Bidirectional authentication method and device based on certificateless system, equipment and medium
Through the two-way authentication method using digital signature and public key encryption algorithms in a certificate-free system, the problem of secure communication between users is solved, the integrity of information and the authenticity of identity is realized, and the security and efficiency of communication are improved.
Patent Information
- Application Number
- CN202510432586.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-08
AI Technical Summary
The certificate-free system cannot realize secure communication between users. It only defines a single point of operation between the user and the key generation center, and cannot effectively guarantee the security between users.
Through the communication party combining the main public key of the certificate-free system, the user identification and random number are digitally signed using their respective private keys, and the digital signature is verified using the other party's public key. The initiator generates the first session key and sends it to the response end through the public key encryption algorithm. The response end generates the second session key and returns it. Both parties finally generate the target session key to ensure communication security.
It realizes secure communication between users, ensures the integrity and authenticity of information, prevents information tampering and identity impersonation, simplifies the key distribution process, and improves the security and efficiency of the system.
Smart Images

Figure CN120281534A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network information security, and in particular, to a two-way authentication method, device, equipment and medium based on a certificateless system. Background Art
[0002] The certificateless system is a certificateless mechanism based on the elliptic curve public key cryptography algorithm (SM2 algorithm), including a key generation and verification mechanism, a digital signature mechanism, and a public key encryption mechanism. The key generation and verification mechanism includes a main key generation mechanism, as well as a generation and verification mechanism and process for user key pairs. The main key is generated by a key generation center, including a system main private key and a system main public key. The private key and the declared public key of a user are jointly generated by the key generation center and the user. The user discloses its user identifier and declared public key, and its actual public key is calculated and generated according to a specific method based on the elliptic curve system parameters, the system main public key, the user identifier, and the user's declared public key. Summary of the Invention
[0003] The present invention provides a two-way authentication method, device, equipment and medium based on a certificateless system to solve the problem that the certificateless system cannot achieve secure communication between users.
[0004] According to one aspect of the present invention, there is provided a two-way authentication method based on a certificateless system, including:
[0005] Both communication parties combine the main public key of the certificateless system, use their respective private keys to digitally sign their respective user identifiers and respective random numbers, and use the public key of the other party to verify the digital signature of the other party;
[0006] If the digital signatures of both communication parties are verified, the initiating end generates a first session key and sends the first session key to the responding end through a public key encryption algorithm;
[0007] After securely receiving the first session key, the responding end generates a second session key and sends the second session key to the initiating end through a public key encryption algorithm;
[0008] After securely receiving the second session key, the two-way authentication process ends, and the initiating end and the responding end generate a target session key according to the first session key and the second session key.
[0009] According to another aspect of the present invention, there is provided a two-way authentication device based on a certificateless system, including:
[0010] A digital signature verification module, configured to enable both communication parties to combine the main public key of the certificateless system, use their respective private keys to digitally sign their respective user identifiers and respective random numbers, and use the public key of the other party to verify the digital signature of the other party;
[0011] The first session key module is configured to, if the digital signatures of both communication parties are verified successfully, generate a first session key at the initiating end and send the first session key to the responding end through a public key encryption algorithm;
[0012] The second session key module is configured to, after securely receiving the first session key, generate a second session key at the responding end and send the second session key to the initiating end through a public key encryption algorithm;
[0013] The target session key module is configured to, after the initiating end securely receives the second session key and the two-way authentication process ends, generate a target session key at the initiating end and the responding end based on the first session key and the second session key.
[0014] According to another aspect of the present invention, there is provided a computer program product including a computer program which, when executed by a processor, implements the two-way authentication method based on a certificateless system according to any embodiment of the present invention.
[0015] According to another aspect of the present invention, there is provided an electronic device, including:
[0016] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program, when executed by the at least one processor, enables the at least one processor to execute the two-way authentication method based on a certificateless system according to any embodiment of the present invention.
[0017] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions which, when executed by a processor, implement the two-way authentication method based on a certificateless system according to any embodiment of the present invention.
[0018] According to another aspect of the present invention, there is provided a computer program product including computer program / instructions which, when executed by a processor, implement the two-way authentication method based on a certificateless system as described in any embodiment of the present invention.
[0019] In the embodiments of the present invention, both communicating parties combine the public master key of the certificateless system, use their respective private keys to digitally sign the user identifier and the random number, and use the public key of the other party to verify the digital signature. After the digital signatures of both communicating parties are verified, the initiating end generates a first session key and sends the first session key to the responding end through a public key encryption algorithm. After the responding end securely receives the first session key, it generates a second session key and sends the second session key to the initiating end through a public key encryption algorithm. After the initiating end securely receives the second session key, the two-way authentication process ends, and the initiating end and the responding end generate a target session key according to the first session key and the second session key. This solves the problem that the certificateless system only defines single-point operations between users and the key generation center and cannot achieve secure communication between users. By verifying the integrity of the information transmitted during the communication process, malicious attackers are prevented from forging or modifying the transmitted information. After the two-way authentication is completed, the communicating parties can generate a common session key for secure communication, ensuring the security of subsequent communication.
[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0022] Figure 1 is the first flowchart of a two-way authentication method based on a certificateless system provided by an embodiment of the present invention;
[0023] Figure 2 is the second flowchart of a two-way authentication method based on a certificateless system provided by an embodiment of the present invention;
[0024] Figure 3 is the structural schematic diagram of a two-way authentication device based on a certificateless system provided by an embodiment of the present invention;
[0025] Figure 4 is the structural schematic diagram of an electronic device for implementing the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.
[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0028] Figure 1 is the first flowchart of a two-way authentication method based on a certificate-free system provided by an embodiment of the present invention. This embodiment is applicable to two-way authentication based on a certificate-free system to enable secure communication between users. This method can be executed by a two-way authentication device based on a certificate-free system, and this device can be implemented in the form of hardware and / or software. This device can be configured in an electronic device with corresponding data processing capabilities. As Figure 1 shown, the method includes:
[0029] S110. The two communication parties combine the master public key of the certificate-free system and use their respective private keys to digitally sign their respective user identities and respective random numbers, and use the public key of the other party to verify the digital signature of the other party.
[0030] The Key Generation Center (KGC) acts as the server, and the two communication parties act as the clients, such as user A and user B. The KGC has a master key, including the master private key masterPrivateKey and the master public key masterPublicKey of the certificate-free system. User A has a user identity IDA, a user private key userPrivateKeyA, and a user public key userPublicKeyA. User B has a user identity IDB, a user private key userPrivateKeyB, and a user public key userPublicKeyB. The master public key of the certificate-free system and the user public keys can all be made public.
[0031] The initiating end among the two communication parties generates a random number, uses the master public key of the certificate-free system and its own user private key to digitally sign its own user identification and the generated random number, and sends the digital signature of the initiating end to the responding end. After receiving the digital signature of the initiating end, the responding end uses the user public key of the initiating end to verify the digital signature of the initiating end. If the verification passes, the responding end sends its own digital signature to the initiating end, and the initiating end uses the user public key of the responding end to verify the digital signature of the responding end.
[0032] By using the master public key of the certificate-free system and its own user private key for digital signature, the initiating end ensures the non-forgeability and non-repudiation of the signature. Only the initiating end can generate a valid signature, and once the signature is verified, the initiating end cannot deny its signature behavior, which helps to maintain the authenticity and credibility of the communication. The responding end uses the user public key of the initiating end to verify the digital signature, ensuring the integrity and authenticity of the data. If the information sent by the initiating end is tampered with during transmission, the digital signature will not pass the verification, thus promptly detecting the risk of information tampering and helping to protect the communication content from being maliciously modified or stolen. The entire digital signature and verification process also improves the security and efficiency of the communication. Through the digital signature technology, the two communication parties can ensure the authenticity of their identities and the integrity of the information, thus establishing a secure and trustworthy communication environment. This helps to reduce disputes and losses caused by security issues such as identity impersonation and information tampering.
[0033] S120. If the digital signatures of both communication parties are verified, the initiating end generates a first session key and sends the first session key to the responding end through a public key encryption algorithm.
[0034] S130. After securely receiving the first session key, the responding end generates a second session key and sends the second session key to the initiating end through a public key encryption algorithm.
[0035] After the initiating end verifies the digital signature of the responding end, it indicates that the digital signatures of both communication parties are verified. The initiating end generates a first session key and securely sends the first session key to the responding end through a public key encryption algorithm to ensure the secure transmission of the first session key. After securely receiving the first session key, the responding end generates a second session key and securely sends the second session key to the initiating end.
[0036] S140. After securely receiving the second session key, the two-way authentication process ends, and the initiating end and the responding end generate a target session key according to the first session key and the second session key.
[0037] After securely receiving the second session key at the initiating end, the two-way authentication process between the communication parties ends. The initiating end and the responding end generate a target session key based on the first session key and the second session key, and the subsequent communication between the communication parties uses this target session key for encryption.
[0038] In the embodiment of the present invention, the communication parties combine the master public key of the certificateless system, use their respective private keys to digitally sign the user identifier and the random number, and use the public key of the other party to verify the digital signature; after the digital signatures of both communication parties are verified, the initiating end generates the first session key and sends the first session key to the responding end through a public key encryption algorithm; after securely receiving the first session key, the responding end generates the second session key and sends the second session key to the initiating end through a public key encryption algorithm; after securely receiving the second session key, the two-way authentication process ends, and the initiating end and the responding end generate a target session key based on the first session key and the second session key. This solves the problem that the certificateless system only defines the single-point operation between the user and the key generation center and cannot achieve secure communication between users. By verifying the integrity of the information transmitted during the communication process, malicious attackers are prevented from forging or modifying the transmitted information. After the two-way authentication is completed, the communication parties can generate a common session key for secure communication, ensuring the security of subsequent communication.
[0039] In an alternative embodiment, the communication parties combine the master public key of the certificateless system, use their respective private keys to digitally sign their respective user identifiers and respective random numbers, and use the public key of the other party to verify the digital signature of the other party, including: the initiating end generates an initiating end comprehensive identity hash value based on the initiating end user identifier, the elliptic curve system parameters, and the master public key of the certificateless system; the initiating end generates a first random number, and digitally signs the first random number and the initiating end user identifier based on the initiating end user private key and the initiating end comprehensive identity hash value to obtain a first identity authentication signature; the initiating end sends the initiating end user identifier, the first random number, and the first identity authentication signature to the responding end; the responding end verifies the first identity authentication signature based on the master public key of the certificateless system and the initiating end user public key. If the verification is passed, the responding end generates a second random number and generates a second identity authentication signature based on the second random number and the responding end user identifier for the initiating end to authenticate the responding end.
[0040] Specifically, an initiating - end comprehensive identity hash value is generated based on the initiating - end user identifier IDA, elliptic - curve system parameters, and the master public key of the certificate - less system. Exemplarily, the SM3 cryptographic hash algorithm, simply referred to as the national - standard SM3 algorithm, can be used to calculate the initiating - end comprehensive identity hash value HA, where HA = H256(ENTLA||IDA||a||b||xG||yG||xpub||ypub). Here, H256 represents the SM3 cryptographic hash algorithm. The SM3 cryptographic hash algorithm is a one - way hash function that can map input data of any length to an output digest value of a fixed length (256 bits), but it is impossible to reverse - derive the original input data from the digest value. ENTLA is two bytes converted from the bit length of the initiating - end user identifier IDA, representing the length information of IDA and used to increase the diversity and complexity of the hash input. a and b are the parameters of the elliptic - curve equation. Elliptic Curve Cryptography (ECC) is a public - key cryptosystem based on the mathematical structure of elliptic curves. a and b are the coefficients of the elliptic - curve equation y 2 = x 3 + ax + b; xG and yG are the coordinates of the elliptic - curve base point G. In ECC, the base point G is a pre - determined point, and the public keys of all users are generated through multiples (i.e., scalar multiplication) of the base point G. xpub and ypub are the coordinates of the master public key of the certificate - less system; || represents concatenating these parameters.
[0041] The initiating end generates a first random number RDM_A1, and performs a digital signature on the first random number RDM_A1 and the initiating - end user identifier IDA according to the initiating - end user private key userPrivateKeyA and the initiating - end comprehensive identity hash value HA to obtain a first identity authentication signature SA1, denoted as SA1 = SIGN(param, HA, IDA||RDM_A1, userPrivateKeyA). Exemplarily, the message to be signed IDA||RDM_A1 is denoted as M, the initiating - end user private key is denoted as dA, and SIGN(param, HA, M, dA) represents the digital - signature generation algorithm, which uses the elliptic - curve system parameters param, the hash value HA, and the private key dA to sign the message M and output (r, s).
[0042] The specific calculation process of the digital - signature generation algorithm SIGN(param, HA, M, dA) includes:
[0043] Step 1: Set
[0044] Step 2: Calculate where Hv represents a cryptographic hash function with a message - digest length of v bits, based on the SM3 algorithm;
[0045] Step 3: Use a random number generator to generate a random number \(k\in[1,n - 1]\);
[0046] Step 4: Calculate the elliptic curve point \((x_1,y_1)=[k]G\); where, \([k]P\): the \(k\)-fold point of point \(P\) on the elliptic curve, that is: \([k]P=\{P + P+\cdots+P\}\) (\(k\) times), where \(k\) is a positive integer;
[0047] Step 5: Calculate \(r=(e + x_1)\bmod n\), if \(r = 0\) or \(r + k=n\), then return to Step 3; where, \(\bmod n\) represents the modulo \(n\) operation, for example, \(23\bmod7 = 2\);
[0048] Step 6: Calculate \(s=((1 + d_A)^{-1}\cdot(k - r\cdot d_A))\bmod n\), if \(s = 0\), then return to Step 3;
[0049] Step 7: Convert the data types of \(r\) and \(s\) into byte strings, and obtain the digital signature of the message \(M\) to be signed as \((r,s)\).
[0050] The initiator packets and sends the initiator user identifier \(ID_A\), the first random number \(RDM_A1\) and the first identity authentication signature \(SA1\) to the responder.
[0051] After receiving the data packet, the responder parses out the initiator user identifier \(ID_A\), the first random number \(RDM_A1\) and the first identity authentication signature \(SA1\). Calculate the initiator comprehensive identity hash value \(H_A\), obtain the initiator user public key \(userPublicKey_A\) from the key generation center \(KGC\) according to the initiator user identifier \(ID_A\), calculate the initiator reduced hash value \(Y_A\), \(Y_A = H256(userPublicKey_A||H_A)\bmod n\), calculate the initiator elliptic curve public key \(P_A=userPublicKey_A+[Y_A]masterPublicKey\), and verify the received initiator user identifier \(ID_A\), the first random number \(RDM_A1\) and the first identity authentication signature \(SA1\). Exemplarily, denote the digital signature verification function as: \(VERIFY(param,H_A,ID_A||RDM_A1,P_A,SA1)\); Denote the message to be verified \(ID_A||RDM_A1\) as \(M'\); Denote the signature to be verified \(SA1\) as \((r',s')\), and the specific verification process of the digital signature verification function \(VERIFY(param,H_A,M',P_A,(r',s'))\) includes:
[0052] Step 1: Check whether \(r'\in[1,n - 1]\) holds. If it does not hold, the verification fails;
[0053] Step 2: Check whether \(s'\in[1,n - 1]\) holds. If it does not hold, the verification fails;
[0054] Step 3: Set
[0055] Step 4: Calculate e' = Hv(M');
[0056] Step 5: Calculate t = (r' + s') mod n. If t = 0, the verification fails.
[0057] Step 6: Calculate the elliptic curve point (x1', y1') = [s']G + [t]PA;
[0058] Step 7: Calculate R = (e' + x1') mod n, and check if R = r' holds. If it holds, the verification passes; otherwise, the verification fails.
[0059] If the responder successfully verifies the identity information of the initiator, the responder generates a second random number and uses the same calculation logic as the initiator to generate the second identity authentication signature based on the second random number and the responder's user identifier, so that the initiator can authenticate the responder. During the identity authentication process, if the verification fails at any link, the authentication fails and the two-way authentication process ends.
[0060] By combining elliptic curve encryption, certificateless public key system, and digital signature technology, efficient two-way identity authentication is achieved. Adding random numbers during the authentication process prevents replay attacks and prevents illegal attackers from impersonating legitimate users. The initiator can securely generate and send authentication information containing the user identifier and random number, and after the responder verifies the identity of the initiator, it can also generate its own authentication signature for reverse authentication, ensuring the authenticity of the identities of both communication parties and the security of communication. It does not rely on traditional certificate management, simplifies the key distribution process, and improves the efficiency and security of the overall system.
[0061] Optionally, the Key Generation Center (KGC) uses a random number ms ∈ [1, n - 1] as the system master private key masterPrivateKey, and calculates the system master public key masterPublicKey = [ms]G.
[0062] The generation process of the user public key and user private key includes:
[0063] Step 1. The user uses a random number generator to generate a random number d' ∈ [1, n - 1];
[0064] Step 2. The user calculates UA = [d']G and submits the identifier IDA and UA to the KGC;
[0065] Step 3. The KGC calculates HA = H256(ENTLA||IDA||a||b||xG||yG||xpub||ypub);
[0066] Step 4. The KGC uses a random number generator to generate a random number w ∈ [1, n - 1];
[0067] Step 5. The KGC calculates WA = [w]G + UA;
[0068] Step 6. The KGC converts the data types of the coordinates xwa and ywa of WA into bit strings, and calculates
[0069] λ = H256(xwa || ywa || HA) mod n;
[0070] Step 7. The KGC calculates tA = (w + λ * ms) mod n, and securely returns t and WA to the user;
[0071] Step 8. User A calculates dA = (tA + d') mod n;
[0072] Step 9. If 0 < d' < n - 1, output (d', WA); otherwise, return to Step 1.
[0073] Wherein, when the KGC returns tA to User A, it can use UA as the public key to encrypt the data including tA through the public key encryption algorithm and then transfer the ciphertext to User A. User A decrypts the ciphertext using d' to restore the data including tA. G is the elliptic curve base point.
[0074] Figure 2 It is the second flowchart of a two-way authentication method based on a certificateless system provided by an embodiment of the present invention. This embodiment is optimized and improved on the basis of the above embodiment. As Figure 2 shown, the method includes:
[0075] S210. The two communication parties combine the master public key of the certificateless system, use their respective private keys to digitally sign their respective user identities and respective random numbers, and use the public key of the other party to verify the digital signature of the other party.
[0076] If the digital signatures of both communication parties are verified, then execute the following S220 - S240.
[0077] S220. The initiating party generates a first session key and a first parameter, and uses the public key encryption algorithm to encrypt the initiating party's user identity, the first parameter, and the first session key according to the responder's user public key to obtain a first encrypted data packet, and sends the first encrypted data packet to the responder.
[0078] Wherein, the first parameter is generated based on a first random number; the first random number is generated when the initiating party generates a digital signature.
[0079] Specifically, during the digital signature verification process between two communication parties, the initiating end and the responding end respectively generate a first random number and a second random number, which are used to generate the first identity authentication signature of the initiating end and the second identity authentication signature of the responding end. After the digital signatures of both communication parties are verified successfully, the initiating end generates a first session key and a first parameter, and uses a public key encryption algorithm to encrypt the initiating end user identifier, the first parameter, and the first session key according to the responding end user public key to obtain a first encrypted data packet, and sends the first encrypted data packet to the responding end. The first parameter is generated based on the first random number. Exemplarily, the first parameter RDM_A2 is equal to the first random number RDM_A1 + 1. Since during the digital signature verification process between two communication parties, both communication parties have confirmed that they have accurately received the first random number or the second random number of the other party, therefore, based on the first random number, a first parameter is generated, and a public key encryption algorithm is used to encrypt the initiating end user identifier, the first parameter, and the first session key according to the responding end user public key to obtain a first encrypted data packet, and the first encrypted data packet is sent to the responding end. The responding end can confirm whether the received first session key is accurate by verifying the first parameter.
[0080] After the digital signature verification of both communication parties is successful, the initiating end generates a first parameter based on the first random number that has been confirmed by the responding end, and securely sends an encrypted data packet containing the initiating end user identifier, the first parameter, and the first session key to the responding end using a public key encryption algorithm, which not only ensures the secure transmission of the first session key, but also allows the responding end to accurately confirm the received first session key by verifying the first parameter, thereby enhancing the security and reliability of the communication.
[0081] S230. After securely receiving the first session key, the responding end generates a second session key and sends the second session key to the initiating end through a public key encryption algorithm.
[0082] After receiving the first encrypted data packet EA1, the responding end uses the responding end user private key userPrivateKeyB to decrypt the first encrypted data packet EA1 to obtain the initiating end user identifier IDA, the first parameter, and the first session key, and verifies the initiating end user identifier IDA. A first reference value is obtained by converting the first random number obtained during the verification process of the digital signature of the initiating end, that is, the first identity authentication signature, using a preset calculation rule, and it is judged whether the first reference value is equal to the first parameter. If the verification of the initiating end user identifier passes and the first reference value is equal to the first parameter, the responding end securely receives the first session key.
[0083] After securely receiving the first session key, the responder generates a second session key and generates a second parameter based on a second random number. Using the same calculation process as the initiator to generate the first encrypted data packet, the responder uses a public key encryption algorithm to encrypt the responder user identifier, the second parameter, and the second session key according to the initiator user public key to obtain a second encrypted data packet, and sends the second encrypted data packet to the initiator.
[0084] S240. After securely receiving the second session key, the two-way authentication process ends, and the initiator and the responder generate a target session key according to the first session key and the second session key.
[0085] Optionally, the first session key and the second session key are generated based on a random number generator. The initiator and the responder generate a target session key according to the first session key and the second session key, including: using the exclusive OR result of the first session key and the second session key as the target session key. The first session key and the second session key are generated by a random number generator, ensuring the randomness and security of the keys. The initiator and the responder generate a target session key by performing an exclusive OR operation on these two keys, which can not only efficiently combine the information of both parties, but also quickly obtain a secure and unique session key through simple calculations, thereby enhancing the security and efficiency of the communication process.
[0086] In the embodiment of the present invention, after the digital signature verification of both communication parties is successful, the initiator generates a first parameter through the first random number confirmed by the responder, and securely sends an encrypted data packet containing the initiator user identifier, the first parameter, and the first session key to the responder using a public key encryption algorithm, which not only ensures the secure transmission of the first session key, but also allows the responder to accurately confirm the received first session key by verifying the first parameter, thereby enhancing the security and reliability of the communication. Adding random numbers during the authentication process prevents replay attacks and prevents illegal attackers from impersonating legitimate users. On the other hand, it can also verify the integrity of the information transmitted during the communication process, avoiding malicious attackers from forging or modifying the transmitted information. It solves the problem that the certificate-free system only defines a single-point operation between the user and the key generation center and cannot achieve secure communication between users. After the two-way authentication is completed, the two communication parties can generate a common session key for secure communication, ensuring the security of subsequent communication.
[0087] In an alternative embodiment, the initiating end generates a first session key and a first parameter, and uses a public key encryption algorithm to encrypt the initiating end user identifier, the first parameter, and the first session key according to the responder user public key to obtain a first encrypted data packet, including: the initiating end generates a responder comprehensive identity hash value according to the responder user identifier, the elliptic curve system parameters, and the master public key of the certificateless system; obtains a responder reduced hash value according to the responder user public key and the responder comprehensive identity hash value; obtains a responder elliptic curve public key according to the responder user public key, the master public key of the certificateless system, and the responder reduced hash value; and encrypts the initiating end user identifier, the first parameter, and the first session key according to the responder elliptic curve public key using a public key encryption algorithm to obtain a first encrypted data packet.
[0088] Specifically, after the initiating end verifies the second identity authentication signature of the responder, it generates a responder comprehensive identity hash value HB according to the responder user identifier IDB, the elliptic curve system parameters, and the master public key of the certificateless system. Exemplarily, the responder comprehensive identity hash value HB can be calculated using the SM3 cryptographic hash algorithm, HB = H256(ENTLB||IDB||a||b||xG||yG||xpub||ypub). The responder user public key userPublicKeyB is obtained from the key generation center KGC according to the responder user identifier IDB, and a responder reduced hash value YB is obtained according to the responder user public key and the responder comprehensive identity hash value, YB = H256(userPublicKeyB||HB)modn. A responder elliptic curve public key PB is obtained according to the responder user public key, the master public key of the certificateless system, and the responder reduced hash value, PB = userPublicKeyB + [YB]masterPublicKey. Since the initiating end needs to generate the responder comprehensive identity hash value HB, the responder reduced hash value YB, and the responder elliptic curve public key PB during the verification process of the second identity authentication signature of the responder, and verifies the signature VERIFY(param, HB, IDB||RDM_B1, PB, SB1) for IDB||RDM_B1 and SB1, therefore, when the initiating end generates the first encrypted data packet, the responder elliptic curve public key PB can be directly reused.
[0089] The initiating end generates the first session key sessionkeyA, and generates the first parameter according to the first random data generated during the first identity authentication signature generation process. Exemplarily, the first parameter RDM_A2 = the first random number RDM_A1 + 1. The initiating end user identifier IDA, the first parameter RDM_A2, and the first session key sessionkeyA are encrypted using a public key encryption algorithm based on the responder elliptic curve public key to obtain the first encrypted data packet EA1. Exemplarily, EA1 = ENC(param, IDA||RDM_A2||sessionkeyA, PB), where ENC is the public key encryption algorithm. Denote the message to be encrypted IDA||RDM_A2||sessionkeyA as M; the specific encryption process of the public key encryption algorithm ENC(param, M, PB) includes:
[0090] Step 1: Generate a random number k ∈ [1, n - 1] using a random number generator;
[0091] Step 2: Calculate the elliptic curve point C1 = [k]G = (x1, y1), and convert the data type of C1 to a bit string;
[0092] Step 3: Calculate the elliptic curve point [k]PB = (x2, y2), and convert the data types of the coordinates x2 and y2 to bit strings;
[0093] Step 4: Calculate t = KDF(x2||y2, klen). If t is an all-zero bit string, return to Step 1;
[0094] Step 5: Calculate C2 = M ⊕ t; where ⊕ represents the exclusive OR operation;
[0095] Step 6: Calculate C3 = Hash(x2||M||y2);
[0096] Step 7: Output the ciphertext C = C1||C3||C2.
[0097] Where t = KDF(x2||y2, klen) means using the Key Derivation Function (KDF) to generate a key t from a given elliptic curve point (x2, y2) and a key length klen; x2||y2 means first converting the coordinates of the elliptic curve point (x2, y2) to a bit string and then concatenating them. C3 = Hash(x2||M||y2) means converting the coordinate values of the point (x2, y2) on the elliptic curve to a bit string, concatenating it with the original message M, and then inputting it into the hash function to obtain the output result C3.
[0098] The initiator sends the first encrypted data packet to the responder. After receiving the first encrypted data packet, the responder decrypts the first encrypted data packet EA1 using the responder's user private key userPrivateKeyB. Exemplarily, the decryption algorithm is denoted as DEC(param, EA1, userPrivateKeyB), and the data to be decrypted, i.e., the ciphertext, is denoted as C, where the ciphertext C = C1||C3||C2; the user private key used for decryption is denoted as d, then the decryption process of the decryption algorithm DEC(param, C, d) includes:
[0099] Step 1: Extract the bit string C1 from C, convert the data type of C1 to a point on the elliptic curve, and verify whether C1 satisfies the elliptic curve equation. If it does not satisfy, report an error and exit;
[0100] Step 2: Calculate [d]C1 = (x2, y2), and convert the data types of the coordinates x2 and y2 to bit strings;
[0101] Step 3: Calculate t = KDF(x2||y2, klen). If t is a bit string of all 0s, report an error and exit;
[0102] Step 4: Extract the bit string C2 from C, and calculate M' = C2 ⊕ t;
[0103] Step 5: Calculate u = Hash(x2||M'||y2), extract the bit string C3 from C. If u ≠ C3, report an error and exit;
[0104] Step 6: Output the plaintext M'.
[0105] The responder verifies the initiator's user identifier IDA based on the parsed plaintext, and converts the first random number obtained during the verification of the initiator's digital signature, i.e., the first identity authentication signature, using a preset calculation rule to obtain a first reference value, and determines whether the first reference value is equal to the first parameter. If the verification of the initiator's user identifier passes and the first reference value is equal to the first parameter, it indicates that the responder has securely received the first session key.
[0106] The initiator goes through a series of complex encryption steps, including generating a session key and a first parameter, generating a comprehensive identity hash value and a reduced hash value by using the responder's user public key in combination with the characteristics of the elliptic curve and the certificateless system, thereby obtaining the responder's elliptic curve public key, and finally encrypting the key information using a public key encryption algorithm to form the first encrypted data packet. This not only improves the strength and complexity of encryption but also enhances the confidentiality and integrity of data transmission, effectively preventing the session key from being stolen or tampered with during transmission, providing a solid security guarantee for the communication between both parties.
[0107] Figure 3The figure is a schematic structural diagram of a two-way authentication device based on a certificateless system provided by an embodiment of the present invention. As Figure 3 shown, the device includes:
[0108] A digital signature verification module 310, configured to enable both communication parties to combine the public master key of the certificateless system, use their respective private keys to digitally sign their respective user identities and respective random numbers, and use the public key of the other party to verify the digital signature of the other party;
[0109] A first session key module 320, configured to, if the digital signatures of both communication parties are verified, generate a first session key by the initiating end, and send the first session key to the responding end through a public key encryption algorithm;
[0110] A second session key module 330, configured to, after securely receiving the first session key, generate a second session key by the responding end, and send the second session key to the initiating end through a public key encryption algorithm;
[0111] A target session key module 340, configured to, after the initiating end securely receives the second session key, the two-way authentication process ends, and the initiating end and the responding end generate a target session key according to the first session key and the second session key.
[0112] The two-way authentication device based on the certificateless system provided by the embodiment of the present invention can execute the two-way authentication method based on the certificateless system provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0113] Optionally, the first session key module includes a first session key unit, and the first session key unit is configured to generate a first session key and a first parameter by the initiating end, encrypt the initiating end user identity, the first parameter, and the first session key according to the responding end user public key by using a public key encryption algorithm to obtain a first encrypted data packet, and send the first encrypted data packet to the responding end;
[0114] Wherein, the first parameter is generated based on a first random number; the first random number is generated when the initiating end generates a digital signature.
[0115] Optionally, the first session key unit is specifically configured to: generate a responding end comprehensive identity hash value by the initiating end according to the responding end user identity, elliptic curve system parameters, and the public master key of the certificateless system; obtain a responding end reduced hash value according to the responding end user public key and the responding end comprehensive identity hash value; obtain a responding end elliptic curve public key according to the responding end user public key, the public master key of the certificateless system, and the responding end reduced hash value; encrypt the initiating end user identity, the first parameter, and the first session key according to the responding end elliptic curve public key by using a public key encryption algorithm to obtain a first encrypted data packet.
[0116] Optionally, the first session key and the second session key are generated based on a random number generator. The target session key module is specifically configured to: use the exclusive OR result of the first session key and the second session key as the target session key.
[0117] Optionally, the digital signature verification module is specifically configured to: the initiator generates an initiator comprehensive identity hash value according to the initiator user identifier, the elliptic curve system parameters, and the master public key of the certificate-free system; the initiator generates a first random number, and digitally signs the first random number and the initiator user identifier according to the initiator user private key and the initiator comprehensive identity hash value to obtain a first identity authentication signature; the initiator sends the initiator user identifier, the first random number, and the first identity authentication signature to the responder; the responder verifies the first identity authentication signature according to the master public key of the certificate-free system and the initiator user public key. If the verification is passed, the responder generates a second random number, and generates a second identity authentication signature according to the second random number and the responder user identifier, so that the initiator can authenticate the responder.
[0118] Furthermore, the two-way authentication device based on the certificate-free system according to the present invention can also execute the two-way authentication method based on the certificate-free system provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0119] According to an embodiment of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.
[0120] Figure 4 FIG. shows a schematic structural diagram of an electronic device 40 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described herein and / or claimed.
[0121] As Figure 4As shown, the electronic device 40 includes at least one processor 41 and a memory communicatively connected to the at least one processor 41, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc. The memory stores a computer program executable by the at least one processor. The processor 41 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. In the RAM 43, various programs and data required for the operation of the electronic device 40 can also be stored. The processor 41, the ROM 42, and the RAM 43 are connected to each other via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0122] Multiple components in the electronic device 40 are connected to the I / O interface 45, including: an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disc, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0123] The processor 41 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 41 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 41 executes the various methods and processes described above, such as the two-way authentication method based on the certificate-free system.
[0124] In some embodiments, the two-way authentication method based on the certificate-free system can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the two-way authentication method based on the certificate-free system described above can be executed. Alternatively, in other embodiments, the processor 41 can be configured to execute the two-way authentication method based on the certificate-free system in any other appropriate way (e.g., by means of firmware).
[0125] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0126] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0127] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0128] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0129] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0130] The computing system can include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0131] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0132] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A two-way authentication method based on a certificateless system, characterized in that The method includes: Both communication parties combine the master public key of the certificateless system, use their respective private keys to digitally sign their respective user identities and respective random numbers, and use the public key of the other party to verify the digital signature of the other party; If the digital signatures of both communication parties are verified successfully, the initiating end generates a first session key, and sends the first session key to the responding end through a public key encryption algorithm; After securely receiving the first session key, the responding end generates a second session key, and sends the second session key to the initiating end through a public key encryption algorithm; After securely receiving the second session key, the two-way authentication process ends, and the initiating end and the responding end generate a target session key according to the first session key and the second session key.
2. The method according to claim 1, characterized in that, The initiating end generates a first session key, and sends the first session key to the responding end through a public key encryption algorithm, including: The initiating end generates a first session key and a first parameter, uses the public key encryption algorithm to encrypt the initiating end user identity, the first parameter, and the first session key according to the responding end user public key to obtain a first encrypted data packet, and sends the first encrypted data packet to the responding end; Wherein, the first parameter is generated based on a first random number; the first random number is generated when the initiating end generates a digital signature.
3. The method according to claim 2, wherein The initiating end generates a first session key and a first parameter, uses the public key encryption algorithm to encrypt the initiating end user identity, the first parameter, and the first session key according to the responding end user public key to obtain a first encrypted data packet, including: The initiating end generates a responding end comprehensive identity hash value according to the responding end user identity, elliptic curve system parameters, and the master public key of the certificateless system; Obtain a responding end reduced hash value according to the responding end user public key and the responding end comprehensive identity hash value; Obtain a responding end elliptic curve public key according to the responding end user public key, the master public key of the certificateless system, and the responding end reduced hash value; Use the public key encryption algorithm to encrypt the initiating end user identity, the first parameter, and the first session key according to the responding end elliptic curve public key to obtain a first encrypted data packet.
4. The method according to claim 1, wherein The first session key and the second session key are generated based on a random number generator. The initiating end and the responding end generate a target session key according to the first session key and the second session key, including: Use the exclusive OR result of the first session key and the second session key as the target session key.
5. The method according to claim 1, wherein Both communication parties combine the master public key of the certificateless system, use their respective private keys to digitally sign their respective user identities and respective random numbers, and use the public key of the other party to verify the digital signature of the other party, including: The initiating end generates an initiating end comprehensive identity hash value according to the initiating end user identity, elliptic curve system parameters, and the master public key of the certificateless system; The initiating end generates a first random number, and digitally signs the first random number and the initiating end user identity according to the initiating end user private key and the initiating end comprehensive identity hash value to obtain a first identity authentication signature; The initiating end sends the initiating end user identity, the first random number, and the first identity authentication signature to the responding end; The responder verifies the first identity authentication signature based on the master public key of the certificate-free system and the public key of the initiator user. If the verification is passed, the responder generates a second random number and generates a second identity authentication signature based on the second random number and the responder user identifier, so that the initiator can authenticate the responder.
6. A certificate-free system-based two-way authentication device, characterized in that, The device includes: A digital signature verification module, which is used for both communication parties to combine the master public key of the certificate-free system, use their respective private keys to perform digital signatures on their respective user identifiers and respective random numbers, and use the public key of the other party to verify the digital signature of the other party; A first session key module, which is used for the initiator to generate a first session key and send the first session key to the responder through a public key encryption algorithm if the digital signatures of both communication parties are verified; A second session key module, which is used for the responder to generate a second session key after securely receiving the first session key and send the second session key to the initiator through a public key encryption algorithm; A target session key module, which is used for the initiator to end the two-way authentication process after securely receiving the second session key, and the initiator and the responder generate a target session key based on the first session key and the second session key.
7. The device according to claim 6, wherein The first session key module includes a first session key unit; the first session key unit is used for the initiator to generate a first session key and a first parameter, encrypt the initiator user identifier, the first parameter and the first session key according to the responder user public key by using a public key encryption algorithm to obtain a first encrypted data packet, and send the first encrypted data packet to the responder; Wherein, the first parameter is generated based on a first random number; the first random number is generated when the initiator generates a digital signature.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the certificate-free system-based two-way authentication method according to any one of claims 1-5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the certificate-free system-based two-way authentication method according to any one of claims 1-5 when executed by a processor.
10. A computer program product, including a computer program, which implements the certificate-free system-based two-way authentication method according to any one of claims 1-5 when executed by a processor.