Machine identity management method based on SM9 algorithm

Through the machine identity management method combined with SM9 algorithm and key generation center, the problem of complex certificate management and poor real-time performance of the traditional PKI system is solved, lightweight identity authentication and access control are realized, and the security and efficiency of the system are improved.

CN120301592APending Publication Date: 2025-07-11SHANGHAI GEER SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510624251.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the machine identity management, traditional PKI system has problems such as complex certificate management, large computing and storage overhead, poor real-time performance, and easy CA attack.

Method used

The SM9 algorithm is used to combine the key generation center to generate a signed main public-private key pair. The device private key is stored in the password module and identity authentication is performed through signature data, simplifying the certificate management and authentication process, and using session tokens to achieve lightweight access control.

Benefits of technology

It realizes efficient identity authentication and access control without managing complex certificates, reduces the complexity of the authentication process, simplifies the revocation mechanism, and improves the security and real-time nature of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301592A_ABST
    Figure CN120301592A_ABST
Patent Text Reader

Abstract

The invention discloses a machine identity management method based on an SM9 algorithm, and the method comprises the steps: a secret key generation center generates a random number, and generates a signature main public and private key pair; the device sends a registration request and sends a device ID to the authentication server; the key generation center calculates an equipment private key and safely transmits the equipment private key to the equipment; the device securely stores the device private key in a password module; and in the identity authentication stage, the equipment signs the equipment ID by using the equipment private key to generate signature data, and sends the equipment ID and the signature data to the authentication server, and the like, the machine identity management method does not need to manage complex certificates, but still can provide considerable identity authentication and access control capabilities. And meanwhile, CRL or OCSP inspection is avoided, so that the equipment authentication process is lighter. And the revocation mechanism of the method is simpler, and only the KGC and the authentication server need to be updated. According to the method, identity authentication and an SM9 signature algorithm are combined, the complexity of an authentication process is reduced, and the authentication strength with the capacity equivalent to that of PKI (Public Key Infrastructure) is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical fields of information security and cryptography, and particularly relates to a machine identity management method based on the combination of the SM9 algorithm and multiple cryptographic modules. Background Art

[0002] In machine identity management, traditional PKI mainly issues X.509 digital certificates to users or devices through a CA, combines asymmetric encryption to implement device identity authentication, and relies on the TLS protocol to ensure secure communication between devices. The public-private key pair is generated by the device, and the private key is usually stored in a TPM, HSM, or other module to prevent leakage. The PKI system ensures that the identity of the machine is trusted and guards against man-in-the-middle attacks and forged identities through certificate management, key management, device identity authentication, and secure communication mechanisms. However, traditional PKI still faces many drawbacks: such as complex certificate management, where devices need to issue certificates and need to be updated and revoked regularly; improper key protection may lead to leakage of the user's private key; certificate revocation depends on CRL or OCSP, with poor real-time performance; dependence on the CA, and if the CA is attacked, the entire system will collapse, etc. Summary of the Invention

[0003] The purpose of the present invention is to provide a machine identity management method based on the SM9 algorithm that is not restricted by traditional PKI, effectively solving the problems of complex certificate management and large computational and storage overheads in the PKI system.

[0004] To achieve the above purpose, the present invention provides the following technical solution: A machine identity management method based on the SM9 algorithm, comprising the following steps: Step 1, the key generation center generates a random number and generates a signature master public-private key pair; Step 2, the device sends a registration request and sends the device ID to the authentication server; Step 3, the key generation center calculates the device private key and securely transmits it to the device; Step 4, the device securely stores the device private key in the cryptographic module; Step 5, in the identity authentication stage, the device signs the device ID with the device private key to generate signature data, and sends the device ID and the signature data to the authentication server; Step 6, the authentication server checks whether the device is registered and the device status according to the device ID. If it is not registered or the device status is abnormal, the request is rejected, otherwise it continues; Step 7, the authentication server verifies the signature data. If the verification passes, the identity authentication is successful, otherwise the authentication fails; Step 8, the authentication server authorizes the device to access the corresponding resources.

[0005] Further, the device ID in step one may include additional information such as device model and device type, facilitating the assignment of different access permissions according to different devices.

[0006] Further, the password module in step four may be a hardware module such as TPM or HSM, which can better protect the device private key.

[0007] Further, the data sent to the authentication server in step five may also include information such as device type and timestamp, facilitating the authentication server to assign different access permissions according to different devices and preventing replay attacks, etc.

[0008] Further, a session token may be generated in step eight for short-term access.

[0009] Further, a session token may be generated in step eight, facilitating subsequent access to directly use the Token without repeated identity authentication.

[0010] This machine identity management method based on the SM9 algorithm does not require the management of complex certificates, but still can provide a relatively strong ability of identity authentication and access control. At the same time, this machine identity management method based on the SM9 algorithm does not have the verification of CRL or OCSP, and the device authentication process is more lightweight. And the revocation mechanism of this machine identity management method based on the SM9 algorithm is simpler, only requiring the update of the KGC and the authentication server. This machine identity management method based on the SM9 algorithm combines identity authentication with the SM9 signature algorithm, reducing the complexity of the authentication process and providing an authentication strength equivalent to that of PKI. Brief Description of the Drawings

[0011] The specification drawings forming a part of the present disclosure are used to provide a further understanding of the present disclosure. The illustrative embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure.

[0012] Figure 1 It is a flowchart of machine identity management based on the SM9 algorithm. Detailed Embodiments

[0013] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present disclosure belongs.

[0014] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should also be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof. Embodiment

[0015] Please refer to Figure 1 , a machine identity management method based on the SM9 algorithm. This embodiment includes the following steps: Step 1: The Key Generation Center (KGC) generates a random number and generates a signature master public-private key pair; Step 2: The device sends a registration request and sends the device ID to the authentication server; Step 3: The Key Generation Center calculates the device private key and securely transmits it to the device; Step 4: The device securely stores the device private key in the cryptographic module; Step 5: In the identity authentication stage, the device uses the device private key to sign the device ID to generate signature data, and sends the device ID and the signature data to the authentication server; Step 6: The authentication server checks whether the device is registered and the device status based on the device ID. If it is not registered or the device status is abnormal, the request is rejected; otherwise, it continues; Step 7: The authentication server verifies the signature data. If the verification passes, the identity authentication is successful; otherwise, the authentication fails; Step 8: The authentication server authorizes the device to access the corresponding resources.

[0016] Specifically, the device ID in Step 1 may include additional information such as the device model and device type, which is convenient for assigning different access permissions according to different devices.

[0017] Specifically, the cryptographic module in Step 4 may be a hardware module such as TPM or HSM, which can better protect the device private key.

[0018] Specifically, the data sent to the authentication server in Step 5 may also include information such as the device type and timestamp, which is convenient for the authentication server to assign different access permissions according to different devices and prevent replay attacks, etc.

[0019] Specifically, a session token may be generated in Step 8 for short-term access.

[0020] Specifically, a session token may be generated in Step 8, which is convenient for subsequent access to directly use the Token without repeated identity authentication.

[0021] The machine identity management method based on the SM9 algorithm does not need to manage complex certificates, but can still provide a relatively strong ability for identity authentication and access control. At the same time, the machine identity management method based on the SM9 algorithm does not have the verification of CRL or OCSP, and the device authentication process is more lightweight. Moreover, the revocation mechanism of the machine identity management method based on the SM9 algorithm is simpler, and only the KGC and the authentication server need to be updated.

[0022] The above are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A machine identity management method based on the SM9 algorithm, characterized in that It includes the following steps: Step 1: The key generation center generates a random number and generates a signature master public-private key pair; Step 2: The device sends a registration request and sends the device ID to the authentication server; Step 3: The key generation center calculates the device private key and securely transmits it to the device; Step 4: The device securely stores the device private key in a cryptographic module; Step 5: In the identity authentication stage, the device uses the device private key to sign the device ID to generate signature data, and sends the device ID and signature data to the authentication server; Step 6: The authentication server checks whether the device is registered and the device status according to the device ID. If it is not registered or the device status is abnormal, the request is rejected, otherwise it continues; Step 7: The authentication server verifies the signature data. If the verification passes, the identity authentication is successful, otherwise the authentication fails; Step 8: The authentication server authorizes the device to access the corresponding resources.

2. The machine identity management method based on the SM9 algorithm according to claim 1, wherein The device ID in Step 1 may include additional information such as device model and device type, which is convenient for assigning different access permissions according to different devices.

3. The machine identity management method based on the SM9 algorithm according to claim 1, characterized in that The cryptographic module in Step 4 may be a hardware module such as TPM or HSM, which can better protect the device private key.

4. A machine identity management method based on the SM9 algorithm according to claim 1, characterized in that, The data sent to the authentication server in Step 5 may also include information such as device type and timestamp, which is convenient for the authentication server to assign different access permissions according to different devices and prevent replay attacks, etc.

5. A machine identity management method based on the SM9 algorithm according to claim 1, characterized in that, In Step 8, a session token can be generated for short-term access.

6. The machine identity management method based on the SM9 algorithm according to claim 1, characterized in that, In Step 8, a session token can be generated, which is convenient for subsequent access to directly use the Token without repeated identity authentication.