Identity authentication method and related equipment
By using physical non-clone functions in the quantum key distribution device to generate a challenge response list and public key, and requesting a quantum security certificate from the authentication server, the problem of high complexity of identity authentication of the quantum key distribution device is solved, and identity authentication with lower complexity and higher scalability is achieved.
Patent Information
- Application Number
- CN202511087484.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-08-04
AI Technical Summary
Existing quantum key distribution devices have high complexity and high workload in identity authentication. Especially when accessing new devices in complex QKD networks, key management is difficult and cannot be effectively expanded.
The physical non-clone function is used to generate a challenge response list. By generating the post-quantum cipher PQC public key and classic signature public key, a quantum security certificate is requested from the authentication server, and the PUF's non-clone response is used for identity authentication, reducing key presetting and reducing complexity.
It reduces the complexity of identity authentication between quantum key distribution devices, reduces workload, and improves the scalability of the QKD network and the simplicity of access to new devices.
Smart Images

Figure CN120602103A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technology, and in particular to an identity authentication method and related equipment. Background Art
[0002] Quantum Key Distribution (QKD) devices cannot authenticate the source of transmissions, requiring the pre-setting of numerous keys. For a QKD network with n users, every user must pre-set keys, requiring a total of n(n-1) / 2 key pairs. This significantly increases the difficulty of authentication and key management in complex QKD networks and hinders scalability. When a QKD user accesses the network, they must also pre-set keys with all other QKD devices, making authentication complex and labor-intensive.
[0003] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute prior art known to ordinary technicians in the field. Summary of the Invention
[0004] The present disclosure provides an identity authentication method and related equipment, which at least to a certain extent overcome the problems of high complexity and heavy workload in identity authentication between QKD devices in related technologies.
[0005] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.
[0006] In a first aspect, embodiments of the present disclosure provide an identity authentication method, applied to a first quantum key distribution device, the method comprising: Inputting challenge information into the physical unclonable function to generate a challenge-response list; the challenge-response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, and a third challenge and a corresponding third response; Generate a post-quantum cryptography (PQC) public key based on the second response; and / or generate a classical signature public key based on the third response; Sending a first security certificate request to the authentication server; the first security certificate request includes: a first challenge, a hash value of the first response, a PQC public key and / or a classic signature public key; Receive the first quantum security certificate for identity authentication fed back by the authentication server.
[0007] In a possible embodiment, the challenge information input into the physical unclonable function is a random number.
[0008] In a possible embodiment, the method further includes: Constructing a first identity authentication request message according to the first quantum security certificate, the first challenge, and the hash value of the corresponding first response; A first identity authentication request message is sent to the second quantum key distribution device, so that the second quantum key distribution device performs identity authentication on the first quantum key distribution device.
[0009] In a possible embodiment, the method further includes: receiving a second identity authentication request message sent by a second quantum key distribution device; the second identity authentication request message including: a second quantum security certificate of the second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; the fifth response is used to identify the second quantum key distribution device; Sending a first identity authentication request to the authentication server, where the first identity authentication request includes: a second identity authentication request message; Receive first verification success information.
[0010] In a possible embodiment, the challenge-response list further includes: a fourth challenge and a corresponding fourth response; a value in the fourth response is used as a signature identification bit in a quantum-safe hybrid signature; the quantum-safe hybrid signature includes: a classical signature and a PQC signature; The method also includes: For the nth generated quantum-secure hybrid signature, obtain the value of the nth bit in the fourth response; If the value of the nth bit is 1, a PQC signature is generated; Generate the nth quantum-secure hybrid signature based on the nth bit value, the PQC signature, the classical signature, and the original message; If the nth bit is 0, the nth quantum-secure hybrid signature is generated based on the value of the nth bit, the classical signature, and the original information; The n-th quantum secure hybrid signature is sent to the second quantum key distribution device.
[0011] In a possible embodiment, the method further includes: receiving a quantum secure hybrid signature sent by a second quantum key distribution device; Obtain the signature identification bit in the quantum-safe hybrid signature; If the signature flag is 1, obtain the PQC public key and the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum security hybrid signature; If the signature flag is 0, the classical signature public key in the quantum security certificate of the second quantum key distribution device is obtained to verify the quantum security hybrid signature.
[0012] In a possible embodiment, the method further includes: When all signature identification bits of the fourth response are used to generate a quantum-secure hybrid signature, the fourth challenge and the fourth response are deleted from the challenge-response list; A new fourth challenge is input to the PUF to generate a new fourth response.
[0013] In a possible embodiment, the first challenge and the first response are used to identify the first quantum key distribution device; the second challenge and the second response are used as random numbers for PQC signatures to participate in key generation; and the third challenge and the third response are used as random numbers for classical signatures to participate in key generation.
[0014] In a second aspect, an embodiment of the present disclosure provides an identity authentication method, applied to an authentication server, the method comprising: Receive a first security certificate request; the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key; Generate and feedback a first quantum security certificate; wherein, the PQC public key and / or the classical signature public key are serially connected in the public key main information part of the first quantum security certificate; the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.
[0015] In a possible embodiment, the method further includes: Receive a first identity authentication request, the first identity authentication request including: a second identity authentication request message; the second identity authentication request message including: a second quantum security certificate of a second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; Perform multi-level verification. If the multi-level verification passes, it is determined that the second quantum key distribution device is compliant and the first verification pass information is sent.
[0016] In one possible embodiment, multi-level verification is performed, including: Verify based on the second quantum security certificate in the second identity authentication request message and the verification certificate stored in the authentication server; and, based on the fifth challenge, querying the verification hash value stored in the authentication server; Verification is performed based on the verification hash value and the fifth response in the second identity authentication request message.
[0017] In a third aspect, an embodiment of the present disclosure provides a quantum key distribution device, comprising: a first generating unit, configured to input a challenge into a physical unclonable function and generate a challenge-response list; the challenge-response list comprising: a first challenge and a corresponding first response, and at least one of: a second challenge and a corresponding second response, and a third challenge and a corresponding third response; A second generating unit is configured to generate a post-quantum cryptography PQC public key according to the second response; and / or generate a classical signature public key according to the third response; The first sending unit is configured to send a first security certificate request to the authentication server; the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key; The first receiving unit is further configured to receive a first quantum security certificate for identity authentication fed back by the authentication server.
[0018] In a possible embodiment, the quantum key distribution device further includes: A construction unit, configured to construct a first identity authentication request message according to the first quantum security certificate, the first challenge, and a hash value of the corresponding first response; The first sending unit is further configured to send a first identity authentication request message to the second quantum key distribution device, so that the second quantum key distribution device performs identity authentication on the first quantum key distribution device.
[0019] In a possible embodiment, the quantum key distribution device further includes: a third generating unit, configured to generate the quantum-secure hybrid signature for the nth time, obtain the value of the nth bit in the fourth response; if the value of the nth bit is 1, generate a PQC signature; generate the nth quantum-secure hybrid signature based on the value of the nth bit, the PQC signature, the classical signature, and the original information; and if the nth bit is 0, generate the nth quantum-secure hybrid signature based on the value of the nth bit, the classical signature, and the original information; The first sending unit is used to send the n-th quantum secure hybrid signature to the second quantum key distribution device.
[0020] In a possible embodiment, the quantum key distribution device further includes: A first receiving unit is configured to receive a quantum secure hybrid signature sent by a second quantum key distribution device; The first verification unit is used to obtain the signature identification bit in the quantum-safe hybrid signature; if the signature identification bit is 1, the PQC public key and the classical signature public key in the quantum-safe certificate of the second quantum key distribution device are obtained to verify the quantum-safe hybrid signature; if the signature identification bit is 0, the classical signature public key in the quantum-safe certificate of the second quantum key distribution device is obtained to verify the quantum-safe hybrid signature.
[0021] In a possible embodiment, the quantum key distribution device further includes: The fourth generation unit is configured to delete the fourth challenge and the fourth response from the challenge-response list when all signature identification bits of the fourth response are used to generate a quantum-secure hybrid signature; and input a new fourth challenge into the PUF to generate a new fourth response.
[0022] In a fourth aspect, an embodiment of the present disclosure provides an authentication server, including: The second receiving unit is configured to receive a first security certificate request; the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key; The second sending unit is configured to generate and feed back a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in the public key main information portion of the first quantum security certificate; and the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.
[0023] In a possible embodiment, the authentication server further includes: A second receiving unit is configured to receive a first identity authentication request, the first identity authentication request including: a second identity authentication request message; the second identity authentication request message including: a second quantum security certificate of a second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; The second verification unit is used to perform multi-level verification. If the multi-level verification passes, it is determined that the second quantum key distribution device is compliant and the first verification pass information is sent.
[0024] In a fifth aspect, an embodiment of the present disclosure provides an electronic device comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the method in the above-mentioned first aspect by executing the executable instructions.
[0025] In a sixth aspect, an embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon, which implements the method in the first aspect when the computer program is executed by a processor.
[0026] In a seventh aspect, according to another aspect of the present disclosure, a computer program product or computer program is further provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform any of the above methods.
[0027] Embodiments of the present disclosure provide an identity authentication method and related devices, relating to the field of network security technology. The method comprises: inputting challenge information into a physically unclonable function (PUF) to generate a challenge-response list; the challenge-response list comprising: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, or a third challenge and a corresponding third response; generating a post-quantum cryptography (PQC) public key based on the second response; and / or generating a classical signature public key based on the third response; sending a first security certificate request to an authentication server; the first security certificate request comprising: the first challenge, a hash value of the first response, a PQC public key, and / or a classical signature public key; and receiving a first quantum security certificate for identity authentication from the authentication server. The unique response generated for each challenge using a PUF is unclonable, a truly random number, and highly random. It can be used to generate quantum security certificates for identity authentication, reducing the complexity of identity authentication and the workload of identity authentication between QKD devices.
[0028] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.
[0030] Figure 1 A schematic diagram of a channel in an embodiment of the present disclosure is shown; Figure 2 A schematic structural diagram of an identity authentication system according to an embodiment of the present disclosure is shown; Figure 3 A flow chart showing an identity authentication method according to an embodiment of the present disclosure is shown; Figure 4 A flowchart of generating a quantum-safe hybrid signature according to an embodiment of the present disclosure is shown; Figure 5 A flowchart for verifying a quantum-safe hybrid signature according to an embodiment of the present disclosure is shown; Figure 6 A flow chart showing another identity authentication method according to an embodiment of the present disclosure is shown; Figure 7 An interactive schematic diagram illustrating an identity authentication method in an embodiment of the present disclosure is shown; Figure 8 A schematic diagram showing the structure of a quantum key distribution device in an embodiment of the present disclosure is shown; Figure 9 A schematic diagram showing the structure of an authentication server in an embodiment of the present disclosure is shown; Figure 10 A schematic structural diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0031] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0032] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0033] The following are explanations of the terms used in the embodiments of the present disclosure: Quantum Key Distribution (QKD) uses the properties of quantum mechanics to ensure communication security, enabling both communicating parties to generate and share a random, secure key to encrypt and decrypt messages.
[0034] Post-quantum cryptography (PQC), also known as "quantum-resistant cryptography", is a new generation of cryptographic algorithms that can resist attacks by quantum computers on existing cryptographic algorithms. It is a key technology for maintaining network security in the quantum information age and an important part of combating the threat of quantum computers.
[0035] Physical Unclonable Functions (PUF) are an important type of hardware security technology that uses the inherent properties of silicon-based semiconductors to randomly extract unclonable physical features, similar to biological fingerprints, and serve as a unique identifier for each chip.
[0036] Among related technologies, the quantum key distribution protocol, based on the principles of quantum mechanics, can provide information-theoretic security and is an important development direction in the field of information security. The implementation of quantum key distribution includes quantum channels and classical channels. The former is used to transmit quantum states, and the latter is used to transmit information in the post-processing process of data. Figure 1 A schematic diagram of a channel in an embodiment of the present disclosure is shown in FIG. Figure 1 As shown, taking two QKD devices as an example, namely a QKD transmitter and a QKD receiver, an intermediate device may also be included.
[0037] The currently widely used classic channel identity authentication method is to pre-set a symmetric key before authentication, and both parties use the key to encrypt (sign) and decrypt (verify). This method has the following problems in practical applications: 1. To ensure the security of the key, the preset key is generally transmitted offline. For a QKD network with n users, key pre-setting is required between every two users, requiring a total of n(n-1) / 2 pairs of keys, which is very labor-intensive and highly complex.
[0038] 2. When a new QKD device joins the QKD network, the new QKD device needs to pre-set keys with all QKD devices in the original QKD network, which is a lot of work.
[0039] Based on this, after considering the problems in the related art, the present invention provides an identity authentication method and related equipment in the field of network security technology. The method includes: inputting challenge information into a physical unclonable function to generate a challenge-response list; the challenge-response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, a third challenge and a corresponding third response; generating a post-quantum cryptography (PQC) public key based on the second response; and / or generating a classical signature public key based on the third response; sending a first security certificate request to an authentication server; the first security certificate request includes: the first challenge, a hash value of the first response, a PQC public key, and / or a classical signature public key; and receiving a first quantum security certificate for identity authentication from the authentication server. The unique response generated by the PUF for each challenge is unclonable, a truly random number, and has strong randomness. It can be used to generate quantum security certificates for identity authentication, reducing the complexity of identity authentication and the workload of identity authentication between QKD devices.
[0040] Figure 2 FIG. 1 shows a schematic diagram of the structure of an identity authentication system in an embodiment of the present disclosure. Figure 2 As shown, the identity authentication system 100 may include: a first QKD device 101, a second QKD device 102 and an authentication server 103.
[0041] The first QKD device 101 and the second QKD device 102 can both serve as a transmitter or a receiver, which is not limited in the embodiments of the present disclosure. The authentication server 103 can be deployed in a certificate issuing center.
[0042] Those skilled in the art will know that Figure 1 The number of QKD devices and authentication servers 103 is merely illustrative, and any number of QKD devices and authentication servers may be provided as needed. This disclosure does not limit this.
[0043] This exemplary implementation is described in detail below with reference to the accompanying drawings and examples.
[0044] The present disclosure provides an identity authentication method that can be applied to a first QKD device. Figure 3 A flow chart of an identity authentication method according to an embodiment of the present disclosure is shown as follows: Figure 3 As shown, the identity authentication method provided in the embodiment of the present disclosure includes the following steps: S302: Input challenge information to the physical unclonable function to generate a challenge response list, where the challenge response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, and a third challenge and a corresponding third response.
[0045] In one possible embodiment, PUFs work by implementing challenge-response authentication. For a given PUF, a specific input, called a "challenge," produces an output response, known as a challenge-response. This output response is unique to the specific PUF and therefore unclonable. The challenge is the raw binary value asserted to the DRAM / SRAM cell array, while the response is the value of the array after a given time interval. This technology can be used to generate truly random numbers, and the output response can be used for cryptographic key generation or as a device identifier for device identification and anti-counterfeiting protection.
[0046] In a possible embodiment, the challenge information in the embodiment of the present disclosure may be a random number, and the input challenge information may include a first challenge, a second challenge and / or a third challenge. One or both of the second challenge and the third challenge may be input.
[0047] In a possible embodiment, the first challenge and the first response are used to identify the first quantum key distribution device; the second challenge and the second response are used as random numbers for PQC signatures to participate in key generation; and the third challenge and the third response are used as random numbers for classical signatures to participate in key generation.
[0048] S304: Generate a post-quantum cryptography PQC public key based on the second response, and / or generate a classical signature public key based on the third response.
[0049] In a possible embodiment, a PQC public key may be generated based on the value of the second response.
[0050] In a possible embodiment, a classic signature public key may be generated based on the value of the third response, wherein the classic signature algorithm takes ECDSA as an example.
[0051] S306: Send a first security certificate request to the authentication server, where the first security certificate request includes: a first challenge, a hash value of the first response, a PQC public key, and / or a classic signature public key.
[0052] In a possible embodiment, the first security certificate request includes: a first challenge, a hash value of the first response, and a PQC public key.
[0053] In a possible embodiment, the first security certificate request includes: a first challenge, a hash value of the first response, and a classic signature public key.
[0054] In a possible embodiment, the first security certificate request includes: a first challenge, a hash value of the first response, a PQC public key, and a classic signature public key.
[0055] S308: Receive the first quantum security certificate for identity authentication fed back by the authentication server.
[0056] Through the above method, the first response, second response and third response output by PUF are used as the basis for constructing keys and performing identity authentication, and a quantum security certificate is requested from the authentication server of the authentication center. When identity authentication is required between multiple QKD devices, the authentication can be completed through the quantum security certificate. There is no need to perform identity authentication through pre-set keys, which reduces the complexity of identity authentication and the workload of identity authentication between quantum key distribution devices. For new QKD devices, quantum security certificates can also be obtained from the authentication server of the authentication center to complete identity authentication.
[0057] In a possible embodiment, the challenge response list may be as shown in Table 1 below.
[0058] Table 1
[0059] In a possible embodiment, the challenge-response list further includes: a fourth challenge and a corresponding fourth response; the value in the fourth response is used as a signature identification bit in the quantum-secure hybrid signature; the quantum-secure hybrid signature includes: a classical signature and a PQC signature.
[0060] In a possible embodiment, the challenge response list may be as shown in Table 2 below.
[0061] Table 2
[0062] Since the PQC signature size is large, if quantum-secure hybrid signatures are used when transmitting basis vector comparison, error correction information, and other information over classical channels, the resources required are too large. To address this problem, the inventors have proposed the following method, taking the first quantum key distribution device as the transmitter to generate a quantum-secure hybrid signature as an example: Figure 4 A flow chart of generating a quantum-safe hybrid signature in an embodiment of the present disclosure is shown. Figure 4 As shown, the following steps are included: S402: For the nth generation of the quantum-secure hybrid signature, obtain the value of the nth bit in the fourth response.
[0063] S404: If the value of the nth bit is 1, a PQC signature is generated.
[0064] S406: Generate an n-th quantum secure hybrid signature based on the value of the n-th bit, the PQC signature, the classical signature, and the original information.
[0065] S408: If the nth bit is 0, generate the nth quantum secure hybrid signature based on the value of the nth bit, the classical signature and the original information.
[0066] S410: Send the nth quantum secure hybrid signature to the second quantum key distribution device.
[0067] In one possible embodiment, each bit of the fourth response value identifies a signature flag, where 0 represents not using a PQC signature and 1 represents using a PQC signature. The signature flag is shifted one bit with each communication until the value of the fourth response is exhausted. If the signature flag is 1, a PQC signature is performed on the hash value to generate a quantum-safe hybrid signature. If the signature flag is 0, a PQC signature is not performed, and a quantum-safe hybrid signature is generated based on the classical signature.
[0068] In a possible embodiment, the function represented by the value of the fourth response is represented by Table 3, as shown in Table 3 below: Table 3
[0069] In a possible embodiment, taking the signature identification bit as 1 as an example, the quantum secure hybrid signature is: signature identification bit (1) + M (original information) + signature (PQC signature + classical signature).
[0070] In a possible embodiment, taking the signature identification bit as 0 as an example, the quantum secure hybrid signature is: signature identification bit (0) + M (original information) + signature (classical signature).
[0071] In a possible embodiment, when the receiver receives the quantum-safe hybrid signature, the receiver verifies the quantum-safe hybrid signature to determine whether the received data is compliant. The first quantum key distribution device is used as the receiving end. Figure 5 A flow chart of verifying a quantum-safe hybrid signature in an embodiment of the present disclosure is shown. Figure 5 As shown, the following steps are included: S502: Receive the quantum secure hybrid signature sent by the second quantum key distribution device.
[0072] S504: Obtain the signature identification bit in the quantum secure hybrid signature.
[0073] S506: If the signature flag is 1, obtain the PQC public key and the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum security hybrid signature.
[0074] S508: If the signature flag is 0, obtain the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum security hybrid signature.
[0075] In one possible embodiment, the receiving end determines whether a PQC signature is included based on the signature identification bit. If the value of the signature identification bit is 0, that is, the PQC signature is not included, the signature is verified based on the classical signature public key in the quantum security certificate. If the value of the signature identification bit is 1, the PQC public key and the classical signature public key in the quantum security certificate are extracted respectively to verify the quantum security hybrid signature. If both pass, it means that the data is compliant and legal.
[0076] In a possible embodiment, when all signature identification bits of the fourth response are used to generate a quantum-secure hybrid signature, the fourth challenge and the fourth response are deleted from the challenge-response list; a new fourth challenge is input to the PUF to generate a new fourth response.
[0077] Exemplarily, each bit of the fourth response is used to generate a quantum-secure hybrid signature once. Taking 256 random binary values as an example, after generating the quantum-secure hybrid signature 256 times, the value of the fourth response is exhausted. In this case, the fourth challenge and the value of the fourth response are deleted from the challenge-response list, and a new fourth challenge is re-input into the PUF to generate a new fourth response value as the signature identification bit.
[0078] Through the above method, the device only needs to periodically update the values in a list, which can reduce the resource consumption when transmitting basis vector comparison, error correction information and other information in the classical channel. The response generated by PUF is highly random, and security is effectively improved.
[0079] It should be noted that the new fourth challenge and the deleted fourth challenge can be the same or different. This is not limited in the embodiment of the present disclosure. The input challenge information is a random number. If it is limited to be different, the challenge information of the new fourth challenge needs to be judged. The increase in the judgment process will improve the processing flow. If there is no limit on whether they are the same, the processing flow can be streamlined and the operation can be simplified.
[0080] In a possible embodiment, it may be stipulated that the new fourth challenge must be different from the deleted fourth challenge, so as to improve the randomness of the value of the subsequent new fourth response and improve the security of the quantum-safe hybrid signature.
[0081] In a possible embodiment, after obtaining the quantum security certificate, identity authentication is performed with other QKD devices. Identity authentication between QKD devices requires mutual authentication between both parties and completion of identity compliance verification.
[0082] As the sending end, the first QKD device can perform the following steps: construct a first identity authentication request message based on the hash value of the first quantum security certificate, the first challenge and the corresponding first response; send the first identity authentication request message to the second quantum key distribution device, so that the second quantum key distribution device can authenticate the first quantum key distribution device.
[0083] The first QKD device acts as a receiving end, receives the authentication request message sent by the second QKD device, and submits the authentication request to the authentication center. The following steps can be performed: receiving the second identity authentication request message sent by the second quantum key distribution device; the second identity authentication request message includes: the second quantum security certificate of the second quantum key distribution device, the fifth challenge and the hash value of the corresponding fifth response; the fifth response is used to identify the second quantum key distribution device; sending the first identity authentication request to the authentication server, the first identity authentication request includes: the second identity authentication request message; receiving the first verification pass information.
[0084] Another identity authentication method is provided in the embodiment of the present disclosure and can be applied to the authentication server. Figure 6 A flow chart of an identity authentication method according to an embodiment of the present disclosure is shown as follows: Figure 6 As shown, the identity authentication method provided in the embodiment of the present disclosure includes the following steps: S602: Receive a first security certificate request, where the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key, and / or a classic signature public key.
[0085] S604: Generate and feedback a first quantum security certificate, wherein the PQC public key and / or the classical signature public key are concatenated in the public key body information portion of the first quantum security certificate, and the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.
[0086] In one possible embodiment, the authentication server of the authentication center can concatenate the classical signature with the first 256 bits of the PQC signature in the final signature part of the certificate to generate a quantum secure certificate.
[0087] Through the above method, the issuance of quantum security certificates is completed. When identity authentication is required between multiple QKD devices, the authentication can be completed through the quantum security certificate. There is no need to perform identity authentication through pre-set keys, which reduces the complexity of identity authentication and the workload of identity authentication between quantum key distribution devices. For new QKD devices, quantum security certificates can also be obtained from the authentication server of the authentication center to complete identity authentication.
[0088] In a possible embodiment, when the authentication server of the authentication center receives an identity authentication request, the following steps may be performed: receiving a first identity authentication request, the first identity authentication request including: a second identity authentication request message; the second identity authentication request message including: a second quantum security certificate of a second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; performing multi-level verification, and if the multi-level verification passes, determining that the second quantum key distribution device is compliant, and sending a first verification pass message.
[0089] In a possible embodiment, the authentication server of the authentication center may maintain a correspondence list to ensure a correspondence list between the QKD device, challenge, response and quantum security certificate, as shown in Table 4 below.
[0090] Table 4
[0091] Verification can be completed using a multi-level verification approach to determine the compliance of the QKD device and inform the corresponding QKD device.
[0092] In a possible embodiment, the multi-level verification method may include multiple verification methods, which are illustrated by the following two verification methods.
[0093] Exemplarily, according to the fifth challenge, the verification hash value stored in the authentication server is queried; and verification is performed according to the verification hash value and the fifth response in the second identity authentication request message.
[0094] Exemplarily, verification is performed based on the second quantum security certificate in the second identity authentication request message and the verification certificate stored in the authentication server.
[0095] The above two verification methods do not limit the specific execution order.
[0096] In a possible embodiment, the verification hash value stored in the authentication server can be queried based on the fifth challenge; verification is performed based on the verification hash value and the fifth response in the second identity authentication request message. If the first-level verification passes, verification is performed based on the second quantum security certificate in the second identity authentication request message and the verification certificate stored in the authentication server to complete multi-level verification.
[0097] If the first level verification fails, it means that the QKD device authentication based on the response output by the PUF has failed, and the verification based on the quantum security certificate will no longer proceed.
[0098] In one possible embodiment, Figure 7 An interactive diagram of an identity authentication method in an embodiment of the present disclosure is shown. Figure 7 As shown, the following steps are included: S702: The first QKD device sends a first security certificate request to the authentication server, where the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key.
[0099] S704: The authentication server generates a first quantum security certificate, and concatenates the PQC public key and / or the classical signature public key in the public key body information portion of the first quantum security certificate; the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.
[0100] S706: The authentication server sends a first quantum security certificate to the first QKD device.
[0101] S708: The second QKD device sends a second security certificate request to the authentication server.
[0102] S710: The authentication server generates a second quantum security certificate.
[0103] S712: The authentication server sends a second quantum security certificate to the second QKD device.
[0104] S714: The first QKD device constructs a first identity authentication request message according to the hash value of the first quantum security certificate, the first challenge and the corresponding first response.
[0105] In a possible embodiment, the first identity authentication request message may be M1 as an example, where M1 = first challenge + Hash (first response) + first quantum security certificate.
[0106] S716: The first QKD device sends a first identity authentication request message to the second QKD device.
[0107] S718: The second QKD device sends a second identity authentication request to the authentication server, where the second identity authentication request includes: a first identity authentication request message.
[0108] S720: The authentication server sends second verification pass information to the second QKD device.
[0109] S722: The second QKD device constructs a second identity authentication request message according to the hash value of the second quantum security certificate, the fifth challenge and the corresponding fifth response.
[0110] In a possible embodiment, the second identity authentication request message may be M2 as an example, where M2=fifth challenge+Hash (fifth response)+second quantum security certificate.
[0111] S724: The second QKD device sends a second identity authentication request message to the first QKD device.
[0112] S726: The first QKD device sends a first identity authentication request to the authentication server, where the first identity authentication request includes: a second identity authentication request message.
[0113] S728: The authentication server sends first verification pass information to the first QKD device.
[0114] Through the above method, the identity authentication of different QKD devices is completed. During the entire authentication process, there is no need to pre-set a large number of keys for authentication, which reduces the difficulty of identity authentication and key management in complex QKD networks and improves scalability. When new QKD devices are connected to the QKD network, the above method can also be used to reduce the complexity of identity authentication and reduce the workload of identity authentication between quantum key distribution devices.
[0115] Based on the same inventive concept, the present disclosure also provides a quantum key distribution device and authentication server, as shown in the following embodiment. Since the principles of this embodiment are similar to those of the above-mentioned method embodiment, the implementation of this embodiment can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated here.
[0116] Figure 8 A schematic diagram of the structure of a quantum key distribution device according to an embodiment of the present disclosure is shown. Figure 8As shown, the quantum key distribution device 80 includes: a first generation unit 801, used to input a challenge to a physical unclonable function to generate a challenge-response list; the challenge-response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, a third challenge and a corresponding third response; a second generation unit 802, used to generate a post-quantum cryptography PQC public key according to the second response; and / or, based on the third response, generate a classical signature public key; a first sending unit 803, used to send a first security certificate request to an authentication server; the first security certificate request includes: the first challenge, a hash value of the first response, a PQC public key and / or a classical signature public key; a first receiving unit 804, used to receive a first quantum security certificate for identity authentication fed back by the authentication server.
[0117] Figure 9 A schematic diagram of the structure of an authentication server in an embodiment of the present disclosure is shown. Figure 9 As shown, the authentication server 90 includes: a second receiving unit 901, configured to receive a first security certificate request; the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classical signature public key; a second sending unit 902, configured to generate and feedback a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in the public key body information portion of the first quantum security certificate; and the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.
[0118] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods, or program products. Therefore, various aspects of the present disclosure may be implemented in the following forms: entirely in hardware, entirely in software (including firmware, microcode, etc.), or in a combination of hardware and software, collectively referred to herein as "circuits," "modules," or "systems."
[0119] Refer to the following Figure 10 1000 according to this embodiment of the present disclosure will be described. Figure 10 The electronic device 1000 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0120] like Figure 10 As shown, electronic device 1000 is implemented as a general-purpose computing device. Components of electronic device 1000 may include, but are not limited to, the aforementioned at least one processing unit 1010, the aforementioned at least one storage unit 1020, and a bus 1030 connecting various system components (including storage unit 1020 and processing unit 1010).
[0121] The storage unit stores program code, which can be executed by the processing unit 1010, so that the processing unit 1010 performs the steps of various exemplary embodiments of the present disclosure described in the "Exemplary Methods" section above. For example, the processing unit 1010 can perform the steps of any of the above method embodiments.
[0122] The storage unit 1020 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 10201 and / or a cache memory unit 10202 , and may further include a read-only memory unit (ROM) 10203 .
[0123] The storage unit 1020 may also include a program / utility 10204 having a set (at least one) of program modules 10205, such program modules 10205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0124] Bus 1030 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.
[0125] Electronic device 1000 may also communicate with one or more external devices 1040 (e.g., a keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with electronic device 1000, and / or any device that enables electronic device 1000 to communicate with one or more other computing devices (e.g., a router, modem, etc.). This communication may occur via input / output (I / O) interface 1050. Furthermore, electronic device 1000 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via network adapter 1060. As shown, network adapter 1060 communicates with other modules of electronic device 1000 via bus 1030. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with electronic device 1000, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0126] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, terminal device, or network device) to execute the methods according to the embodiments of the present disclosure.
[0127] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods of the above embodiments.
[0128] In an exemplary embodiment of the present disclosure, a computer-readable storage medium is also provided. The computer-readable storage medium may be a readable signal medium or a readable storage medium. A program product capable of implementing the above-mentioned method of the present disclosure is stored thereon. In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product, which includes program code. When the program product is executed on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Methods" section above of this specification.
[0129] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0130] In the present disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0131] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.
[0132] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, and conventional procedural programming languages such as C or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0133] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.
[0134] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.
[0135] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, mobile terminal, or network device) to execute the methods according to the embodiments of the present disclosure.
[0136] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.
Claims
1. An identity authentication method, characterized in that: Applied to a first quantum key distribution device, the method includes: Inputting challenge information into a physical unclonable function to generate a challenge-response list; the challenge-response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, and a third challenge and a corresponding third response; generating a post-quantum cryptography (PQC) public key based on the second response; and / or generating a classical signature public key based on the third response; Sending a first security certificate request to the authentication server; the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key; Receive a first quantum security certificate for identity authentication fed back by the authentication server.
2. The method according to claim 1, characterized in that The method further comprises: Constructing a first identity authentication request message according to the first quantum security certificate, the first challenge, and the hash value of the corresponding first response; The first identity authentication request message is sent to a second quantum key distribution device, so that the second quantum key distribution device performs identity authentication on the first quantum key distribution device.
3. The method according to claim 1, characterized in that The method further comprises: Receive a second identity authentication request message sent by a second quantum key distribution device; the second identity authentication request message includes: a second quantum security certificate of the second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; the fifth response is used to identify the second quantum key distribution device; Sending a first identity authentication request to the authentication server, wherein the first identity authentication request includes: a second identity authentication request message; Receive first verification success information.
4. The method according to claim 1, wherein The challenge-response list also includes: a fourth challenge and a corresponding fourth response; the value in the fourth response is used as a signature identification bit in the quantum-safe hybrid signature; the quantum-safe hybrid signature includes: a classical signature and a PQC signature; The method further comprises: For the nth generation of the quantum-secure hybrid signature, obtain a value of the nth bit in the fourth response; If the value of the nth bit is 1, the PQC signature is generated; Generate an n-th quantum-secure hybrid signature based on the value of the n-th bit, the PQC signature, the classical signature, and the original information; If the nth bit is 0, generating an nth quantum-secure hybrid signature based on the value of the nth bit, the classical signature, and the original information; The n-th quantum secure hybrid signature is sent to the second quantum key distribution device.
5. The method according to claim 1, wherein The method further comprises: receiving a quantum secure hybrid signature sent by a second quantum key distribution device; Obtaining a signature identification bit in the quantum secure hybrid signature; If the signature flag is 1, obtaining the PQC public key and the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum security hybrid signature; If the signature flag is 0, the classical signature public key in the quantum security certificate of the second quantum key distribution device is obtained to verify the quantum security hybrid signature.
6. The method according to claim 4, characterized in that The method further comprises: When all signature identification bits of the fourth response are used to generate the quantum-secure hybrid signature, deleting the fourth challenge and the fourth response from the challenge-response list; A new fourth challenge is input to the PUF to generate a new fourth response.
7. The method according to claim 1, characterized in that The challenge information input into the physical unclonable function is a random number.
8. The method according to claim 1, characterized in that The first challenge and the first response are used to identify the first quantum key distribution device; the second challenge and the second response are used as random numbers for PQC signature participation in key generation; and the third challenge and the third response are used as random numbers for classical signature participation in key generation.
9. An identity authentication method, characterized in that: Applied to an authentication server, the method includes: Receive a first security certificate request; the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key; Generate and feedback a first quantum security certificate; wherein, the PQC public key and / or the classical signature public key are concatenated in the public key body information portion of the first quantum security certificate; and the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.
10. The method according to claim 9, characterized in that The method further comprises: Receive a first identity authentication request, the first identity authentication request including: a second identity authentication request message; the second identity authentication request message including: a second quantum security certificate of a second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; Perform multi-level verification. If the multi-level verification passes, it is determined that the second quantum key distribution device is compliant and the first verification pass information is sent.
11. The method according to claim 10, characterized in that The multi-level verification includes: Performing verification based on the second quantum security certificate in the second identity authentication request message and the verification certificate stored in the authentication server; and, based on the fifth challenge, querying the verification hash value stored in the authentication server; Verification is performed based on the verification hash value and a fifth response in the second identity authentication request message.
12. A quantum key distribution device, characterized in that: include: a first generating unit, configured to input a challenge into a physical unclonable function and generate a challenge-response list; The challenge-response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, a third challenge and a corresponding third response; A second generating unit is configured to generate a post-quantum cryptography PQC public key according to the second response; and / or generate a classical signature public key according to the third response; A first sending unit is configured to send a first security certificate request to an authentication server; the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key; The first receiving unit is configured to receive a first quantum security certificate for identity authentication fed back by the authentication server.
13. An authentication server, characterized in that: include: A second receiving unit, configured to receive a first security certificate request; The first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key; The second sending unit is configured to generate and feed back a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in the public key body information portion of the first quantum security certificate; and the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.
14. An electronic device, characterized in that: include: processor; as well as a memory for storing executable instructions of the processor; The processor is configured to perform the method according to any one of claims 1 to 11 by executing the executable instructions.
15. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 11 is implemented.
16. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the method according to any one of claims 1 to 11.
Citation Information
Patent Citations
Use of puf for checking authentication, in particular for protecting against unauthorized access to function of ic or control device
CN104782076A
Lightweight identity authentication method based on physical unclonable function
CN113282898A
Fuzzy extractor working method based on rounding error correction algorithm
CN117931504A
Multi-mode challenge response identity authentication method and system based on PUF (Physical Unclonable Function)
CN120263420A
IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key
CN120281485A
Cited By
Remote access handshake method, device and equipment based on double anti-quantum protection and medium
CN121984679A