid encryption result, search for the corresponding hybrid digital certificate, and use the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data.

[0050] In this embodiment, based on the hybrid encryption result, searching for the corresponding hybrid digital certificate, and using the private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data includes: obtaining the receiver information storage structure of the first key transmission, the receiver information storage structures of each second key transmission, and the encrypted content storage structure according to the hybrid encryption result; determining the target private key of the corresponding hybrid digital certificate according to the key identifier of the target public key in the receiver information storage structure of the first key transmission, and using the target private key to decrypt the first ciphertext to obtain the first plaintext; determining the post-quantum private keys corresponding to each post-quantum public key according to the post-quantum algorithms of the post-quantum public keys in the receiver information storage structures of each second key transmission, in combination with the hybrid digital certificate, and using each post-quantum private key to decrypt the corresponding second ciphertext to obtain the corresponding second plaintext; parsing the encrypted content storage structure to obtain the encryption algorithm and the encrypted data; obtaining the corresponding key derivation algorithm according to the encryption algorithm, and obtaining the decryption key using the key derivation algorithm according to the first plaintext and the second plaintext; using the decryption key to decrypt the encrypted data to obtain the plaintext data.

[0051] In summary, the embodiments of the present invention generate a hybrid digital certificate by combining the target algorithm and the post-quantum algorithm, so as to utilize the protection capabilities of two different types of algorithms to resist traditional computing attacks and possible future quantum computing attacks, greatly improving the security of data in storage, transmission and other links, and effectively protecting the plaintext data from being maliciously obtained and tampered with.

[0052] Next, the data processing system provided by the present invention will be described. The data processing system described below can be correspondingly referred to the data processing method described above.

[0053] Figure 3 A schematic structural diagram of a data processing system is shown. The system includes: A result receiving module 31 that receives the hybrid encryption result sent by the data encryptor; the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on the previously obtained hybrid digital certificate, and the hybrid digital certificate is requested from the certificate authority CA based on the certificate acquisition request and sent to the data encryptor; A decryption module 32 that, based on the hybrid encryption result, searches for the corresponding hybrid digital certificate, and uses the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data.

[0054] It should be noted that before the certificate holder receives the hybrid encryption result sent by the data encryptor, it includes: the data encryptor receives the hybrid digital certificate forwarded by the certificate holder; the data encryptor encrypts the previously obtained data to be encrypted based on the hybrid digital certificate to obtain the hybrid encryption result, and sends the hybrid encryption result to the certificate holder for decryption to obtain the decrypted plaintext data, thereby realizing the secure transmission of data and improving the security of data transmission.

[0055] It should be added that the hybrid digital certificate sent by the certificate holder to the data encryptor can be actively forwarded by the certificate holder or sent based on the request of the data encryptor, which can be specifically set according to actual design requirements and will not be further limited here.

[0056] In this embodiment, the hybrid encryption result is obtained by the data encryptor based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each post-quantum public key, a preset encryption algorithm, the first ciphertext, the second ciphertext corresponding to each post-quantum public key, and the encrypted data; the target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of each post-quantum public key are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; the hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and the certificate holder information in the certificate acquisition request; the first ciphertext is obtained by the data encryptor encrypting the first random number in the previously generated random number set using the target public key; the second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the random number set except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to each other random number one by one; the encrypted data is obtained by the data encryptor encrypting the previously obtained data to be encrypted using the encryption key and the encryption algorithm, and the encryption key is derived by the data encryptor according to the random number set using the pre-obtained key derivation algorithm.

[0057] Accordingly, the data encryption party includes: a certificate acquisition module that receives a hybrid digital certificate sent by a certificate holder, where the hybrid digital certificate includes a target public key, a key identifier of the target public key, at least one post-quantum public key, and key identifiers of each post-quantum public key; a random number generation module that generates a set of random numbers, where the set of random numbers includes a preset number of random numbers; a random number encryption module that uses the target public key to encrypt the first random number in the set of random numbers to obtain a first ciphertext, and for each post-quantum public key, uses the post-quantum public key to encrypt the other random numbers in the set of random numbers except the first random number to obtain a second ciphertext corresponding to the post-quantum public key; where each post-quantum public key corresponds to one of the other random numbers; a key derivation module that obtains an encryption key according to the set of random numbers using a preset key derivation algorithm; a data encryption module that uses the encryption key and a preset encryption algorithm to encrypt the pre-acquired data to be encrypted to obtain encrypted data; a result generation module that obtains a hybrid encryption result according to the target public key, the first ciphertext, the key identifier of the target public key, each post-quantum public key, the second ciphertext corresponding to each post-quantum public key, the key identifier of each post-quantum public key, the encryption algorithm, and the encrypted data.

[0058] Furthermore, the hybrid encryption result is obtained by the data encryption party encapsulating the target public key, the key identifier of the target public key, and the first ciphertext into a receiver information storage structure for the first key transmission, encapsulating each post-quantum public key, the key identifier corresponding to the post-quantum public key, and the second ciphertext into a receiver information storage structure for the second key transmission corresponding to each post-quantum public key, and encapsulating the encryption algorithm and the encrypted data into an encrypted content storage structure.

[0059] Accordingly, the data encryption party further includes: an encapsulation module that encapsulates the target public key, the key identifier of the target public key, and the first ciphertext into a receiver information storage structure for the first key transmission, and encapsulates each post-quantum public key, the key identifier corresponding to the post-quantum public key, and the second ciphertext into a receiver information storage structure for the second key transmission corresponding to each post-quantum public key; and encapsulates the encryption algorithm and the encrypted data into an encrypted content storage structure; a structure acquisition module that obtains a hybrid encryption result according to the receiver information storage structure for the first key transmission, the receiver information storage structures for the second key transmissions, and the encrypted content storage structure.

[0060] In an alternative embodiment, the system further includes: a parsing module that parses the hybrid digital certificate before the certificate holder sends the hybrid digital certificate to the data encryptor, and extracts the corresponding target algorithm, target signature value, and target public key according to the parsed hybrid digital certificate; a first verification module that uses the target public key to verify the validity of the target signature value and the hybrid digital certificate other than the target signature value according to the verification rules corresponding to the target algorithm; and a second verification module that preprocesses each post-quantum signature value in the hybrid digital certificate to set each post-quantum signature value to zero; extracts each post-quantum algorithm, each post-quantum signature value, and each post-quantum public key according to the parsed hybrid digital certificate; and uses each post-quantum public key to verify the validity of the corresponding post-quantum signature value and the hybrid digital certificate with the corresponding post-quantum signature value set to zero according to the verification rules corresponding to each post-quantum algorithm.

[0061] In an alternative embodiment, the system further includes: a certificate request module that sends a certificate acquisition request to the CA before receiving the hybrid encryption result sent by the data encryptor, where the certificate acquisition request is generated based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each post-quantum public key, and the certificate holder information; a certificate receiving module that receives the hybrid digital certificate returned by the CA based on the certificate acquisition request; where the hybrid digital certificate is the certificate data to be signed with the post-quantum signature value set to zero determined by the CA based on the target public key, all post-quantum public keys, and the certificate holder information parsed from the certificate acquisition request, and is signed with the post-quantum private key corresponding to each post-quantum public key to obtain the certificate data to be signed with the post-quantum signature value based on the key identifier of each post-quantum public key, and is signed with the target private key corresponding to the target public key for the certificate data to be signed with the post-quantum signature value.

[0062] Specifically, the system further includes: a key generation module that generates a post-quantum public-private key pair before sending the certificate acquisition request to the CA; and a request generation module that generates a certificate acquisition request according to the post-quantum public-private key pair and the certificate holder information.

[0063] Further, the request generation module includes: a data acquisition unit that obtains certificate request data according to the post-quantum public key and the certificate holder information; a signature unit that signs the certificate request data with the post-quantum private key to obtain a signature result; and a request generation unit that generates a certificate acquisition request according to the signature result and the certificate request data.

[0064] The hybrid digital certificate is obtained by the CA based on the key identifier of the target public key and signing the certificate data to be signed with the post-quantum signature value using the corresponding target private key; the certificate data to be signed with the post-quantum signature value is obtained by the CA based on the key identifier of each post-quantum public key and signing the certificate data to be signed with a zero post-quantum signature value using the corresponding post-quantum private key; the certificate data to be signed with a zero post-quantum signature value is obtained by the CA encapsulating the target public key, all post-quantum public keys, the certificate holder information, and the zeroed post-quantum signature value received based on the received certificate acquisition request; the zeroed post-quantum signature value is obtained by the CA determining the storage space for the corresponding post-quantum signature according to each post-quantum algorithm, and allocating space for the corresponding post-quantum signature value based on the storage space for the corresponding post-quantum signature and zeroing the content of the allocated space.

[0065] Correspondingly, the CA includes: a request parsing module that, after the certificate holder sends a certificate acquisition request to the CA, receives and parses the certificate acquisition request to obtain the target public key, all post-quantum public keys, and the certificate holder information; a space determination module that determines the storage space for the corresponding post-quantum signature pqcSignatureValue according to the post-quantum algorithm; a space allocation module that allocates space for the corresponding post-quantum signature value based on the storage space for the corresponding post-quantum signature and zeroes its content to obtain a zeroed post-quantum signature value; a data encapsulation module that encapsulates the target public key, all post-quantum public keys, the certificate holder information, and the post-quantum signature value with zeroed content into the certificate data to be signed with a zero post-quantum signature value TBSCertificate; a first signature module that signs the certificate data to be signed with a zero post-quantum signature value using the corresponding post-quantum private key according to the key identifier of each post-quantum public key and fills the signature result value into the corresponding position in the TBSCertificate to obtain the certificate data to be signed with the post-quantum signature value; a second signature module that signs the certificate data to be signed with the post-quantum signature value using the corresponding target private key according to the key identifier of the target public key to obtain the hybrid digital certificate.

[0066] Furthermore, the CA further includes: a data writing module that, after signing the certificate data to be signed with a zero post-quantum signature value using the corresponding post-quantum private key, writes the corresponding post-quantum signature value into the previously allocated space to obtain the certificate data to be signed with the post-quantum signature value, and after signing the certificate data to be signed with the post-quantum signature value using the corresponding target private key, writes the target signature value into the preset space of the hybrid digital certificate. Additionally, after obtaining the data to be signed TBSCertificate, perform DER encoding on the TBSCertificate structure.

[0067] In addition, the CA further includes: a verification module. After the CA receives and parses a certificate acquisition request to obtain the target public key, all post-quantum public keys, and certificate holder information, the CA verifies the validity of the signature result in the certificate acquisition request. After the validity verification passes, the CA signs the request data using the post-quantum private key. For the specific method, refer to the above text and it will not be repeated here.

[0068] The decryption module 32 includes: a first result parsing unit that obtains the receiver information storage structure of the first key transmission, the receiver information storage structures of each second key transmission, and the encrypted content storage structure according to the hybrid encryption result; a first decryption unit that determines the target private key of the corresponding hybrid digital certificate according to the key identifier of the target public key in the receiver information storage structure of the first key transmission, and decrypts the first ciphertext using the target private key to obtain the first plaintext; a second decryption unit that determines the post-quantum private keys corresponding to the respective post-quantum public keys by combining the post-quantum algorithms of the post-quantum public keys in the receiver information storage structures of the respective second key transmissions with the hybrid digital certificate, and decrypts the corresponding second ciphertexts using the respective post-quantum private keys to obtain the corresponding second plaintexts; a second result parsing unit that parses the encrypted content storage structure to obtain the encryption algorithm and encrypted data; a key derivation unit that obtains the corresponding key derivation algorithm according to the encryption algorithm, and obtains the decryption key using the key derivation algorithm based on the first plaintext and the second plaintext; a decryption unit that decrypts the encrypted data using the decryption key to obtain the plaintext data.

[0069] In summary, in the embodiment of the present invention, a hybrid digital certificate is generated by combining the target algorithm and the post-quantum algorithm, so as to utilize the protection capabilities of two different types of algorithms to resist traditional computing attacks and future possible quantum computing attacks, greatly enhancing the security of data in storage, transmission, and other links, and effectively protecting the plaintext data from being maliciously obtained and tampered with.

[0070] Figure 4 Illustrates a schematic diagram of the physical structure of an electronic device, such as Figure 4As shown in the figure, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communications interface 420, and the memory 430 complete communication with each other through the communication bus 440. The processor 410 may call logical instructions in the memory 430 to execute a data processing method, which includes: receiving a hybrid encryption result sent by a data encryptor; wherein the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on a previously obtained hybrid digital certificate, and the hybrid digital certificate is requested from a certificate authority CA based on a certificate acquisition request and sent to the data encryptor; according to the hybrid encryption result, searching for the corresponding hybrid digital certificate, and using the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain plaintext data; the hybrid encryption result is obtained by the data encryptor based on a target public key, a key identifier of the target public key, at least one post-quantum public key, key identifiers of each post-quantum public key, a preset encryption algorithm, a first ciphertext, a second ciphertext corresponding to each post-quantum public key, and the data to be encrypted; the target public key, the key identifier of the target public key, at least one post-quantum public key, and key identifiers of each post-quantum public key are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; the hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and certificate holder information in the certificate acquisition request; the first ciphertext is obtained by the data encryptor encrypting the first random number in a previously generated set of random numbers using the target public key; the second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the set of random numbers except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to one of the other random numbers; the data to be encrypted is obtained by the data encryptor encrypting the previously obtained data to be encrypted using an encryption key and an encryption algorithm, and the encryption key is derived by the data encryptor based on the set of random numbers using a previously obtained key derivation algorithm.

[0071] In addition, when the logical instructions in the above-mentioned memory 430 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0072] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data processing method provided by the above-mentioned various methods. The method includes: receiving a hybrid encryption result sent by a data encryptor; wherein the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on a previously obtained hybrid digital certificate, and the hybrid digital certificate is obtained by requesting from a certificate authority CA based on a certificate acquisition request and sent to the data encryptor; according to the hybrid encryption result, searching for the corresponding hybrid digital certificate, and using the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain plaintext data; the hybrid encryption result is obtained by the data encryptor based on a target public key, a key identifier of the target public key, at least one post-quantum public key, key identifiers of each post-quantum public key, a preset encryption algorithm, a first ciphertext, a second ciphertext corresponding to each post-quantum public key, and the data to be encrypted; the target public key, the key identifier of the target public key, at least one post-quantum public key, and key identifiers of each post-quantum public key are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; the hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and certificate holder information in the certificate acquisition request; the first ciphertext is obtained by the data encryptor encrypting the first random number in a previously generated random number set using the target public key; the second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the random number set except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to each other random number one by one; the data to be encrypted is obtained by the data encryptor encrypting the previously obtained data to be encrypted using an encryption key and an encryption algorithm, and the encryption key is obtained by the data encryptor performing key derivation based on the random number set using a previously obtained key derivation algorithm.

[0073] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the data processing method provided by the above various methods. The method includes: receiving a hybrid encryption result sent by a data encryptor; wherein the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on a previously obtained hybrid digital certificate, and the hybrid digital certificate is requested from a certificate authority (CA) based on a certificate acquisition request and sent to the data encryptor; according to the hybrid encryption result, finding the corresponding hybrid digital certificate, and using the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data; the hybrid encryption result is obtained by the data encryptor based on a target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of the respective post-quantum public keys, a preset encryption algorithm, a first ciphertext, the second ciphertexts corresponding to the respective post-quantum public keys, and the data to be encrypted; the target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of the respective post-quantum public keys are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; the hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and the certificate holder information in the certificate acquisition request; the first ciphertext is obtained by the data encryptor encrypting the first random number in a previously generated random number set using the target public key; the second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the random number set except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to one of the other random numbers; the data to be encrypted is obtained by the data encryptor encrypting the previously obtained data to be encrypted using an encryption key and an encryption algorithm, and the encryption key is derived by the data encryptor based on the random number set using a pre-obtained key derivation algorithm.

[0074] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.

[0075] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0076] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data processing method, characterized in that, Including: Receiving the hybrid encryption result sent by the data encryptor; wherein, the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on the previously obtained hybrid digital certificate, and the hybrid digital certificate is requested from the certificate authority CA based on the certificate acquisition request and sent to the data encryptor; According to the hybrid encryption result, searching for the corresponding hybrid digital certificate, and using the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data; The hybrid encryption result is obtained by the data encryptor based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each post-quantum public key, a preset encryption algorithm, the first ciphertext, the second ciphertext corresponding to each post-quantum public key, and the encrypted data; The target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of each post-quantum public key are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; The hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and the certificate holder information in the certificate acquisition request; The first ciphertext is obtained by the data encryptor encrypting the first random number in the previously generated random number set using the target public key; The second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the other random numbers in the random number set except the first random number using the corresponding post-quantum public key, and each post-quantum public key corresponds to one of the other random numbers; The encrypted data is obtained by the data encryptor encrypting the previously obtained data to be encrypted using the encryption key and the encryption algorithm, and the encryption key is derived by the data encryptor based on the random number set using a pre-obtained key derivation algorithm.

2. The data processing method according to claim 1, characterized in that, The hybrid encryption result is obtained by the data encryptor encapsulating the target public key, the key identifier of the target public key, and the first ciphertext into a receiver information storage structure for the first key transmission, encapsulating each post-quantum public key, the key identifier corresponding to the post-quantum public key, and the second ciphertext into a receiver information storage structure for the second key transmission corresponding to each post-quantum public key, and encapsulating the encryption algorithm and the encrypted data into an encrypted content storage structure.

3. The data processing method according to claim 2, wherein According to the hybrid encryption result, searching for the corresponding hybrid digital certificate, and using the target private key corresponding to the hybrid digital certificate to decrypt the hybrid encryption result to obtain the plaintext data, including: According to the hybrid encryption result, obtaining the receiver information storage structure for the first key transmission, the receiver information storage structures for the second key transmissions, and the encrypted content storage structure; According to the key identifier of the target public key in the receiver information storage structure for the first key transmission, determining the target private key of the corresponding hybrid digital certificate, and using the target private key to decrypt the first ciphertext to obtain the first plaintext; Based on the post-quantum algorithm of the post-quantum public key in the receiver information storage structure transmitted according to each of the second keys, in combination with the hybrid digital certificate, determine the post-quantum private keys corresponding to each of the post-quantum public keys, and use each of the post-quantum private keys to decrypt the corresponding second ciphertext to obtain the corresponding second plaintext; Analyze the encrypted content storage structure to obtain the encryption algorithm and encrypted data; According to the encryption algorithm, obtain the corresponding key derivation algorithm, and according to the first plaintext and the second plaintext, use the key derivation algorithm to obtain the decryption key; Use the decryption key to decrypt the encrypted data to obtain the plaintext data.

4. The data processing method according to claim 1, characterized in that, The hybrid encryption result is obtained by the data encryptor after parsing the hybrid digital certificate, based on the successful validation of the validity of the parsed hybrid digital certificate, based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each of the post-quantum public keys, a preset encryption algorithm, the first ciphertext, the second ciphertext corresponding to each of the post-quantum public keys, and the encrypted data; The validity verification is that the data encryptor, according to the target algorithm, the target signature value, the target public key, each post-quantum algorithm, each post-quantum signature value, and each post-quantum public key in the parsed hybrid digital certificate, uses the target public key and according to the verification rules corresponding to the target algorithm, to perform validity verification on the target signature value and the hybrid digital certificate other than the target signature value; And, use each of the post-quantum public keys and according to the verification rules of the corresponding post-quantum algorithm, to perform validity verification on the corresponding post-quantum signature value and the hybrid digital certificate after the corresponding post-quantum signature value is set to zero.

5. The data processing method according to claim 1, characterized in that, Before receiving the hybrid encryption result sent by the data encryptor, it further includes: Send a certificate acquisition request to the CA, where the certificate acquisition request is generated based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each of the post-quantum public keys, and the certificate holder information; Receive the hybrid digital certificate returned by the CA based on the certificate acquisition request; wherein, the hybrid digital certificate is determined by the CA for the data to be signed based on the target public key, all post-quantum public keys, and certificate holder information parsed from the certificate acquisition request, and based on the key identifiers of each of the post-quantum public keys, uses the post-quantum private keys corresponding to each of the post-quantum public keys to sign the data to be signed, and based on the key identifier of the target public key, uses the target private key corresponding to the target public key to sign the signed data to be signed.

6. The data processing method according to claim 5, wherein The hybrid digital certificate is obtained by the CA signing the certificate data to be signed with a post-quantum signature value based on the key identifier of the target public key and using the corresponding target private key; The certificate data to be signed with a post-quantum signature value is obtained by the CA signing the certificate data to be signed with a zero post-quantum signature value based on the key identifier of each of the post-quantum public keys and using the corresponding post-quantum private key; The certificate data to be signed with a post-quantum signature value of zero is encapsulated by the CA based on the target public key, all post-quantum public keys, certificate holder information, and the post-quantum signature value set to zero obtained from the received certificate acquisition request; The post-quantum signature value set to zero is obtained by the CA determining the storage space for the corresponding post-quantum signature based on each post-quantum algorithm, and then allocating space for the corresponding post-quantum signature value and setting the content of the allocated space to zero according to the storage space of the corresponding post-quantum signature; 7. The data processing method according to claim 5, wherein Before sending the certificate acquisition request to the CA, it includes: Obtaining certificate request data based on the certificate holder information, pre-generated post-quantum public keys, and the target public key; Signing the certificate request data with the pre-generated post-quantum private key to obtain a signature result; Generating a certificate acquisition request based on the signature result and the certificate request data.

8. A data processing system, characterized in that, It includes: A result receiving module that receives the hybrid encryption result sent by the data encryptor; wherein, the hybrid encryption result is obtained by the data encryptor encrypting the data to be encrypted based on the previously obtained hybrid digital certificate, and the hybrid digital certificate is requested from the certificate authority CA based on the certificate acquisition request and sent to the data encryptor; A decryption module that, based on the hybrid encryption result, locates the corresponding hybrid digital certificate and decrypts the hybrid encryption result using the target private key corresponding to the hybrid digital certificate to obtain the plaintext data; The hybrid encryption result is obtained by the data encryptor based on the target public key, the key identifier of the target public key, at least one post-quantum public key, the key identifiers of each post-quantum public key, a preset encryption algorithm, a first ciphertext, the second ciphertexts corresponding to each post-quantum public key, and the data to be encrypted; The target public key, the key identifier of the target public key, at least one post-quantum public key, and the key identifiers of each post-quantum public key are obtained by the data encryptor based on parsing the previously obtained hybrid digital certificate; The hybrid digital certificate is generated by the CA based on the target public key, at least one post-quantum public key, and certificate holder information in the certificate acquisition request; The first ciphertext is obtained by the data encryptor encrypting the first random number in the pre-generated random number set using the target public key; The second ciphertext corresponding to the post-quantum public key is obtained by the data encryptor encrypting the random numbers other than the first random number in the random number set using the corresponding post-quantum public key, and each post-quantum public key corresponds to one of the other random numbers; The data to be encrypted is obtained by the data encryptor encrypting the previously obtained data to be encrypted using an encryption key and the encryption algorithm, and the encryption key is derived by the data encryptor using a pre-obtained key derivation algorithm based on the random number set; 9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the data processing method according to any one of claims 1 to 7.

10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the data processing method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Secure storage method of flash memory, electronic device and storage medium

    CN122241781A