Anti-quantum computing identity authentication method, device and equipment based on digital certificate

Through the anti-quantum computing identity authentication method based on digital certificates, the key security evaluation index and life cycle evaluation index are used to solve the problem of key life cycle management difficulties, and more accurate key updates are achieved, improving the security and efficiency of identity authentication.

CN120474693AInactive Publication Date: 2025-08-12无锡极数宝大数据科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510533781.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, with the development of quantum computing technology, some quantum-resistant algorithms may be gradually weakened or cracked, so the key needs to be updated more frequently, and there is a problem of difficulty in key life cycle management in quantum computing identity authentication.

Method used

Through the anti-quantum computing identity authentication method based on digital certificates, the key security evaluation index, update evaluation index and life cycle evaluation index are used to systematically determine whether the key needs to be updated, including key security evaluation, update evaluation and life cycle evaluation, and combining anti-quantum key negotiation and encrypted transmission to achieve more accurate key update management.

Benefits of technology

It realizes more accurate key update management, improves the security and efficiency of anti-quantum computing identity authentication, avoids unnecessary key update operations, and ensures the efficiency and security of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474693A_ABST
    Figure CN120474693A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-quantum computing identity authentication method, device and equipment based on a digital certificate, and relates to the technical field of security authentication. The anti-quantum computing identity authentication method based on the digital certificate comprises the following steps of secret key security evaluation, secret key updating evaluation and secret key life cycle evaluation. According to the method, whether key updating evaluation is carried out or not is judged through the key security evaluation index obtained through the key security evaluation data, if key updating evaluation is carried out, the key updating evaluation index is obtained according to the key updating evaluation data, whether life cycle evaluation is carried out or not is judged, if not, key updating is directly carried out, and if life cycle evaluation is carried out, key updating is carried out. If yes, whether key updating is carried out or not is judged based on the key life cycle evaluation index obtained based on the key life cycle data, otherwise, key updating is directly carried out, the effect of more accurately carrying out anti-quantum computing identity authentication is achieved, and the problem that in the prior art, key life cycle management is difficult in anti-quantum computing identity authentication is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security authentication technology, and in particular to a quantum computing-resistant identity authentication method, apparatus, and device based on digital certificates. Background Art

[0002] With the rapid development of quantum computing technology, traditional public-key cryptography algorithms (such as RSA, Rivest–Shamir–Adleman, ECC, and Elliptic Curve Cryptography) face the risk of being easily cracked by quantum computers. Quantum computing can theoretically break through encryption methods that are insurmountable by classical computers. Therefore, the critical issues of ensuring information security and identity authentication have become particularly important. To address the threat of quantum computing, researchers have proposed quantum-resistant encryption algorithms. These algorithms aim to ensure the security of data and communications even in quantum computing environments. Quantum-resistant authentication methods based on digital certificates have emerged in this context. They utilize quantum-resistant algorithms to encrypt the authentication process, ensuring that identity authentication remains efficient and secure even in the face of quantum computing attacks. These new methods combine quantum-resistant cryptography with traditional public key infrastructure (PKI) to provide an authentication solution that is resilient to quantum computing threats, laying the foundation for future network security.

[0003] Existing digital certificate-based authentication methods primarily rely on traditional public key infrastructure (PKI) and encryption algorithms, such as RSA and ECC, to verify user identities. However, with the rapid development of quantum computing, these classical algorithms will become less secure in the face of quantum computing attacks. Therefore, researchers have proposed digital certificate authentication methods based on quantum-resistant cryptography (PQC) algorithms to ensure the security of identity authentication in the quantum computing era. These quantum-resistant algorithms, including lattice-based encryption, hash signatures, and coding theory, are designed with key lengths and computational complexity sufficient to cope with the computing power of quantum computers. Digital certificate authentication methods based on these algorithms combine the traditional PKI architecture with quantum-resistant algorithms in the certificate generation, verification, and management processes, ensuring that identity authentication and data transmission remain secure even in an environment where quantum computers are prevalent. However, existing technologies still face challenges in computational complexity, hardware support, and standardization, and are in urgent need of further optimization and development.

[0004] For example, the identity authentication method, device, electronic device and computer-readable storage medium disclosed in the patent application with publication number: CN116614268A include: receiving a digital certificate sent by a vehicle-mounted terminal, the digital certificate containing encrypted information, the encrypted information is obtained by the authentication server using the device identification of the first mobile terminal as an encryption key to encrypt a first random character, the first mobile terminal is a mobile terminal pre-bound to the vehicle-mounted terminal; decrypting the encrypted information based on the device identification of the second mobile terminal to obtain a second random character; sending the second random character to the vehicle-mounted terminal, so that the vehicle-mounted terminal performs identity authentication on the second mobile terminal based on the consistency of the second random character with the first random character.

[0005] For example, the invention patent announcement with announcement number: CN112087428B discloses a quantum computing-resistant identity authentication system and method based on digital certificates, including: a client and a CA organization equipped with a key management server; the key management server allocates keys to the CA organization and the client based on ID cryptography, so that during the entire identity authentication process, the client and the CA organization can negotiate keys with the communicating object based on the allocated keys based on ID cryptography, so as to realize quantum computing-resistant confidential communication of data transmitted during the identity authentication process.

[0006] However, in the process of implementing the technical solutions of the invention in the embodiments of the present application, the present application found that the above technology has at least the following technical problems:

[0007] In existing technologies, with the development of quantum computing technology, some quantum-resistant algorithms may be gradually weakened or cracked, so keys need to be updated more frequently, and there is a problem of difficulty in key lifecycle management in quantum computing-resistant identity authentication. Summary of the Invention

[0008] The embodiments of the present application solve the problem of difficulty in key lifecycle management in quantum computing-resistant identity authentication in the prior art by providing a quantum computing-resistant identity authentication method, apparatus and device based on digital certificates, and achieve more accurate quantum computing-resistant identity authentication.

[0009] An embodiment of the present application provides a quantum computing-resistant identity authentication method based on a digital certificate, comprising the following steps: when performing quantum computing-resistant key negotiation after identity authentication based on the issued digital certificate, obtaining key security assessment data through a test tool, and determining whether to perform a key update assessment based on a key security assessment index obtained from the key security assessment data, wherein the key security assessment index is used to quantify the degree of necessity of triggering a key update due to security issues during the quantum computing-resistant identity authentication process based on the digital certificate; performing encrypted transmission after quantum computing-resistant key negotiation, if a key update assessment is performed, obtaining key update assessment data and obtaining a key update assessment index, determining whether to perform a life cycle assessment based on the key update assessment index, otherwise performing a key update directly, wherein the key update assessment index is used to quantify the degree of compliance of the key with the quantum computing-resistant identity authentication update requirements; after encrypted transmission, if a life cycle assessment is performed, obtaining key life cycle data, determining whether to perform a key update based on a key life cycle assessment index obtained from the key life cycle data, otherwise performing a key update directly, wherein the key life cycle assessment index is used to evaluate the degree of compliance of the key life cycle based on the current digital certificate with the quantum computing-resistant identity authentication update requirements.

[0010] Furthermore, the key security assessment data includes the number of consecutive key unlocking attempts, key length and key entropy; the key update assessment data includes the key usage frequency, average encrypted data size and encrypted data volume; the key life cycle data includes the key validity period, key usage duration, first key update duration, second key update duration and key scheduled update cycle; the first key update duration represents the duration between the current time and the last key update time; the second key update duration represents the duration between the last key update time and the key creation time.

[0011] Furthermore, the key security evaluation index is obtained based on the key security evaluation data and the maximum number of decryption times. The method for obtaining the key security evaluation index is as follows:

[0012]

[0013] Where α represents the key length, β represents the key entropy, γ represents the number of consecutive key unlocking attempts, γ0 represents the maximum number of decryption times, and KSE represents the key security evaluation index.

[0014] Furthermore, the specific acquisition process of the key update evaluation index is as follows: obtaining reference update data from a preset database, the reference update data including the maximum key usage frequency, the average maximum limit of encrypted data and the maximum limit of encrypted data volume; judging the key update evaluation data, if the key update evaluation data meets the judgment conditions, processing the key update evaluation data to obtain the key update evaluation index, otherwise the key update evaluation index is recorded as 1; the judgment conditions indicate that the maximum key usage frequency, the average maximum limit of encrypted data and the maximum limit of encrypted data volume are all greater than the corresponding key usage frequency, average encrypted data size and encrypted data volume.

[0015] Furthermore, the specific acquisition process of the key life cycle evaluation index is as follows: number the number of times the key is updated, and obtain a first ratio by performing a ratio operation on the key usage time and the key validity period; obtain a second ratio by performing a ratio operation on the sum of the first key update duration and the second key update duration and the scheduled key update period; and obtain the key life cycle evaluation index by processing the first ratio, the second ratio and the first key update duration.

[0016] An embodiment of the present application provides a quantum computing-resistant identity authentication device based on a digital certificate, comprising a key security assessment module, a key update assessment module and a key lifecycle assessment module; wherein the key security assessment module is used to obtain key security assessment data through a test tool, and determine whether to perform a key update assessment based on a key security assessment index obtained from the key security assessment data, and the key security assessment index is used to quantify the degree of necessity of triggering a key update due to security issues; the key update assessment module is used to obtain key update assessment data and obtain a key update assessment index if a key update assessment is performed, and determine whether to perform a lifecycle assessment based on the key update assessment index, otherwise directly perform a key update, and the key update assessment index is used to quantify the degree of compliance of the key with the update requirements; the key lifecycle assessment module is used to obtain key lifecycle data if a lifecycle assessment is performed, and determine whether to perform a key update based on the key lifecycle assessment index obtained from the key lifecycle data, otherwise directly perform a key update, and the key lifecycle assessment index is used to evaluate the degree of compliance of the current key lifecycle with the update requirements.

[0017] An embodiment of the present application provides an electronic device, characterized in that the electronic device includes a memory for storing computer program instructions and a processor for executing the program instructions, wherein, when the computer program instructions are executed by the processor, the electronic device is triggered to execute the digital certificate-based quantum computing-resistant identity authentication method.

[0018] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:

[0019] 1. Determine whether to perform a key update assessment based on the key security assessment index obtained. If a key update assessment is performed, determine whether to perform a life cycle assessment based on the key update assessment index obtained. If a life cycle assessment is performed, determine whether to perform a key update based on the key life cycle assessment index obtained based on the key life cycle data. This allows for a more accurate assessment of the necessity of key updates, thereby achieving more accurate quantum computing-resistant identity authentication and effectively solving the problem of difficulty in key life cycle management in quantum computing-resistant identity authentication in the prior art.

[0020] 2. By obtaining reference update data from a preset database, the key update evaluation data is judged. If the key update evaluation data meets the judgment conditions, the key update evaluation data is processed to obtain a key update evaluation index. Otherwise, the key update evaluation index is recorded as 1, thereby more accurately judging whether the key meets the key update requirements, thereby achieving more timely key updates.

[0021] 3. A first ratio is obtained by performing a ratio operation on the key usage time and the key validity period, and then a second ratio is obtained by performing a ratio operation on the sum of the first key update duration and the second key update duration and the scheduled key update period. Finally, the first ratio, the second ratio and the first key update duration are processed to obtain a key life cycle assessment index, thereby more accurately assessing whether the key life cycle meets the key update requirements, thereby achieving more timely key updates. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 A flowchart of a quantum computing-resistant identity authentication method based on digital certificates provided in an embodiment of the present application;

[0023] Figure 2 A schematic diagram of the changes in the key security assessment index provided in an embodiment of the present application. DETAILED DESCRIPTION

[0024] The embodiments of the present application provide a quantum computing-resistant identity authentication method, apparatus, and device based on digital certificates, which solve the problem of difficult key lifecycle management in quantum computing-resistant identity authentication in the prior art. Key security assessment data is obtained through a test tool, and a key security assessment index obtained from the key security assessment data is used to determine whether to perform a key update assessment. If a key update assessment is to be performed, reference update data is obtained from a preset database and the key update assessment data is judged. If the key update assessment data meets the judgment conditions, the key update assessment data is processed to obtain a key update assessment index. Otherwise, the key update assessment index is recorded as 1. Then, based on the key update assessment index, it is determined whether to perform a lifecycle assessment. Otherwise, a key update is performed directly. If a lifecycle assessment is to be performed, a first ratio is obtained by calculating the ratio of the key usage time to the key validity period. Then, a second ratio is obtained by calculating the ratio of the sum of the first key update duration and the second key update duration to the predetermined key update period. Then, the first ratio, the second ratio, and the first key update duration are processed to obtain a key lifecycle assessment index to determine whether a key update is to be performed. Otherwise, a key update is performed directly, thereby achieving more accurate quantum computing-resistant identity authentication.

[0025] The technical solution in the embodiments of this application is to solve the above-mentioned problem of difficult key lifecycle management in quantum computing-resistant identity authentication. The overall idea is as follows:

[0026] The key security assessment index obtained through the key security assessment data is used to determine whether a key update assessment is to be performed. If a key update assessment is to be performed, the key update assessment index obtained based on the key update assessment data is used to determine whether a life cycle assessment is to be performed. Otherwise, the key update is performed directly. If a life cycle assessment is to be performed, the key life cycle assessment index obtained based on the key life cycle data is used to determine whether a key update is to be performed. Otherwise, the key update is performed directly, thereby achieving a more accurate effect of anti-quantum computing identity authentication.

[0027] In order to better understand the above technical solution, the above technical solution will be described in detail below with reference to the accompanying drawings and specific implementation methods.

[0028] like Figure 1As shown, it is a flowchart of a quantum computing-resistant identity authentication method based on a digital certificate provided in an embodiment of the present application. The method is applied to a quantum computing-resistant identity authentication device based on a digital certificate. The method includes the following steps: when performing quantum computing-resistant key negotiation after identity authentication based on the issued digital certificate, key security assessment data is obtained through a test tool, and a key security assessment index obtained based on the key security assessment data is used to determine whether to perform a key update assessment. The key security assessment index is used to quantify the degree of necessity of triggering a key update due to security issues during the quantum computing-resistant identity authentication process based on the digital certificate; after the quantum computing-resistant key negotiation, encrypted transmission is performed. If a key update assessment is performed, key update assessment data is obtained and a key update assessment index is obtained. Whether a life cycle assessment is performed is determined based on the key update assessment index. Otherwise, the key update is performed directly. The key update assessment index is used to quantify the degree of compliance of the key with the quantum computing-resistant identity authentication update requirements; after the encrypted transmission, if a life cycle assessment is performed, key life cycle data is obtained. Based on the key life cycle assessment index obtained from the key life cycle data, whether a key update is performed is determined. Otherwise, the key update is performed directly. The key life cycle assessment index is used to evaluate the degree of compliance of the key life cycle under the current digital certificate with the quantum computing-resistant identity authentication update requirements.

[0029] In this embodiment, the provided method provides a systematic and quantitative evaluation framework for key management, which can more accurately determine whether the key needs to be updated, avoid unnecessary update operations, thereby improving the efficiency and accuracy of key management and achieving more accurate quantum computing-resistant identity authentication.

[0030] Specifically, the specific process of the quantum computing-resistant identity authentication method based on digital certificates is as follows: the user generates a quantum-resistant key pair (such as a lattice-based key pair or a hash signature key pair) and registers the public key to the authentication server; the user generates and sends a signature request, and uses the private key to digitally sign the request information (using a quantum-resistant signature algorithm, such as FALCON, SPHINCS+, etc.). After receiving the request, the authentication server uses the public key to verify the validity of the digital signature; after the user identity authentication is successful, the two parties can establish a session key through a quantum-resistant key exchange algorithm (such as a lattice-based key exchange algorithm) for encrypted communication; by verifying the signature and key exchange, the authentication server confirms the user's identity and grants corresponding permissions; by combining quantum computing-resistant encryption algorithms (such as lattice-based encryption and hash signatures) with digital signature authentication mechanisms, the security of user identity authentication is guaranteed when users communicate encryptively in the face of quantum computing threats.

[0031] It should be added that the key security assessment data includes the number of consecutive key unlocking attempts, key length and key entropy; the key update assessment data includes the key usage frequency, average encrypted data size and encrypted data volume; the key life cycle data includes the key validity period, key usage duration, first key update duration, second key update duration and key scheduled update cycle; the first key update duration represents the duration between the current time and the last key update time; the second key update duration represents the duration between the last key update time and the key creation time.

[0032] Obtain key lifecycle data through the key management system, obtain key update assessment data through log management tools (such as ELK Stack and Splunk), and obtain key security assessment data through security inspection tools (such as Cryptographic Algorithm Validation Program, CAVP). Obtaining data through the above methods and tools helps to collect key-related data more comprehensively and provide a basis for determining whether key updates are necessary.

[0033] Furthermore, a key security evaluation index is obtained based on the key security evaluation data and the maximum number of decryption attempts. The method for obtaining the key security evaluation index is as follows:

[0034]

[0035] Where α represents the key length, β represents the key entropy, γ represents the number of consecutive key unlocking attempts, γ0 represents the maximum number of decryption times, and KSE represents the key security evaluation index.

[0036] In this embodiment, the algorithm combines the key length, key entropy, and the number of consecutive key unlocking attempts and the corresponding maximum decryption times to obtain a key security evaluation index. The closer it is to 1, the closer the key length is to the key entropy, and the larger the value of the key security evaluation index is; similarly, when The closer it is to 1, the closer the number of unlocking attempts is to the theoretical number of attacks, and the larger the key security assessment index is. When the number of consecutive key unlocking attempts is smaller, the larger the value of the key security assessment index is, which means the key security is higher and the key does not need to be updated. The key entropy represents the degree of randomness of the key and is a key indicator for measuring the key's anti-cracking ability. Ideally, the key entropy is equal to the key length (that is, a completely random key). For keys with shorter key lengths (such as 64 bits), more frequent key updates are required. If the randomness of the key generation process is insufficient, resulting in the key entropy being lower than the key length, the difficulty for attackers to crack the key will be reduced. However Even if the key length is long, the actual security cannot be guaranteed. When the key entropy is low, the key needs to be updated more frequently to compensate for the risk of insufficient randomness. When the key entropy is high, the key lifespan can be extended. That is, the key length defines the theoretical upper limit of security, and the key entropy determines whether the actual security is close to the theoretical upper limit. The number of consecutive unlocking attempts provides an opportunity window that attackers can exploit, which directly affects the difficulty of the attack. By analyzing the key entropy, key length and consecutive unlocking attempts, it is helpful to timely understand the security status of the key, so as to perform timely key updates, prevent data leakage, improve data security and reduce the risk of data leakage.

[0037] Specifically, such as Figure 2 As shown, a schematic diagram of the change of the key security evaluation index provided by an embodiment of the present application is shown, where it is assumed that the key length and key entropy are not considered and the maximum decryption number is 3. When the number of consecutive unlocking attempts is less than the maximum decryption number of 3, the key security evaluation index decreases as the number of consecutive unlocking attempts increases. When the number of consecutive unlocking attempts is not less than the maximum decryption number of 3, the key security evaluation index directly decreases to the minimum, indicating that the key is less secure at this time; when the number of consecutive unlocking attempts is 10 and the key entropy is 256, the closer the key length is to the key entropy of 256, the larger the value of the key security evaluation index is, indicating that the closer the key length and key entropy are to the theoretical situation, the more secure the key is. Similarly, when the number of consecutive unlocking attempts is 10 and the key length is 256, the larger the key entropy is, the larger the value of the key security evaluation index is, indicating that the larger the key entropy is, the more secure the key is and the less it needs to be updated. Therefore, by analyzing the key security evaluation index, it is helpful to more accurately evaluate the security of the key, thereby determining whether a key update is needed.

[0038] Specifically, the maximum number of unlock attempts is obtained from a preset database. In one specific embodiment, the maximum number of unlock attempts is set by professionals based on specific identity authentication scenarios. For example, if the identity authentication scenario is a highly sensitive scenario (such as system administrator or state secret access) and the identity authentication is based on a lattice cryptographic algorithm, the maximum number of unlock attempts can be set to 3.

[0039] Furthermore, the specific process for determining whether to perform a key update evaluation is as follows: obtaining a security threshold from a preset database, the security threshold is used to determine whether to perform a key update evaluation; the key security evaluation index is compared with the security threshold: if the key security evaluation index is not less than the security threshold, the key update is performed and the key update information is recorded in the system log as well as the public key in the updated digital certificate. The key update indicates generating a new key pair to achieve quantum computing-resistant identity authentication. The key update information includes key information data, update operation data, new and old state data, audit verification data, and error handling data. The quantum computing-resistant identity authentication indicates replacing the existing algorithm with a quantum-resistant algorithm for identity authentication. If the key security evaluation index is less than the security threshold, a key update evaluation is performed.

[0040] In this embodiment, key information data includes a key identifier (key ID and version number), key attributes, and key information before the update; update operation data includes time data (update timestamp, effective time, and transition period), executor (operator information, approver information, and automated tool); new and old state data includes the new key ID and data encryption status; audit verification data includes update results and audit logs; error handling data includes error logs and rollback plans. The above data is automatically recorded and updated in the system log during the key update process. The public key in a digital certificate is the core of the asymmetric encryption system and is used for data encryption, signature verification, and identity authentication. Its public nature enables communicating parties to securely establish encrypted communications with the certificate holder without worrying about security issues caused by public key leakage. Existing algorithms include but are not limited to RSA (Rivest–Shamir–Adleman) and ECC (Elliptic Curve Cryptography), and quantum-resistant algorithms include but are not limited to Kyber and Dilithium. Dynamic decision-making through a security threshold mechanism improves the security, efficiency, and traceability of the system, meeting the key management requirements in high-security scenarios (such as quantum-resistant computing authentication systems) while also taking into account resource optimization and compliance requirements.

[0041] Specifically, the security threshold is obtained from a preset database. In one specific embodiment, the key security assessment data corresponding to the key update required in the historical data is substituted into the specific restriction expression of the key security assessment index to obtain the corresponding data set, and the result of the mean operation on the data set is recorded as the security threshold.

[0042] Furthermore, a specific process for obtaining the key update evaluation index is as follows: obtaining reference update data from a preset database, the reference update data including a maximum key usage frequency, an average maximum limit of encrypted data, and a maximum limit of the amount of encrypted data; judging the key update evaluation data, and if the key update evaluation data meets a judgment condition, processing the key update evaluation data to obtain a key update evaluation index; otherwise, recording the key update evaluation index as 1; the judgment condition indicates that the maximum key usage frequency, the average maximum limit of encrypted data, and the maximum limit of the amount of encrypted data are all greater than the corresponding key usage frequency, average encrypted data size, and amount of encrypted data;

[0043] The specific restriction expression of the key update evaluation index is as follows:

[0044]

[0045] Where UF represents the key usage frequency, AD represents the average encrypted data size, ED represents the amount of encrypted data, UF0 represents the maximum key usage frequency, AD0 represents the maximum limit of average encrypted data, ED0 represents the maximum limit of encrypted data, KUE represents the key update evaluation index, and e represents a natural constant.

[0046] In this embodiment, the algorithm combines the key usage frequency, the average encrypted data size, the encrypted data volume, and the corresponding reference update data to obtain a key update evaluation index. The formula is divided into two situations according to the judgment conditions. Among them, when the judgment conditions are met, when the key usage frequency, the average encrypted data size, and the encrypted data volume are less than the corresponding maximum key usage frequency, the average encrypted data maximum limit, and the encrypted data volume maximum limit, the key update evaluation index is smaller, indicating that the key update evaluation data does not meet the key update requirements, the key does not need to be updated, and the corresponding key update evaluation index value is smaller; assuming that the maximum key usage frequency is 100 times / hour, the average encrypted data maximum limit is 500MB, and the encrypted data maximum limit is 10 3 MB, combined with the key update evaluation data, obtains a data change table of the key update evaluation index, as shown in Table 1:

[0047] Table 1 Data changes of key update evaluation index

[0048]

[0049]

[0050] As can be seen from Table 1, the key update assessment index increases with the increase in key usage frequency, average encrypted data size, and encrypted data volume. This indicates that the greater the key usage frequency, average encrypted data size, and encrypted data volume, the greater the likelihood of a key update. For example, when the key usage frequency increases from 60 times / hour in the first row to 90 times / hour in the fourth row, the average encrypted data size increases from 450MB in the first row to 480MB in the fourth row, and the encrypted data volume increases from 1000MB in the first row to 9000MB in the fourth row, the corresponding key update assessment index increases from 0.66 in the first row to 0.92 in the fourth row, indicating an increased likelihood of a key update. Therefore, analyzing the key update assessment index helps to detect key usage in a timely manner, thereby enabling timely key updates to ensure data security.

[0051] Specifically, the reference update data is obtained from a preset database. In a specific embodiment, the reference update data is obtained from security restriction requirements for key update, which are set by professionals based on the specific conditions of the key.

[0052] Furthermore, the specific process for determining whether to perform a life cycle assessment is as follows: obtaining an update assessment threshold from a preset database, and the update assessment threshold is used to determine whether to perform a life cycle assessment; judging the key update assessment index and the update assessment threshold: if the key update assessment index is not less than the update assessment threshold, executing the key update and recording the key update information in the system log and the public key in the updated digital certificate; if the key update assessment index is less than the update assessment threshold, performing a life cycle assessment.

[0053] In this embodiment, performing lifecycle assessment when the key update evaluation index is low can fundamentally analyze whether the current state of the key is still suitable for use, thereby preventing misjudgment caused by relying solely on the update evaluation threshold; and dynamically evaluating the key update and lifecycle status to avoid using expired, degraded or low-security keys also helps to improve the overall security of the key.

[0054] Specifically, the update assessment threshold is obtained from a preset database. In one specific embodiment, the key update assessment data corresponding to the key update required in the historical data is substituted into the specific restriction expression of the key update assessment index to obtain a corresponding data set. The result of performing a mean operation on the data set is recorded as the update assessment threshold.

[0055] Furthermore, the specific process of obtaining the key life cycle evaluation index is as follows: numbering the number of key updates and obtaining key life cycle data, obtaining a first ratio by performing a ratio operation on the key usage time and the key validity period; obtaining a second ratio by performing a ratio operation on the sum of the first key update duration and the second key update duration and the predetermined key update period; and processing the first ratio, the second ratio, and the first key update duration to obtain the key life cycle evaluation index.

[0056] The specific restriction expression of the key life cycle evaluation index is as follows:

[0057]

[0058] Where n represents the number of key updates, n = 2, 3, ..., N, N represents the total number of key updates, KV represents the key validity period, KT n Indicates the key usage time until the nth key update, KL n Indicates the first key update duration of the nth key update, KO n Indicates the second key update duration of the nth key update, KR indicates the scheduled key update period, F n Indicates the first ratio of the nth key update, S n The second ratio of the nth key update, KLA n represents the key lifecycle evaluation index up to the nth key update, and e represents a natural constant.

[0059] In this embodiment, the algorithm combines the first ratio (ie, F n ) and the second ratio (ie S n ) and the first key update duration are comprehensively analyzed to obtain a key lifecycle assessment index, where, when the first ratio is closer to 1, it indicates that the key usage duration is closer to the key validity period, the possibility of a key update is greater, and the key lifecycle assessment index is greater. When the second ratio is closer to 1, it indicates that the time to the scheduled update is closer, the possibility of a key update is greater, and the key lifecycle assessment index is greater. When the first key update duration is longer, it indicates that the time from the last key update is longer, the possibility of a key update is greater, the key lifecycle assessment index is greater, and the possibility of a key update is greater. When the sum of the first key update duration and the second key update duration is longer, the key usage duration is longer and the key validity period is shorter. When the first key update duration is longer, the second ratio is larger. Therefore, through a comprehensive analysis of the key validity period, key usage duration, first key update duration, second key update duration, and scheduled key update period, it is helpful to better understand the key lifecycle, thereby performing key updates in a timely manner and reducing the risk of data transmission leakage.

[0060] Furthermore, the specific process of determining whether to perform a key update is as follows: obtaining a key update threshold from a preset database, the key update threshold is used to determine whether to perform a key update; the key update evaluation index is judged against the key update threshold: if the key life cycle evaluation index is not less than the key update threshold, the key is updated and the public key in the digital certificate is updated at the same time; if the key life cycle evaluation index is less than the key update threshold, the key is not updated and key update feedback is performed. The key update feedback means sending a key update report to the user when the user tries to unlock the key. The key update report includes the key update record and the remaining validity period of the key.

[0061] In this embodiment, the process combines quantitative evaluation, automated decision-making, and user feedback to achieve intelligent control of key management, which helps to improve the intelligence level of the system and provide a more efficient, convenient, and secure solution for key management. By scientifically judging whether the key needs to be updated, a more efficient, convenient, and secure solution is provided for key management.

[0062] Specifically, the key update threshold is obtained from a preset database. In one specific embodiment, the key lifecycle data corresponding to the key update required in the historical data is substituted into the specific restriction expression of the key lifecycle assessment index to obtain a corresponding data set, and the result of the mean operation on the data set is recorded as the key update threshold.

[0063] The quantum computing-resistant identity authentication device based on digital certificates provided in an embodiment of the present application includes a key security assessment module, a key update assessment module and a key lifecycle assessment module; wherein the key security assessment module is used to obtain key security assessment data through a test tool, and determine whether to perform a key update assessment based on a key security assessment index obtained from the key security assessment data, and the key security assessment index is used to quantify the degree of necessity of triggering a key update due to security issues; the key update assessment module is used to obtain key update assessment data and obtain a key update assessment index if a key update assessment is performed, and determine whether to perform a lifecycle assessment based on the key update assessment index, otherwise directly perform a key update, and the key update assessment index is used to quantify the degree of compliance of the key with the update requirements; the key lifecycle assessment module is used to obtain key lifecycle data if a lifecycle assessment is performed, and determine whether to perform a key update based on the key lifecycle assessment index obtained from the key lifecycle data, otherwise directly perform a key update, and the key lifecycle assessment index is used to evaluate the degree of compliance of the current key lifecycle with the update requirements.

[0064] In this embodiment, through intelligent key management strategies, optimized key update strategies and comprehensive security assessment mechanisms, the security and intelligence level of identity authentication are improved, providing strong support for key security requirements; at the same time, the device can ensure the stability and reliability of the identity authentication system through intelligent key management strategies, and can maintain the normal operation and efficient response of the system even in the face of new security challenges such as quantum computing.

[0065] Among them, an embodiment of the present application also provides an electronic device, characterized in that the electronic device includes a memory for storing computer program instructions and a processor for executing program instructions, wherein when the computer program instructions are executed by the processor, the electronic device is triggered to execute a quantum computing-resistant identity authentication method based on a digital certificate.

[0066] To sum up, the embodiment of the present application determines whether to perform a key update evaluation through the obtained key security assessment index. If a key update evaluation is performed, whether to perform a life cycle evaluation is determined based on the obtained key update assessment index. If a life cycle evaluation is performed, whether to perform a key update is determined based on the key life cycle assessment index obtained based on the key life cycle data, thereby more accurately evaluating the necessity of key update, and further achieving more accurate anti-quantum computing identity authentication, effectively solving the problem of difficulty in key life cycle management in anti-quantum computing identity authentication in the prior art.

[0067] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0068] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0069] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0070] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0071] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0072] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A quantum computing-resistant identity authentication method based on digital certificates, characterized in that: The following steps are involved: When performing quantum-resistant key negotiation after identity authentication based on a signed digital certificate, key security assessment data is obtained through a test tool, and a key security assessment index obtained from the key security assessment data is used to determine whether to perform a key update assessment. The key security assessment index is used to quantify the degree to which a key update is necessary due to security issues during identity authentication based on quantum-resistant computing using digital certificates. After quantum-resistant key negotiation, encrypted transmission is performed. If a key update assessment is performed, key update assessment data is obtained and a key update assessment index is obtained. The key update assessment index is used to determine whether a lifecycle assessment should be performed. Otherwise, a key update is performed directly. The key update assessment index is used to quantify the degree to which the key complies with the quantum-resistant identity authentication update requirements; After encrypted transmission, if a lifecycle assessment is performed, the key lifecycle data is obtained, and the key lifecycle assessment index obtained based on the key lifecycle data is used to determine whether to update the key. Otherwise, the key is updated directly. The key lifecycle assessment index is used to evaluate the degree of compliance with the key lifecycle under the current digital certificate and the anti-quantum computing identity authentication update requirements.

2. The quantum computing-resistant identity authentication method based on digital certificates according to claim 1, characterized in that: The key security assessment data includes the number of consecutive key unlocking attempts, key length and key entropy; The key update evaluation data includes key usage frequency, average encrypted data size and encrypted data volume; The key life cycle data includes the key validity period, key usage duration, first key update duration, second key update duration and key scheduled update period; The first key update duration represents the duration between the current time and the last key update time; The second key update duration indicates the duration between the last key update time and the key creation time.

3. The quantum computing-resistant identity authentication method based on digital certificates according to claim 2, characterized in that: The key security evaluation index is obtained based on the key security evaluation data and the maximum number of decryption times. The method for obtaining the key security evaluation index is as follows: Where α represents the key length, β represents the key entropy, γ represents the number of consecutive key unlocking attempts, γ0 represents the maximum number of decryption times, and KSE represents the key security evaluation index.

4. The quantum computing-resistant identity authentication method based on digital certificates according to claim 3, characterized in that: The specific process of determining whether to perform key update evaluation is as follows: Obtaining a security threshold from a preset database, wherein the security threshold is used to determine whether to perform a key update evaluation; Compare the key security assessment index with the security threshold: If the key security assessment index is not less than the security threshold, a key update is performed and the key update information is recorded in the system log, as well as the public key in the updated digital certificate. The key update represents the generation of a new key pair to implement quantum computing-resistant identity authentication. The key update information includes key information data, update operation data, new and old state data, audit verification data, and error handling data. The quantum computing-resistant identity authentication represents the replacement of the existing algorithm with a quantum-resistant algorithm for identity authentication. If the key security evaluation index is less than the security threshold, a key update evaluation is performed.

5. The quantum computing-resistant identity authentication method based on digital certificates according to claim 2, characterized in that: The specific process of obtaining the key update evaluation index is as follows: Obtain reference update data from a preset database, wherein the reference update data includes a maximum key usage frequency, a maximum average encrypted data limit, and a maximum encrypted data amount limit; The key update evaluation data is judged. If the key update evaluation data meets the judgment condition, the key update evaluation data is processed to obtain a key update evaluation index; otherwise, the key update evaluation index is recorded as 1; The judgment condition indicates that the maximum key usage frequency, the average encrypted data maximum limit and the encrypted data amount maximum limit are all greater than the corresponding key usage frequency, average encrypted data size and encrypted data amount.

6. The quantum computing-resistant identity authentication method based on digital certificates according to claim 5, characterized in that: The specific process for determining whether to conduct a life cycle assessment is as follows: Obtaining an update assessment threshold from a preset database, wherein the update assessment threshold is used to determine whether to perform a life cycle assessment; The key update evaluation index is compared with the update evaluation threshold: If the key update evaluation index is not less than the update evaluation threshold, the key update is performed and the key update information is recorded in the system log and the public key in the digital certificate is updated; If the key update evaluation index is less than the update evaluation threshold, a lifecycle evaluation is performed.

7. The quantum computing-resistant identity authentication method based on digital certificates according to claim 2, characterized in that: The specific process of obtaining the key life cycle evaluation index is as follows: Numbering the number of times the key is updated, and obtaining a first ratio by performing a ratio operation on the key usage time and the key validity period; A second ratio is obtained by performing a ratio operation on the sum of the first key update duration and the second key update duration and the predetermined key update period; The first ratio, the second ratio, and the first key update duration are processed to obtain a key lifecycle assessment index.

8. The quantum computing-resistant identity authentication method based on digital certificates according to claim 7, characterized in that: The specific process of determining whether to perform key update is as follows: Obtaining a key update threshold from a preset database, wherein the key update threshold is used to determine whether to perform a key update; The key update evaluation index and the key update threshold are compared: If the key lifecycle assessment index is not less than the key update threshold, the key is updated and the public key in the digital certificate is updated at the same time; If the key lifecycle evaluation index is less than the key update threshold, no key update is performed and key update feedback is performed.

9. A quantum computing-resistant identity authentication device based on digital certificates, including a key security assessment module, a key update assessment module, and a key lifecycle assessment module; in, The key security assessment module is used to obtain key security assessment data through a test tool, and determine whether to perform a key update assessment based on a key security assessment index obtained from the key security assessment data. The key security assessment index is used to quantify the degree of necessity of triggering a key update due to security issues; The key update assessment module is used to obtain key update assessment data and obtain a key update assessment index if a key update assessment is performed, and determine whether to perform a lifecycle assessment based on the key update assessment index. Otherwise, the key update is directly performed. The key update assessment index is used to quantify the degree of compliance of the key with the update requirements; The key lifecycle assessment module is used to obtain key lifecycle data if a lifecycle assessment is performed, and determine whether to update the key based on the key lifecycle assessment index obtained from the key lifecycle data; otherwise, the key is directly updated. The key lifecycle assessment index is used to evaluate the degree of compliance of the current key lifecycle with the update requirements.

10. An electronic device, characterized in that: The electronic device includes a memory for storing computer program instructions and a processor for executing the program instructions, wherein, when the computer program instructions are executed by the processor, the electronic device is triggered to execute the digital certificate-based quantum computing-resistant identity authentication method as described in any one of claims 1-8.

Citation Information

Patent Citations

  • A quantum-resistant identity authentication system and method based on digital certificates

    CN112087428B

  • Identity authentication method and device, electronic equipment and computer readable storage medium

    CN116614268A