Message negotiation method, secret key downloading method and electronic equipment
By employing a lattice-based modular key encapsulation algorithm and a message negotiation method based on digital signature algorithms, the security problem of key download under quantum computing attacks is solved, achieving security and legitimacy of key transmission in a quantum computing environment.
Patent Information
- Application Number
- CN202511875970.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-02-10
AI Technical Summary
Existing key download processes are vulnerable to quantum computing attacks, making key download channels susceptible to cracking and impacting the security of electronic devices, especially payment devices.
A message negotiation method is adopted, which uses a lattice-based modular key encapsulation algorithm to generate key pairs, and transmits the shared secret through public key encryption. Combined with a modular digital signature algorithm for authentication, the security of the key is ensured during transmission.
In a quantum computing environment, the security of key transmission is enhanced through complex computations and noise, preventing key leakage and ensuring the security and legitimacy of electronic devices.
Smart Images

Figure CN121508841A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of key download, in particular to a message negotiation method, a key download method and an electronic device. BACKGROUND
[0002] In the related art, the key download process cannot resist quantum computing attacks, thereby easily affecting the security of the key download process when facing quantum computing attacks, so that the channel of key download is easily cracked, thereby causing the risk of key leakage and affecting the use safety of electronic devices, especially payment devices. SUMMARY
[0003] The technical problem to be solved by the present application is to provide a key distribution method and electronic device that can resist quantum computing attacks, thereby improving the defense capability when subjected to quantum computing attacks.
[0004] To solve the above technical problems, one technical solution adopted by the present application is: A message negotiation method applied to an electronic device, wherein the electronic device is connected with a key distribution device, and the method comprises: sending a start message to the key distribution device; the start message comprises a first receiver random number; receiving a binding message and a binding message signature sent by the key distribution device; verifying the binding message and the binding message signature, and generating a second receiver random number if the verification is passed; generating a key pair using a key encapsulation algorithm, wherein the encapsulation algorithm comprises a lattice-based modular key encapsulation algorithm; constructing a first key exchange message, wherein the first key exchange message comprises a public key in the key pair; and signing the first key exchange message to obtain a first exchange message signature; sending the first key exchange message and the first exchange message signature to the key distribution device, and receiving a second key exchange message and a second exchange message signature sent by the key distribution device; verifying the second key exchange message and the second exchange message signature, and completing message negotiation to obtain a first session key and a first message authentication code key after the verification is passed.
[0005] To solve the above technical problems, another technical solution adopted by the present application is: A key download method applied to an electronic device, wherein the electronic device is connected with a key distribution device, and the method comprises: generating a third receiver random number, and constructing a key request message according to the third receiver random number; calculating a request message verification code of the key request message using a first message verification code key; after sending the key request message and the request message verification code to the key distribution device, receiving a key injection message returned by the key distribution device and an injection message verification code of the key injection message; verifying the legality of the injection message verification code by the first message verification code key, if legal, decrypting the injection key ciphertext in the key injection message by the first session key to obtain the injection key plaintext; calculating a first injection key verification value corresponding to the injection key plaintext, if the first injection key verification value is the same as a second injection key verification value in the key injection message, saving the injection key plaintext; the first session key and the first message verification code key are obtained by the above-mentioned message negotiation method.
[0006] In order to solve the above technical problems, another technical solution adopted by the present application is: A message negotiation method applied to an electronic device connected with a key receiving device, the method comprising: after receiving a start message sent by the key receiving device, generating a first distribution end random number; constructing a binding message according to the first receiving end random number in the start message and the first distribution end random number; signing the binding message to obtain a binding message signature; sending the binding message and the binding message signature to the key receiving device; receiving a first key exchange message sent by the key receiving device and a first exchange message signature corresponding to the first key exchange message; verifying the first key exchange message and the first exchange message signature, generating shared secret plaintext by a key encapsulation algorithm based on the public key, generating a second session key and a second message verification code key based on the shared secret plaintext; calculating a second key verification value corresponding to the second session key and a fourth key verification value corresponding to the second message verification code key; the key encapsulation algorithm comprises an algorithm based on lattice modular key encapsulation; encrypting the shared secret plaintext by the public key to obtain shared secret ciphertext; constructing a second key exchange message according to the shared secret ciphertext, the second key verification value and the fourth key verification value; signing the second key exchange message to obtain a second exchange message signature; sending the second key exchange message and the second exchange message signature to the key receiving device to complete the message negotiation.
[0007] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: An electronic device includes a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of the above-described message negotiation method or the steps of the above-described key download method.
[0008] The beneficial effects of this invention are as follows: After sending a start message to the key distribution device to initiate the key negotiation process, and verifying the legitimacy of the key distribution device through a binding message and its signature, a key pair is generated based on a key encapsulation algorithm. The public key in the key pair is then sent to the key distribution device in the form of a first key exchange message. Simultaneously, the key distribution device verifies the legitimacy of the key receiving device. If legitimate, it returns a second key exchange message and its signature. If the second key exchange message and its signature pass verification, the message negotiation process is completed without directly transmitting the session key and message verification code key to the key distribution device. When transmitting parameters used for message negotiation, the key pair is generated using an encapsulation algorithm. The private key is stored in the device, while only the public key is sent to the key distribution device, thus avoiding security issues caused by key leakage. Furthermore, the key encapsulation algorithm includes a lattice-based modular key encapsulation algorithm. Its lattice structure enhances the computational complexity of the problem and incorporates the influence of noise, further increasing the number of possible results. Therefore, even with the computing power of a quantum computer, data can be prevented from being forcibly cracked. Attached Figure Description
[0009] Figure 1 A flowchart illustrating the steps of a message negotiation method provided in an embodiment of the present invention; Figure 2 A flowchart illustrating the steps of a key downloading method provided in an embodiment of the present invention; Figure 3 A flowchart illustrating the steps of another message negotiation method provided in an embodiment of the present invention; Figure 4 A timing diagram of a message negotiation method and a key download method performed by a key receiver and a key distributor according to an embodiment of the present invention; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0010] To make the technical problems, technical solutions, and beneficial effects to be solved by this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and are not intended to limit the scope of this application.
[0011] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0012] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.
[0013] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0014] The terms used in this application are defined as follows: KRD, Key Receiving Device, including POS terminals.
[0015] KDH, Key Distribution Host, remotely distributes keys to KRD.
[0016] KCV, Key Check Value, is used to verify whether the key has been correctly downloaded to the KRD.
[0017] POS stands for Point of Sales, which refers to a point of sale terminal.
[0018] PQC, or Post-Quantum Cryptography, is a type of cryptography designed to resist quantum computing attacks. It is also known as quantum resistance or quantum safe cryptography.
[0019] ML-KEM, Module-Lattice-Based Key-Encapsulation Mechanism, is a lattice-based modular key encapsulation mechanism.
[0020] POI encapsulation key, a key used for key encapsulation at the KRD end, is obtained based on the ML-KEM algorithm.
[0021] POI decapsulation key, the key used by the KRD end for decapsulating the key, is obtained based on the ML-KEM algorithm.
[0022] ML-DSA, a lattice-based modular digital signature standard.
[0023] SHAKE encryption is an extensible output function (XOF) based on the SHA-3 standard, supporting the generation of hash values of arbitrary length and conforming to NIST certification standards. It provides two security levels: 128-bit (SHAKE128) and 256-bit (SHAKE256), suitable for security scenarios such as digital signatures and key derivation.
[0024] POI-S-WCRT is a certificate used for signing on the KRD side, obtained based on the ML-DSA algorithm.
[0025] POI-S-WCRT PrivateKey, the private key used for signing on the KRD side, is obtained based on the ML-DSA algorithm.
[0026] POI CA, the parent root certificate of POI-E-WCRT / POI-S-WCRT, is obtained based on the ML-DSA algorithm.
[0027] KDH-S-WCRT is a certificate used for signing on the KDH side, obtained based on the ML-DSA algorithm.
[0028] KDH-S-WCRT PrivateKey, the private key used for signing on the KDH side, is obtained based on the ML-DSA algorithm.
[0029] KDH CA, the parent root certificate of KDH-S-WCRT, is obtained based on the ML-DSA algorithm.
[0030] CRL, Certificate Revocation List, is a mechanism in Public Key Infrastructure (PKI) used to record and manage revoked digital certificates.
[0031] KEK is a temporary session key used to encrypt financial keys (injected keys in KRD).
[0032] MAC, Message Authentication Code, is a cryptographic technique used to verify the integrity and authenticity of messages, ensuring that data has not been tampered with during transmission or storage and that its source is trustworthy.
[0033] DATA MAC KEY is a key used to calculate the MAC (Message Authentication Code) and protect message integrity.
[0034] In related technologies, the key is the most important data in the POS terminal. How to securely and compliantly inject the key into the POS terminal is the most concerning issue for various POS manufacturers, banks and other institutions.
[0035] In related technologies, there are two main key injection methods: local key injection and remote key injection. Local key injection involves a direct data cable connection between the key injection device and the POS terminal, with the key being injected directly from the device into the terminal. While this method has a simpler key download protocol, it is costly to maintain. If a merchant's POS terminal needs a key update, the entire terminal must be returned to a designated location and the key re-downloaded. Remote key injection, on the other hand, uses the public internet to inject the key into the POS terminal. This method has a more complex key download protocol, often employing public key infrastructure (PKI) to prevent attacks on public networks. However, it has lower maintenance costs, and the key can be updated remotely from the merchant's perspective, even if the terminal is in their possession. Therefore, remote key injection is more commonly used in related technologies.
[0036] In related technologies, POS terminals generally use RSA (an asymmetric encryption algorithm) or ECC (Ellipse Curve Ctyptography, a public-key encryption algorithm based on elliptic curve mathematics) to design remote key download schemes. Traditional public-key encryption systems, such as RSA and ECC, rely on mathematical problems like large integer factorization and discrete logarithm problems for security. Quantum computers, utilizing the superposition and entanglement properties of qubits, possess powerful parallel computing capabilities and could potentially break these traditional encryption algorithms in a relatively short time.
[0037] Quantum computing technology is developing rapidly, and devices capable of breaking current encryption methods may emerge within a decade, threatening the security and privacy of individuals, organizations, and entire nations. Because quantum computers operate fundamentally differently from ordinary computers, they can break encryption algorithms that currently provide security and privacy for our online activities, such as RSA and ECC. Therefore, to protect key security, it is necessary to design remote key downloading using post-quantum cryptography (PQC) algorithms.
[0038] To address the aforementioned problems, this application provides a message negotiation method, a key download method, and an electronic device. The message negotiation method of this application is described in detail below.
[0039] The message negotiation method in this application can be used in a key receiving device. The electronic device in this application can be an electronic device that needs to remotely receive key injection, such as a POS machine, cash register, or other financial equipment.
[0040] The following describes a message negotiation method of the present invention in detail, with reference to the appendix. Figure 1 This includes steps 110-170.
[0041] Step 110: Send a startup message to the key distribution device. The startup message includes a first receiver random number KRD-RND1. The startup message may also include the serial number (SN) of the electronic device. After receiving the startup message, the key distribution device can verify whether the electronic device has the necessary permissions to download the key based on the SN. For example, it can verify whether the SN is included in a preset whitelist. If so, subsequent processes will proceed, thus achieving preliminary verification of the electronic device's permissions.
[0042] Step 120: Receive the binding message and binding message signature sent by the key distribution device.
[0043] The binding message includes a first distributor random number KDH-RND1, a first receiver random number KRD-RND1, and a distributor certificate KDH-S-WCRT. The binding message is signed using the distributor private key KDH-S-WCRT Privatekey corresponding to the distributor certificate.
[0044] Step 130: Verify the binding message and the binding message signature. If the verification passes, generate a second receiver random number KRD-RND2.
[0045] Step 140: Generate a key pair using a key encapsulation algorithm, including a lattice-based modular key encapsulation algorithm (ML-KEM). For example, a key pair is generated using the key encapsulation algorithm, including a public key (POI encapsulation key) for key encapsulation and a private key (POI decapsulation key) for key decapsulation. The key distribution device can then encrypt the generated shared secret using the public key and send the encrypted shared secret to the key receiving device. The key receiving device can then decrypt the shared secret using the private key to obtain the shared secret for subsequent steps. Here, the shared secret is also obtained by the key distribution device based on the public key and the key encapsulation algorithm, thus achieving resistance to quantum attacks by utilizing the computational complexity of the lattice-based modular key encapsulation algorithm. Its lattice structure enhances the computational complexity of the problem and introduces the influence of noise, further increasing the number of possible results. Therefore, even with the computing power of a quantum computer, it is possible to prevent the data from being forcibly cracked.
[0046] Step 150: Construct a first key exchange message, which includes the public key in the key pair and a second receiver random number; sign the first key exchange message to obtain a first exchange message signature. The first exchange message includes the second receiver random number KRD-RND2, the first distributor random number KDH-RND1, the receiver certificate POI-S-WCRT, and the seed public key POI encapsulation key in the seed key pair. The first exchange message is signed using an encryption algorithm, including a lattice-based modular digital signature algorithm (ML-KEM).
[0047] The first exchange message is signed using an encryption algorithm using the receiver's private key (POI-S-WCRT Privatekey) corresponding to the receiver's certificate. POI-S-WCRT Privatekey is based on lattice-based difficult problems, overcoming the vulnerability of traditional digital signature algorithms that rely on large number factorization or discrete logarithm problems to quantum computers. Lattice-based difficult problems, such as the shortest vector problem and the nearest vector problem, are also computationally difficult in quantum computers, thus improving the overall security of the system.
[0048] Step 160: Send the first key exchange message and its signature to the key distribution device, and receive the second key exchange message and its signature from the key distribution device. The second exchange message includes the second distributor random number KDH-RND2, the second receiver random number KRD-RND2, the shared secret ciphertext, the second key verification value of the second session key, and the fourth key verification value of the second message verification code key. The second exchange message is also signed using the distributor private key KDH-S-WCRT Privatekey corresponding to the distributor certificate.
[0049] Step 170: Verify the second key exchange message and the signature of the second exchange message. If the verification is successful, complete the message negotiation to obtain the first session key and the first message verification code key.
[0050] This application completes the authentication and message negotiation process between the key receiving device and the key distribution device through steps 110 to 170. During the message negotiation process, the key receiving device generates a key pair using a key encapsulation algorithm and sends the public key of the key pair to the key distribution device. The key distribution device can then use this public key to generate the parameters (shared secret) required for the derived session key and message verification code key, and encrypt the parameters using the public key before sending them back. This ensures that the session key and message verification code key are transmitted in plaintext between the key receiving device and the key distribution device. Furthermore, the parameters used to generate the session key and message verification code key are also encrypted using the public key sent in the first key exchange message. Even if the parameters used to generate the session key and message verification code key are leaked, the specific algorithm used in the generation process is kept secret, making it impossible to crack the session key and message verification code key. Moreover, the key pair used to transmit the parameters is generated using a lattice-based modular key encapsulation algorithm, which requires a large amount of computation and high computational complexity to crack, thus ensuring security even in quantum computing attack scenarios and preventing the leakage of transmitted parameters.
[0051] In one embodiment of this application, steps 101 to 102 are included before step 110.
[0052] Step 101: Preload the distribution certificate chain (KDH CA certificate chain) corresponding to the key distribution device. The distribution certificate chain is also generated using the above encryption algorithm. Simultaneously, the key distribution device also preloads the receiving certificate chain, distribution certificate, and distribution private key corresponding to the key receiving device; all three are generated using the above encryption algorithm.
[0053] Step 102: Generate a first receiver random number KRD-RND1, and construct a startup message based on the first receiver random number and the serial number SN of the electronic device.
[0054] Step 130 includes steps 131 to 132.
[0055] Step 131: Verify the legitimacy of the distribution end certificate KDH-S-WCRT in the binding message based on the distribution end certificate chain. If the verification passes, verify the legitimacy of the binding message signature based on the distribution end certificate. This step can also preload a certificate revocation list file, first verifying if the distribution end certificate is in the certificate revocation list file. If not, verify the legitimacy of the distribution end certificate based on the distribution end certificate chain. Since the certificate revocation list file is essentially a blacklist of certificates, if the distribution end certificate is in the certificate revocation list file, it means that it no longer possesses security, and no further judgment is needed, thus improving the efficiency of verifying certificate legitimacy.
[0056] Step 132: If the signature of the binding message is valid, obtain the first receiver random number KRD-RND1 in the binding message, and determine whether the first receiver random number in the binding message is the same as the first receiver random number generated in step 110. If so, the verification is successful.
[0057] By preloading the distribution certificate chain corresponding to the key distribution device, the legitimacy of the distribution certificate sent by the key distribution device can be verified based on the distribution certificate chain. Furthermore, a first receiver random number is included in the startup message. When the key distribution device returns a binding message, it must carry this first receiver random number. This increases the difficulty and cost for unauthorized devices to impersonate the key distribution device. When verifying the received binding message, the legitimacy of the distribution certificate is first verified based on the distribution certificate chain. If legitimate, the legitimacy of the binding message signature is then verified using the distribution certificate. If successful, the first receiver random number in the binding message is finally verified to be the same as the generated first receiver random number. This achieves identity verification of the key distribution device, ensuring connection to authorized key distribution devices.
[0058] In one embodiment of this application, constructing the first key exchange message in step 150 includes step 151.
[0059] Step 151: Construct a first key exchange message based on the first distribution end random number, the second receiving end random number, and the public key in the key pair in the binding message.
[0060] Step 170 includes verifying the second key exchange message and the signature of the second exchange message, which is part of step 171.
[0061] Step 171: Verify the validity of the second exchange message signature using the saved distribution certificate. If valid, obtain the second receiving random number from the second exchange message. If the obtained second receiving random number is the same as the second receiving random number generated in step 130, the verification passes.
[0062] That is, after receiving the binding message in step 120 and verifying the distribution certificate in the binding message, the distribution certificate is saved. Then, the key distribution device does not need to resend its own distribution certificate. It can directly verify the message signature corresponding to the message sent by the key distribution device through the saved distribution certificate.
[0063] In this way, the distribution certificate is saved after the initial receipt, eliminating the need to repeatedly verify it through the distribution certificate chain. Subsequent messages received from the key distribution device can be directly verified using the saved distribution certificate. A second receiver random number is added when constructing the first exchange message. Similarly, when the key distribution device returns the second exchange message, the second receiver random number in the second exchange message is compared with the generated second receiver random number to assist in verifying the legitimacy of the key distribution device. If there is a discrepancy, the interaction process is stopped to ensure the security of the interaction and to verify the legitimacy of the key distribution device.
[0064] In one embodiment of this application, step 170, which involves completing message negotiation, includes steps 172 to 174.
[0065] Step 172: Obtain the shared secret ciphertext, the second key verification value, and the fourth key verification value from the second key exchange message; decrypt the shared secret ciphertext to obtain the shared secret plaintext; the shared secret ciphertext is obtained by encrypting with the public key; the second key verification value is calculated from the second session key generated by the key distribution device; and the fourth key verification value is calculated from the second message verification code key generated by the key distribution device.
[0066] Step 173: Obtain the first session key KEK and the first message verification code key DATA MAC Key based on the shared secret plaintext using a preset derivation algorithm, and calculate the first key verification value corresponding to the first session key and the third key verification value corresponding to the first message verification code key. The preset derivation algorithm includes the SHAKE algorithm.
[0067] Step 174: If the first key verification value is consistent with the second key verification value and the third key verification value is consistent with the fourth key verification value, then the message negotiation is completed.
[0068] In this manner, a key pair is generated according to the key encapsulation algorithm, and the public key is sent to the key distribution device. To avoid the key receiving device and the key distribution device transmitting the session key and message verification code key in plaintext directly, and to ensure that the key receiving device and the key distribution device can generate the same session key and message verification code key, the key receiving device sends the public key to the key distribution device. The key distribution device then generates a shared secret plaintext based on the public key and encrypts the shared secret plaintext using the public key to obtain the shared secret ciphertext. The key receiving device can then decrypt the shared secret ciphertext using the private key in the key pair to obtain the shared secret plaintext, enabling both ends to use the same parameters (total...) The key distribution device generates a session key and a message verification key to complete the message negotiation process. After generating the session key and message verification key, it sends the corresponding second key verification value and fourth key verification value to the key receiving device. The key receiving device can then use the second key verification value and fourth key verification value to determine whether its own generated session key and message verification key are consistent with those generated by the key distribution device. This ensures that the injected key encrypted by the key distribution device can be decrypted by the key receiving device during subsequent key injection transmission, thus ensuring the security of the two-end interaction while guaranteeing the normal key download process.
[0069] In one embodiment of this application, step 103 is included before step 110.
[0070] Step 103: Preload the receiver certificate (POI-S-WCRT certificate) and the receiver private key (POI-S-WCRT private key).
[0071] The construction of the first key exchange message in step 150 includes step 152.
[0072] Step 152: Construct the first key exchange message based on the public key in the key pair, the second receiver random number, the binding message, and the receiver certificate.
[0073] In this way, the pre-loaded receiver certificate and receiver private key are generated through encryption algorithms, including lattice-based modular digital signature algorithms. The resulting signature is capable of resisting quantum attacks. When the key receiving device sends a message, it can sign the message using the receiver private key and add the receiver certificate to the first exchange message and send it to the key distribution device together. The key distribution device can then verify the signature of all subsequent messages sent by the key receiving device using the stored receiver certificate, thereby authenticating the key receiving device.
[0074] In one embodiment of this application, steps 181 to 185 are included after step 170.
[0075] Step 181: Calculate the first receiver hash value KRD HASH1 of the startup message, binding message, first exchange message, and second exchange message.
[0076] Step 182: Calculate the first message authentication code KRDMAC1 using the first message verification code key to obtain the hash value of the first receiver.
[0077] Step 183: Construct a receiver termination message based on the first message authentication code and send the receiver termination message to the key distribution device.
[0078] Step 184: Receive the distribution end termination message sent by the key distribution device. The distribution end termination message includes the second message authentication code KRD MAC2. The key distribution device calculates the first distribution end hash value KDH HASH of the start message, binding message, first exchange message, second exchange message, and receiver end termination message, and then calculates the second message authentication code KRD MAC2 of the first distribution end hash value using the second message verification code key.
[0079] Step 185: Calculate the second receiver hash value KRD HASH2 of the start message, binding message, first exchange message, second exchange message, and receiver end message. If the second receiver hash value is equal to the first distributor hash value, then start the key download process.
[0080] In summary, the message negotiation method provided in this application involves the key receiving device generating a key pair for transmitting the shared secret during the message negotiation process between the key receiving device and the key distribution device. The key receiving device then sends the public key from the key pair to the key distribution device. The key encapsulation algorithm includes a lattice-based modular key encapsulation algorithm, which, due to its computational complexity in quantum computing, can resist quantum attacks and ensure the security of the shared secret transmission process. The key receiving device pre-loads a distribution certificate chain that verifies the legitimacy of the distribution certificate in the key distribution device, as well as its own receiving certificate and private key. These are all generated using encryption algorithms, including a lattice-based modular digital signature algorithm. Since the message is signed during transmission, it can resist quantum attacks during message transmission. When key download is required, the device actively initiates a startup message, which includes its own sequence number as an identifier. After receiving the binding message, it provides a seed key pair for encrypting the shared secret and sends the seed public key to the key distribution device. Upon receiving the encrypted shared secret from the key distribution device, the device can decrypt it using the corresponding seed private key. Furthermore, the key receiving device and the key distribution device use the same preset derivation algorithm to complete key derivation based on the same shared secret plaintext. This ensures that the key receiving device and the key distribution device ultimately have the same session key and message verification code key, enabling the subsequent key download process to be completed.
[0081] This application also provides a key downloading method for an electronic device connected to a key distribution device, such as a key receiving device. Please refer to [reference needed]. Figure 2 The method includes steps 210 to 260.
[0082] Step 210: Generate a third receiver random number KRD-RND3, and construct a key request message based on the third receiver random number. The key request message includes the third receiver random number and the second distributor random number KDH-RND2.
[0083] Step 220: Calculate the MAC request message of the key request message using the first message verification key DATA MAC Key.
[0084] Step 230: After sending the key request message and the request message verification code to the key distribution device, receive the key injection message and the injection message verification code (MAC) returned by the key distribution device. The key injection message includes the third receiver random number KRD-RND3, the injected key ciphertext (CK ciphertext), and the second injected key verification value.
[0085] Step 240: Verify the legitimacy of the injected message verification code using the first message verification code key DATA MAC Key. If it is legitimate, decrypt the injected key ciphertext in the key injection message using the first session key to obtain the injected key plaintext.
[0086] In one embodiment of this application, if the injected message verification code is valid, the third receiver random number in the key injection message is verified. If the third receiver random number in the key injection message is equal to the third receiver random number generated in step 210, and if they are equal, the injected key ciphertext in the key injection message is decrypted using the first session key to obtain the injected key plaintext.
[0087] Step 250: Calculate the first injection key verification value corresponding to the injection key plaintext. If the first injection key verification value is the same as the second injection key verification value in the key injection message, save the injection key plaintext and complete the key download process.
[0088] The first session key and the first message verification code key are obtained through one of the message negotiation methods described above.
[0089] This application also provides a message negotiation method applied to an electronic device connected to a key receiving device, such as a key distribution device. (See reference...) Figure 3 The method includes steps 310 to 311. Step 310: After receiving the start message sent by the key receiving device, generate a first distribution end random number; Step 320: Construct a binding message based on the first receiver random number and the first distributor random number in the startup message; sign the binding message to obtain the binding message signature; Step 330: Send the binding message and the binding message signature to the key receiving device; Step 340: Receive the first key exchange message and the first exchange message signature corresponding to the first key exchange message sent by the key receiving device; Step 350: Verify the first key exchange message and the first exchange message signature. If they pass, generate a shared secret plaintext based on the public key using a key encapsulation algorithm. Then, generate a second session key and a second message verification code key based on the shared secret plaintext. Calculate the second key verification value corresponding to the second session key and the fourth key verification value corresponding to the second message verification code key. The key encapsulation algorithm includes a lattice-based modular key encapsulation algorithm. Step 360: Obtain the shared secret ciphertext by encrypting the shared secret plaintext with the public key; Step 370: Construct a second key exchange message based on the shared secret ciphertext, the second key verification value, and the fourth key verification value; sign the second key exchange message to obtain the second exchange message signature; Step 380: Send the second key exchange message and the second exchange message signature to the key receiving device to complete the message negotiation.
[0090] In one embodiment of this application, step 301 is included before step 320.
[0091] Step 301: Preload the receiving end certificate chain, the distributor certificate, and the distributor private key corresponding to the key receiving device.
[0092] Steps 320, 321 and 322.
[0093] Step 321: Construct a binding message based on the first distribution end random number, the first receiving end random number in the startup message, and the distribution end certificate.
[0094] Step 322: Sign the bound message using the private key of the distribution end to obtain the bound message signature.
[0095] Step 350, which verifies the first key exchange message and the first exchange message signature, includes steps 351 to 352.
[0096] Step 351: Verify the validity of the receiver certificate in the first key exchange message according to the receiver certificate chain. If the verification is successful, verify the validity of the signature of the first exchange message according to the receiver certificate.
[0097] Step 352: If the signature of the first exchange message is valid, obtain the first distribution end random number in the first key exchange message, and determine whether the first distribution end random number in the first key exchange message is the same as the generated first distribution end random number. If so, the verification is passed.
[0098] In one embodiment of this application, step 350, which generates a second session key and a second message verification code key based on the shared secret plaintext, includes step 353.
[0099] Step 353: Obtain the second session key and the second message verification code key based on the shared secret plaintext using a preset derivation algorithm.
[0100] This application also provides a key download system, which includes a key receiving device and a key distribution device. The key receiving device includes a first memory, a first processor, and a first computer program stored in the first memory and running on the first processor. When the first processor executes the first computer program, it implements each of the steps 110 to 170 of the above-described message negotiation method. The key distribution device includes a second memory, a second processor, and a second computer program stored in the second memory and running on the second processor. When the second processor executes the second computer program, it implements each of the steps 310 to 380 of the above-described message negotiation method.
[0101] Please refer to Figure 4 The message negotiation method implemented by the key download system is as follows: steps 01 to 94.
[0102] Step 01: Preload the distributor certificate chain (KDH CA certificate chain), the receiver certificate (POI-S-WCRT certificate), the receiver private key (POI-S-WCRT Privatekey), and the Certificate Revocation List (CRL) file into the key receiving device. This is equivalent to steps 101 and 103 above.
[0103] Step 02: Preload the receiver certificate chain POI CA certificate chain, the distributor certificate KDH-S-WCRT certificate, the distributor private key KDH-S-WCRT Privatekey, and the certificate revocation list file into the key distribution device.
[0104] Step 11: The key receiving device generates a first receiving random number KRD-RND1; this is equivalent to step 102 above.
[0105] Step 12: The key receiving device constructs a startup message including a first receiver random number and the key receiving device serial number SN; Step 13: The key receiving device sends a startup message to the key distribution device. Steps 11 to 13 are equivalent to step 110 above.
[0106] Step 21: After receiving the start message, the key distribution device generates a first distribution end random number KDH-RND1; this is equivalent to step 310 above. Step 22: The key distribution device constructs a binding message including a first distribution end random number, a first receiving end random number, and a distribution end certificate; equivalent to step 320 above. Step 23: The key distribution device uses the private key of the distribution end to sign the bound message to obtain the bound message signature; this is equivalent to step 320 above. Step 24: The key distribution device sends the binding message and its signature to the key receiving device. This is equivalent to step 120 above.
[0107] Step 31: The key receiving device verifies whether the distribution end certificate in the binding message is in the certificate revocation list file. If not, the distribution end certificate chain is used to verify the legality of the distribution end certificate. If legal, the distribution end certificate is saved and step 32 is executed. If the distribution end certificate is in the certificate revocation list or the distribution end certificate chain verification shows that the distribution end certificate is invalid, the distribution end certificate is prompted that it is invalid. Step 32: The key receiving device uses the distribution end certificate to verify the legality of the binding message signature. If the binding message signature is legal, proceed to step 33; otherwise, indicate that the certificate is invalid. Step 33: The key receiving device confirms whether the first receiving random number in the binding message is consistent with the first receiving random number generated in step 11. If they are consistent, proceed to step 34; if they are inconsistent, prompt that the authentication is invalid. Step 34: Generate a second receiver random number KRD-RND2; Steps 31 to 34 are equivalent to step 130 above.
[0108] Step 35: The key receiving device generates a seed key pair according to the key generation algorithm. The seed key pair includes a seed public key (POI encapsulation key) and a seed private key. The key generation algorithm includes the ML-KEM algorithm; this is equivalent to step 140 above.
[0109] Step 36: The key receiving device constructs a first exchange message based on the second receiving end random number, the first distributing end random number, the receiving end certificate, and the seed public key; Step 37: The key receiving device signs the first exchange message using the receiving end's private key to obtain the signature of the first exchange message; Steps 36 and 37 are equivalent to step 150 above. Step 38: The key receiving device sends the first exchange message and its signature to the key distribution device. This is equivalent to step 160 above.
[0110] Step 41: The key distribution device verifies whether the receiving certificate in the first exchange message is in the certificate revocation list file. If not, the receiving certificate chain is used to verify the legality of the receiving certificate. If legal, the receiving certificate is saved and step 42 is executed. If the receiving certificate is in the certificate revocation list file or the receiving certificate chain verification shows that the receiving certificate is invalid, the receiving certificate is prompted that it is invalid. Step 42: The key distribution device uses the receiving end certificate to verify the validity of the first exchange message signature. If the first exchange message signature is valid, proceed to step 43; otherwise, indicate that the certificate is invalid. Step 43: The key distribution device confirms whether the first distribution end random number in the first exchange message is consistent with the first distribution end random number generated in step 21. If it is consistent, proceed to step 44. If it is inconsistent, prompt that the authentication is invalid. Step 44: The key distribution device generates a second distribution end random number KDH-RND2; Step 45: The key distribution device uses the seed public key to perform key packaging operation through the key generation algorithm to generate the shared secret plaintext, and encrypts the shared secret plaintext with the seed public key to obtain the shared secret ciphertext; wherein, the key generation algorithm includes ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism). Step 46: Based on the shared secret plaintext, the key distribution device uses a preset derivation algorithm to obtain the second session key KEK and the second message verification code key DATA MAC Key, and calculates the second key verification value corresponding to the second session key and the fourth key verification value corresponding to the second message verification code key.
[0111] Step 47: The key distribution device constructs a second exchange message based on the second distribution end random number, the second receiving end random number, the shared secret ciphertext, the second key verification value, and the fourth key verification value.
[0112] Step 48: The key distribution device signs the second exchange message using the private key of the distribution end to obtain the signature of the second exchange message; Step 49: The key distribution device sends the second exchange message and its signature to the key receiving device. This is equivalent to step 160 above.
[0113] Step 51: The key receiving device verifies the validity of the signature of the second exchange message by using the stored distribution end certificate. If it is valid, proceed to step 52; otherwise, prompt that the signature is invalid. Step 52: The key receiving device confirms whether the second receiver random number in the second exchange message is consistent with the second receiver random number generated in step 34. If yes, proceed to step 53; otherwise, prompt that the authentication is invalid. Step 53: The key receiving device uses the seed private key (POI decapsulation key) to decrypt the shared secret ciphertext in the second exchange message to obtain the shared secret plaintext; Step 54: Based on the shared secret plaintext, the key receiving device obtains the first session key KEK and the first message verification code key DATA MAC Key through a preset derivation algorithm, and calculates the first key verification value corresponding to the first session key and the third key verification value corresponding to the first message verification code key; the preset derivation algorithm here is the same as the preset derivation algorithm used in step 46; it is determined whether the first key verification value is the same as the second key verification value, and whether the third key verification value is the same as the fourth key verification value. If both are the same, then step 55 is executed, indicating that the message negotiation process is complete, and the key receiving device and the key distribution device have the same session key (first session key and second session key) and the same message verification code key (first message verification code key and second message verification code key); if one of them is different, it prompts that the message negotiation needs to be re-performed. This is equivalent to step 170 above.
[0114] Step 55: The key receiving device calculates the first hash value KRD HASH of the startup message, binding message, first exchange message, and second exchange message; equivalent to step 181 above. Step 56: The key receiving device calculates the first message authentication code KRD MAC using the first message verification code key; this is equivalent to step 182 above. Step 57: The key receiving device constructs a receiver termination message based on the first message authentication code; this is equivalent to step 183 above. Step 58: The key receiving device sends a receiving end message to the key distribution device. This is equivalent to step 183 above.
[0115] Step 61: After calculating the second hash values of the startup message, binding message, first exchange message, and second exchange message, the key distribution device calculates the second message authentication code of the second hash value using the second message verification code key. If the second message authentication code matches the first message authentication code, proceed to step 62; otherwise, a security verification failure message is displayed, indicating that the messages received by both ends are inconsistent. It is evident that the key receiving device uses the message stored within itself when calculating the first hash value, and the key distribution device uses the message stored within itself when calculating the second hash value. If the final first message authentication code and second message authentication code are different, it indicates that the messages stored in the two devices are different, and the messages may have been tampered with during transmission. Step 62: The key distribution device calculates the third hash value of the startup message, binding message, first exchange message, and second exchange message; Step 63: The key distribution device uses the second message verification code key to calculate the third message authentication code corresponding to the third hash value; Step 64: The key distribution device constructs a distribution end termination message based on the third message authentication code; Step 65: The key distribution device sends a distribution end termination message to the key receiver. This is equivalent to step 184 above.
[0116] Step 71: The key receiving device calculates the fourth hash value of the startup message, binding message, first exchange message, and second exchange message, and calculates the fourth message authentication code corresponding to the fourth hash value using the first message verification code key. If the fourth message authentication code is the same as the third message authentication code, then the key download process can proceed to step 72. This is equivalent to step 185 above.
[0117] Step 72: The key receiving device generates a third-end random number KRD-RND3; equivalent to step 210 above. Step 73: The key receiving device constructs a key request message based on the random number from the third receiving end and the random number from the second distributing end; this is equivalent to step 210 above. Step 74: The key receiving device calculates the request message authentication code of the key request message using the first message verification code key; this is equivalent to step 220 above. Step 75: The key receiving device sends the key request message and the request message authentication code to the key distribution device. This is equivalent to step 230 above.
[0118] Step 81: The key distribution device verifies the validity of the key request message and the request message authentication code using the second message verification code key. If valid, proceed to step 82; otherwise, indicate invalidity. Step 82: The key distribution device determines whether the received random number from the second distribution end is consistent with the random number generated in step 44. If so, proceed to step 83; otherwise, prompt that the authentication failed. Step 83: Encrypt the injection key (CK) using the second session key to obtain the injection key ciphertext, the injection key, and the key that needs to be downloaded to the key receiving device. Step 84: Calculate the injection key verification value of the injection key; Step 85: Construct a key injection message based on the random number from the third receiving end, the injected key ciphertext, and the injected key verification value; Step 86: Calculate the injection message authentication code of the key injection message based on the second message verification code key; Step 87: Send the key injection message and the injection message authentication code to the key receiver.
[0119] Step 91: The key receiving device verifies the legality of the key injection message and the injection message authentication code using the first message verification code key. If the verification passes, proceed to step 92; this is equivalent to step 240 above. Step 92: The key receiving device determines whether the third receiver random number in the key injection message is consistent with the third receiver random number generated in step 72. If so, proceed to step 93. Step 93: Decrypt the injected key ciphertext using the first session key to obtain the injected key (CK); equivalent to step 250 above; Step 94: Calculate the injection key checksum of the injected key and compare it with the injection key checksum in the received key injection message. If they match, save the injected key and end the process; otherwise, prompt that the key needs to be downloaded again. This is equivalent to step 250 above.
[0120] Please refer to Figure 5 The present invention also provides an electronic device 400, including a memory 402 and a processor 401, and a computer program stored in the memory 402 and running on the processor 401. When the processor 401 executes the computer program, it implements the various steps in the message negotiation method described above or the various steps in the key download method described above.
[0121] The beneficial effects of the electronic device of the present invention are the same as those of the method described above, and will not be repeated here.
[0122] The above are merely embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention's specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A message negotiation method, characterized in that, Applied to an electronic device connected to a key distribution device, the method includes: Send a start message to the key distribution device; the start message includes a first receiver random number; Receive the binding message and binding message signature sent by the key distribution device; The binding message and the binding message signature are verified. If the verification passes, a second receiver random number is generated. A key pair is generated using a key encapsulation algorithm, including a lattice-based modular key encapsulation algorithm. Construct a first key exchange message, the first key exchange message including the public key in the key pair; sign the first key exchange message to obtain a first exchange message signature; Send the first key exchange message and the first exchange message signature to the key distribution device, and receive the second key exchange message and the second exchange message signature sent by the key distribution device; Verify the signatures of the second key exchange message and the second exchange message. If the verification is successful, message negotiation is completed to obtain the first session key and the first message verification code key.
2. The message negotiation method according to claim 1, characterized in that, Before sending the start message to the key distribution device, the following steps are included: Preload the distribution certificate chain corresponding to the key distribution device; Generate a first random number for the receiving end, and construct a startup message based on the first random number for the receiving end and the serial number of the electronic device; The verification of the bound message and the bound message signature includes: The validity of the distribution certificate in the binding message is verified according to the distribution certificate chain. If the verification is successful, the validity of the binding message signature is verified according to the distribution certificate. If the signature of the binding message is valid, the first receiver random number in the binding message is obtained, and it is determined whether the first receiver random number in the binding message is the same as the generated first receiver random number. If so, the verification is successful.
3. The message negotiation method according to claim 1, characterized in that, The construction of the first key exchange message includes: Generate a second receiver random number, and construct a first key exchange message based on the binding message and the second receiver random number; The verification of the second key exchange message and the second exchange message signature includes: The validity of the second exchange message signature is verified by the saved distribution certificate. If it is valid, the second receiving random number is obtained from the second exchange message. If the obtained second receiving random number is the same as the generated second receiving random number, the verification is successful.
4. A message negotiation method according to claim 1 or 3, characterized in that, The completion message negotiation includes: Obtain the shared secret ciphertext, the second key verification value, and the fourth key verification value from the second key exchange message; decrypt the shared secret ciphertext to obtain the shared secret plaintext; the shared secret ciphertext is obtained by encrypting with the public key; the second key verification value is calculated by the second session key generated by the key distribution device; and the fourth key verification value is calculated by the second message verification code key generated by the key distribution device. The first session key and the first message verification code key are obtained by using a preset derivation algorithm based on the shared secret plaintext, and the first key verification value corresponding to the first session key and the third key verification value corresponding to the first message verification code key are calculated. If the first key verification value is consistent with the second key verification value and the third key verification value is consistent with the fourth key verification value, then the message negotiation is completed.
5. The message negotiation method according to claim 1, characterized in that, Before sending the start message to the key distribution device, the following steps are included: Preload the receiver's certificate and private key; The construction of the first key exchange message includes: The first key exchange message is constructed based on the public key, the second receiver random number, the binding message, and the receiver certificate in the key pair.
6. A key download method, characterized in that, Applied to an electronic device connected to a key distribution device, the method includes: Generate a third receiver random number, and construct a key request message based on the third receiver random number; The request message verification code of the key request message is calculated using the first message verification code key; After sending the key request message and the request message verification code to the key distribution device, the key injection message and the injection message verification code of the key injection message are received from the key distribution device. The legality of the injected message verification code is verified by the first message verification code key. If it is legal, the injected key ciphertext in the key injection message is decrypted by the first session key to obtain the injected key plaintext. Calculate the first injection key verification value corresponding to the injected key plaintext. If the first injection key verification value is the same as the second injection key verification value in the key injection message, then save the injected key plaintext. The first session key and the first message verification code key are obtained through a message negotiation method as described in any one of claims 1-5.
7. A message negotiation method, characterized in that, Applied to an electronic device connected to a key receiving device, the method includes: After receiving the start message sent by the key receiving device, a first distribution end random number is generated; A binding message is constructed based on the first receiving end random number and the first distributing end random number in the startup message; the binding message is then signed to obtain a binding message signature; The binding message and the binding message signature are sent to the key receiving device; Receive the first key exchange message sent by the key receiving device and the first exchange message signature corresponding to the first key exchange message; The first key exchange message and its signature are verified. If they pass the verification, a shared secret plaintext is generated based on the public key in the first key exchange message using a key encapsulation algorithm. A second session key and a second message verification code key are then generated based on the shared secret plaintext. A second key verification value corresponding to the second session key and a fourth key verification value corresponding to the second message verification code key are calculated. The key encapsulation algorithm includes a lattice-based modular key encapsulation algorithm. The shared secret ciphertext is obtained by encrypting the shared secret plaintext using the public key. A second key exchange message is constructed based on the shared secret ciphertext, the second key verification value, and the fourth key verification value; the second key exchange message is then signed to obtain a second exchange message signature. The second key exchange message and its signature are sent to the key receiving device to complete the message negotiation.
8. The message negotiation method according to claim 7, characterized in that, Before constructing the binding message based on the first receiving random number and the first distributing random number in the startup message, the following steps are included: Preload the receiver certificate chain, distributor certificate, and distributor private key corresponding to the key receiving device; The step of constructing a binding message based on the first receiving random number and the first distributing random number in the startup message includes: A binding message is constructed based on the first distribution end random number, the first receiving end random number in the startup message, and the distribution end certificate; The step of signing the bound message to obtain the bound message signature includes: The binding message is signed using the private key of the distribution end to obtain the binding message signature; The verification of the first key exchange message and the first exchange message signature includes: The validity of the receiver certificate in the first key exchange message is verified according to the receiver certificate chain. If the verification is successful, the validity of the signature of the first exchange message is verified according to the receiver certificate. If the signature of the first exchange message is valid, the first distribution terminal random number in the first key exchange message is obtained, and it is determined whether the first distribution terminal random number in the first key exchange message is the same as the generated first distribution terminal random number. If so, the verification is passed.
9. A message negotiation method according to claim 7, characterized in that, The step of generating the second session key and the second message verification code key based on the shared secret plaintext includes: The second session key and the second message verification code key are obtained from the shared secret plaintext through a preset derivation algorithm.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements each step of the message negotiation method according to any one of claims 1-5, or the steps of the key download method according to claim 6, or each step of the message negotiation method according to any one of claims 7-9.