Identity authentication method and related device

By using a physical unclonable function in a quantum key distribution device to generate a challenge-response list and a public key, and requesting a quantum security certificate from an authentication server, the problem of high complexity in identity authentication of quantum key distribution devices in complex networks is solved, achieving lower workload and higher scalability.

CN120602103BActive Publication Date: 2025-10-24CHINA TELECOM CORP LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511087484.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-10-24
Estimated Expiration
2045-08-04

AI Technical Summary

Technical Problem

The identity authentication of quantum key distribution devices in complex networks is highly complex and labor-intensive, especially when new devices are connected, keys need to be pre-set with all devices, resulting in poor scalability.

Method used

A physical unclonable function is used to generate a challenge-response list, generate a post-quantum cryptography PQC public key and a classical signature public key, request a quantum security certificate from the authentication server, and use the unclonable response of PUF for identity authentication, reducing key pre-setting.

Benefits of technology

It reduces the complexity of identity authentication between quantum key distribution devices, reduces workload, and improves the scalability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602103B_ABST
    Figure CN120602103B_ABST
Patent Text Reader

Abstract

The present disclosure provides an identity authentication method and related equipment, and relates to the technical field of network security. The method comprises the following steps: inputting challenge information into a physically unclonable function, generating a challenge response list, generating a post-quantum cryptography (PQC) public key according to a second response, and / or generating a classical signature public key according to a third response, sending a first security certificate request to an authentication server, wherein the first security certificate request comprises a first challenge, a hash value of a first response, a PQC public key and / or a classical signature public key, and receiving a first quantum security certificate for identity authentication fed back by the authentication server. The physically unclonable function is used to generate a unique response for each challenge. The unique response is unclonable, belongs to a real random number, has strong randomness, can be used to generate a quantum security certificate for identity authentication, reduces the complexity of identity authentication, and reduces the workload of identity authentication between quantum key distribution devices.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of network security, and in particular, to an identity authentication method and related devices. BACKGROUND

[0002] A quantum key distribution (QKD) device cannot authenticate the identity of a transmission source, and still needs to prestore a large number of keys to solve the authentication problem. For a QKD network of n users, keys need to be pre-stored between each pair of users, a total of n(n-1) / 2 pairs of keys, which greatly increases the difficulty of identity authentication and key management in a complex QKD network, and has poor scalability. When a QKD user accesses a QKD network, it also needs to pre-store keys with all other QKD devices, and the identity authentication is complex and the workload is large.

[0003] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY

[0004] The present disclosure provides an identity authentication method and related devices, which at least partially solves the problem of high complexity and large workload of identity authentication between QKD devices in the related art.

[0005] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.

[0006] In a first aspect, the embodiments in the present disclosure provide an identity authentication method, applied to a first quantum key distribution device, and the method comprises:

[0007] inputting challenge information to a physically unclonable function to generate a challenge response list; the challenge response list comprises: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, a third challenge and a corresponding third response;

[0008] generating a post-quantum cryptography (PQC) public key according to the second response; and / or generating a classical signature public key according to the third response;

[0009] sending a first security certificate request to an authentication server; the first security certificate request comprises: the first challenge, a hash value of the first response, the PQC public key and / or the classical signature public key;

[0010] receiving a first quantum security certificate for identity authentication fed back by the authentication server.

[0011] In a possible embodiment, the challenge information input to the physically unclonable function is a random number.

[0012] In a possible implementation, the method further includes:

[0013] constructing a first identity authentication request message according to the first quantum security certificate, the first challenge, and the hash value of the corresponding first response;

[0014] sending the first identity authentication request message to the second quantum key distribution device to enable the second quantum key distribution device to perform identity authentication on the first quantum key distribution device.

[0015] In a possible implementation, the method further includes:

[0016] receiving a second identity authentication request message sent by the second quantum key distribution device; the second identity authentication request message includes a second quantum security certificate of the second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; the fifth response is used to identify the second quantum key distribution device;

[0017] sending a first identity verification request to the authentication server, the first identity verification request including the second identity authentication request message;

[0018] receiving first verification pass information.

[0019] In a possible implementation, the challenge-response list further includes a fourth challenge and a corresponding fourth response; a value in the fourth response is used as a signature identification bit in a quantum security hybrid signature; the quantum security hybrid signature includes a classical signature and a PQC signature.

[0020] The method further includes:

[0021] for the nth time, obtaining a value of an nth bit in the fourth response to generate a quantum security hybrid signature;

[0022] if the value of the nth bit is 1, generating a PQC signature;

[0023] generating the nth quantum security hybrid signature according to the value of the nth bit, the PQC signature, the classical signature, and the original information;

[0024] if the nth bit is 0, generating the nth quantum security hybrid signature according to the value of the nth bit, the classical signature, and the original information;

[0025] sending the nth quantum security hybrid signature to the second quantum key distribution device.

[0026] In a possible implementation, the method further includes:

[0027] receiving a quantum security hybrid signature sent by the second quantum key distribution device;

[0028] Obtaining a signature identification bit in the quantum secure hybrid signature;

[0029] If the signature identification bit is 1, obtaining the PQC public key and the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum secure hybrid signature;

[0030] If the signature identification bit is 0, obtaining the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum secure hybrid signature.

[0031] In a possible embodiment, the method further comprises:

[0032] When all the signature identification bits of the fourth response are used to generate the quantum secure hybrid signature, deleting the fourth challenge and the fourth response in the challenge response list;

[0033] Inputting a new fourth challenge to the PUF to generate a new fourth response.

[0034] In a possible embodiment, the first challenge and the first response are used to identify the first quantum key distribution device; the second challenge and the second response are used as random numbers participating in key generation of the PQC signature; and the third challenge and the third response are used as random numbers participating in key generation of the classical signature.

[0035] In a second aspect, the embodiments in the present disclosure provide an identity authentication method, applied to an authentication server, and the method comprises:

[0036] Receiving a first security certificate request; the first security certificate request comprises a first challenge, a hash value of a first response, a PQC public key and / or a classical signature public key;

[0037] Generating and feeding back a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in the public key subject information part of the first quantum security certificate; and the certificate signature of the first quantum security certificate comprises a classical signature and a PQC signature.

[0038] In a possible embodiment, the method further comprises:

[0039] Receiving a first identity verification request, and the first identity verification request comprises a second identity authentication request message; the second identity authentication request message comprises a second quantum security certificate of a second quantum key distribution device, a fifth challenge and a hash value of a corresponding fifth response;

[0040] Performing multi-level verification, and if the multi-level verification is passed, determining that the second quantum key distribution device is compliant, and sending first verification pass information.

[0041] In a possible embodiment, performing multi-level verification comprises:

[0042] verify the second quantum security certificate in the second identity authentication request message with the verification certificate stored in the authentication server;

[0043] and, according to the fifth challenge, query the verification hash value stored in the authentication server;

[0044] verify the verification hash value with the fifth response in the second identity authentication request message.

[0045] In a third aspect, the embodiments in the present disclosure provide a quantum key distribution device, comprising:

[0046] a first generating unit configured to input a challenge to a physically unclonable function and generate a challenge response list; the challenge response list comprises: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, and a third challenge and a corresponding third response;

[0047] a second generating unit configured to generate a post-quantum cryptography (PQC) public key according to the second response, and / or generate a classical signature public key according to the third response;

[0048] a first sending unit configured to send a first security certificate request to an authentication server; the first security certificate request comprises: the first challenge, a hash value of the first response, the PQC public key, and / or the classical signature public key;

[0049] The first receiving unit is further configured to receive a first quantum security certificate for identity authentication fed back by the authentication server.

[0050] In a possible embodiment, the quantum key distribution device further comprises:

[0051] a constructing unit configured to construct a first identity authentication request message according to the first quantum security certificate, the first challenge, and the hash value of the corresponding first response;

[0052] The first sending unit is further configured to send the first identity authentication request message to a second quantum key distribution device, so that the second quantum key distribution device performs identity authentication on the first quantum key distribution device.

[0053] In a possible embodiment, the quantum key distribution device further comprises:

[0054] a third generating unit configured to obtain a value of an nth bit in the fourth response for generating a quantum security hybrid signature for the nth time; if the value of the nth bit is 1, generate a PQC signature; generate a quantum security hybrid signature for the nth time according to the value of the nth bit, the PQC signature, a classical signature, and original information; if the nth bit is 0, generate a quantum security hybrid signature for the nth time according to the value of the nth bit, the classical signature, and the original information;

[0055] The first sending unit is configured to send the nth quantum secure hybrid signature to the second quantum key distribution device.

[0056] In a possible embodiment, the quantum key distribution device further includes:

[0057] The first receiving unit is configured to receive the quantum secure hybrid signature sent by the second quantum key distribution device.

[0058] The first verification unit is configured to acquire a signature identification bit in the quantum secure hybrid signature; if the signature identification bit is 1, the quantum secure hybrid signature is verified by using a PQC public key and a classical signature public key in a quantum secure certificate of the second quantum key distribution device; if the signature identification bit is 0, the quantum secure hybrid signature is verified by using the classical signature public key in the quantum secure certificate of the second quantum key distribution device.

[0059] In a possible embodiment, the quantum key distribution device further includes:

[0060] The fourth generating unit is configured to, when all signature identification bits of the fourth response are used to generate the quantum secure hybrid signature, delete the fourth challenge and the fourth response in the challenge response list; input a new fourth challenge to the PUF to generate a new fourth response.

[0061] In a fourth aspect, the embodiments in the present disclosure provide an authentication server, including:

[0062] The second receiving unit is configured to receive a first security certificate request; the first security certificate request includes a first challenge, a hash value of a first response, a PQC public key and / or a classical signature public key.

[0063] The second sending unit is configured to generate and feed back a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in a public key subject information part of the first quantum security certificate; a certificate signature of the first quantum security certificate includes a classical signature and a PQC signature.

[0064] In a possible embodiment, the authentication server further includes:

[0065] The second receiving unit is configured to receive a first identity verification request, and the first identity verification request includes a second identity authentication request message; the second identity authentication request message includes a second quantum security certificate of the second quantum key distribution device, a fifth challenge and a hash value of a corresponding fifth response.

[0066] The second verification unit is configured to perform multi-level verification, and if the multi-level verification is passed, it is determined that the second quantum key distribution device is compliant, and first verification passing information is sent.

[0067] In a fifth aspect, the embodiments in the present disclosure provide an electronic device, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the method in the first aspect above via execution of the executable instructions.

[0068] In a sixth aspect, the embodiments in the present disclosure provide a computer-readable storage medium having stored thereon a computer program, the computer program being executed by a processor to implement the method in the first aspect above.

[0069] In a seventh aspect, according to another aspect of the present disclosure, a computer program product or computer program is also provided, the computer program product or computer program comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the method of any one of the above aspects.

[0070] The identity authentication method and related device provided by the embodiments of the present disclosure relate to the technical field of network security, and the method comprises: inputting challenge information to a physically unclonable function (PUF) to generate a challenge response list; the challenge response list comprises: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, and a third challenge and a corresponding third response; generating a post-quantum cryptography (PQC) public key according to the second response; and / or generating a classical signature public key according to the third response; sending a first security certificate request to an authentication server; the first security certificate request comprises: the first challenge, a hash value of the first response, the PQC public key, and / or the classical signature public key; and receiving a first quantum security certificate for identity authentication fed back by the authentication server. The unique response of each challenge generated by the PUF is unclonable, belongs to a real random number, has strong randomness, can be used to generate a quantum security certificate for identity authentication, reduces the complexity of identity authentication, and reduces the workload of identity authentication between QKD devices.

[0071] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0072] The drawings herein are incorporated into the specification and form a part of the specification, show embodiments consistent with the present disclosure, and together with the specification serve to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0073] Figure 1 A channel schematic diagram in the embodiments of the present disclosure is shown;

[0074] Figure 2 Fig. 1 shows a structural schematic diagram of an identity authentication system in an embodiment of the present disclosure;

[0075] Figure 3 Fig. 2 shows a flowchart of an identity authentication method in an embodiment of the present disclosure;

[0076] Figure 4 Fig. 3 shows a flowchart of generating a quantum secure hybrid signature in an embodiment of the present disclosure;

[0077] Figure 5 Fig. 4 shows a flowchart of verifying a quantum secure hybrid signature in an embodiment of the present disclosure;

[0078] Figure 6 Fig. 5 shows a flowchart of another identity authentication method in an embodiment of the present disclosure;

[0079] Figure 7 Fig. 6 shows an interaction schematic diagram of an identity authentication method in an embodiment of the present disclosure;

[0080] Figure 8 Fig. 7 shows a structural schematic diagram of a quantum key distribution device in an embodiment of the present disclosure;

[0081] Figure 9 Fig. 8 shows a structural schematic diagram of an authentication server in an embodiment of the present disclosure;

[0082] Figure 10 Fig. 9 shows a structural schematic diagram of an electronic device in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0083] Example implementations will now be described with reference to the drawings; however, example implementations can be implemented in many different forms and should not be construed as being limited to the examples set forth herein; rather, these implementations are provided so that the disclosure will be thorough and complete, and will fully convey the concept of example implementations to those skilled in the art. The described features, structures, or characteristics can be combined in one or more implementations in any suitable form.

[0084] In addition, the accompanying drawings are only schematic and are not necessarily drawn to scale. Identical components have been given the same reference numerals in the various drawings and the description, and so repeated descriptions of these components will be omitted. Some of the blocks in the drawings are functional blocks, and can not necessarily correspond to physical or logical entities. These functional blocks can be implemented in software, or in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0085] The terms in the embodiments of the present disclosure are explained and described, including:

[0086] Quantum Key Distribution (QKD) is to use quantum mechanics to ensure the security of communication, which enables both parties of communication to generate and share a random, secure key to encrypt and decrypt messages.

[0087] Post Quantum Cryptography (PQC), also known as "quantum-resistant cryptography", is a new generation of cryptographic algorithm that can resist quantum computer attacks on existing cryptographic algorithms. It is a key technology for maintaining network security in the quantum information era and an important part of resisting quantum computer threats.

[0088] Physical Unclonable Functions (PUF) is an important hardware security technology that uses the inherent properties of silicon-based semiconductors to extract unclonable physical features randomly. It is similar to a biological fingerprint and is a unique identifier for each chip.

[0089] In related technologies, the quantum key distribution protocol can provide information-theoretic security based on quantum mechanics, and is an important development direction in the field of information security. The implementation of quantum key distribution includes a quantum channel and a classical channel. The former is used to transmit quantum states, and the latter is used to transmit information in the data post-processing process, Figure 1 A channel diagram in the embodiment of the present disclosure is shown, as Figure 1 shown, taking two QKD devices as an example, the QKD sending end and the QKD receiving end can also include intermediate devices.

[0090] The commonly used classical channel identity authentication method is to preset a symmetric key before authentication, and the authentication parties use the key for encryption (signature) and decryption (verification). This method has the following problems in practical application:

[0091] 1. In order to ensure the security of the key, the preset key is generally transmitted offline. For a QKD network of n users, key presetting is required between each pair of users, a total of n(n-1) / 2 pairs of keys, which is a very large amount of work and has high complexity.

[0092] 2. When a new QKD device joins the QKD network, the new QKD device needs to preset the key with all the QKD devices in the original QKD network, which is a very large amount of work.

[0093] Based on this, after considering the problems in the related art, the present invention provides an identity authentication method and related equipment in the field of network security technology. The method includes: inputting challenge information into a physical unclonable function to generate a challenge-response list; the challenge-response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, a third challenge and a corresponding third response; generating a post-quantum cryptography (PQC) public key based on the second response; and / or generating a classical signature public key based on the third response; sending a first security certificate request to an authentication server; the first security certificate request includes: the first challenge, a hash value of the first response, a PQC public key, and / or a classical signature public key; and receiving a first quantum security certificate for identity authentication from the authentication server. The unique response generated by the PUF for each challenge is unclonable, a truly random number, and has strong randomness. It can be used to generate quantum security certificates for identity authentication, reducing the complexity of identity authentication and the workload of identity authentication between QKD devices.

[0094] Figure 2 FIG. 1 shows a schematic diagram of the structure of an identity authentication system in an embodiment of the present disclosure. Figure 2 As shown, the identity authentication system 100 may include: a first QKD device 101, a second QKD device 102 and an authentication server 103.

[0095] The first QKD device 101 and the second QKD device 102 can both serve as a transmitter or a receiver, which is not limited in the embodiments of the present disclosure. The authentication server 103 can be deployed in a certificate issuing center.

[0096] Those skilled in the art will know that Figure 1 The number of QKD devices and authentication servers 103 is merely illustrative, and any number of QKD devices and authentication servers may be provided as needed. This disclosure does not limit this.

[0097] This exemplary implementation is described in detail below with reference to the accompanying drawings and examples.

[0098] The present disclosure provides an identity authentication method that can be applied to a first QKD device. Figure 3 A flow chart of an identity authentication method according to an embodiment of the present disclosure is shown as follows: Figure 3 As shown, the identity authentication method provided in the embodiment of the present disclosure includes the following steps:

[0099] S302: Input challenge information to the physical unclonable function to generate a challenge response list, where the challenge response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, and a third challenge and a corresponding third response.

[0100] In a possible embodiment, the PUF works by implementing a challenge-response authentication. For a given PUF, a specific input, which can be referred to as "challenge" information, will produce an output response, i.e., a challenge-response authentication, the output response is unique to the specific PUF and thus unclonable. The challenge information is a raw binary value asserted to the DRAM / SRAM cell array, and the response is the value of the array after a given time interval. This technology can be used to generate a true random number, the output response can be used for the generation of encryption keys, and can also be used as a device identifier for device identification for anti-counterfeiting protection.

[0101] In a possible embodiment, the challenge information in the embodiments of the present disclosure can be a random number, the input challenge information can include a first challenge, a second challenge and / or a third challenge, and the second challenge and the third challenge can be input one or two.

[0102] In a possible embodiment, the first challenge and the first response are used to identify the first quantum key distribution device; the second challenge and the second response are used as random numbers participating in key generation of the PQC signature; and the third challenge and the third response are used as random numbers participating in key generation of the classical signature.

[0103] S304: generating a post-quantum cryptography PQC public key according to the second response, and / or generating a classical signature public key according to the third response.

[0104] In a possible embodiment, the PQC public key can be generated based on the value of the second response.

[0105] In a possible embodiment, the classical signature public key can be generated based on the value of the third response. For example, the classical signature algorithm is ECDSA.

[0106] S306: sending a first security certificate request to an authentication server, the first security certificate request including: the first challenge, a hash value of the first response, the PQC public key and / or the classical signature public key.

[0107] In a possible embodiment, the first security certificate request includes: the first challenge, the hash value of the first response, and the PQC public key.

[0108] In a possible embodiment, the first security certificate request includes: the first challenge, the hash value of the first response, and the classical signature public key.

[0109] In a possible embodiment, the first security certificate request includes: the first challenge, the hash value of the first response, the PQC public key and the classical signature public key.

[0110] S308: receiving the first quantum security certificate for identity authentication fed back by the authentication server.

[0111] In the above manner, the first response, the second response and the third response output by the PUF are taken as the basis for constructing a key and performing an identity authentication process, and the authentication server of the authentication center is requested for a quantum security certificate. When identity authentication needs to be performed between multiple QKD devices, the authentication can be completed through the quantum security certificate, without the need to perform identity authentication through a preset key, thereby reducing the complexity of identity authentication and reducing the workload of identity authentication between quantum key distribution devices. For a new QKD device, a quantum security certificate can also be obtained from the authentication server of the authentication center to complete identity authentication.

[0112] In a possible embodiment, the challenge-response list can be as shown in Table 1 below.

[0113] Table 1

[0114]

[0115] In a possible embodiment, the challenge-response list further includes: a fourth challenge and a corresponding fourth response; a value in the fourth response is used as a signature identification bit in a quantum security hybrid signature; the quantum security hybrid signature includes: a classical signature and a PQC signature.

[0116] In a possible embodiment, the challenge-response list can be as shown in Table 2 below.

[0117] Table 2

[0118]

[0119] Since the PQC signature size is large, if the base vector comparison, error correction information and other information are transmitted in the classical channel, if the quantum security hybrid signature is used, the required resources are too large. To solve this problem, the inventors have given the following manner, taking the first quantum key distribution device as an example for generating a quantum security hybrid signature, Figure 4 A flowchart of generating a quantum security hybrid signature in an embodiment of the present disclosure is shown, as shown in Figure 4 The flowchart includes the following steps:

[0120] S402: For the nth time of generating a quantum security hybrid signature, the value of the nth bit in the fourth response is obtained.

[0121] S404: If the value of the nth bit is 1, a PQC signature is generated.

[0122] S406: According to the value of the nth bit, the PQC signature, the classical signature and the original information, the nth quantum security hybrid signature is generated.

[0123] S408: If the nth bit is 0, generate the nth quantum secure hybrid signature according to the value of the nth bit, the classical signature and the original information.

[0124] S410: Send the nth quantum secure hybrid signature to the second quantum key distribution device.

[0125] In a possible embodiment, each bit of the value of the fourth response identifies a signature identification bit, 0 represents not using PQC signature, and 1 represents using PQC signature. As a signature identification bit, the signature identification bit is shifted one bit after each communication until the value of the fourth response is exhausted. If the signature identification is 1, the PQC signature is performed on the hash value to generate a quantum secure hybrid signature. If the signature identification bit is 0, the PQC signature is not performed, and the quantum secure hybrid signature is generated according to the classical signature.

[0126] In a possible embodiment, the function represented by the value of the fourth response is represented by Table 3, as shown in the following Table 3:

[0127] Table 3

[0128]

[0129] In a possible embodiment, taking the signature identification bit as 1 as an example, the quantum secure hybrid signature is: signature identification bit (1) + M (original information) + signature (PQC signature + classical signature).

[0130] In a possible embodiment, taking the signature identification bit as 0 as an example, the quantum secure hybrid signature is: signature identification bit (0) + M (original information) + signature (classical signature).

[0131] In a possible embodiment, when the quantum secure hybrid signature is received by the receiving party, the quantum secure hybrid signature is verified to determine whether the received data is compliant, and the first quantum key distribution device is taken as a receiving end, Figure 5 A flowchart of verifying the quantum secure hybrid signature in the embodiment of the present disclosure is shown, as shown in Figure 5 The flowchart includes the following steps:

[0132] S502: Receive the quantum secure hybrid signature sent by the second quantum key distribution device.

[0133] S504: Obtain the signature identification bit in the quantum secure hybrid signature.

[0134] S506: If the signature identification bit is 1, obtain the PQC public key and the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum secure hybrid signature.

[0135] S508: If the signature identification bit is 0, the classical signature public key in the quantum security certificate of the second quantum key distribution device is obtained to verify the quantum security hybrid signature.

[0136] In a possible embodiment, the receiving end determines whether to contain the PQC signature according to the signature identification bit. If the value of the signature identification bit is 0, that is, the PQC signature is not contained, the signature is verified based on the classical signature public key in the quantum security certificate. If the value of the signature identification bit is 1, the PQC public key and the classical signature public key in the quantum security certificate are extracted respectively to verify the quantum security hybrid signature. If both pass, it means that the data is compliant and legal.

[0137] In a possible embodiment, when all the signature identification bits of the fourth response are used to generate the quantum security hybrid signature, the fourth challenge and the fourth response are deleted in the challenge response list. A new fourth challenge is input to the PUF to generate a new fourth response.

[0138] Exemplarily, each bit of the fourth response is used to generate a quantum security hybrid signature once. Taking 256 random binary values as an example, after 256 times of generating the quantum security hybrid signature, the value of the fourth response is exhausted. The value of the fourth challenge and the fourth response is deleted in the challenge response list. A brand new fourth challenge is input to the PUF to generate a brand new fourth response value as the signature identification bit.

[0139] In the above manner, the device only needs to update the value in the list periodically, which can reduce the resource consumption when transmitting the basis vector comparison, error correction information and other information in the classical channel. Moreover, the randomness of the response generated by the PUF is strong, and the security is effectively improved.

[0140] It should be noted that the brand new fourth challenge can be the same as or different from the deleted fourth challenge. The disclosure does not limit whether the brand new fourth challenge is the same as or different from the deleted fourth challenge. The challenge information input is a random number. If it is limited that the brand new fourth challenge must be different from the deleted fourth challenge, the challenge information of the brand new fourth challenge needs to be judged, which increases the judgment process and improves the processing flow. If it is not limited whether the brand new fourth challenge is the same as or different from the deleted fourth challenge, the processing flow can be simplified and the operation can be simplified.

[0141] In a possible embodiment, the brand new fourth challenge can be limited to be different from the deleted fourth challenge, so as to improve the randomness of the value of the brand new fourth response and improve the security of the quantum security hybrid signature.

[0142] In a possible embodiment, after obtaining the quantum security certificate, identity authentication is performed with other QKD devices. The identity authentication between the QKD devices needs mutual authentication of both parties and completion of identity compliance verification.

[0143] As the sending end, the first QKD device can perform the following steps: construct a first identity authentication request message based on the hash value of the first quantum security certificate, the first challenge and the corresponding first response; send the first identity authentication request message to the second quantum key distribution device, so that the second quantum key distribution device can authenticate the first quantum key distribution device.

[0144] The first QKD device acts as a receiving end, receives the authentication request message sent by the second QKD device, and submits the authentication request to the authentication center. The following steps can be performed: receiving the second identity authentication request message sent by the second quantum key distribution device; the second identity authentication request message includes: the second quantum security certificate of the second quantum key distribution device, the fifth challenge and the hash value of the corresponding fifth response; the fifth response is used to identify the second quantum key distribution device; sending the first identity authentication request to the authentication server, the first identity authentication request includes: the second identity authentication request message; receiving the first verification pass information.

[0145] Another identity authentication method is provided in the embodiment of the present disclosure and can be applied to the authentication server. Figure 6 A flow chart of an identity authentication method according to an embodiment of the present disclosure is shown as follows: Figure 6 As shown, the identity authentication method provided in the embodiment of the present disclosure includes the following steps:

[0146] S602: Receive a first security certificate request, where the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key, and / or a classic signature public key.

[0147] S604: Generate and feedback a first quantum security certificate, wherein the PQC public key and / or the classical signature public key are concatenated in the public key body information portion of the first quantum security certificate, and the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.

[0148] In one possible embodiment, the authentication server of the authentication center can concatenate the classical signature with the first 256 bits of the PQC signature in the final signature part of the certificate to generate a quantum secure certificate.

[0149] Through the above method, the issuance of quantum security certificates is completed. When identity authentication is required between multiple QKD devices, the authentication can be completed through the quantum security certificate. There is no need to perform identity authentication through pre-set keys, which reduces the complexity of identity authentication and the workload of identity authentication between quantum key distribution devices. For new QKD devices, quantum security certificates can also be obtained from the authentication server of the authentication center to complete identity authentication.

[0150] In a possible embodiment, when the authentication server of the authentication center receives the identity authentication request, the following steps can be performed: receiving a first identity authentication request, the first identity authentication request comprising: a second identity authentication request message; the second identity authentication request message comprising: a second quantum security certificate of a second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; performing multi-level verification, and if the multi-level verification is passed, determining that the second quantum key distribution device is compliant, and sending first verification pass information.

[0151] In a possible embodiment, the authentication server of the authentication center can maintain a correspondence list to ensure the correspondence between the QKD device, the challenge, the response, and the quantum security certificate, as shown in Table 4 below.

[0152] Table 4

[0153]

[0154] The verification can be completed in a multi-level verification manner to determine that the QKD device is compliant and to inform the corresponding QKD device.

[0155] In a possible embodiment, the multi-level verification manner can include multiple verification manners, and the following two verification manners are exemplarily described.

[0156] Exemplarily, according to the fifth challenge, the verification hash value stored in the authentication server is queried, and verification is performed according to the verification hash value and the fifth response in the second identity authentication request message.

[0157] Exemplarily, verification is performed based on the second quantum security certificate in the second identity authentication request message and the verification certificate stored in the authentication server.

[0158] The above two verification manners are not limited in a specific execution order.

[0159] In a possible embodiment, the verification hash value stored in the authentication server can be queried according to the fifth challenge first, and verification is performed according to the verification hash value and the fifth response in the second identity authentication request message. If the first-level verification is passed, verification is performed based on the second quantum security certificate in the second identity authentication request message and the verification certificate stored in the authentication server, and the multi-level verification is completed.

[0160] If the first-level verification is not passed, it indicates that the QKD device authentication based on the response output by the PUF fails, and the verification based on the quantum security certificate is no longer continued.

[0161] In a possible embodiment, Figure 7 An interaction schematic diagram of an identity authentication method in the embodiment of the present disclosure is shown, as shown in Figure 7 The interaction schematic diagram of the identity authentication method in the embodiment of the present disclosure is shown, as shown in

[0162] S702: The first QKD device sends a first security certificate request to the authentication server, where the first security certificate request includes: a first challenge, a hash value of a first response, a PQC public key and / or a classic signature public key.

[0163] S704: The authentication server generates a first quantum security certificate, and concatenates the PQC public key and / or the classical signature public key in the public key body information portion of the first quantum security certificate; the certificate signature of the first quantum security certificate includes: a classical signature and a PQC signature.

[0164] S706: The authentication server sends a first quantum security certificate to the first QKD device.

[0165] S708: The second QKD device sends a second security certificate request to the authentication server.

[0166] S710: The authentication server generates a second quantum security certificate.

[0167] S712: The authentication server sends a second quantum security certificate to the second QKD device.

[0168] S714: The first QKD device constructs a first identity authentication request message according to the hash value of the first quantum security certificate, the first challenge and the corresponding first response.

[0169] In a possible embodiment, the first identity authentication request message may be M1 as an example, where M1 = first challenge + Hash (first response) + first quantum security certificate.

[0170] S716: The first QKD device sends a first identity authentication request message to the second QKD device.

[0171] S718: The second QKD device sends a second identity authentication request to the authentication server, where the second identity authentication request includes: a first identity authentication request message.

[0172] S720: The authentication server sends second verification pass information to the second QKD device.

[0173] S722: The second QKD device constructs a second identity authentication request message according to the hash value of the second quantum security certificate, the fifth challenge and the corresponding fifth response.

[0174] In a possible embodiment, the second identity authentication request message may be M2 as an example, where M2=fifth challenge+Hash (fifth response)+second quantum security certificate.

[0175] S724: The second QKD device sends a second identity authentication request message to the first QKD device.

[0176] S726: The first QKD device sends a first identity authentication request to the authentication server, where the first identity authentication request includes: a second identity authentication request message.

[0177] S728: The authentication server sends first verification pass information to the first QKD device.

[0178] Through the above method, the identity authentication of different QKD devices is completed. During the entire authentication process, there is no need to pre-set a large number of keys for authentication, which reduces the difficulty of identity authentication and key management in complex QKD networks and improves scalability. When new QKD devices are connected to the QKD network, the above method can also be used to reduce the complexity of identity authentication and reduce the workload of identity authentication between quantum key distribution devices.

[0179] Based on the same inventive concept, the present disclosure also provides a quantum key distribution device and authentication server, as shown in the following embodiment. Since the principles of this embodiment are similar to those of the above-mentioned method embodiment, the implementation of this embodiment can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated here.

[0180] Figure 8 A schematic diagram of the structure of a quantum key distribution device according to an embodiment of the present disclosure is shown. Figure 8 As shown, the quantum key distribution device 80 includes: a first generation unit 801, used to input a challenge to a physical unclonable function to generate a challenge-response list; the challenge-response list includes: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, a third challenge and a corresponding third response; a second generation unit 802, used to generate a post-quantum cryptography PQC public key according to the second response; and / or, based on the third response, generate a classical signature public key; a first sending unit 803, used to send a first security certificate request to an authentication server; the first security certificate request includes: the first challenge, a hash value of the first response, a PQC public key and / or a classical signature public key; a first receiving unit 804, used to receive a first quantum security certificate for identity authentication fed back by the authentication server.

[0181] Figure 9 A schematic diagram of the structure of an authentication server in an embodiment of the present disclosure is shown. Figure 9As shown, the authentication server 90 comprises: a second receiving unit 901, configured to receive a first security certificate request; the first security certificate request comprises: a first challenge, a hash value of a first response, a PQC public key and / or a classical signature public key; a second sending unit 902, configured to generate and feedback a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in the public key subject information part of the first quantum security certificate; the certificate signature of the first quantum security certificate comprises: a classical signature and a PQC signature.

[0182] Those skilled in the art can understand that the various aspects of the present disclosure can be implemented as a system, a method or a program product. Therefore, the various aspects of the present disclosure can be embodied as a whole hardware implementation, a whole software implementation (including firmware, microcode, etc.), or an implementation combined with hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" here.

[0183] The electronic device 1000 according to this embodiment of the present disclosure will be described below with reference to the accompanying drawings. Figure 10 The electronic device 1000 shown is merely an example, and should not impose any limitation on the function and use range of the embodiments of the present disclosure. Figure 10 The electronic device 1000 shown is merely an example, and should not impose any limitation on the function and use range of the embodiments of the present disclosure.

[0184] As shown in Figure 10 The components of the electronic device 1000 can include, but are not limited to, the at least one processing unit 1010 described above, the at least one storage unit 1020 described above, and a bus 1030 connecting different system components, including the storage unit 1020 and the processing unit 1010.

[0185] The storage unit stores program code that can be executed by the processing unit 1010, so that the processing unit 1010 performs the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section of the present specification. For example, the processing unit 1010 can perform the steps of any one of the above method embodiments.

[0186] The storage unit 1020 can include a readable medium in the form of a volatile storage unit, such as a random access memory (RAM) 10201 and / or a cache memory unit 10202, and can further include a read-only memory (ROM) 10203.

[0187] The storage unit 1020 can also include a program / utility 10204 having a set of program modules 10205 such as an operating system, one or more application programs, other program modules, and program data, each of which can govern aspects of the operating environment of the electronic device 1000. It is to be appreciated that one or more other programs can be loaded into the memory 1022 and run under the operating system of the electronic device 1000.

[0188] The bus 1030 can represent one or more of several types of bus structures, including a storage bus or bus controller, a peripheral bus, a graphics bus, a processor or local bus using any of a variety of bus architectures.

[0189] The electronic device 1000 can also communicate with one or more external devices 1040 such as a keyboard or pointing device, a Bluetooth device, etc.; other devices such as printers, scanners, etc.; and / or various types of networks. In general, use of the term device herein is intended to be broad, encompassing both devices and networks. The I / O interface 1050 can enable the electronic device 1000 to interface to such external devices and / or networks. The electronic device 1000 can also include a modem 1060, a network interface card, a satellite transceiver, or other apparatus for interfacing the electronic device 1000 to in one or more networks. In any such implementations, the modem 1060 can be considered to be part of an input / output interface or a network interface. The bus 1030 can also include one or more buses utilizing any of a variety of bus architectures including a Memory bus or bus controller, a Peripheral bus, a Graphics bus, a Processor or Local bus using any of a variety of bus architectures.

[0190] Those skilled in the art will readily understand that the example embodiments described herein can be implemented by software and / or by hardware coupled with software, as described above. Thus, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to perform the methods according to the embodiments of the present disclosure.

[0191] In particular, according to the embodiments of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer program product or a computer program, which includes computer instructions stored in a computer readable storage medium. The processor of the computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes the method in the above embodiments.

[0192] In the exemplary embodiments of the present disclosure, a computer readable storage medium is also provided, which can be a readable signal medium or a readable storage medium. A program product capable of implementing the above method of the present disclosure is stored thereon. In some possible implementations, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program codes for causing the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the above “Exemplary Method” section of the specification when the program product is run on the terminal device.

[0193] More specific examples of the computer readable storage medium in the present disclosure can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0194] In the present disclosure, the computer readable storage medium can include a data signal propagated in a baseband or as a part of a carrier wave, in which readable program codes are carried. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable signal medium can also be any readable medium other than the readable storage medium, which can send, propagate or transmit programs for use by or in connection with an instruction execution system, apparatus or device.

[0195] Optionally, the program codes contained on the computer readable storage medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0196] In particular embodiments, the program code utilized by the program code instructions can be implemented in any of various ways. For example, it can be implemented in various programming languages, including compiled or interpreted languages, and can be implemented using scripting languages such as VBScript, JavaScript, Perl, Python, etc. In some embodiments, different programming languages can be employed in various combinations. In particular embodiments, the program code instructions utilized by the program code can be executed by one or more programmable processors electonically. The input can be supplied to the electronic processor(s) via user input, from sensors, and / or from other electronically stored data. The output can be provided on a display, to a storage device, and / or to other output devices. In particular embodiments, the program code instructions utilized by the program code can be implemented in any of various ways. For example, it can be implemented in various programming languages, including compiled or interpreted languages, and can be implemented using scripting languages such as VBScript, JavaScript, Perl, Python, etc. In some embodiments, different programming languages can be employed in various combinations. In particular embodiments, the program code instructions utilized by the program code can be executed by one or more programmable processors electonically. The input can be supplied to the electronic processor(s) via user input, from sensors, and / or from other electronically stored data. The output can be provided on a display, to a storage device, and / or to other output devices.

[0197] It should be noted that while the foregoing detailed description has set forth a number of means or units for performing the actions of the methods described herein, such delineation is not mandatory. Indeed, the features and functions of the above-described two or more means or units can be embodied in a single module or unit. Conversely, a single module or unit can be split into a plurality of modules or units. It should also be noted that, although the foregoing detailed description has set forth numerous specific embodiments of the devices and methods of the present disclosure, other alternatives will occur to those persons skilled in the art. For example, the devices and methods described herein can be used in a variety of different contexts and applications. Thus, the disclosure is not intended to be limited to the described embodiments, but rather is to be accorded the widest scope consistent with the claims.

[0198] Moreover, while the methods of the present disclosure have been described in terms of a particular sequence of steps of those methods, and of accomplishing those steps as opposed to other ways of accomplishing the steps, it will be apparent that the steps need not be performed in this order and need not be performed at all, unless explicitly claimed otherwise. Steps can be omitted, repeated, or replaced, in whole or in part, additional steps can be added, and / or the order of the steps can be changed.

[0199] Those skilled in the art will readily observe that the example embodiments described herein can be implemented by software and / or firmware in addition to or instead of necessarily hardware. Thus, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, U disk, mobile hard disk, etc.) or network, and includes a number of instructions to enable a computing device (which can be a personal computer, server, mobile terminal, or network device, etc.) to perform the methods according to the embodiments of the present disclosure.

[0200] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.

Claims

1. An identity authentication method, characterized by, The method is applied to a first quantum key distribution device, and the method comprises: inputting challenge information into a physically unclonable function to generate a challenge response list; the challenge response list comprises: a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, a third challenge and a corresponding third response; generating a post-quantum cryptography (PQC) public key according to the second response; and / or generating a classical signature public key according to the third response; sending a first security certificate request to an authentication server; the first security certificate request comprises: the first challenge, a hash value of the first response, the PQC public key, and / or the classical signature public key; receiving a first quantum security certificate for identity authentication fed back by the authentication server.

2. The method of claim 1, wherein, The method further comprises: constructing a first identity authentication request message according to the first quantum security certificate, the first challenge, and the hash value of the corresponding first response; sending the first identity authentication request message to a second quantum key distribution device to enable the second quantum key distribution device to perform identity authentication on the first quantum key distribution device.

3. The method of claim 1, wherein, The method further comprises: receiving a second identity authentication request message sent by the second quantum key distribution device; the second identity authentication request message comprises: a second quantum security certificate of the second quantum key distribution device, a hash value of a fifth challenge and a corresponding fifth response; the fifth response is used to identify the second quantum key distribution device; sending a first identity verification request to the authentication server, wherein the first identity verification request comprises the second identity authentication request message; receiving first verification passing information.

4. The method of claim 1, wherein, The challenge response list further comprises: a fourth challenge and a corresponding fourth response; a value in the fourth response is used as a signature identification bit in a quantum security hybrid signature; the quantum security hybrid signature comprises: a classical signature and a PQC signature; The method further comprises: for the nth time, generating a quantum security hybrid signature, obtaining a value of an nth bit in the fourth response; if the value of the nth bit is 1, generating the PQC signature; generating an nth quantum security hybrid signature according to the value of the nth bit, the PQC signature, the classical signature, and original information; if the nth bit is 0, generating an nth quantum security hybrid signature according to the value of the nth bit, the classical signature, and the original information; sending the nth quantum security hybrid signature to the second quantum key distribution device.

5. The method of claim 1, wherein, The method further comprises: receiving a quantum security hybrid signature sent by the second quantum key distribution device; obtaining a signature identification bit in the quantum security hybrid signature; if the signature identification bit is 1, obtaining a PQC public key and a classical signature public key in a quantum security certificate of the second quantum key distribution device to verify the quantum security hybrid signature; if the signature identification bit is 0, obtaining the classical signature public key in the quantum security certificate of the second quantum key distribution device to verify the quantum security hybrid signature.

6. The method of claim 4, wherein, The method further comprises: when all signature identification bits of the fourth response are used to generate the quantum security hybrid signature, deleting the fourth challenge and the fourth response in the challenge response list; A new fourth challenge is input to the PUF to generate a new fourth response.

7. The method of claim 1, wherein, The challenge information input to the physically unclonable function is a random number.

8. The method of claim 1, wherein, The first challenge and the first response are used to identify the first quantum key distribution device; the second challenge and the second response are random numbers participating in key generation as PQC signatures; and the third challenge and the third response are random numbers participating in key generation as classical signatures.

9. An identity authentication method characterized by, The method is applied to an authentication server, and the method comprises: receiving a first security certificate request; the first security certificate request comprises a first challenge, a hash value of a first response, a PQC public key, and / or a classical signature public key; generating and feeding back a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in a public key subject information part of the first quantum security certificate; and a certificate signature of the first quantum security certificate comprises a classical signature and a PQC signature.

10. The method of claim 9, wherein, The method further comprises: receiving a first identity authentication request, wherein the first identity authentication request comprises a second identity authentication request message; and the second identity authentication request message comprises a second quantum security certificate of a second quantum key distribution device, a fifth challenge, and a hash value of a corresponding fifth response; performing multi-level verification, and if the multi-level verification is passed, determining that the second quantum key distribution device is compliant, and sending first verification pass information.

11. The method of claim 10, wherein, The multi-level verification comprises: verifying the second quantum security certificate in the second identity authentication request message against a verification certificate stored in the authentication server; querying a verification hash value stored in the authentication server according to the fifth challenge; verifying the verification hash value against the fifth response in the second identity authentication request message.

12. A quantum key distribution device, characterized in that: Comprise: a first generating unit configured to input a challenge to a physically unclonable function to generate a challenge response list; the challenge response list comprises a first challenge and a corresponding first response, and at least one of the following: a second challenge and a corresponding second response, and a third challenge and a corresponding third response; a second generating unit configured to generate a post-quantum cryptography (PQC) public key according to the second response, and / or generate a classical signature public key according to the third response; a first sending unit configured to send a first security certificate request to an authentication server; the first security certificate request comprises a first challenge, a hash value of a first response, a PQC public key, and / or a classical signature public key; a first receiving unit configured to receive a first quantum security certificate for identity authentication fed back by the authentication server.

13. An authentication server, characterized by Comprise: a second receiving unit configured to receive a first security certificate request; the first security certificate request comprises a first challenge, a hash value of a first response, a PQC public key, and / or a classical signature public key; a second sending unit configured to generate and feed back a first quantum security certificate; wherein the PQC public key and / or the classical signature public key are concatenated in a public key subject information part of the first quantum security certificate; and a certificate signature of the first quantum security certificate comprises a classical signature and a PQC signature.

14. An electronic device, comprising: Comprise: a processor; and a memory configured to store executable instructions of the processor; The processor is configured to execute the method of any one of claims 1-11 by executing the executable instructions.

15. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1-11.

16. A computer program product, comprising: The computer program or instructions are executed by the processor to implement the method of any one of claims 1-11.

Citation Information

Patent Citations

  • Use of puf for checking authentication, in particular for protecting against unauthorized access to function of ic or control device

    CN104782076A

  • IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key

    CN120281485A