Identity processing method and device

By combining the dual signature scheme of identity cryptography algorithm and post-quantum digital signature algorithm, the security threat of quantum algorithm to identity processing is solved, the security and efficiency of identity authentication are improved, and the communication security and privacy of public key query are ensured.

CN120768655AActive Publication Date: 2025-10-10CHINA TELECOM CORP LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511061793.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-10-10
Estimated Expiration
2045-07-30

AI Technical Summary

Technical Problem

In existing technologies, quantum algorithms pose a huge threat to the security of identity processing, resulting in the security of identity processing being unable to be guaranteed.

Method used

A dual signature scheme combining the identification cryptography algorithm and the post-quantum digital signature algorithm is adopted. The authentication string is verified by the identification cryptography algorithm public key and the post-quantum digital signature algorithm public key to ensure the success of identity authentication, and the corresponding public key query and update are performed in the public key management center.

Benefits of technology

It improves the security and efficiency of identity authentication, avoids the impact of quantum algorithms on communication security, and ensures the security of user data and the privacy of the public key query process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768655A_ABST
    Figure CN120768655A_ABST
Patent Text Reader

Abstract

The invention provides an identity processing method and device, and relates to the technical field of communication. The method comprises the following steps: receiving an authentication string sent by a first user and used for identity authentication; calculating an identification cryptographic algorithm public key of the first user based on the user identification of the first user; querying a post-quantum digital signature algorithm public key of the first user based on the identification password algorithm public key of the first user; and verifying the first identification signature in the authentication string according to the identification password algorithm public key of the first user, verifying the post-quantum signature in the authentication string according to the post-quantum digital signature algorithm public key of the first user, and determining that the identity authentication of the first user is successful after the two verifications are passed. By means of the technical means, the problem that identity processing safety cannot be guaranteed due to the fact that a quantum algorithm affects identity processing in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to an identity processing method and device. Background Art

[0002] Continuous breakthroughs in quantum computing hardware and the emergence of quantum algorithms have posed a significant threat to traditional cryptographic algorithms based on computational complexity, such as factoring large numbers. Because identity processing involves sensitive user information, communication security is particularly important. Preventing the impact of quantum algorithms on identity processing and ensuring its security are pressing challenges. Summary of the Invention

[0003] The present disclosure provides an identity processing method and apparatus, which at least to a certain extent improve the security of users.

[0004] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.

[0005] According to one aspect of the present disclosure, an identity processing method is provided, which is applied to a public key management center side, and includes: receiving an authentication string sent by a first user for identity authentication, wherein the authentication string includes first signature data, a first identification signature, and a post-quantum signature, and the first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; calculating the identification cryptographic algorithm public key of the first user based on the user identifier of the first user; querying the post-quantum digital signature algorithm public key of the first user based on the identification cryptographic algorithm public key of the first user; verifying the first identification signature in the authentication string according to the identification cryptographic algorithm public key of the first user, and verifying the post-quantum signature in the authentication string according to the post-quantum digital signature algorithm public key of the first user, and after both verifications are passed, determining that the identity authentication of the first user is successful.

[0006] In one embodiment of the present disclosure, after determining that the identity authentication of the first user is successful, the method also includes: receiving a public key query request sent by the first user, wherein the public key query request carries the identification cryptographic algorithm public key of the second user to be queried; querying the second user's post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key based on the second user's identification cryptographic algorithm public key; performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on second signature data composed of the second user's identification cryptographic algorithm public key, post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key to obtain a first dual signature; and sending the second signature data and the first dual signature to the first user.

[0007] In one embodiment of the present disclosure, after determining that the identity authentication of the first user is successful, the method further comprises: receiving third signature data and a second identity signature sent by the first user, wherein the third signature data comprises a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second identity signature is obtained by performing an identity cryptography algorithm digital signature operation on the third signature data; calculating an identity cryptography algorithm public key of the first user based on a user identifier of the first user; verifying the second identity signature according to the identity cryptography algorithm public key of the first user, and after verification, updating the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the first user in the key information table.

[0008] In one embodiment of the present disclosure, after determining that the identity authentication of the first user is successful, the method further comprises: receiving third signature data and a second dual signature sent by the first user, wherein the third signature data comprises a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second dual signature is obtained by sequentially performing an identity cryptography algorithm digital signature operation and a post-quantum digital signature operation on the third signature data; calculating an identity cryptography algorithm public key of the first user based on a user identifier of the first user, and querying the post-quantum digital signature algorithm public key of the first user based on the identity cryptography algorithm public key of the first user; verifying the second dual signature according to the identity cryptography algorithm public key and the post-quantum digital signature algorithm public key of the first user, and after verification, updating the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the first user in the key information table.

[0009] According to another aspect of the present disclosure, there is provided an identity processing method applied to a first user side, comprising: obtaining a center identifier of a post-quantum cryptography public key management center, and using a current timestamp and the center identifier to form first signature data; performing an identity cryptography algorithm digital signature operation and a post-quantum digital signature operation on the first signature data respectively to generate a first identity signature and a post-quantum signature; forming an authentication string by combining the first signature data, the first identity signature and the post-quantum signature, and sending the authentication string to the post-quantum cryptography public key management center for identity authentication.

[0010] In one embodiment of the present disclosure, after determining that the identity authentication is successful, the method further includes: after sending a public key query request for querying the identification cryptographic algorithm public key of the second user to the post-quantum cryptography public key management center, receiving the second signature data and the first dual signature fed back by the post-quantum cryptography public key management center, wherein the second signature data includes the identification cryptographic algorithm public key, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the second user, and the first dual signature is obtained by sequentially performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the second signature data; obtaining the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center; verifying the first dual signature in turn according to the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center, and after the verification is passed, obtaining the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the second user.

[0011] In one embodiment of the present disclosure, after determining that the identity authentication is successful, the method further includes: using the current timestamp, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key to form a third signature data; performing an identification cryptography algorithm digital signature operation on the third signature data to generate a second identification signature; and sending the third signature data and the second identification signature to a post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

[0012] In one embodiment of the present disclosure, after determining that the identity authentication is successful, the method further includes: using the current timestamp, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key to form a third signature data; performing an identification cryptography algorithm digital signature operation and a post-quantum digital signature operation on the third signature data in sequence to generate a second dual signature; and sending the third signature data and the second dual signature to a post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

[0013] According to another aspect of the present disclosure, an identity processing device is provided, which is applied to a public key management center side, and includes: a receiving module, configured to receive an authentication string sent by a first user for identity authentication, wherein the authentication string includes first signature data, a first identification signature and a post-quantum signature, and the first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; a calculation module, configured to calculate the identification cryptographic algorithm public key of the first user based on the user identification of the first user; a query module, configured to query the post-quantum digital signature algorithm public key of the first user based on the identification cryptographic algorithm public key of the first user; a signature verification module, configured to verify the first identification signature in the authentication string according to the identification cryptographic algorithm public key of the first user, and to verify the post-quantum signature in the authentication string according to the post-quantum digital signature algorithm public key of the first user. After both verifications are passed, it is determined that the identity authentication of the first user is successful.

[0014] According to another aspect of the present disclosure, an identity processing device is provided, which is applied to a first user side, and includes: an acquisition module, configured to obtain a central identifier of a post-quantum cryptography public key management center, and use a current timestamp and the central identifier to form first signature data; a signature module, configured to perform an identification cryptography algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively, to generate a first identification signature and a post-quantum signature; a sending module, configured to compose an authentication string with the first signature data, the first identification signature, and the post-quantum signature, and send the authentication string to the post-quantum cryptography public key management center for identity authentication.

[0015] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform any of the above-mentioned identity processing methods by executing the executable instructions.

[0016] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, any of the above-mentioned identity processing methods is implemented.

[0017] In the disclosed embodiments, the first user's identification cryptographic algorithm public key is calculated based on the user identifier. The first user's post-quantum digital signature algorithm public key is queried based on the identification cryptographic algorithm public key. The first identification signature is verified using the identification cryptographic algorithm public key. The post-quantum signature in the authentication string is verified using the post-quantum digital signature algorithm public key. After both verifications pass, the first user's identity authentication is determined to be successful. These technical measures address the existing issue of quantum algorithms affecting identity processing, resulting in a lack of security in identity processing. This allows for dual signing of user data to ensure communication security.

[0018] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0020] Figure 1 A schematic diagram showing the identity processing system architecture in an embodiment of the present disclosure.

[0021] Figure 2 A flowchart of an identity processing method in an embodiment of the present disclosure is shown.

[0022] Figure 3 A flowchart of a method for querying a user public key in an embodiment of the present disclosure is shown.

[0023] Figure 4 A flowchart of a method for updating a user public key in an embodiment of the present disclosure is shown.

[0024] Figure 5 A flowchart of another identity processing method in an embodiment of the present disclosure is shown.

[0025] Figure 6 A flowchart of another method for querying a user public key in an embodiment of the present disclosure is shown.

[0026] Figure 7 A flowchart of another method for updating a user public key in an embodiment of the present disclosure is shown.

[0027] Figure 8 A schematic diagram of an identity processing device in an embodiment of the present disclosure is shown.

[0028] Figure 9 A schematic diagram showing another identity processing device in an embodiment of the present disclosure.

[0029] Figure 10 A schematic diagram of an electronic device provided in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0030] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0031] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0032] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0033] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0034] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0035] It should be pointed out that, in the absence of conflict, the embodiments of the present disclosure and the technical features therein may be combined with each other.

[0036] For ease of understanding, several terms involved in this disclosure are explained below: Identity-Based Cryptography (IBC): IBC is an identity-based cryptography system. In the traditional public key cryptography system, the public key of a user is a string of random numbers, and the correspondence between the public key and the user's identity needs to be verified through digital certificates and other means. In IBC, the public key of a user can be directly generated from the user's identity (such as an email address, an identity card number, etc.), and the private key is generated by the Private Key Generator (PKG) according to the system master key and the user's identity and securely distributed to the user.

[0037] Post-Quantum cryptography (PQC) is a new generation of cryptographic algorithm that can resist quantum computing attacks on existing cryptographic algorithms, and can ensure the security of the cryptographic algorithm in a quantum environment.

[0038] Digital Signature: Digital signature is a method of verifying the authenticity and integrity of electronic documents using asymmetric encryption technology.

[0039] The digital signature in the identity-based cryptography algorithm is denoted as an identity-based cryptography digital signature operation, and the public key used is denoted as an identity-based cryptography public key. The digital signature in the post-quantum cryptography algorithm is denoted as a post-quantum digital signature operation, and the public key used is denoted as a post-quantum digital signature algorithm public key. The post-quantum cryptography algorithm also has a post-quantum key encapsulation algorithm public key, which is used to encrypt the session.

[0040] The specific implementation of the embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0041] Figure 1 A schematic diagram showing the structure of an identity processing system in an embodiment of the present disclosure, which can apply the identity processing method or identity processing apparatus in various embodiments of the present disclosure.

[0042] As shown in Figure 1 , the system architecture can include a user 101 and a public key management center 102. The user 101 can be various electronic devices, including but not limited to mobile phones, computers, and tablets, etc., and the public key management center 102 can be various servers. The user 101 can perform identity authentication, query the public key of other users, and update his own public key, etc. in the public key management center 102.

[0043] Figure 2 A flowchart showing an identity processing method in an embodiment of the present disclosure, which is applied to the public key management center side, as shown in Figure 2 , the method includes the following steps: S201: Receive an authentication string for identity authentication sent by a first user, where the authentication string includes first signature data, a first identification signature, and a post-quantum signature, where the first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; S202, calculating the identification cryptographic algorithm public key of the first user based on the user identifier of the first user; S203, querying the first user's post-quantum digital signature algorithm public key based on the first user's identification cryptographic algorithm public key; S204: Verify the first identification signature in the authentication string according to the first user's identification cryptographic algorithm public key, and verify the post-quantum signature in the authentication string according to the first user's post-quantum digital signature algorithm public key. After both verifications pass, it is determined that the identity authentication of the first user is successful.

[0044] Based on the first user's user identifier, the first user's identification cryptographic algorithm public key is calculated using the identification cryptographic algorithm. A key information table is maintained in the public key management center to store the correspondence between the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key. Based on the first user's identification cryptographic algorithm public key, the first user's post-quantum digital signature algorithm public key is retrieved from the key information table.

[0045] The first identification signature in the authentication string is then verified using the first user's identification cryptographic algorithm public key. If the data in the first identification signature obtained is identical to the first signature data, the authentication is determined to have passed. The post-quantum signature in the authentication string is then verified using the first user's post-quantum digital signature algorithm public key. If the data in the post-quantum signature obtained is identical to the first signature data, the authentication is determined to have passed. If both verifications pass, the first user's identity authentication with the public key management center is completed. If either verification fails, the authentication is determined to have failed.

[0046] According to the technical solution provided by the embodiment of the present disclosure, an authentication string for identity authentication sent by the first user is received, wherein the authentication string includes the first signature data, the first identification signature and the post-quantum signature, and the first identification signature and the post-quantum signature are obtained by performing the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation on the first signature data respectively; the identification cryptographic algorithm public key of the first user is calculated based on the user identification of the first user; the post-quantum digital signature algorithm public key of the first user is queried based on the identification cryptographic algorithm public key of the first user; the first identification signature in the authentication string is verified according to the identification cryptographic algorithm public key of the first user, and the post-quantum signature in the authentication string is verified according to the post-quantum digital signature algorithm public key of the first user. After both verifications are passed, it is determined that the identity authentication of the first user is successful. Through the above technical means, the problem that the quantum algorithm affects identity processing in the prior art, resulting in the lack of security in identity processing, is solved, and then the user data is double-signed to ensure communication security.

[0047] In an optional embodiment, the first signature data includes a timestamp and a center identifier. The timestamp and center identifier in the first signature data are verified. If the verification is successful, the first user's identification cryptographic algorithm public key is calculated based on the first user's user identifier. If the verification fails, the identity authentication may be directly determined to have failed.

[0048] When the timestamp is within the preset range, the timestamp verification is confirmed to have passed. When the center identifier in the first signature data is consistent with the center identifier of the public key management center, the center identifier verification is confirmed to have passed. The disclosed embodiment can improve the efficiency of identity authentication and avoid resource waste through the above technical means.

[0049] Figure 3 A flowchart of a method for querying a user public key in an embodiment of the present disclosure is shown. The method is applied to a public key management center. Figure 3 As shown, the following steps are included: S301, receiving a public key query request sent by a first user, wherein the public key query request carries an identification cryptographic algorithm public key of a second user to be queried; S302: querying the second user's post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key based on the second user's identification cryptographic algorithm public key; S303, performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the second signature data composed of the identification cryptographic algorithm public key, the post-quantum digital signature algorithm public key, and / or the post-quantum key encapsulation algorithm public key of the second user in sequence to obtain a first dual signature; S304: Send the second signature data and the first dual signature to the first user.

[0050] After receiving the public key query request sent by the first user, the identification cryptographic algorithm public key of the second user to be queried is identified from the public key query request, and based on the identification cryptographic algorithm public key of the second user, the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the second user is queried in the key information table. The second signature data composed of the identification cryptographic algorithm public key, post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the second user is used, and the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation are performed on the second signature data in sequence to obtain a first double signature. Finally, the second signature data and the first double signature are sent together to the first user. After the first user verifies the signature, the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the second user can be obtained. The embodiment of the present disclosure avoids the impact of quantum algorithms on communication security through the above-mentioned technical means, and ensures that the user public key will not be leaked during the query process.

[0051] Figure 4 A flowchart of a method for updating a user public key in an embodiment of the present disclosure is shown. The method is applied to a public key management center. Figure 4 As shown, the following steps are included: S401: Receive third signature data and a second identification signature sent by a first user, where the third signature data includes a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second identification signature is obtained by performing an identification cryptographic algorithm digital signature operation on the third signature data; S402, calculating the identification cryptographic algorithm public key of the first user based on the user identifier of the first user; S403: Verify the second identification signature according to the identification cryptographic algorithm public key of the first user. After the verification is successful, update the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the first user in the key information table.

[0052] Based on the first user's user identifier, the first user's identifier cryptographic algorithm public key is calculated using the identifier cryptographic algorithm. The second identifier signature is verified based on the first user's identifier cryptographic algorithm public key. If the data in the second identifier signature obtained is the same as the third signature data, the verification is determined to have passed. After the verification is passed, the first user's public key is updated in the key information table using the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key in the third signature data. Through the above-mentioned technical means, the disclosed embodiments can quickly update user public keys and improve efficiency.

[0053] In an optional embodiment, the third signature data includes a timestamp. The timestamp in the third signature data is verified; if the verification is successful, the first user's identification cryptographic algorithm public key is calculated based on the first user's user identifier. If the verification fails, the user public key update can be directly determined to have failed. The disclosed embodiments utilize the above-described technical measures to improve the efficiency of updating user public keys.

[0054] In one embodiment of the present disclosure, after determining that the identity authentication of the first user is successful, the method also includes: receiving third signature data and a second dual signature sent by the first user, wherein the third signature data includes a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second dual signature is obtained by sequentially performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the third signature data; calculating the identification cryptographic algorithm public key of the first user based on the user identifier of the first user, and querying the post-quantum digital signature algorithm public key of the first user based on the identification cryptographic algorithm public key of the first user; verifying the second dual signature according to the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the first user, and after the verification is passed, updating the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the first user in the key information table.

[0055] To mitigate the impact of quantum algorithms on communication security and prevent the leakage of user public keys, when the first user updates their public key, they perform both an identification cryptographic algorithm digital signature and a post-quantum digital signature on the third signature data. The corresponding public key management center verifies the second dual signature sent by the first user based on the first user's identification cryptographic algorithm public key and post-quantum digital signature algorithm public key.

[0056] Figure 5 A flowchart of an identity processing method according to an embodiment of the present disclosure is shown. The method is applied to a first user side. Figure 5 As shown, the following steps are included: S501, obtaining the central identifier of the post-quantum cryptography public key management center, and using the current timestamp and the central identifier to form first signature data; S502, performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data to generate a first identification signature and a post-quantum signature; S503: The first signature data, the first identification signature, and the post-quantum signature are combined into an authentication string, and sent to a post-quantum cryptography public key management center for identity authentication.

[0057] The first user uses their own identification signature private key to perform an identification cryptographic algorithm digital signature operation on the first signature data to obtain a first identification signature. They then use their own post-quantum signature private key to perform a post-quantum digital signature operation on the first signature data to obtain a post-quantum signature. The first signature data, the first identification signature, and the post-quantum signature are then combined into an authentication string, which is sent to a post-quantum cryptography public key management center. The post-quantum cryptography public key management center then authenticates the first user based on the authentication string.

[0058] According to the technical solution provided by the embodiment of the present disclosure, an authentication string for identity authentication sent by a first user is received, wherein the authentication string includes first signature data, a first identification signature, and a post-quantum signature. The first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; the identification cryptographic algorithm public key of the first user is calculated based on the user identification of the first user; and the post-quantum digital signature algorithm public key of the first user is queried based on the identification cryptographic algorithm public key of the first user. Through the above technical means, the problem in the prior art that quantum algorithms affect identity processing, resulting in the lack of security in identity processing, is solved, and user data is double-signed to ensure communication security.

[0059] Figure 6 A flowchart of a method for querying a user public key in an embodiment of the present disclosure is shown. The method is applied to a first user side, such as Figure 6 As shown, the following steps are included: S601, after sending a public key query request for querying the identification cryptographic algorithm public key of a second user to a post-quantum cryptography public key management center, receiving second signature data and a first dual signature fed back by the post-quantum cryptography public key management center, wherein the second signature data includes the identification cryptographic algorithm public key, the post-quantum digital signature algorithm public key, and / or the post-quantum key encapsulation algorithm public key of the second user, and the first dual signature is obtained by sequentially performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the second signature data; S602, obtaining the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptographic public key management center; S603, verifying the first dual signature in turn according to the identification cryptography algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center. After the verification is passed, obtaining the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the second user.

[0060] The identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center are public, and the first user side can query and obtain the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center. The first double signature is verified according to the identification cryptographic algorithm public key of the post-quantum cryptography public key management center to obtain a verification result, and then the verification result is verified according to the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center. If the data obtained in this verification is the same as the second signature data, the verification is confirmed to be successful, and the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the second user are obtained. The embodiment of the present disclosure avoids the impact of quantum algorithms on communication security through the above-mentioned technical means, and ensures that the user's public key will not be leaked during the query process.

[0061] Figure 7 A flowchart of a method for updating a user public key in an embodiment of the present disclosure is shown. The method is applied to a first user side, such as Figure 7 As shown, the following steps are included: S701, using the current timestamp, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key to form third signature data; S702, performing a digital signature operation using an identification cryptographic algorithm on the third signature data to generate a second identification signature; S703: Send the third signature data and the second identification signature to the post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

[0062] The first user uses their own private identification signature key to perform an identification cryptographic algorithm digital signature operation on the third signature data, obtaining a second identification signature. The third signature data and the second identification signature are then sent together to the post-quantum cryptography public key management center. The post-quantum cryptography public key management center updates the first user's post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key in the key information table based on the third signature data and the second identification signature. The disclosed embodiments utilize the aforementioned technical means to rapidly update user public keys, improving efficiency.

[0063] In one embodiment of the present disclosure, after determining that the identity authentication is successful, the method further includes: using the current timestamp, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key to form a third signature data; performing an identification cryptography algorithm digital signature operation and a post-quantum digital signature operation on the third signature data in sequence to generate a second dual signature; and sending the third signature data and the second dual signature to a post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

[0064] In order to avoid the impact of quantum algorithms on communication security and ensure that user public keys will not be leaked, when the first user updates the user public key, the third signature data is sequentially subjected to the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation.

[0065] Through the above technical means, based on the PQC public key query function, users can: Verify the other party's PQC digital signature (post-quantum signature) based on its PQC digital signature algorithm public key (post-quantum digital signature algorithm public key) to achieve identity authentication or data integrity protection.

[0066] Based on the other party's PQC key encapsulation algorithm public key, the symmetric key is shared with the other party, thereby achieving secure communication between the two parties.

[0067] It can also be used in combination with the IBC algorithm and PQC algorithm to implement various IBC and PQC hybrid solutions.

[0068] Based on the same inventive concept, the present disclosure also provides an identity processing device, such as the following embodiment. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0069] Figure 8 A schematic diagram of an identity processing device according to an embodiment of the present disclosure is shown, which is applied to a public key management center. Figure 8 As shown, the identity processing device may include: Receiving module 801 is configured to receive an authentication string sent by a first user for identity authentication, wherein the authentication string includes first signature data, a first identification signature, and a post-quantum signature, where the first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; A calculation module 802 is configured to calculate an identification cryptographic algorithm public key of the first user based on the user identification of the first user; A query module 803 is configured to query the first user's post-quantum digital signature algorithm public key based on the first user's identification cryptographic algorithm public key; The signature verification module 804 is configured to verify the first identification signature in the authentication string according to the first user's identification cryptographic algorithm public key, and verify the post-quantum signature in the authentication string according to the first user's post-quantum digital signature algorithm public key. After both verifications are passed, it is determined that the identity authentication of the first user is successful.

[0070] According to the technical solution provided by the embodiment of the present disclosure, an authentication string for identity authentication sent by the first user is received, wherein the authentication string includes the first signature data, the first identification signature and the post-quantum signature, and the first identification signature and the post-quantum signature are obtained by performing the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation on the first signature data respectively; the identification cryptographic algorithm public key of the first user is calculated based on the user identification of the first user; the post-quantum digital signature algorithm public key of the first user is queried based on the identification cryptographic algorithm public key of the first user; the first identification signature in the authentication string is verified according to the identification cryptographic algorithm public key of the first user, and the post-quantum signature in the authentication string is verified according to the post-quantum digital signature algorithm public key of the first user. After both verifications are passed, it is determined that the identity authentication of the first user is successful. Through the above technical means, the problem that the quantum algorithm affects identity processing in the prior art, resulting in the lack of security in identity processing, is solved, and then the user data is double-signed to ensure communication security.

[0071] In one embodiment, the calculation module 802 is further configured to verify the timestamp and the center identifier in the first signature data, and if the verification is successful, calculate the first user's identification cryptographic algorithm public key based on the first user's user identifier. If the verification fails, it can be directly determined that the identity authentication has failed.

[0072] In one embodiment, the signature verification module 804 is further configured to receive a public key query request sent by the first user, wherein the public key query request carries the identification cryptographic algorithm public key of the second user to be queried; query the second user's post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key based on the second user's identification cryptographic algorithm public key; perform identification cryptographic algorithm digital signature operation and post-quantum digital signature operation on the second signature data composed of the second user's identification cryptographic algorithm public key, post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key in sequence to obtain a first dual signature; and send the second signature data and the first dual signature to the first user.

[0073] In one embodiment, the signature verification module 804 is further configured to receive a third signature data and a second identification signature sent by the first user, wherein the third signature data includes a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second identification signature is obtained by performing an identification cryptographic algorithm digital signature operation on the third signature data; calculate the identification cryptographic algorithm public key of the first user based on the user identifier of the first user; verify the second identification signature according to the identification cryptographic algorithm public key of the first user, and after the verification is passed, update the post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key of the first user in the key information table.

[0074] In one embodiment, signature verification module 804 is further configured to verify the timestamp in the third signature data; if verification is successful, the first user's identification cryptographic algorithm public key is calculated based on the first user's user identifier. If verification fails, the user public key update can be directly determined to have failed. The disclosed embodiments utilize the aforementioned technical measures to improve the efficiency of updating user public keys.

[0075] In one embodiment, the signature verification module 804 is further configured to receive a third signature data and a second dual signature sent by the first user, wherein the third signature data includes a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second dual signature is obtained by sequentially performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the third signature data; calculating the identification cryptographic algorithm public key of the first user based on the user identifier of the first user, and querying the post-quantum digital signature algorithm public key of the first user based on the identification cryptographic algorithm public key of the first user; verifying the second dual signature based on the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the first user, and after the verification is passed, updating the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the first user in the key information table.

[0076] Figure 9 A schematic diagram of an identity processing device according to an embodiment of the present disclosure is shown, wherein the identity processing device is applied to a public key management center. Figure 9 As shown, the identity processing device may include: An acquisition module 901 is configured to obtain a central identifier of a post-quantum cryptography public key management center, and use the current timestamp and the central identifier to form first signature data; Signature module 902 is configured to perform an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively, to generate a first identification signature and a post-quantum signature; The sending module 903 is configured to combine the first signature data, the first identification signature and the post-quantum signature into an authentication string, and send it to the post-quantum cryptography public key management center for identity authentication.

[0077] According to the technical solution provided by the embodiment of the present disclosure, an authentication string for identity authentication sent by a first user is received, wherein the authentication string includes first signature data, a first identification signature, and a post-quantum signature. The first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; the identification cryptographic algorithm public key of the first user is calculated based on the user identification of the first user; and the post-quantum digital signature algorithm public key of the first user is queried based on the identification cryptographic algorithm public key of the first user. Through the above technical means, the problem in the prior art that quantum algorithms affect identity processing, resulting in the lack of security in identity processing, is solved, and user data is double-signed to ensure communication security.

[0078] In one embodiment, the sending module 903 is further configured to send a public key query request for querying the identification cryptographic algorithm public key of the second user to the post-quantum cryptography public key management center, and then receive the second signature data and the first dual signature fed back by the post-quantum cryptography public key management center, wherein the second signature data includes the identification cryptographic algorithm public key, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the second user, and the first dual signature is obtained by sequentially performing the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation on the second signature data; S602, obtaining the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center; S603, verifying the first dual signature in turn according to the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center, and after the verification is passed, obtaining the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the second user.

[0079] In one embodiment, the sending module 903 is further configured to use the current timestamp, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key to form a third signature data; perform an identification cryptography algorithm digital signature operation on the third signature data to generate a second identification signature; and send the third signature data and the second identification signature to the post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

[0080] In one embodiment, the sending module 903 is further configured to use the current timestamp, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key to form a third signature data; perform the identification cryptography algorithm digital signature operation and the post-quantum digital signature operation on the third signature data in sequence to generate a second dual signature; and send the third signature data and the second dual signature to the post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

[0081] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods, or program products. Therefore, various aspects of the present disclosure may be implemented in the following forms: entirely in hardware, entirely in software (including firmware, microcode, etc.), or in a combination of hardware and software, collectively referred to herein as "circuits," "modules," or "systems."

[0082] Refer to the following Figure 10 1000 according to this embodiment of the present disclosure will be described. Figure 10 The electronic device 1000 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0083] like Figure 10 As shown, electronic device 1000 is implemented as a general-purpose computing device. Components of electronic device 1000 may include, but are not limited to, the aforementioned at least one processing unit 1010, the aforementioned at least one storage unit 1020, and a bus 1030 connecting various system components (including storage unit 1020 and processing unit 1010).

[0084] The storage unit stores program code, and the program code can be executed by the processing unit 1010, so that the processing unit 1010 performs the steps described in the "Exemplary Method" section of this specification according to various exemplary embodiments of the present disclosure. For example, the processing unit 1010 can perform the following steps of the above-mentioned method embodiment: receiving an authentication string sent by a first user for identity authentication; calculating the first user's identification cryptographic algorithm public key based on the first user's user identity; querying the first user's post-quantum digital signature algorithm public key based on the first user's identification cryptographic algorithm public key; verifying the first identification signature in the authentication string based on the first user's identification cryptographic algorithm public key, and verifying the post-quantum signature in the authentication string based on the first user's post-quantum digital signature algorithm public key. After both verifications are passed, it is determined that the identity authentication of the first user is successful.

[0085] The storage unit 1020 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 10201 and / or a cache memory unit 10202 , and may further include a read-only memory unit (ROM) 10203 .

[0086] The storage unit 1020 may also include a program / utility 10204 having a set (at least one) of program modules 10205, such program modules 10205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0087] Bus 1030 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0088] Electronic device 1000 may also communicate with one or more external devices 1040 (e.g., a keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with electronic device 1000, and / or any device that enables electronic device 1000 to communicate with one or more other computing devices (e.g., a router, modem, etc.). This communication may occur via input / output (I / O) interface 1050. Furthermore, electronic device 1000 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via network adapter 1060. As shown, network adapter 1060 communicates with other modules of electronic device 1000 via bus 1030. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with electronic device 1000, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0089] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, terminal device, or network device) to execute the methods according to the embodiments of the present disclosure.

[0090] In the disclosed exemplary embodiments, a computer-readable storage medium is also provided. The computer-readable storage medium may be a readable signal medium or a readable storage medium.

[0091] In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product, which includes program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps of various exemplary implementations of the present disclosure described in the above "Specific Implementation Methods" section of this specification.

[0092] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0093] In the present disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0094] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0095] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, and conventional procedural programming languages ​​such as C or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0096] The present disclosure provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the identity processing method provided in any of the optional embodiments of the present disclosure.

[0097] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.

[0098] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0099] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, mobile terminal, or network device) to execute the methods according to the embodiments of the present disclosure.

[0100] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope of the present disclosure being indicated by the appended claims.

Claims

1. An identity processing method, applied to a public key management center, characterized in that: include: Receiving an authentication string for identity authentication sent by a first user, wherein the authentication string includes first signature data, a first identification signature, and a post-quantum signature, where the first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; Calculating an identification cryptographic algorithm public key of the first user based on the user identification of the first user; querying the first user's post-quantum digital signature algorithm public key based on the first user's identification cryptographic algorithm public key; The first identification signature in the authentication string is verified according to the identification cryptographic algorithm public key of the first user, and the post-quantum signature in the authentication string is verified according to the post-quantum digital signature algorithm public key of the first user. After both verifications are passed, it is determined that the identity authentication of the first user is successful.

2. The method according to claim 1, characterized in that After determining that the identity authentication of the first user is successful, the method further includes: Receiving a public key query request sent by the first user, wherein the public key query request carries an identification cryptographic algorithm public key of a second user to be queried; querying the second user's post-quantum digital signature algorithm public key and / or post-quantum key encapsulation algorithm public key based on the second user's identification cryptographic algorithm public key; performing the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation on the second signature data composed of the identification cryptographic algorithm public key, the post-quantum digital signature algorithm public key, and / or the post-quantum key encapsulation algorithm public key of the second user in sequence to obtain a first dual signature; The second signature data and the first dual signature are sent to the first user.

3. The method according to claim 1, characterized in that After determining that the identity authentication of the first user is successful, the method further includes: receiving third signature data and a second identification signature sent by the first user, wherein the third signature data includes a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second identification signature is obtained by performing the identification cryptographic algorithm digital signature operation on the third signature data; Calculating an identification cryptographic algorithm public key of the first user based on the user identification of the first user; The second identification signature is verified according to the identification cryptographic algorithm public key of the first user. After the verification is passed, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the first user is updated in the key information table.

4. The method according to claim 1, wherein After determining that the identity authentication of the first user is successful, the method further includes: receiving third signature data and a second dual signature sent by the first user, wherein the third signature data includes a post-quantum digital signature algorithm public key and / or a post-quantum key encapsulation algorithm public key, and the second dual signature is obtained by sequentially performing the identification cryptography algorithm digital signature operation and the post-quantum digital signature operation on the third signature data; Calculating the first user's identification cryptographic algorithm public key based on the first user's user identifier, and querying the first user's post-quantum digital signature algorithm public key based on the first user's identification cryptographic algorithm public key; The second dual signature is verified according to the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the first user. After the verification is passed, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the first user is updated in the key information table.

5. An identity processing method, applied to a first user side, characterized in that: include: Obtaining a central identifier of a post-quantum cryptography public key management center, and using the current timestamp and the central identifier to form first signature data; Performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data to generate a first identification signature and a post-quantum signature; The first signature data, the first identification signature and the post-quantum signature form an authentication string, and send it to the post-quantum cryptography public key management center for identity authentication.

6. The method according to claim 5, characterized in that After determining that the identity authentication is successful, the method further includes: After sending a public key query request for querying the identification cryptographic algorithm public key of the second user to the post-quantum cryptography public key management center, receiving second signature data and a first dual signature fed back by the post-quantum cryptography public key management center, wherein the second signature data includes the identification cryptographic algorithm public key, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the second user, and the first dual signature is obtained by sequentially performing the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation on the second signature data; Obtaining the identification cryptographic algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center; The first dual signature is verified in sequence according to the identification cryptography algorithm public key and the post-quantum digital signature algorithm public key of the post-quantum cryptography public key management center. After the verification is passed, the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key of the second user is obtained.

7. The method according to claim 5, characterized in that After determining that the identity authentication is successful, the method further includes: Utilizing the current timestamp, the post-quantum digital signature algorithm public key, and / or the post-quantum key encapsulation algorithm public key to form third signature data; Performing an identification cryptographic algorithm digital signature operation on the third signature data to generate a second identification signature; The third signature data and the second identification signature are sent to the post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

8. The method according to claim 5, characterized in that After determining that the identity authentication is successful, the method further includes: Utilizing the current timestamp, the post-quantum digital signature algorithm public key, and / or the post-quantum key encapsulation algorithm public key to form third signature data; performing the identification cryptographic algorithm digital signature operation and the post-quantum digital signature operation on the third signature data in sequence to generate a second dual signature; The third signature data and the second dual signature are sent to the post-quantum cryptography public key management center to update the post-quantum digital signature algorithm public key and / or the post-quantum key encapsulation algorithm public key in the key information table of the post-quantum cryptography public key management center.

9. An identity processing device, applied to a public key management center, characterized in that: include: a receiving module configured to receive an authentication string sent by a first user for identity authentication, wherein the authentication string includes first signature data, a first identification signature, and a post-quantum signature, wherein the first identification signature and the post-quantum signature are obtained by performing an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively; A calculation module, configured to calculate an identification cryptographic algorithm public key of the first user based on the user identification of the first user; A query module configured to query the first user's post-quantum digital signature algorithm public key based on the first user's identification cryptographic algorithm public key; The signature verification module is configured to verify the first identification signature in the authentication string according to the first user's identification cryptographic algorithm public key, and verify the post-quantum signature in the authentication string according to the first user's post-quantum digital signature algorithm public key. After both verifications are passed, it is determined that the identity authentication of the first user is successful.

10. An identity processing device, applied to a first user side, characterized in that: include: an acquisition module configured to obtain a central identifier of a post-quantum cryptography public key management center, and to compose first signature data using a current timestamp and the central identifier; a signature module configured to perform an identification cryptographic algorithm digital signature operation and a post-quantum digital signature operation on the first signature data, respectively, to generate a first identification signature and a post-quantum signature; The sending module is configured to combine the first signature data, the first identification signature and the post-quantum signature into an authentication string, and send the authentication string to the post-quantum cryptography public key management center for identity authentication.

Citation Information

Patent Citations

  • Anti-quantum computing RFID authentication method and system based on asymmetric key pool and IBS

    CN110768782A

  • Identity authentication method and system

    CN119519980A

  • Certificate-based encryption implemented with multiple encryption schemes

    US20250086321A1