A secure channel establishment method and related device

By registering with the service provider and calculating a shared key, a secure channel can be established without a CA, which solves the security risks caused by digital certificate dependence and enhances the security and reliability of communication.

CN120675712BActive Publication Date: 2025-11-21SHENZHEN BROADTON COMM TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511188873.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2025-11-21
Estimated Expiration
2045-08-25

AI Technical Summary

Technical Problem

The establishment of secure internet channels in existing technologies heavily relies on digital certificates, which poses security risks due to attacks on or malicious operations of the Certificate Authority (CA). There is an urgent need for a solution that can establish secure channels without a CA.

Method used

By having the first and second communicating parties register with their respective service providers, calculate and verify their public keys, generate a shared key, and establish a secure communication channel between them, identity verification can be achieved without relying on digital certificates.

Benefits of technology

This technology enables the establishment of secure channels without the need for a Certificate Authority (CA) during the establishment of secure internet channels, thus solving the problem of dependence on digital certificates and enhancing the security and reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675712B_ABST
    Figure CN120675712B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network communication, in particular to a security channel establishment method and related equipment, which comprises the following steps: a first communication party initiates a registration request to a first service provider and registers at the first service provider; a second communication party initiates a registration request to a second service provider and registers at the second service provider; if the first communication party and the second communication party are both registered, the first communication party calculates a first shared key, and the second communication party calculates a second shared key; if the first shared key is consistent with the second shared key, a security communication channel is established between the first communication party and the second communication party based on the first shared key and the second shared key. The application helps to solve the problem of dependence on digital certificates in the related art when establishing an Internet security channel, thereby realizing the effect of establishing a security channel without CA.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to a secure channel establishment method and related equipment. Background Technology

[0002] In today's internet communication, establishing secure channels is crucial for ensuring the confidentiality, integrity, and authentication of information transmission. Currently, the construction of secure internet channels heavily relies on digital certificate systems. Digital certificates are issued by Certificate Authorities (CAs). During network communication, both parties use digital certificates issued by CAs to authenticate each other's identities and further establish a shared key, thereby ensuring the security of communication.

[0003] Taking SSL / TLS server certificates as an example, while they provide strong protection for network communication security under normal circumstances, a significant security vulnerability exists. When the CA trusted by the client is attacked, or when the CA itself performs malicious operations, it may issue server certificates containing false information that can still pass verification. In this case, even if the client strictly follows the correct certificate verification process and domain name check steps, man-in-the-middle attacks are still highly likely to succeed. Looking back at past security incidents, such as the TurkTrust CA's false certificate incident, the DigiNotar CA attack, and the Comodo CA security incident, these real-world cases clearly demonstrate that such attacks are not merely theoretical possibilities, but have actually occurred and posed serious security threats. Therefore, a novel solution is urgently needed to address the reliance on digital certificates in establishing secure internet channels, thereby achieving the effect of establishing secure channels without a CA. Summary of the Invention

[0004] To help solve the problem of dependence on digital certificates when establishing secure Internet channels in related technologies, and thus achieve the effect of establishing secure channels without the need for a CA, this application provides a secure channel establishment method and related equipment.

[0005] Firstly, this application provides a secure channel establishment method, which adopts the following technical solution:

[0006] A secure channel establishment method, comprising:

[0007] The first communication provider initiates a registration request to the first service provider and registers with the first service provider;

[0008] The second communication provider initiates a registration request to the second service provider and registers with the second service provider.

[0009] If the first communication party and the second communication party are both registered, the first communication party calculates a first shared key, and the second communication party calculates a second shared key;

[0010] Based on the first shared key and the second shared key, a secure communication channel is established between the first communication party and the second communication party;

[0011] If the first communication party and the second communication party are both registered, the first communication party calculates a first shared key, and the second communication party calculates a second shared key, including:

[0012] If the first communication party and the second communication party are both registered, the first communication party sends a request for obtaining a second public key to the second service provider, and the second communication party sends a request for obtaining a first public key to the first service provider;

[0013] The first service provider generates a first identity certificate based on the first public key, and the second service provider generates a second identity certificate based on the second public key;

[0014] The first service provider sends the first identity certificate and the first public key to the second communication party, and the second service provider sends the second identity certificate and the second public key to the first communication party;

[0015] The first communication party judges whether the second public key is correct, and the second communication party judges whether the first public key is correct;

[0016] If the first public key and the second public key are both correct, the first communication party calculates a first shared key based on the second public key, and the second communication party calculates a second shared key based on the first public key.

[0017] By using the above technical solution, the first communication party registers at the first service provider, the second communication party registers at the second service provider, when the first communication party and the second communication party are both registered, the first communication party calculates a second shared key corresponding to the second communication party, the second communication party calculates a first shared key corresponding to the first communication party, if the first shared key and the second shared key are consistent, a secure communication channel is established between the first communication party and the second communication party according to the first shared key and the second shared key; by calculating the first shared key and the second shared key, and judging whether the first shared key and the second shared key are consistent, if they are consistent, it means that the identity confirmation between the first communication party and the second communication party is completed, and there is no need to rely on digital certificate, thus helping to solve the problem of relying on digital certificate in establishing internet secure channel in related technology, so as to realize the effect of establishing secure channel without CA.

[0018] Optionally, the first communication direction initiates a registration request to the first service provider, and the registration at the first service provider comprises:

[0019] The first communication direction initiates a registration request to the first service provider, and sends a first user identifier to the first service provider;

[0020] The first service provider sends a target parameter to the first communication direction;

[0021] The first communication direction generates a first public-private key pair based on the target parameter, and sends a first public key in the first public-private key pair to the first service provider;

[0022] The first service provider updates the public key directory.

[0023] Optionally, the first communication direction generates a first public-private key pair based on the target parameter, and sends a first public key in the first public-private key pair to the first service provider comprises:

[0024] The first communication direction obtains target data as a first private key based on a preset rule;

[0025] The first communication direction calculates the first public key based on the first user identifier, the target parameter and the first private key;

[0026] The first communication direction sends the first public key to the first service provider.

[0027] Optionally, the first service provider generates a first identity certificate based on the first public key comprises:

[0028] The first service provider obtains a first user identifier corresponding to the first communication direction and the first public key;

[0029] The first service provider obtains a random parameter and calculates a first random public key based on the random parameter;

[0030] The first service provider calculates a first proof parameter based on the first user identifier, the first public key and the first random public key;

[0031] The first service provider obtains the first identity certificate based on the random parameter and the first proof parameter;

[0032] The first proof parameter satisfies the following calculation formula:

[0033] ;

[0034] Wherein, The first proof parameter is represented by The cryptographic hash algorithm is represented by represents the first user identity, represents the first public key, represents the first random public key, and || represents connection.

[0035] Optionally, the second communication party judging whether the first public key is correct comprises:

[0036] When the second communication party receives the first public key and the first identity certificate sent by the first service provider, the first user identity, the first public key, the first random public key and the first identity certificate are obtained;

[0037] The second communication party calculates a second proof parameter based on the first user identity, the first public key, the first random public key and the first identity certificate;

[0038] The second communication party calculates a second random public key based on the target parameter and the second proof parameter;

[0039] The second communication party judges whether the second random public key is consistent with the first random public key;

[0040] If the second random public key is consistent with the first random public key, the second communication party determines that the first public key is correct;

[0041] The second random public key satisfies the second calculation formula:

[0042] ;

[0043] wherein, is the second random public key, and ɡ and q are target parameters, is the first identity certificate, is the second proof parameter.

[0044] Optionally, the first communication party calculates the first shared key based on the second public key comprises:

[0045] The first communication party obtains a second private key;

[0046] Based on the second public key, the first private key, the target parameter and the second private key, the first shared key is calculated;

[0047] The first shared key satisfies the following calculation formula:

[0048] ;

[0049] wherein, key1 is the first shared key, is the second public key, ɡ and q are target parameters, is the first private key, and b is the second private key.

[0050] In a second aspect, the application further discloses a secure channel establishment system, which adopts the technical scheme as follows:

[0051] The secure channel establishment system comprises:

[0052] The first communication party module initiates a registration request to the first service provider module and registers at the first service provider module;

[0053] The second communication party module initiates a registration request to the second service provider module and registers at the second service provider module;

[0054] If the first communication party module and the second communication party module are both registered, the first communication party module calculates a second shared key corresponding to the second communication party module, and the second communication party module calculates a first shared key corresponding to the first communication party module;

[0055] If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party module and the second communication party module based on the first shared key and the second shared key.

[0056] By adopting the above technical scheme, the first communication party registers at the first service provider, the second communication party registers at the second service provider, when the first communication party and the second communication party are both registered, the first communication party calculates a second shared key corresponding to the second communication party, the second communication party calculates a first shared key corresponding to the first communication party, if the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party according to the first shared key and the second shared key; by calculating the first shared key and the second shared key and judging whether the first shared key is consistent with the second shared key, if consistent, it indicates that the identity confirmation between the first communication party and the second communication party is completed, and it is not necessary to rely on the digital certificate, thus helping to solve the problem of relying on the digital certificate in establishing the internet secure channel in the related art, so as to realize the effect of establishing the secure channel without CA.

[0057] In a third aspect, the application provides a computer device, which adopts the technical scheme as follows:

[0058] The intelligent terminal comprises a memory and a processor, the memory is used for storing a computer program capable of running on the processor, and the processor loads the computer program to execute the method of the first aspect.

[0059] By adopting the technical scheme, the computer program generated based on the method of the first aspect is stored in the memory to be loaded and executed by the processor, so that the intelligent terminal is manufactured according to the memory and the processor, and the user is facilitated to use.

[0060] In a fourth aspect, the present application provides a computer readable storage medium, which adopts the technical scheme as follows:

[0061] A computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is loaded by a processor to execute the method of the first aspect.

[0062] By adopting the technical scheme, the computer program generated based on the method of the first aspect is stored in the computer readable storage medium to be loaded and executed by the processor, and the computer readable storage medium facilitates the readability and storage of the computer program.

[0063] In summary, the present application has the following beneficial technical effects:

[0064] The first communication party registers at the first service provider, and the second communication party registers at the second service provider. After the registration of the first communication party and the second communication party is completed, the first communication party calculates the second shared key corresponding to the second communication party, and the second communication party calculates the first shared key corresponding to the first communication party. If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party according to the first shared key and the second shared key. By calculating the first shared key and the second shared key and judging whether the first shared key is consistent with the second shared key, if consistent, it indicates that the identity confirmation between the first communication party and the second communication party is completed, and the digital certificate is no longer needed, thereby helping to solve the problem of dependence on the digital certificate in establishing the internet secure channel in the related art, so as to achieve the effect of establishing the secure channel without CA. BRIEF DESCRIPTION OF DRAWINGS

[0065] Figure 1 is the main flowchart of the secure channel establishment method of the embodiment of the present application;

[0066] Figure 2 is the step flowchart of steps S201 to S204;

[0067] Figure 3 is the step flowchart of steps S301 to S303;

[0068] Figure 4 is the step flowchart of steps S401 to S405;

[0069] Figure 5is a step flowchart of steps S501 to S504;

[0070] Figure 6 is a step flowchart of steps S601 to S605;

[0071] Figure 7 is a step flowchart of steps S701 to S702. DETAILED DESCRIPTION

[0072] In a first aspect, the present application discloses a secure channel establishment method.

[0073] Reference Figure 1 A secure channel establishment method comprises steps S101 to S104:

[0074] Step S101: The first communication party initiates a registration request to the first service provider and registers at the first service provider.

[0075] Specifically, in the embodiment, the first service provider SPA is the service provider of the first communication party A.

[0076] Step S102: The second communication party initiates a registration request to the second service provider and registers at the second service provider.

[0077] Specifically, in the embodiment, the second service provider SPB is the service provider of the second communication party B.

[0078] Step S103: If the first communication party and the second communication party are both registered, the first communication party calculates a first shared key and the second communication party calculates a second shared key.

[0079] Specifically, in the embodiment, the first shared key is the shared key calculated by the first communication party A, and the second shared key is the shared key calculated by the second communication party B.

[0080] Step S104: If the first shared key and the second shared key are consistent, a secure communication channel is established between the first communication party and the second communication party based on the first shared key and the second shared key.

[0081] Specifically, in the embodiment, it is determined whether the first shared key and the second shared key are consistent. If they are consistent, it indicates that the shared key calculated by the first communication party and the shared key calculated by the second communication party are the same, thus indicating that the identity confirmation between the first communication party A and the second communication party B is completed, and the secure communication channel between the first communication party and the second communication party is successfully established.

[0082] The method for establishing a secure channel provided by the embodiment includes the following steps: a first communication party registers at a first service provider, a second communication party registers at a second service provider, the first communication party calculates a second shared key corresponding to the second communication party, the second communication party calculates a first shared key corresponding to the first communication party, and if the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party according to the first shared key and the second shared key. The first shared key and the second shared key are calculated, and it is determined whether the first shared key is consistent with the second shared key. If the first shared key is consistent with the second shared key, identity confirmation between the first communication party and the second communication party is completed, and digital certificates are not needed, thereby helping to solve the problem of dependence on digital certificates in related art when establishing an Internet secure channel, and achieving the effect of establishing a secure channel without CA.

[0083] Reference Figure 2 In one embodiment of the embodiment, the step S101 that the first communication party initiates a registration request to the first service provider and registers at the first service provider further includes steps S201 to S204.

[0084] The step S201 includes the following steps: the first communication party initiates a registration request to the first service provider, and sends a first user identifier to the first service provider.

[0085] Specifically, in the embodiment, when the first communication party A initiates a registration request to the first service provider SPA, the first communication party A sends its own first user identifier A to the first service provider SPA. The first user identifier is unique and independent in the whole system, and is used to prevent identity impersonation.

[0086] The step S202 includes the following steps: the first service provider sends a target parameter to the first communication party.

[0087] Specifically, when the first service provider SPA receives the registration request sent by the first communication party A, the first service provider SPA selects and saves a target parameter, and sends the target parameter to the first communication party A. In the embodiment, the target parameter includes q and g, where q is a prime number greater than 2, and g is an integer greater than 1 and less than q.

[0088] The step S203 includes the following steps: the first communication party generates a first public-private key pair based on the target parameter, and sends a first public key in the first public-private key pair to the first service provider.

[0089] Specifically, in the embodiment, the first communication party A obtains a corresponding first public-private key pair according to the target parameters q and g, where the first public-private key pair includes a first public key and a first private key .

[0090] Step S204: The first service provider updates the public key directory.

[0091] Specifically, in the embodiment, after receiving the first public key, the first service provider SPA stores the first user identifier a id and the first public key in the local data directory, thereby updating the public key directory.

[0092] It is worth noting that, in the embodiment, through similar steps, the second communication party B can register its second user identifier and the second public key at the second service provider SPB, wherein b is the second private key corresponding to the second communication party B.

[0093] Referring to Figure 3 , in one of the implementation manners of the embodiment, the step S203 in which the first communication party generates the first public-private key pair based on the target parameter and sends the first public key in the first public-private key pair to the first service provider includes steps S301 to S303:

[0094] Step S301: The first communication party obtains target data as the first private key based on a preset rule.

[0095] Specifically, the preset rule is a rule for selecting target data in advance. In the embodiment, according to the preset rule, the first communication party A selects a random integer greater than 1 and less than q as the target data, and takes the target data as the first private key.

[0096] Step S302: The first communication party calculates the first public key based on the first user identifier, the target parameter, and the first private key.

[0097] Specifically, the first public key satisfies the following calculation formula:

[0098] .

[0099] Step S303: The first communication party sends the first public key to the first service provider.

[0100] Referring to Figure 4 , in one of the implementation manners of the embodiment, the step S103 in which, if the first communication party and the second communication party are both registered, the first communication party calculates the first shared key and the second communication party calculates the second shared key includes steps S401 to S405:

[0101] Step S401: If the first communication party and the second communication party are both registered, the first communication party sends a request for the second public key to the second service provider, and the second communication party sends a request for the first public key to the first service provider.

[0102] Specifically, in the embodiment, when the first communication party and the second communication party are both registered, the second communication party B requests the first public key corresponding to the first communication party A from the first service provider SPA , and the first communication party A requests the second public key corresponding to the second communication party B from the second service provider SPB .

[0103] Step S402: The first service provider generates a first identity certificate based on the first public key, and the second service provider generates a second identity certificate based on the second public key.

[0104] Specifically, in the embodiment, the first service provider SPA generates a certificate for the first public key corresponding to the first communication party A , which is the first identity certificate; and the second service provider SPB generates a certificate for the second public key corresponding to the second communication party B , which is the second identity certificate.

[0105] Step S403: The first service provider sends the first identity certificate and the first public key to the second communication party, and the second service provider sends the second identity certificate and the second public key to the first communication party.

[0106] Specifically, the first service provider SPA sends the first identity certificate and the first public key corresponding to the first communication party A to the second communication party B, in the embodiment, the first service provider SPA can send to the second communication party B, wherein, is the first public key, is the first identity certificate; and the second service provider SPB sends the second identity certificate and the second public key corresponding to the second communication party B to the first communication party A, in the embodiment, the second service provider SPB can send to the first communication party A, wherein, is the second public key, is the second identity certificate.

[0107] Step S404: The first communication party judges whether the second public key is correct, and the second communication party judges whether the first public key is correct.

[0108] Specifically, in the embodiment, the first communication party A verifies whether the second public key corresponding to the second communication party B is correct, and the second communication party B verifies whether the first public key Is correct.

[0109] Step S405: If the first public key and the second public key are both correct, the first communication party calculates a first shared key based on the second public key, and the second communication party calculates a second shared key based on the first public key.

[0110] Referring to Figure 5 In one implementation of the embodiment, the first service provider generates the first identity certificate based on the first public key in step S402 includes steps S501 to S504:

[0111] Step S501: The first service provider obtains a first user identifier and the first public key corresponding to the first communication party.

[0112] Specifically, in the embodiment, the first service provider SPA finds the first user identifier and the first public key corresponding to the first communication party A from the storage.

[0113] Step S502: The first service provider obtains a random parameter and calculates a first random public key based on the random parameter.

[0114] Specifically, in the embodiment, the first random public key , where the random parameter is an integer.

[0115] Step S503: The first service provider calculates a first proof parameter based on the first user identifier, the first public key, and the first random public key.

[0116] Specifically, in the embodiment, the first proof parameter satisfies the following calculation formula:

[0117] ;

[0118] wherein denotes the first proof parameter, denotes a cryptographic hash algorithm, denotes the first user identifier, denotes the first public key, denotes the first random public key, and || denotes concatenation.

[0119] Step S504: The first service provider obtains the first identity certificate based on the random parameter and the first proof parameter.

[0120] Specifically, in the embodiment, the first identity certificate .

[0121] Similarly, in the embodiment, the second service provider SPB can also obtain the second identity certificate for the second public key Generating a second identity proof .

[0122] Referring Figure 6 In one implementation of the embodiment, the step S404 of determining by the second communication party whether the first public key is correct includes steps S601-S605:

[0123] Step S601: After receiving the first public key and the first identity proof sent by the first service provider, the second communication party obtains the first user identifier, the first public key, the first random public key and the first identity proof.

[0124] Specifically, in the embodiment, the second communication party B receives the first public key and the first identity proof sent by the first service provider SPA After that, the first user identifier , , and are extracted.

[0125] Step S602: The second communication party calculates a second proof parameter based on the first user identifier, the first public key, the first random public key and the first identity proof.

[0126] Specifically, in the embodiment, the second proof parameter satisfies the following calculation formula:

[0127] .

[0128] Step S603: The second communication party calculates a second random public key based on the target parameter and the second proof parameter.

[0129] Specifically, in the embodiment, the second random public key satisfies the second calculation formula:

[0130]

[0131] wherein, is the second random public key, g and q are the target parameter, is the first identity proof, is the second proof parameter.

[0132] Step S604: The second communication party determines whether the second random public key is consistent with the first random public key.

[0133] Specifically, the second communication party B determines whether the second random public key is consistent with the first random public key by determining whether is established.

[0134] Step S605: If the second random public key is consistent with the first random public key, the second communication party determines that the first public key is correct.

[0135] Specifically, in the embodiment, if the second random public key is consistent with the first random public key , it indicates that is established, and thus it can be determined that the first public key is correct, and if it is not established, it indicates that the first public key is incorrect, and then the second communication party B exits the security channel establishment stage and sends a message of “security channel establishment failure” to the first communication party A.

[0136] In the embodiment, the first communication party A also verifies whether the second public key R b corresponding to the second communication party B is correct through similar steps.

[0137] Referring to Figure 7 , in one of the implementation manners of the embodiment, the step of calculating the first shared key based on the second public key by the first communication party in step S405 includes steps S701 to S702:

[0138] Step S701: The first communication party acquires the second private key.

[0139] Specifically, in the embodiment, the second private key b is a random integer greater than 1 and less than q.

[0140] Step S702: The first shared key is calculated based on the second public key, the first private key, the target parameter, and the second private key.

[0141] Specifically, in the embodiment, the first shared key satisfies the following calculation formula:

[0142] ;

[0143] Wherein, key1 is the first shared key, is the second public key, g and q are the target parameter, is the first private key, and b is the second private key.

[0144] In the embodiment, the second shared key can also be calculated through similar steps, and the second shared key satisfies the following calculation formula:

[0145] ;

[0146] Wherein, key2 is the second shared key.

[0147] In a second aspect, the application further discloses a security channel establishment system.

[0148] A security channel establishment system comprises:

[0149] The first communication party module initiates a registration request to the first service provider module and is registered at the first service provider module;

[0150] The second communication party module initiates a registration request to the second service provider module and registers at the second service provider module;

[0151] If the first communication party module and the second communication party module are both registered, the first communication party module calculates a second shared key corresponding to the second communication party module, and the second communication party module calculates a first shared key corresponding to the first communication party module;

[0152] If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party module and the second communication party module based on the first shared key and the second shared key.

[0153] In a third aspect, the embodiments of the present application disclose an intelligent terminal, comprising a memory and a processor, the memory is used for storing a computer program capable of running on the processor, when the processor loads the computer program, a security channel establishment method of the above-mentioned embodiments is executed.

[0154] In a fourth aspect, the embodiments of the present application disclose a computer readable storage medium, and the computer readable storage medium stores a computer program, when the processor loads the computer program, a security channel establishment method of the above-mentioned embodiments is executed.

[0155] The above are the preferred embodiments of the present application, and are not intended to limit the protection scope of the present application, therefore: all equivalent changes made according to the structure, shape, principle of the present application should be covered within the protection scope of the present application.

Claims

1. A method for establishing a secure channel, characterized in that, include: The first communication provider initiates a registration request to the first service provider and registers with the first service provider; The second communication provider initiates a registration request to the second service provider and registers with the second service provider. If both the first and second communicating parties have completed registration, the first communicating party calculates the first shared key, and the second communicating party calculates the second shared key. If the first shared key is the same as the second shared key, then a secure communication channel is established between the first communicating party and the second communicating party based on the first shared key and the second shared key; Wherein, if both the first communicating party and the second communicating party have completed registration, the first communicating party calculates the first shared key, and the second communicating party calculates the second shared key, including: If both the first communication party and the second communication party have completed registration, the first communication party sends a request to the second service provider to obtain the second public key, and the second communication party sends a request to the first service provider to obtain the first public key. The first service provider generates a first identity certificate based on the first public key, and the second service provider generates a second identity certificate based on the second public key; The first service provider sends the first identity certificate and the first public key to the second communication party, and the second service provider sends the second identity certificate and the second public key to the first communication party; The first communicating party determines whether the second public key is correct, and the second communicating party determines whether the first public key is correct. If both the first public key and the second public key are correct, the first communicating party calculates the first shared key based on the second public key, and the second communicating party calculates the second shared key based on the first public key.

2. The secure channel establishment method according to claim 1, characterized in that, The first communication party initiates a registration request to the first service provider and registers with the first service provider, including: The first communication party initiates a registration request to the first service provider and sends the first user identifier to the first service provider; The first service provider sends the target parameters to the first communicating party; The first communicating party generates a first public-private key pair based on the target parameters and sends the first public key in the first public-private key pair to the first service provider; The first service provider updates its public key directory.

3. The secure channel establishment method according to claim 2, characterized in that, The first communicating party generates a first public-private key pair based on the target parameters, and sends the first public key in the first public-private key pair to the first service provider, including: The first communicating party obtains the target data as the first private key based on preset rules; The first communicating party calculates the first public key based on the first user identifier, the target parameter, and the first private key; The first communicating party sends the first public key to the first service provider.

4. The secure channel establishment method according to claim 1, characterized in that, The first service provider generates the first identity certificate based on the first public key, including: The first service provider obtains the first user identifier and the first public key corresponding to the first communicating party; The first service provider obtains random parameters and calculates a first random public key based on the random parameters; The first service provider calculates the first proof parameters based on the first user identifier, the first public key, and the first random public key; The first service provider obtains the first identity verification based on the random parameters and the first verification parameters; The first proof parameter satisfies the following calculation formula: ; in, Denotes the first proof parameter. Represents a cryptographic hash algorithm. Indicates the first user identifier. This represents the first public key. This represents the first random public key, and || represents a connection.

5. The secure channel establishment method according to claim 1, characterized in that, The second communicating party determines whether the first public key is correct by including: When the second communication party receives the first public key and the first identity certificate sent by the first service provider, it obtains the first user identifier, the first public key, the first random public key, and the first identity certificate. The second communicating party calculates the second proof parameters based on the first user identifier, the first public key, the first random public key, and the first identity certificate; The second communicating party calculates a second random public key based on the target parameters and the second proof parameters; The second communicating party determines whether the second random public key is consistent with the first random public key; If the second random public key matches the first random public key, then the second communicating party determines that the first public key is correct; The second random public key satisfies the second calculation formula: ; in, Let g be the second random public key, and q be the target parameters. As the primary form of identification, This is the second proof parameter.

6. The secure channel establishment method according to claim 1, characterized in that, The first communicating party calculates the first shared key based on the second public key, including: The first communicating party obtains the second private key; Calculate the first shared key based on the second public key, the first private key, the target parameter, and the second private key; The first shared key satisfies the following calculation formula: ; Here, key1 is the first shared key. Let g be the second public key and q be the target parameters. 'b' is the first private key, and 'b' is the second private key.

7. A secure channel establishment system, comprising performing the method according to any one of claims 1 to 6, characterized in that, include: The first communication module initiates a registration request to the first service provider module and registers with the first service provider module. The second communication module initiates a registration request to the second service provider module and registers with the second service provider module. If both the first communication module and the second communication module have completed registration, the first communication module calculates the second shared key corresponding to the second communication module, and the second communication module calculates the first shared key corresponding to the first communication module. If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication module and the second communication module based on the first shared key and the second shared key.

8. A smart terminal, comprising a memory and a processor, characterized in that, The memory is used to store computer programs that can run on the processor, and when the processor loads the computer program, it executes the method of any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is loaded by the processor, it executes the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Safe communication channel establishment method and system, client and server

    CN105141568A

  • Method for mapping at least two authentication devices to a user account using an authentication server

    CN107771383A