Session key negotiation method and system reusing partial static public key
By reusing a session key negotiation method that partially reuses static public keys, the computational efficiency and communication bandwidth of the AKE protocol are optimized, and security is enhanced. It is applicable to protocols such as TLS 1.3, Signal, and WireGuard, and solves the security and efficiency problems of existing technologies under the threat of quantum computing.
Patent Information
- Application Number
- CN202511298283.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-11
- Publication Date
- 2025-11-18
AI Technical Summary
Existing quantum-resistant session key negotiation technologies are insufficient in terms of overall efficiency, security, and ease of deployment, and face the threat of quantum computing, especially in protocols such as TLS 1.3, Signal, and WireGuard. The communication bandwidth and computational efficiency of the existing AKE protocol need to be improved.
A session key negotiation method that reuses a portion of the static public key is adopted. By generating long-term static public/private key pairs for the session initiating user and the receiving user, the session state is generated and stored using a portion of the long-term static public key, reducing random sampling and communication transmission. The AKE protocol is designed and optimized by combining the LWE/LWR problem in lattice cipher.
While maintaining the same level of security, it reduces computational complexity and communication bandwidth, enhances protocol security, resists attacks such as temporary secret leakage, maximum leakage, and key leakage spoofing, provides implicit authentication and stronger security, and is suitable for AKE handshake modules of protocols such as TLS 1.3, Signal, and WireGuard.
Smart Images

Figure CN120979654A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication security, in particular to a session key agreement method and system reusing part of static public key. BACKGROUND
[0002] In today's large-scale network communication (Internet, mobile communication, etc.), generally, the communication parties first negotiate a session key through a public key authentication key exchange protocol (AKE, Authenticated Key Exchange), and then use a packet encryption method to transmit information. The basic AKE protocol is the cornerstone of many modern communication core security protocols, and has important applications in the handshake processes of different protocols with wide application in network layer (such as IPsec / IKEv2, WireGuard protocol), transport layer (such as TLS1.3 protocol), application layer (such as Signal protocol) and other aspects.
[0003] With the rapid development of quantum computing theory and quantum computer technology, the AKE protocols commonly used in application protocols such as TLS1.3, Signal, WireGuard and widely applied in network information system transmission, which are based on classical number theory problems such as large integer factorization and discrete logarithm, are severely threatened. A basic one-round AKE protocol can be designed based on public key encryption or key encapsulation that meets certain security requirements combined with a hash function. With the publication of the first batch of anti-quantum encryption / key encapsulation commercial cryptographic standards by the United States NIST in 2024, the encryption / key encapsulation algorithms in the AKE components used in the commonly used communication protocols such as TLS1.3, Signal, WireGuard, which play a role in handshake, also face the problem of transition to post-quantum cryptography.
[0004] The existing session key agreement technology based on anti-quantum AKE protocol has deficiencies in comprehensive efficiency, security and easy deployment, etc., which poses a potential threat to network communication. SUMMARY
[0005] In order to solve the above problems, the present application proposes a session key agreement method and system reusing part of static public key, which improves the method of generating first message and session state for session initiator user, reuses part of long-term static public key of session initiator user, and reduces random sampling in calculation, reduces communication bandwidth in communication transmission, while ensuring the theoretical security of AKE protocol.
[0006] According to some embodiments, the present application adopts the following technical solution: A session key agreement method reusing part of static public key, for negotiating a session key between a session initiator user and a session receiver user with security communication needs, comprising: generating a respective long-term static public / private key pair for the session initiating user and the session receiving user; based on the long-term static private key of the session initiating user, the long-term static public key of the session receiving user and the random number, the session initiating user generates a first message and a session state stored locally by reusing part of the long-term static public key, and sends the first message to the session receiving user; based on the received first message, the long-term static private key of the session receiving user, the long-term static public key of the session initiating user and the random number, the session receiving user generates a second message and a second session key stored locally, and sends the second message to the session initiating user; based on the received second message, the long-term static private key of the session initiating user, the long-term static public key of the session receiving user and the session state stored locally, the session initiating user generates a first session key stored locally; wherein the first session key and the second session key are respectively used for the session initiating user and the session receiving user to encrypt and transmit a communication message.
[0007] According to some embodiments, the present application adopts the technical scheme as follows: A session key agreement system reusing part of static public key, comprising a static key generation end, a session initiating user end and a session receiving user end: The static key generation end is configured to generate a respective long-term static public / private key pair for the session initiating user and the session receiving user; The session initiating user end is configured to, based on the long-term static private key of the session initiating user, the long-term static public key of the session receiving user and the random number, the session initiating user generates a first message and a session state stored locally by reusing part of the long-term static public key, and sends the first message to the session receiving user; The session receiving user end is configured to, based on the received first message, the long-term static private key of the session receiving user, the long-term static public key of the session initiating user and the random number, the session receiving user generates a second message and a second session key stored locally, and sends the second message to the session initiating user; The session initiating user end is configured to, based on the received second message, the long-term static private key of the session initiating user, the long-term static public key of the session receiving user and the session state stored locally, the session initiating user generates a first session key stored locally; wherein the first session key and the second session key are respectively used for the session initiating user and the session receiving user to encrypt and transmit a communication message.
[0008] According to some embodiments, the present application adopts the technical scheme as follows: A computer program product comprising a computer program which, when executed by a processor, implements the session key agreement method reusing a partial static public key.
[0009] According to some embodiments, the present application adopts the technical scheme as follows: A non-transitory computer-readable storage medium for storing computer instructions, which, when executed by a processor, implement the session key agreement method reusing a partial static public key.
[0010] According to some embodiments, the present application adopts the technical scheme as follows: An electronic device comprising a processor, a memory and a computer program, wherein the processor is connected with the memory, and the computer program is stored in the memory, and when the electronic device is running, the processor executes the computer program stored in the memory to enable the electronic device to implement the session key agreement method reusing a partial static public key.
[0011] Compared with the prior art, the present application has the beneficial effects that: The general construction method provided by the present application has lower computational complexity and less communication bandwidth under the condition of having the same theoretical security, and can prove to meet at least CK+ or IND-AA security (in fact, stronger security can be defined), in particular (assuming that the two communication parties are users and ): (1) Implicit authentication: only the user who has the long-term static private key and and honestly participates in the session (and thus knows the random number or session state used by the relevant algorithm) can possibly calculate the same session key, and the protocol execution process does not need to use message authentication codes or digital signatures to display whether the two communication parties have calculated the same session key.
[0012] (2) Resistance to temporary secret leakage attack: in the case where the enemy knows the temporary random number , and the session state used in the session of the honest communication parties, the final session key cannot be calculated. Because the protocol design makes the enemy (without knowing the user's long-term static private key) not know the session key and at this time. Note that here, the enemy can know the random number and the session state used in the session at the same time, and thus the security can be defined to be stronger than CK+ and IND-AA.
[0013] (3) Resisting maximum leakage attack: the adversary knows the long-term static private key of one party and the ephemeral secret information of the other party at the same time, and cannot calculate the final session key when both parties are honest, because the protocol design makes the adversary not know the secret information contained in the public transmission message or at this time (without knowing the long-term static private key of one party and the ephemeral secret information of the other party at the same time) to calculate the session key or .
[0014] (4) Weak forward security: the adversary does not actively intervene in the session at the time of session occurrence, does not know the ephemeral secret information used in the session, but knows the long-term static private keys of both parties, and at this time the adversary cannot calculate the final session key, because the protocol design makes the adversary not know the secret information in the partial ciphertext contained in the public transmission message at this time to calculate the session key or .
[0015] (5) Resisting key leakage masquerade attack: the adversary knows the long-term static private key of one party (assuming ), and impersonates to communicate with in the session, and the adversary cannot calculate the final session key, because the protocol design makes the adversary not know the secret information contained in the public transmission message at this time to calculate the session key or .
[0016] The optimization method of the present application is applicable to AKE protocols designed based on PKE / KEM designed based on LWE or LWR problem, and is also applicable to AKE handshake modules in TLS 1.3, Signal, WireGuard and the like (the related modules use two independent PKE or KEM for key agreement).
[0017] The drawings constituting a part of the specification of the present application are used to provide a further understanding of the present application, and the illustrative embodiments of the present application and the description thereof are used to explain the present application, and do not constitute an improper limitation on the present application.
[0018] Figure 1 is the flowchart of the session key agreement and secure communication in embodiment 1. Figure 2 is the process diagram of the session key agreement by AKE protocol in embodiment 1. DETAILED DESCRIPTION
[0019] The application will be further described below with reference to the accompanying drawings and embodiments.
[0020] It should be noted that the following detailed description is exemplary in nature and is intended to provide further description of the application. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs.
[0021] It should be noted that the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit exemplary embodiments according to the present application. As used herein, the singular form is intended to include the plural form unless the context clearly indicates otherwise, and it should also be understood that when the terms "comprise" and / or "comprises" are used in the specification, there is a reference to the presence of a feature, step, operation, device, component, and / or combinations thereof.
[0022] How to reduce the communication bandwidth of the AKE protocol and improve the computing efficiency of the AKE algorithm under similar quantum security strength is a problem to be solved; for many practical network protocols, comprehensive efficiency, security and easy deployment are the key points in design, among which security is the most important, but transmission bandwidth and computing efficiency cannot be ignored. Under similar security strength, lattice cryptography has certain disadvantages in public key ciphertext size or computing efficiency compared with traditional public key cryptography such as RSA and ECC. Considering the wide application of AKE protocol and the process of American post-quantum cryptography standardization (the comprehensive performance of lattice cryptography is the best among all quantum-resistant alternative cryptography), it is of practical significance to study the optimization design of lattice-based basic quantum-resistant AKE protocol, and the optimization and post-quantum migration of AKE related modules in the above protocol to cope with the potential threat of quantum computers.
[0023] The present application is dedicated to giving an AKE protocol optimization design with smaller communication bandwidth, faster computing efficiency and stronger security compared with the known lattice-based AKE protocol design technical route at present, and an optimization design method of authentication key exchange protocol based on LWE / LWR and other commonly used mathematical problems in lattice is used for session key agreement, the related method is applicable to the authentication key exchange protocol designed by combining two sets of public key encryption or key encapsulation algorithm, and in particular, can be applied to the handshake process of security protocols with wide application such as TLS 1.3, WireGuard, Signal, IPsec / IKEv2.
[0024] Embodiment 1 In an embodiment of the present application, a session key agreement method reusing a partial static public key is provided, which is used for negotiating a session key between a session initiating user and a session receiving user with a security communication requirement, and includes the following steps. Step S1: generating a respective long-term static public / private key pair for a session initiating user and a session receiving user; Step S2: based on the long-term static private key of the session initiating user, the long-term static public key of the session receiving user and a random number, reusing part of the long-term static public key, the session initiating user generates a first message and a locally stored session state, and sends the first message to the session receiving user; Step S3: based on the received first message, the long-term static private key of the session receiving user, the long-term static public key of the session initiating user and the random number, the session receiving user generates a second message and a locally stored second session key, and sends the second message to the session initiating user; Step S4: based on the received second message, the long-term static private key of the session initiating user, the long-term static public key of the session receiving user and the locally stored session state, the session initiating user generates a locally stored first session key; Wherein, the first session key and the second session key are respectively used for the session initiating user and the session receiving user to encrypt and transmit a communication message.
[0025] As an embodiment, the session key agreement method of the application reuses part of the long-term static public key of the session initiating user, improves the method of generating a first message and a session state for the session initiating user, reduces random sampling and communication transmission in calculation, and guarantees theoretical security. The specific implementation process is described in detail below, wherein the session initiating user, the session receiving user, the first message, the second message, the first session key and the second session key are respectively referred to as user , user , message , message , session key , session key .
[0026] In view of the problems of the current lattice-based authentication key exchange protocol, such as the need to improve the calculation efficiency and the large communication bandwidth, the embodiment takes the NIST standard algorithm ML-KEM as an example, and gives an optimization design method of an AKE protocol meeting strong security and implicit rejection, which is designed by using a public key encryption scheme meeting IND-CPA security and a KEM scheme meeting IND-CCA security as components. Similar methods can be used for: (1) optimization of AKE protocol designed based on public key encryption meeting OW / IND-CPA security and public key encryption meeting OW / IND-CCA security; (2) optimization of AKE protocol designed based on key encapsulation meeting OW / IND-CPA security and key encapsulation meeting OW / IND-CCA security; (3) Optimization of the AKE protocol based on key encapsulation that satisfies OW / IND-CPA security and public key encryption that satisfies OW / IND-CCA security.
[0027] Meanwhile, the relevant methods can be used to optimize AKE components designed with two public key primitives (key encapsulation and public key encryption) in protocols such as TLS 1.3, WireGuard, Signal, and IPsec / IKEv2.
[0028] In typical network communication, session key negotiation and secure communication between users can be simplified to: Figure 1 The situation shown. In the system, Public Key Infrastructure (PKI) is responsible for user management and distributing long-term public and private keys to users. This includes registration, certificate distribution, identity authentication, and cancellation. A user's identity is bound to a public and private key, and different users can communicate with each other at appropriate times as needed.
[0029] When two users want to communicate securely, firstly, one user... As the initiator, to the other user (with whom it expects to communicate). Send the necessary messages as specified in the protocol, as well as the messages required by AKE to calculate the session key. .
[0030] Then, the user Received message Then, return the necessary messages as specified in the protocol, as well as the messages required by AKE to calculate the session key. .
[0031] Finally, the user and Each party receives a session key for this round of communication and uses this session key in conjunction with block encryption to begin secure communication; after a certain period of time (or after the time limit specified in the protocol), the session key expires and the current round of communication ends.
[0032] In this embodiment, the above-mentioned AKE protocol is referred to as a one-round interactive AKE protocol, that is, the two communicating parties only need to perform one round of interaction.
[0033] A one-round interactive AKE protocol consists of four algorithms. Composition, through a round of interaction between users The process of negotiating the session key is as follows Figure 2 As shown, specifically: algorithm It is a probabilistic polynomial time (PPT) algorithm, with a safety parameter as input. (The default security parameters are the implicit inputs for all algorithms), the output is for a specific user. Long-term static public / private key pairs .
[0034] algorithm This is the PPT algorithm, initiated by the session initiator. Execution, assuming the potential communication user for this session is user. ,but The input is for the user Long-term static private key ,user Long-term static public key and random numbers The corresponding output is what needs to be sent to the user. News And the session state to be stored locally .
[0035] algorithm This is the PPT algorithm, used by the session receiver. Execution, its input is the user Long-term static private key ,user Long-term static public key The messages it received and random numbers The output is what to send to the user. News and session key .
[0036] algorithm It is a deterministic multinomial-time algorithm, initiated by the session initiator. Execute, inputting its long-term static private key. ,user Long-term static public key Session status and messages The output is the session key. .
[0037] Combination Figure 1 and Figure 2 The formal application steps of the basic AKE-related protocols are as follows: (1) Different users participate in the public key system of the communication network, register, and obtain corresponding certificates, public and private keys through KPIs. Generating a public-private key, i.e. a long-term static public / private key pair ; (2) Assuming a user wants to have a secure communication with a user , an algorithm is run to compute the message required by the AKE protocol and the session state stored locally , and then the message is sent to the user along with the rest of the information specified by the communication protocol ; (3) After receiving the message, the user confirms that he wants to have a secure communication with the user , and then an algorithm is run to compute the message required by the AKE protocol and the session key for the current session , and then the message is sent to the user along with the rest of the information specified by the communication protocol ; (4) After receiving the message, the user confirms that it is for a session with the user , and then an algorithm is run to compute the session key for the current session ; (5) The two users and use the computed session key and to encrypt the communication messages by using the group encryption algorithm specified by the protocol, until the session is terminated or the time limit specified by the protocol is reached, and the corresponding session key expires.
[0038] In a communication network, the same user can simultaneously establish a session and negotiate a key with different users, and the same user can also negotiate a key with the same user at different times. The correctness of the AKE protocol guarantees that the session key and are the same with a probability close to , i.e. , where is a security parameter, and in practice, is generally less than .
[0039] At present, the AKE protocol is mainly designed by using public key encryption / key encapsulation, which is called FSXY general construction. The embodiment is based on the FSXY general construction to explain the session key agreement method of reusing part of static public key.
[0040] Firstly, a kind of variant construction form of the AKE protocol of the FSXY general construction is given to meet the PKE protocol of IND-CPA security and the KEM scheme of IND-CCA security : (1) : calculate .
[0041] sample , return . (2) : split into and . Calculate .Enc( ) and .KG( ), let , , return . (3) : split into and , and split into and . Let , calculate .Enc( ) and . , let , then calculate .Dec( ) and . return . (4) : will be split into and , will be split into and , will be split into , and . Recompute , and . Recompute .Enc( ), and .Dec( ) and .Dec( ). Finally, compute and output . In the above construction, the functions , , , , are all hash functions, which are treated as random oracles in security proofs. Among them, , and are used to provide randomness and have no impact on provable security.
[0042] It is worth noting that in practical AKE protocols, the input of the function when computing the final session key will contain some information such as protocol version number, unique session identifier, etc. To simplify the discussion, this embodiment omits these inputs. In this embodiment, the uniform representation of the random space is denoted as , the plaintext space is denoted as , the ciphertext space is denoted as , and the key space is denoted as . The symbol is used to represent the uniform distribution on , and the symbol is used to represent the set of positive integers . It can be proved that the above construction satisfies at least CK+ or IND-AA security under the quantum random oracle model (QROM, Quantum Random Oracle Model).
[0043] Based on the AKE protocol of the FSXY general construction, the method for generating a first message and a session state for a session initiator user Improvements are made, part of the long-term static public key of the session initiation user is reused, random sampling and communication transmission are reduced in calculation, while the theoretical security is ensured. The following is an example of a simplified version of the NIST standard algorithm ML-KEM to illustrate the method of reusing part of the long-term static public key of the user in the embodiment: 、 、 and The method of reusing part of the long-term static public key of the user in the embodiment is illustrated as follows: (1) The key generation algorithm is: : Sampling , and calculating , Then sample , let , . Return . (2) The Init algorithm run by the session initiator is: : First, split into and , calculate .Enc( ). Then sample , and calculate . Let , and let . Finally, let , , return . The algorithms and are the same as the general construction of FSXY, and will not be repeated here.
[0044] The difference from the general construction is that in the algorithm , part of the long-term static public key of the user is reused when generating the temporary private key and . In this way, the sampling of the uniform random matrix and the communication transmission (included in ) are reduced in calculation, and in terms of security, it can be proved that both have the same theoretical security under the QROM model.
[0045] In the above construction, the long-term public key and the temporary public key Compression is performed, similar to the compression method adopted by Kyber in the algorithm design of the first round of NIST candidates, to further reduce storage space and communication bandwidth; the above method is also applicable to similar AKE related protocols designed based on the LWR problem, and is also applicable to the AKE handshake module in protocols such as TLS 1.3, Signal, WireGuard (designs containing long-term and temporary public and private key pairs using two public key encryption / key encapsulation protocols).
[0046] Embodiment 2 In an embodiment of the present application, a session key agreement system reusing part of a static public key is provided, comprising a static key generation end, a session initiation user end and a session receiving user end: The static key generation end is configured to generate a respective long-term static public / private key pair for the session initiation user and the session receiving user; The session initiation user end is configured to reuse part of the long-term static public key based on the long-term static private key of the session initiation user, the long-term static public key of the session receiving user and a random number, the session initiation user generates a first message and a locally stored session state, and sends the first message to the session receiving user; The session receiving user end is configured to generate a second message and a locally stored second session key based on the received first message, the long-term static private key of the session receiving user, the long-term static public key of the session initiation user and a random number, and send the second message to the session initiation user; The session initiation user end is configured to generate a locally stored first session key based on the received second message, the long-term static private key of the session initiation user, the long-term static public key of the session receiving user and the locally stored session state; The first session key and the second session key are respectively used by the session initiation user and the session receiving user to encrypt and transmit communication messages.
[0047] Embodiment 3 In an embodiment of the present application, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the session key agreement method reusing part of a static public key.
[0048] Embodiment 4 In an embodiment of the present application, a non-transitory computer readable storage medium is provided for storing computer instructions, which, when executed by a processor, implement the session key agreement method reusing part of a static public key.
[0049] Embodiment 5 An embodiment of the present application provides an electronic device, comprising a processor, a memory and a computer program; wherein the processor is connected with the memory, and the computer program is stored in the memory; when the electronic device is running, the processor executes the computer program stored in the memory, so that the electronic device executes a method for reusing a part of static public keys in session key agreement.
[0050] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus generate one or more means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in one or more flows and / or blocks.
[0051] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be executed on the computer or other programmable data processing apparatus to produce a computer-implemented process, so that the instructions executed by the computer or other programmable data processing apparatus provide one or more means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 one or more flows and / or blocks
[0052] The above describes the specific embodiments of the present application in conjunction with the drawings, but is not a limitation on the protection scope of the present application. It should be understood by those skilled in the art that various modifications or changes made on the basis of the technical solutions of the present application without creative labor are still within the protection scope of the present application.
Claims
1. A session key negotiation method that reuses a portion of a static public key, characterized in that, Used for negotiating session keys between session initiating and receiving users who require secure communication, including: Generate long-term static public / private key pairs for the session initiating user and the session receiving user; Based on the session initiator's long-term static private key, the session receiver's long-term static public key, and a random number, the session initiator reuses part of the long-term static public key, generates the first message and the session state stored locally, and sends the first message to the session receiver. Based on the received first message, the long-term static private key of the session receiving user, the long-term static public key of the session initiating user, and a random number, the session receiving user generates a second message and a second session key stored locally, and sends the second message to the session initiating user. Based on the received second message, the session initiating user's long-term static private key, the session receiving user's long-term static public key, and the session state stored locally, the session initiating user generates the first session key stored locally. The first session key and the second session key are used by the session initiating user and the session receiving user, respectively, to encrypt and transmit communication messages.
2. The session key negotiation method for reusing a portion of the static public key as described in claim 1, characterized in that, The long-term static public / private key pair is generated by a key generation algorithm during user registration in the communication network, specifically: sampling , and calculate ; sampling , make , ; return ,in, A long-term static public key. A long-term static private key. For long-term static public keys A portion of it is obtained through random sampling.
3. The session key negotiation method for reusing a portion of the static public key as described in claim 1, characterized in that, The generation of the first message and the session state stored locally are specifically as follows: The long-term static private key of the user who initiated the session Split into and ,calculate .Enc( ); sampling , and calculate ; make and order ,remember , ,return ; in, The long-term static public key of the user who initiates the session Part of For first news, This is the session state.
4. The session key negotiation method for reusing a portion of the static public key as described in claim 1, characterized in that, The generation of the second message and the second session key stored locally are specifically as follows: The session will receive the user's long-term static private key. Split into and and the first message Split into and ,remember ,calculate .Enc( )and . ; make ,calculate .Dec( )and ; return ; in, This is the second message. This is the second session key.
5. The session key negotiation method for reusing a portion of the static public key as described in claim 1, characterized in that, The generation of the first session key stored locally is specifically as follows: The long-term static private key of the user who initiated the session Split into and The second message Split into and , will session state Split into , and Recalculate .Enc( ), and calculate .Dec( )and .Dec( ); Calculate and output ; in, This is the first session key.
6. The session key negotiation method for reusing a portion of the static public key as described in claim 1, characterized in that, It also includes the fact that the two communicating parties use the negotiated first session key and second session key to encrypt and transmit communication messages until the session ends or the time limit specified in the agreement is reached, at which point the corresponding session key expires.
7. A session key negotiation system that reuses a portion of a static public key, characterized in that, This includes the static key generator, the session initiating client, and the session receiving client: The static key generator is configured to generate long-term static public / private key pairs for the session initiating user and the session receiving user. The session initiating user is configured to: based on the session initiating user's long-term static private key, the session receiving user's long-term static public key, and a random number, reuse part of the long-term static public key, generate the first message and the session state stored locally, and send the first message to the session receiving user. The session receiving user is configured to generate a second message and a second session key stored locally based on the received first message, the session receiving user's long-term static private key, the session initiating user's long-term static public key, and a random number, and then send the second message to the session initiating user. The session initiating user is configured to generate a first session key stored locally based on the received second message, the session initiating user's long-term static private key, the session receiving user's long-term static public key, and the session state stored locally. The first session key and the second session key are used by the session initiating user and the session receiving user, respectively, to encrypt and transmit communication messages.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements a session key negotiation method for reusing a portion of a static public key as described in any one of claims 1-6.
9. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium is used to store computer instructions, which, when executed by a processor, implement a session key negotiation method for reusing a portion of a static public key as described in any one of claims 1-6.
10. An electronic device, characterized in that, include: The device includes a processor, a memory, and a computer program; wherein the processor is connected to the memory, the computer program is stored in the memory, and when the electronic device is running, the processor executes the computer program stored in the memory to cause the electronic device to perform a session key negotiation method for reusing a portion of a static public key as described in any one of claims 1-6.