Anti-quantum agile incremental digital certificate implementation mode
By embedding multiple quantum-resistant algorithm key pairs in traditional digital certificates and adopting a unified data structure, the scalability and management complexity of existing quantum-resistant hybrid certificate solutions are solved, and high compatibility and flexible upgrades of digital certificates are achieved, improving security and applicability.
Patent Information
- Application Number
- CN202510693103.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-07-18
AI Technical Summary
The existing anti-quantum hybrid certificate solution only supports fixed pairs of quantum algorithms and cannot be flexible to scale, resulting in poor system compatibility and complex certificate management. The entire certificate needs to be issued when the algorithm is updated, increasing costs and business interruption risks.
Multiple anti-quantum algorithm key pairs are embedded in the traditional digital certificate in the form of a list, and a unified defined ASN.1 data structure is adopted, multiple anti-quantum signature and encryption algorithms are supported, and the algorithm is updated in incremental ways to avoid re-issue of certificates.
Improves compatibility and flexibility of digital certificates, reduces certificate management costs, shortens business interruption times, and ensures security and applicability.
Smart Images

Figure CN120342637A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital certificates, and in particular to an implementation method of anti-quantum agile incremental digital certificates. Background Art
[0002] With the rapid development of quantum computing technology, traditional digital certificates based on classical algorithms (such as RSA, ECC, etc.) face potential security threats. Most existing anti-quantum hybrid certificate schemes mostly use anti-quantum algorithm keys as the second key pairs and embed them into traditional digital certificates in the form of extension items or new ASN.1 structures, but there are the following deficiencies: Currently, most anti-quantum hybrid certificate schemes only support a fixed pair of anti-quantum algorithm keys and cannot be flexibly extended according to actual needs. Moreover, most existing anti-quantum algorithms are only for single purposes, such as only for signature or only for encryption, and it is difficult to meet the diverse requirements for data security in complex multi-purpose scenarios. For example, in some financial transaction scenarios with extremely high requirements for data confidentiality and integrity, single-purpose anti-quantum algorithms cannot simultaneously guarantee encryption and signature verification during data transmission, greatly reducing the security of digital certificates in this scenario.
[0003] If multiple anti-quantum algorithms need to be used simultaneously, existing schemes can only be achieved by issuing multiple hybrid certificates. This not only leads to poor system compatibility, making the interaction and coordination between different certificates complex, but also greatly increases the difficulty of certificate management. Taking the network security system of a large enterprise as an example, numerous employees and business processes need to use multiple anti-quantum algorithms. Issuing multiple certificates will significantly increase the enterprise's certificate management costs, including the storage, update, verification, etc. of certificates, which become cumbersome and error-prone.
[0004] Anti-quantum algorithms are currently in the stage of rapid iteration. When existing anti-quantum algorithms need to be updated, existing hybrid certificate schemes can only reissue the entire certificate. This process not only consumes a large amount of human, material, and time costs, but also may cause related services to be unable to operate normally due to certificate problems during the certificate reissuance period. For example, some online services that rely on digital certificates for identity authentication and data encryption may experience service interruptions during the certificate reissuance period, affecting user experience and the normal operation of the services. Summary of the Invention
[0005] To solve the above technical problems, an implementation method of anti-quantum agile incremental digital certificates is provided, and the present technical solution solves the above problems.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is: An implementation method of anti-quantum agile incremental digital certificates, comprising the following steps: Obtain an initial certificate, where the initial certificate is an original digital certificate containing a traditional algorithm key pair, or an original hybrid certificate containing a first key pair of a traditional algorithm and a second key pair of a quantum-resistant algorithm; Obtain multiple quantum-resistant algorithm key pairs to be added, and construct these key pairs in a predetermined format; Store the constructed quantum-resistant algorithm key pairs in the extension field of the initial certificate in the form of a list, enabling the common use of traditional algorithms and multiple quantum-resistant algorithms.
[0007] Preferably, the predetermined format is a uniformly defined ASN.1 data structure, such that all quantum-resistant algorithm key pairs have a consistent format description.
[0008] Preferably, after the certificate is issued, if an existing quantum-resistant algorithm needs to be updated or replaced, obtain a new quantum-resistant algorithm key pair, format it, and append it incrementally to the algorithm list of the original certificate, without the need to reissue the entire digital certificate.
[0009] Preferably, the quantum-resistant algorithm key pairs include, but are not limited to, quantum-resistant signature algorithms and quantum-resistant encryption algorithms, to meet the data security requirements in different application scenarios.
[0010] Preferably, the digital certificate performs verification on the traditional algorithm key pair and multiple quantum-resistant algorithm key pairs respectively according to a predetermined verification logic.
[0011] Preferably, the types of the original hybrid certificates include, but are not limited to, Hybrid Catalyst type and Hybrid Bound type. The definition of the hybrid certificate type refers to NIST SP 1800-38.
[0012] Preferably, the process of appending the new quantum-resistant algorithm key pair to the original certificate algorithm list is as follows: Generate a new quantum-resistant algorithm key pair; Encapsulate the newly generated quantum-resistant algorithm key pair according to the unified ASN.1 data structure format; The superior issuing authority of the key pair digitally signs the encapsulated quantum-resistant algorithm key pair; Append the signed new key pair to the extension field of the original digital certificate in the form of a list.
[0013] Preferably, after storing the quantum-resistant algorithm key pairs in the extension field of the initial certificate in the form of a list, it further includes recording the usage frequency of each quantum-resistant algorithm key pair. When the usage frequency of a certain quantum-resistant algorithm key pair reaches a set frequency threshold, start an update prompt mechanism.
[0014] Preferably, before obtaining multiple quantum-resistant algorithm key pairs to be added, a security score is first given to the quantum-resistant algorithm to be adopted. The scoring formula is as follows: S = w1×C + w2×R + w3×E Where S is the security score, C is the score of the algorithm's anti-attack ability index, R is the score of the algorithm's reliability index, E is the score of the algorithm's efficiency index, and w1, w2, and w3 are the weight coefficients of the corresponding indexes. The quantum-resistant algorithms with security scores higher than the preset score are selected to generate quantum-resistant algorithm key pairs.
[0015] Preferably, a timestamp recording module is provided in the digital certificate to record the time of each addition or update of the quantum-resistant algorithm key pair. The timestamp generation formula is as follows: T = UnixTime + Hash(Message) Where T is the timestamp, UnixTime is the current Unix time, and Hash(Message) is the result of hashing the certificate-related information, so as to trace the change history of the certificate.
[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: An implementation method of a quantum-resistant agile incremental digital certificate proposed by the present invention embeds multiple quantum-resistant algorithm key pairs in the form of a list in a traditional digital certificate, enabling the digital certificate to support multiple different quantum-resistant signature algorithms and encryption algorithms simultaneously. This feature significantly improves the compatibility of the digital certificate in different application scenarios, providing effective security guarantees in both scenarios with high requirements for data confidentiality and scenarios with large demands for data integrity verification, greatly enhancing the application flexibility of the digital certificate.
[0017] The ASN.1 data structure format defined uniformly is used to describe each quantum-resistant algorithm key pair, ensuring the standardization of the extended digital certificate data structure. This standardization enables better interoperability between different systems when processing and parsing digital certificates, reducing compatibility problems caused by inconsistent data formats and facilitating the application of digital certificates in a wider range of systems and platforms.
[0018] When the quantum-resistant algorithm needs to be updated or replaced, the present invention only needs to append new quantum-resistant algorithm key pairs in an incremental manner without reissuing the entire certificate, greatly simplifying the certificate upgrade process, reducing the upgrade cost, shortening the business interruption time caused by certificate upgrade, improving the agility of certificate upgrade, and ensuring that the digital certificate can always maintain good security and applicability in the case of the continuous development of quantum-resistant algorithms. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1It is a schematic diagram of the digital certificate structure of the present invention; Figure 2 It is a flowchart of the key increment addition of the anti - quantum algorithm of the present invention. Specific implementation manner
[0020] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.
[0021] Referring to Figure 1 And Figure 2 As shown, an implementation method for anti - quantum agile incremental digital certificates includes the following steps: Obtain an initial certificate, where the initial certificate is an original digital certificate containing a traditional algorithm key pair, or an original hybrid certificate containing a first traditional algorithm key pair and a second anti - quantum algorithm key pair; Obtain multiple anti - quantum algorithm key pairs to be added, and construct these key pairs in a predetermined format; Store the constructed anti - quantum algorithm key pairs in the extension field of the initial certificate in the form of a list, achieving the common use of traditional algorithms and multiple anti - quantum algorithms.
[0022] Specifically, this implementation method first obtains an initial certificate. This initial certificate has two types. One is the original digital certificate that only contains the traditional algorithm key pair, and the other is the original hybrid certificate that already contains the first traditional algorithm key pair and the second anti - quantum algorithm key pair. Then, it obtains multiple anti - quantum algorithm key pairs to be added, constructs these key pairs in a specific manner, and finally stores the constructed anti - quantum algorithm key pairs in the extension field of the initial certificate in the form of a list. In this way, the traditional algorithm and multiple anti - quantum algorithms can be used simultaneously in one certificate. The greatest advantage of this method is that it can be compatible with traditional digital certificates and add anti - quantum capabilities to them, breaking the limitation that traditional digital certificates only rely on classical algorithms. Without changing the core architecture of traditional certificates, it introduces multiple anti - quantum algorithms, making digital certificates more secure in the face of quantum computing threats, and also broadening the application scenarios of certificates to meet different security requirements.
[0023] The predetermined format is a uniformly defined ASN.1 data structure, so that all anti - quantum algorithm key pairs have a consistent format description.
[0024] Specifically, a uniformly defined ASN.1 data structure is selected as the predetermined format for the quantum-resistant algorithm key pair. This is a standardized data description method that provides a consistent format specification for all quantum-resistant algorithm key pairs, ensuring that the structure of each key pair is the same during storage and transmission, facilitating parsing and processing by different systems and devices. The unified format enhances the universality and interoperability of digital certificates. When different systems process these certificates, there is no need to develop and adapt separately for key pairs in different formats, reducing the complexity and cost of system docking. At the same time, it also improves the stability of data transmission and storage, reducing data errors or losses caused by inconsistent formats.
[0025] After the certificate is issued, if an existing quantum-resistant algorithm needs to be updated or replaced, a new quantum-resistant algorithm key pair is obtained and appended to the algorithm list of the original certificate in an incremental form after formatting, without the need to reissue the entire digital certificate.
[0026] Specifically, in the case where the certificate has already been issued, if the existing quantum-resistant algorithm needs to be updated or replaced, there is no need to reissue the entire digital certificate. Just obtain a new quantum-resistant algorithm key pair, process it according to the unified format, and add it to the algorithm list of the original certificate in an incremental form. This method greatly improves the efficiency and flexibility of certificate management. Reissuing a certificate not only consumes a large amount of time and resources but also may cause business interruptions. Incremental updates can quickly complete algorithm updates without affecting the normal use of the certificate, ensuring that the certificate always has the latest security protection capabilities, while reducing the cost and risk of certificate updates.
[0027] The quantum-resistant algorithm key pair includes, but is not limited to, quantum-resistant signature algorithms and quantum-resistant encryption algorithms to meet the data security requirements in different application scenarios.
[0028] Specifically, the quantum-resistant algorithm key pair includes various types such as quantum-resistant signature algorithms and quantum-resistant encryption algorithms. These different algorithms are designed for different data security requirements. Quantum-resistant signature algorithms are used to verify the integrity and authenticity of the data source, and quantum-resistant encryption algorithms are used to protect the confidentiality of the data. Therefore, the support of multiple algorithms enables digital certificates to adapt to different application scenarios. For example, in financial transactions, it is necessary to encrypt transaction data to protect privacy and also verify the authenticity and integrity of the transaction through signatures. The integration of multiple quantum-resistant algorithms meets this complex security requirement and enhances the practicality and security of digital certificates.
[0029] The digital certificate performs verification on the traditional algorithm key pair and multiple quantum-resistant algorithm key pairs respectively according to the predetermined verification logic.
[0030] Specifically, the digital certificate verifies the traditional algorithm key pair and multiple quantum-resistant algorithm key pairs respectively according to the pre-set verification logic. This verification logic includes a series of verification rules and steps for checking the legality, validity of the key pairs and their consistency with other certificate information. The independent verification mechanism ensures the security and reliability of various algorithms within the certificate. By verifying traditional algorithms and quantum-resistant algorithms separately, illegal or invalid key pair usage can be detected and blocked in a timely manner, ensuring that the digital certificate accurately conducts identity authentication and data protection in a complex network environment, and improving the security and credibility of the entire digital certificate system.
[0031] The original hybrid certificate types include, but are not limited to, Hybrid Catalyst type, Hybrid Bound type. The definition of the hybrid certificate types can be found in NIST SP 1800-38c.
[0032] Specifically, the types of the original hybrid certificates include multiple types such as Hybrid Catalyst type and Hybrid Bound type. These types are clearly defined in NIST SP 1800-38c. Different types of hybrid certificates may have differences in structure and function, but they all possess the characteristics of combining traditional algorithms and quantum-resistant algorithms. The diverse hybrid certificate types provide users with more choices. Different application scenarios and business requirements can select the most suitable hybrid certificate type according to their own characteristics, improving the adaptability of digital certificates in different environments and further expanding the application scope of digital certificates.
[0033] The process of appending the new quantum-resistant algorithm key pair to the original certificate algorithm list is as follows: Generate a new quantum-resistant algorithm key pair; Encapsulate the newly generated quantum-resistant algorithm key pair according to the unified ASN.1 data structure format; The superior issuing authority of the key pair digitally signs the encapsulated quantum-resistant algorithm key pair; Append the signed new key pair to the extension field of the original digital certificate in list form.
[0034] Specifically, the process of appending a new quantum-resistant algorithm key pair to the original certificate algorithm list involves multiple steps. First, a new quantum-resistant algorithm key pair is generated, which is based on the latest quantum-resistant algorithm technology. Then, the new key pair is encapsulated in accordance with the unified ASN.1 data structure format to conform to the specification. Next, the superior issuing authority of the key pair performs a digital signature to ensure the legality and authenticity of the key pair. Finally, the signed new key pair is appended to the extension field of the original digital certificate in list form. This rigorous appending process ensures the security and effectiveness of the new key pair. From generation to signature to appending, each step has strict specifications and verification mechanisms, which not only ensure that the new key pair can be successfully integrated into the original certificate, but also ensure that the security of the entire certificate system will not be threatened by the addition of the new key pair, and at the same time facilitate the management and update of the key pairs in the certificate.
[0035] After storing the quantum-resistant algorithm key pairs in the initial certificate extension field in list form, it also includes recording the usage frequency of each quantum-resistant algorithm key pair. When the usage frequency of a certain quantum-resistant algorithm key pair reaches the set frequency threshold, an update prompt mechanism is started.
[0036] Specifically, after storing the quantum-resistant algorithm key pairs in the initial certificate extension field in list form, the system will record the usage frequency of each quantum-resistant algorithm key pair. When the usage frequency of a certain quantum-resistant algorithm key pair reaches the preset frequency threshold, the update prompt mechanism will be started. By recording the usage frequency, the usage situation of each quantum-resistant algorithm key pair can be understood in a timely manner. When the usage frequency of a key pair is too high, it means that it may face higher security risks. At this time, starting the update prompt mechanism can remind relevant personnel to update the key pair in a timely manner, so as to ensure that the security of the digital certificate is always at a high level and prevent potential security problems.
[0037] Before obtaining multiple quantum-resistant algorithm key pairs to be added, first perform a security score on the quantum-resistant algorithm to be adopted. The scoring formula is: S = w1×C + w2×R + w3×E Where S is the security score, C is the score of the algorithm's anti-attack ability index, R is the score of the algorithm's reliability index, E is the score of the algorithm's efficiency index, and w1, w2, and w3 are the weight coefficients of the corresponding indexes. Select the quantum-resistant algorithms with security scores higher than the preset score to generate quantum-resistant algorithm key pairs.
[0038] Specifically, before obtaining multiple quantum-resistant algorithm key pairs to be added, a security score will be given to the quantum-resistant algorithm to be adopted. This score comprehensively considers the scores of the anti-attack ability index, reliability index, and efficiency index of the algorithm, and obtains a security score through a specific calculation method. Then, a quantum-resistant algorithm with a security score higher than the preset score is selected to generate the quantum-resistant algorithm key pair. Therefore, this screening mechanism ensures that the quantum-resistant algorithms added to the digital certificate have high security, evaluates the algorithm from multiple dimensions, avoids using algorithms with low security, improves the overall security protection ability of the digital certificate, and ensures that the certificate can effectively resist various attacks in a complex network environment.
[0039] A timestamp recording module is provided in the digital certificate to record the time of each addition or update of the quantum-resistant algorithm key pair. The timestamp generation formula is: T = UnixTime + Hash(Message) Where T is the timestamp, UnixTime is the current Unix time, and Hash(Message) is the result of hashing the certificate-related information, so as to trace the change history of the certificate.
[0040] Specifically, a timestamp recording module is set in the digital certificate. This module will record the time of each addition or update of the quantum-resistant algorithm key pair. The generation of the timestamp is based on the current time and the result of hashing the certificate-related information. This facilitates the tracing of the change history of the certificate. When a security problem occurs or the change process of the certificate needs to be reviewed, the addition or update time of each quantum-resistant algorithm key pair can be clearly understood through the timestamp, which helps to analyze the security change process of the certificate, timely discover potential security hazards, and at the same time provides a strong basis for the management and auditing of the certificate.
[0041] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed.
Claims
1. An anti-quantum agile incremental digital certificate implementation method, characterized in that, Including the following steps: Obtain an initial certificate, where the initial certificate is an original digital certificate containing a traditional algorithm key pair, or an original hybrid certificate containing a first key pair of a traditional algorithm and a second key pair of a quantum-resistant algorithm; Obtain multiple quantum-resistant algorithm key pairs to be added, and construct these key pairs in a predetermined format; Store the constructed quantum-resistant algorithm key pairs in the extension field of the initial certificate in a list form to achieve the common use of traditional algorithms and multiple quantum-resistant algorithms.
2. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that The predetermined format is a uniformly defined ASN.1 data structure, so that all quantum-resistant algorithm key pairs have a consistent format description.
3. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that After the certificate is issued, if an existing quantum-resistant algorithm needs to be updated or replaced, obtain a new quantum-resistant algorithm key pair, format it, and append it to the algorithm list of the original certificate in an incremental form, without the need to re-issue the entire digital certificate.
4. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that, The quantum-resistant algorithm key pairs include, but are not limited to, quantum-resistant signature algorithms and quantum-resistant encryption algorithms to meet the data security requirements in different application scenarios.
5. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that, The digital certificate performs verification on the traditional algorithm key pair and multiple quantum-resistant algorithm key pairs respectively according to a predetermined verification logic.
6. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that, The types of the original hybrid certificates include, but are not limited to, Hybrid Catalyst type and Hybrid Bound type. The definition of the hybrid certificate type can be found in NIST SP 1800-38c.
7. An implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that, The process of appending the new quantum-resistant algorithm key pair to the original certificate algorithm list is as follows: Generate a new quantum-resistant algorithm key pair; Encapsulate the newly generated quantum-resistant algorithm key pair according to the unified ASN.1 data structure format; The superior issuing authority of the key pair digitally signs the encapsulated quantum-resistant algorithm key pair; Append the signed new key pair to the extension field of the original digital certificate in a list form.
8. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that After storing the quantum-resistant algorithm key pairs in the extension field of the initial certificate in a list form, it also includes recording the usage frequency of each quantum-resistant algorithm key pair. When the usage frequency of a certain quantum-resistant algorithm key pair reaches the set frequency threshold, start the update prompt mechanism.
9. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that Before obtaining multiple quantum-resistant algorithm key pairs to be added, first perform a security score on the quantum-resistant algorithms to be adopted. The scoring formula is: S = w1×C + w2×R + w3×E where S is the security score, C is the score of the algorithm's anti-attack ability index, R is the score of the algorithm's reliability index, E is the score of the algorithm's efficiency index, and w1, w2, and w3 are the weight coefficients of the corresponding indexes. Select the quantum-resistant algorithms with a security score higher than the preset score to generate quantum-resistant algorithm key pairs.
10. The implementation method of an anti-quantum agile incremental digital certificate according to claim 1, characterized in that The digital certificate is equipped with a timestamp recording module to record the time of each addition or update of the quantum-resistant algorithm key pair. The timestamp generation formula is: T = UnixTime + Hash(Message) where T is the timestamp, UnixTime is the current Unix time, and Hash(Message) is the result of hashing the certificate-related information, so as to trace the change history of the certificate.