Identity authentication method and device, electronic equipment, storage medium and program product

By integrating a security unit and a QRNG module into the super SIM card, and combining anti-quantum and national cryptographic algorithms, quantum random numbers are generated as session key components. This solves the security and convenience problems of existing identity authentication technologies under the threat of quantum computing, achieving a balance between high security and convenience.

CN121770873APending Publication Date: 2026-03-31CHINA MOBILE COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-30
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing identity authentication technologies are insecure and inconvenient in the face of quantum computing threats, and cannot effectively resist quantum computing attacks. At the same time, they are inconvenient for users to operate.

Method used

By integrating a security unit and a quantum random number generator (QRNG) module into a super SIM card, and combining quantum-resistant encryption and national cryptographic algorithms, a security architecture is constructed that generates quantum random numbers as session key components for key negotiation and hybrid signature, thereby building a quantum random source generation, dual-system algorithm fusion, and hardware-level key protection.

Benefits of technology

It achieves quantum-resistant security and compliance with national cryptographic standards in high-security scenarios, while providing users with a convenient plug-and-play experience without the need to carry additional dedicated hardware, thus resolving the contradiction between security and portability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121770873A_ABST
    Figure CN121770873A_ABST
Patent Text Reader

Abstract

The invention provides an identity authentication method and device, electronic equipment, a storage medium and a program product, and relates to the technical field of information security. The method comprises the steps that a security architecture integrating quantum random source generation, dual-system algorithm fusion and hardware-level key protection is constructed by taking a super SIM card as a hardware carrier; the anti-quantum security and the national security compliance are ensured in the authentication process, meanwhile, the user does not need to additionally carry special hardware, the plug-and-play convenient experience is achieved, and the contradiction that security and portability are difficult to consider in a high-security scene is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to an identity authentication method, device, electronic device, storage medium, and program product. Background Technology

[0002] With the evolution of quantum computing technology, traditional cryptographic systems (including Chinese national cryptographic algorithms) are facing potential risks of being cracked by quantum computing in high-security identity authentication scenarios such as finance and government affairs. To address these threats, existing technologies mainly employ two types of solutions, but both have their own shortcomings: The first type of solution uses external dedicated authentication hardware (such as USB (Universal Serial Bus) cryptographic keys). While this type of solution can integrate quantum-resistant cryptographic algorithms, its hardware carrier has poor integration with mainstream mobile terminals such as smartphones, requiring users to carry it separately and perform physical plug-and-play operations, resulting in poor portability and user experience. Furthermore, its authentication process is typically based on a "single challenge value generation - signature response - signature verification" mechanism, but lacks effective protection against replay attacks, and the robustness of the authentication logic is insufficient. At the same time, the random number source on which this type of hardware key generation relies has limitations in true randomness, making it difficult to physically guarantee the quality of the entropy source required for quantum attack resistance.

[0003] The second type of scheme employs collaborative authentication using multiple mobile device groups and independent key cards. While this approach mitigates risk through multiple devices, it leads to complex device management, difficulties in key synchronization, and a heavy burden on users, resulting in poor practical deployment convenience. In terms of cryptographic systems, this type of scheme often still relies on traditional algorithms such as elliptic curve cryptography to build trust chains, which inherently have limited resistance to quantum computing attacks.

[0004] Therefore, how to effectively defend against the threat of quantum computing while ensuring user-friendly authentication has become an urgent problem to be solved. Summary of the Invention

[0005] This application provides an identity authentication method, device, electronic device, storage medium, and program product to address the shortcomings of low security and poor convenience in the prior art of identity authentication, effectively resist the threat of quantum computing, and at the same time ensure user ease of operation.

[0006] This application provides an identity authentication method applied to a Super SIM card, wherein the Super SIM card integrates a security unit and a quantum random number generator (QRNG) module, and the identity authentication method includes the following steps: Receive the encrypted composite certificate from the authentication server sent by the authentication client, and verify the encrypted composite certificate; After successful verification, multiple quantum random numbers are generated based on the QRNG module as session key components; Based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, the session key components are encrypted respectively to generate key negotiation parameters, and the key negotiation parameters are sent to the authentication server through the authentication client. The authentication server receives the challenge value forwarded by the authentication client and signs the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature. Based on the session key, the hybrid signature, the signature composite certificate of the Super SIM card, and the challenge response value are encrypted, and the encrypted authentication response ciphertext is sent to the authentication server via the authentication client; the session key is generated based on the key negotiation parameters, and the authentication response ciphertext is used for identity authentication.

[0007] According to an authentication method provided in this application, the session key component includes a first session key component and a second session key component; the step of encrypting the session key component based on a first quantum-resistant encryption public key and a first national cryptographic encryption public key extracted from the encrypted composite certificate to generate key negotiation parameters includes: Extract the first quantum-resistant encryption public key and the first national cryptographic encryption public key from the encrypted composite certificate; Based on the first quantum-resistant encryption public key, the first session key component is encrypted to obtain the first key negotiation parameters; Based on the first national cryptographic public key, the second session key component is encrypted to obtain the second key negotiation parameters; The key negotiation parameters include the first key negotiation parameters and the second key negotiation parameters.

[0008] According to the identity authentication method provided in this application, the step of signing the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature includes: Based on the quantum-resistant signature private key, the challenge response value is signed to obtain the first signature; Based on the national cryptographic signature private key, the challenge response value is signed to obtain a second signature; The hybrid signature includes the first signature and the second signature; the challenge response value is obtained by concatenating the user identification information with the challenge value.

[0009] According to an authentication method provided in this application, the verification of the encrypted composite certificate includes: Request the pre-configured encrypted composite root certificate of the Super SIM cryptographic service platform from the authentication client; Extract the second quantum-resistant encryption public key and the second national cryptographic encryption public key from the encrypted composite root certificate; Based on the second quantum-resistant encryption public key, the signature value of the first quantum-resistant encryption public key in the encrypted composite certificate is verified; and based on the second national cryptographic encryption public key, the signature value of the first national cryptographic encryption public key in the encrypted composite certificate is verified; and, The validity period and certificate status information of the encrypted composite certificate are verified.

[0010] This application provides an authentication method applied to a Super SIM cryptographic service platform, which integrates a quantum random source module and a hardware security module. The authentication method includes the following steps: In response to the decryption request from the authentication server, the anti-quantum encryption private key and the national cryptographic encryption private key are extracted from the hardware security module, the key negotiation parameters provided by the authentication server are decrypted, and the decrypted session key component is sent to the authentication server. In response to the challenge value generation request from the authentication server, the quantum random source module is invoked to generate a quantum random number as the challenge value, and the challenge value is sent to the authentication server. In response to the encryption request from the authentication server, the challenge value is encrypted based on the session key provided by the authentication server, and the encrypted challenge value is sent to the authentication client via the authentication server. In response to the signature verification request from the authentication server, identity authentication is performed based on the plaintext authentication response data provided by the authentication server; the plaintext authentication response data is obtained by the authentication server decrypting the ciphertext authentication response received from the authentication client.

[0011] According to the identity authentication method provided in this application, the authentication response plaintext data includes a composite certificate of hybrid signature and Super SIM card signature, and the identity authentication based on the authentication response plaintext data provided by the authentication server includes: Verify the signature composite certificate; After successful verification, the first quantum-resistant signature public key and the first national cryptographic signature public key are extracted from the signature composite certificate; Based on the first quantum-resistant signature public key, the first signature in the hybrid signature is verified; Based on the first national cryptographic signature public key, the second signature in the hybrid signature is verified; If both the first and second signature verification results pass, then the user's identity authentication is successful.

[0012] According to an identity authentication method provided in this application, the verification of the signature composite certificate includes: Extract the second quantum-resistant signature public key and the second national cryptographic signature public key from the pre-stored signature composite root certificate; Based on the second quantum-resistant signature public key, the signature value of the first quantum-resistant signature public key is verified; and based on the second national cryptographic signature public key, the signature value of the first national cryptographic signature public key is verified; and, The validity period and certificate status information of the signature composite certificate are verified.

[0013] According to the authentication method provided in this application, the step of extracting the quantum-resistant encryption private key and the national cryptographic encryption private key from the hardware security module, and decrypting the key negotiation parameters provided by the authentication server, includes: Based on the quantum-resistant encryption private key, the first key negotiation parameter in the key negotiation parameters is decrypted to obtain the first session key component; Based on the national cryptographic encryption private key, the second key negotiation parameter in the key negotiation parameters is decrypted to obtain the second session key component.

[0014] According to the identity authentication method provided in this application, the identity authentication method further includes: Based on the random number source generated by the quantum random source module, quantum-resistant key pairs and national cryptographic key pairs are generated; the quantum-resistant key pairs include quantum-resistant signature key pairs and quantum-resistant encryption key pairs; the national cryptographic key pairs include national cryptographic signature key pairs and national cryptographic encryption key pairs. For the signature scenario, the quantum-resistant signature public key in the quantum-resistant signature key pair and the national cryptographic signature public key in the national cryptographic signature key pair are encapsulated in a single certificate carrier, and the quantum-resistant signature public key is signed based on the quantum-resistant signature root private key, and the national cryptographic signature public key is signed based on the national cryptographic signature root private key to generate a signature composite certificate. For encryption scenarios, the quantum-resistant encryption public key in the quantum-resistant encryption key pair and the national cryptographic encryption public key in the national cryptographic encryption key pair are encapsulated in a single certificate carrier. The quantum-resistant encryption public key is signed based on the quantum-resistant encryption root private key, and the national cryptographic encryption public key is signed based on the national cryptographic encryption root private key to generate an encrypted composite certificate.

[0015] This application provides an identity authentication method applied to an authentication client, the identity authentication method comprising the following steps: In response to the user's login request, the encrypted composite certificate from the authentication server is sent to the Super SIM card; The system receives key negotiation parameters sent by the Super SIM card and sends the key negotiation parameters to the authentication server; the key negotiation parameters are generated based on the encrypted composite certificate. Receive the challenge value sent by the authentication server, and send the challenge response value of the challenge value to the Super SIM card; The system receives the encrypted authentication response sent by the Super SIM card and sends the encrypted authentication response to the authentication server; the encrypted authentication response is used for identity authentication. Receive the login token sent by the authentication server and display it to the user.

[0016] According to an authentication method provided in this application, sending a challenge response value of the challenge value to the super SIM card includes: Send the decryption request for the challenge value to the Super SIM card; The system receives the decrypted challenge value sent by the Super SIM card and initiates a user confirmation operation; the user confirmation operation includes prompting the user to enter a personal identification code (PIN) and verifying the entered PIN. After the user confirms the operation, the challenge response value is determined based on the decrypted challenge value and user identification information.

[0017] This application provides an identity authentication method applied to an authentication server, the identity authentication method comprising the following steps: The system receives key negotiation parameters forwarded by the authentication client, sends the key negotiation parameters to the Super SIM cryptographic service platform for decryption, and obtains the session key component; the key negotiation parameters are generated based on the encrypted composite certificate of the authentication server. Send a challenge value generation request to the Super SIM Password Service Platform to obtain the challenge value returned by the Super SIM Password Service Platform; The challenge value and the session key generated based on the session key component are sent to the Super SIM cryptographic service platform to request the Super SIM cryptographic service platform to encrypt the challenge value and send the encrypted challenge value to the authentication client. The system receives the ciphertext authentication response sent by the authentication client, decrypts the ciphertext authentication response, and sends the decrypted plaintext authentication response data to the Super SIM Password Service Platform; the ciphertext authentication response is used for identity authentication. After receiving the successful verification result from the Super SIM Password Service Platform, a login token is generated based on the session key, and the login token is sent to the authentication client.

[0018] According to the authentication method provided in this application, the step of decrypting the ciphertext of the authentication response and sending the decrypted plaintext authentication response data to the Super SIM cryptographic service platform includes: Based on the session key, the ciphertext of the authentication response is decrypted to obtain the plaintext data of the authentication response; the plaintext data of the authentication response includes a hybrid signature, a composite certificate of the Super SIM card signature, and a challenge response value; The challenge response value is verified based on the challenge value and user identification information; After successful verification, the hybrid signature and the signature composite certificate are sent to the Super SIM cryptographic service platform.

[0019] This application also provides an identity authentication device, including the following modules: An encrypted composite certificate receiving module is used to receive an encrypted composite certificate from the authentication server sent by the authentication client and to verify the encrypted composite certificate. The session key component generation module is used to generate multiple quantum random numbers as session key components based on the QRNG module after successful verification. The key negotiation parameter generation module is used to encrypt the session key component based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, generate key negotiation parameters, and send the key negotiation parameters to the authentication server through the authentication client; The hybrid signature generation module is used to receive the challenge value forwarded by the authentication client from the authentication server, and to sign the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit, thereby generating a hybrid signature; The authentication response ciphertext sending module is used to encrypt the hybrid signature, the signature composite certificate of the Super SIM card, and the challenge response value based on the session key, and send the encrypted authentication response ciphertext to the authentication server via the authentication client; the session key is generated based on the key negotiation parameters, and the authentication response ciphertext is used for identity authentication.

[0020] This application also provides an identity authentication device, including the following modules: The first decryption module is used to respond to the decryption request from the authentication server, extract the quantum-resistant encryption private key and the national cryptographic encryption private key from the hardware security module, decrypt the key negotiation parameters provided by the authentication server, and send the decrypted session key component to the authentication server. The challenge value generation module is used to respond to the challenge value generation request from the authentication server by calling the quantum random source module to generate a quantum random number as the challenge value, and sending the challenge value to the authentication server. The challenge value sending module is used to respond to the encryption request from the authentication server, encrypt the challenge value based on the session key provided by the authentication server, and send the encrypted challenge value to the authentication client via the authentication server; The identity authentication module is used to respond to the signature verification request from the authentication server and perform identity authentication based on the plaintext authentication response data provided by the authentication server; the plaintext authentication response data is obtained by the authentication server decrypting the ciphertext authentication response received from the authentication client.

[0021] This application also provides an identity authentication device, including the following modules: The login response module is used to respond to the user's login request by sending the encrypted composite certificate from the authentication server to the Super SIM card; The key negotiation parameter receiving module is used to receive the key negotiation parameters sent by the Super SIM card and send the key negotiation parameters to the authentication server; the key negotiation parameters are generated based on the encrypted composite certificate. The challenge value receiving module is used to receive the challenge value sent by the authentication server and send the challenge response value of the challenge value to the super SIM card; The authentication response ciphertext receiving module is used to receive the authentication response ciphertext sent by the Super SIM card and send the authentication response ciphertext to the authentication server; the authentication response ciphertext is used for identity authentication. The login token receiving module is used to receive the login token sent by the authentication server and display it to the user.

[0022] This application also provides an identity authentication device, including the following modules: The second decryption module is used to receive the key negotiation parameters forwarded by the authentication client, and send the key negotiation parameters to the Super SIM cryptographic service platform for decryption to obtain the session key component; the key negotiation parameters are generated based on the encrypted composite certificate of the authentication server. The challenge value generation request sending module is used to send a challenge value generation request to the Super SIM password service platform in order to obtain the challenge value returned by the Super SIM password service platform; The challenge value encryption module is used to send the challenge value and the session key generated based on the session key component to the Super SIM cryptographic service platform to request the Super SIM cryptographic service platform to encrypt the challenge value and send the encrypted challenge value to the authentication client; The authentication response plaintext data sending module is used to receive the authentication response ciphertext sent by the authentication client, decrypt the authentication response ciphertext, and send the decrypted authentication response plaintext data to the Super SIM cryptographic service platform; the authentication response ciphertext is used for identity authentication. The login token generation module is used to generate a login token based on the session key after receiving the verification success result sent by the Super SIM password service platform, and send the login token to the authentication client.

[0023] This application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the authentication methods described above.

[0024] This application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the authentication method as described above.

[0025] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the authentication method described above.

[0026] The authentication method, apparatus, electronic device, storage medium, and program product provided in this application receive an encrypted composite certificate from the authentication server sent by the authentication client and verify the encrypted composite certificate. After successful verification, multiple quantum random numbers are generated based on a QRNG module as session key components. Based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, the session key components are encrypted to generate key negotiation parameters, which are then sent to the authentication server via the authentication client. The authentication server receives a challenge value forwarded by the authentication client and signs the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature. Based on the session key, the hybrid signature, the signature composite certificate of the super SIM card, and the challenge response value are encrypted, and the encrypted authentication response ciphertext is sent to the authentication server via the authentication client. The session key is generated based on the key negotiation parameters, and the authentication response ciphertext is used for identity authentication. This application constructs a three-in-one security architecture that integrates quantum random source generation, dual-system algorithm fusion, and hardware-level key protection by using a super SIM card as the hardware carrier. While ensuring that the authentication process has quantum-resistant security and national cryptographic compliance, it enables users to have a convenient plug-and-play experience without having to carry additional dedicated hardware, thus solving the contradiction between security and portability in high-security scenarios. Attached Figure Description

[0027] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0028] Figure 1 This is one of the flowcharts illustrating the identity authentication method provided in this application.

[0029] Figure 2 This is the second flowchart illustrating the identity authentication method provided in this application.

[0030] Figure 3 This is the third flowchart illustrating the identity authentication method provided in this application.

[0031] Figure 4 This is the fourth flowchart illustrating the identity authentication method provided in this application.

[0032] Figure 5 This is a schematic diagram of the identity authentication system provided in this application.

[0033] Figure 6 This is a flowchart illustrating the secure encrypted identity authentication method based on a super SIM card and quantum-resistant cryptography provided in this application.

[0034] Figure 7 This is one of the structural schematic diagrams of the identity authentication device provided in this application.

[0035] Figure 8 This is the second structural schematic diagram of the identity authentication device provided in this application.

[0036] Figure 9 This is the third structural schematic diagram of the identity authentication device provided in this application.

[0037] Figure 10 This is the fourth structural schematic diagram of the identity authentication device provided in this application.

[0038] Figure 11 This is a schematic diagram of the structure of the electronic device provided in this application. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0040] To address the problems existing in the prior art, this application provides a secure encrypted identity authentication system and method based on a Super SIM (Subscriber Identity Module) card and quantum-resistant cryptography. The system eliminates the risk of quantum computing cracking during the identity authentication process of mobile terminal users using cryptographic technology through a triple protection design of "QRNG (Quantum Random Number Generator) + national cryptographic standard + quantum resistance". The mobile terminal uses a super SIM card with a built-in QRNG chip as the secure hardware carrier, while the server uses QRNG / QKD (Quantum Key Distribution) as the quantum random source. The QRNG chip and device provide high-quality quantum random numbers, ensuring the randomness of the mobile terminal's national cryptographic and quantum-resistant key generation and encryption signature calculation processes. A hybrid encryption mechanism based on SM2 and Kyber is designed to ensure the security of data transmission during the authentication process. In the face of threats such as quantum computing, the security of either algorithm guarantees the security of transmission. A "composite challenge + hybrid signature" authentication mechanism is designed to ensure the security of the identity authentication process. A composite challenge value binding the user's identity and session is constructed, and hybrid signature and dual verification are performed using SM2 and Dilithium. The security of either algorithm guarantees the security of the authentication mechanism, eliminating the risk of replay attacks and identity forgery. Simultaneously, the system as a whole adopts a hybrid certificate system of "national cryptographic + quantum-resistant," with certificates containing both national cryptographic and quantum-resistant public keys and certificate signatures. Compared to a dual-certificate system, this reduces the overall certificate size while avoiding the risk of forgery of either certificate. Ultimately, the technology aims to achieve "quantum security, hardware trustworthiness, portability and ease of use, and efficient collaboration," meeting the needs of high-security identity authentication scenarios such as financial transactions, government logins, and remote enterprise work, and effectively addressing quantum threats.

[0041] The following is combined Figures 1-11 This application describes the authentication methods, apparatus, electronic devices, storage media, and program products.

[0042] Figure 1 This is one of the flowcharts illustrating the identity authentication method provided in this application. This method is applied to a Super SIM card, which integrates a security unit and a quantum random number generator (QRNG) module, such as... Figure 1 As shown, the method includes: Step 101: Receive the encrypted composite certificate from the authentication server sent by the authentication client, and verify the encrypted composite certificate.

[0043] It should be understood that the Super SIM card, as the core security carrier on the device side, is an embedded trusted execution unit that deeply integrates cryptographic capabilities. Compared with external key devices such as UKEY (USB Key), which require additional carrying and manual insertion and removal, it leverages the natural integration advantage of the SIM card slot in the mobile terminal to achieve a convenient experience that requires no additional equipment and can be used with any authentication client. At the hardware level, the Super SIM card integrates a Secure Element (SE) hardware security isolation zone and a quantum random number generator compliant with the NIST SP800-22 standard. It supports hardware-accelerated computation of SM2 / SM3 / SM4 national cryptographic algorithms and Kyber-768 / Dilithium-III quantum-resistant algorithms, enabling high-strength data encryption and authentication operations. Its built-in key storage unit is dedicated to pre-storing dual-system key pairs (Kyber quantum-resistant encryption key pair, Dilithium quantum-resistant signature key pair, SM2 national cryptographic encryption key pair, and SM2 national cryptographic signature key pair). All keys and random numbers required for cryptographic operations are generated based on QRNG / QKD, improving the quality of key random numbers. The storage area is physically isolated and protected by SE / TEE (Trusted Execution Environment). Private key access can only be triggered through PIN (Personal Identification Number) verification, blocking side-channel attack risks at the hardware level and ensuring the security of key storage and computation.

[0044] The encrypted composite certificate encapsulates two public keys from different cryptographic systems, each independently signed by its corresponding root certificate private key, forming a unified encrypted trust credential. The dual public keys encapsulated in the encrypted composite certificate (ser_EncCrt) can include a quantum-resistant encryption public key (ser_KybPub) and a Chinese national cryptographic encryption public key (ser_GmEPub).

[0045] The authentication client runs on the user terminal and is configured to access the Super SIM card mounted on the same user terminal.

[0046] The Super SIM card receives an encrypted composite certificate from the authentication server sent by the authentication client. For example, a user triggers a login request by entering account information through an authentication client (such as an app) running on a user terminal like a smartphone. In response, the authentication client sends a login request containing user identification information to the authentication server over the network, while simultaneously reading the pre-installed encrypted composite certificate from its secure local storage. It should be understood that the encrypted composite certificate is issued and stored in the authentication client via a secure channel from the Super SIM cryptographic service platform or authentication server during system initialization or user registration. The authentication client establishes a local communication connection with the Super SIM card inserted into or integrated into the same user terminal through the standard hardware access interface provided by the user terminal's operating system. The authentication client then sends the data stream of the read encrypted composite certificate to the Super SIM card in its entirety through the local communication connection. Correspondingly, the Super SIM card receives the encrypted composite certificate from the authentication client through its communication interface.

[0047] Verify the encrypted composite certificate. For example, verify the signature validity, validity period, and status validity of the encrypted composite certificate.

[0048] Step 102: After successful verification, generate multiple quantum random numbers as session key components based on the QRNG module.

[0049] It should be understood that a quantum random number generator (QRNG) module is a specialized hardware that uses the inherent quantum randomness of microscopic particles (such as photon paths, electron tunneling, vacuum fluctuations, etc.) as an entropy source to generate theoretically completely unpredictable true random numbers.

[0050] The session key component is a raw random number generated by the QRNG module of the Super SIM card and used to synthesize the final session key.

[0051] After successful verification of the authentication server's encrypted composite certificate (ser_EncCrt), the Super SIM card initiates the key negotiation preparation phase. This phase aims to generate the key seed with the highest randomness quality required for this session. This process can be executed within the Super SIM card's Secure Element (SE). The physical and logical isolation provided by the SE ensures that intermediate data during the generation process (especially the original quantum random numbers) will not be stolen or interfered with by external malware. For example, the firmware instructions of the security processor call the QRNG module, which is configured to generate two independent quantum random numbers with cryptographic strength. Specifically, the QRNG core can be called consecutively to first generate a random number q1 of a specified length (e.g., 256 bits), and then generate a second random number q2 of the same length. Alternatively, if the QRNG hardware supports parallel output of two independent random bit streams, forming q1 and q2 respectively. The generated q1 and q2 are explicitly identified by the security processor as the first session key component (q1) and the second session key component (q2).

[0052] Step 103: Based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, the session key component is encrypted respectively to generate key negotiation parameters, and the key negotiation parameters are sent to the authentication server through the authentication client.

[0053] It should be understood that key negotiation parameters refer to the ciphertext data packets formed by asymmetric encryption of the session key components (q1, q2), which can be securely transmitted over public channels. Specifically, key negotiation parameters are the encrypted result generated by the Super SIM card using the other party's public key to encrypt local secret information (such as random numbers).

[0054] Extract the different encrypted public keys (the first quantum-resistant encryption public key and the first national cryptographic encryption public key) from the encrypted composite certificate, and perform encryption operations on different session key components to generate key negotiation parameters.

[0055] After the Super SIM card successfully generates the key negotiation parameters (Q1 and Q2) for this session, these parameters need to be securely transmitted to a remote authentication server to complete the key negotiation. For example, the security processor within the Super SIM card assembles the generated first key negotiation parameter (Q1) and second key negotiation parameter (Q2) within a secure unit to form a data packet to be sent. This assembled data packet containing Q1 and Q2 is sent to the authentication client through a local secure communication channel between the Super SIM card and the authentication client. It should be understood that this channel is located inside the user terminal and does not pass through an external network, preventing eavesdropping by attackers within the local area network. The authentication client receives the data packet from the Super SIM card through the corresponding operating system interface, parses the data packet, and identifies the Q1 and Q2 parameters. Following the application layer protocol agreed upon with the authentication server, the authentication client encapsulates Q1 and Q2 as critical payloads into a new, formatted network request message. This message may contain the context identifier of this session (such as session ID and user ID). The terminal's network module (such as Wi-Fi or cellular data) uses Transport Layer Security (TLS) to send an encapsulated network request message to a pre-configured authentication server URL (Uniform Resource Locator). The authentication server's network interface listens for and receives the TLS connection request and subsequent data from the authentication client, parses the network request message sent by the authentication client, and extracts the key negotiation parameters Q1 and Q2 from the message.

[0056] Step 104: Receive the challenge value forwarded by the authentication client from the authentication server, and sign the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature.

[0057] It should be understood that the challenge value, denoted as R1, is a random number generated by the authentication client invoking the Super SIM cryptographic service platform. The challenge response value, denoted as R2, is a combination of information constructed by the authentication client, containing the user's identity and the received challenge value. For example, the challenge response value is constructed by the authentication client based on the challenge value and the user's identification information.

[0058] A hybrid signature is a data structure containing two independent digital signatures generated by the same signer (Super SIM card holder) using two different cryptographic systems' private keys for the same message (challenge response value R2).

[0059] The Super SIM card receives the challenge value forwarded by the authentication client from the authentication server through a local communication interface with the authentication client. It then uses the quantum-resistant signature private key and the national cryptographic signature private key, securely stored in a secure unit, to sign the challenge response value, generating a hybrid signature.

[0060] Step 105: Based on the session key, encrypt the hybrid signature, the signature composite certificate of the Super SIM card, and the challenge response value, and send the encrypted authentication response ciphertext to the authentication server via the authentication client.

[0061] It should be understood that the session key (denoted as SesKey) is a symmetric encryption key temporarily negotiated by the two parties involved in this authentication (Super SIM card and authentication server) and is used only for this session. The session key is generated based on the key negotiation parameters.

[0062] The authentication response ciphertext is used for identity authentication. Specifically, the authentication response ciphertext is the core data (hybrid signature, signature composite certificate, challenge response value) generated by the Super SIM card to prove its identity, which is then encrypted with the session key (SesKey) to form the overall ciphertext data packet.

[0063] After the Super SIM card generates a hybrid signature (Sig1, Sig2) representing the user's identity, these core credentials need to be securely transmitted to the authentication server for final verification. The core of this process is to encapsulate all verification materials and encrypt them with a key unique to this session, forming a secure data packet. This can be achieved, for example, in the following way: The Super SIM card's security processor, within the security unit (SE), assembles the following three key data elements into a structured plaintext data packet (P): Hybrid signature: Includes quantum-resistant signature Sig2 and Chinese national cryptographic signature Sig1; Signature composite certificate: The Super SIM card's own sim_SigCrt certificate, which contains two public keys used to verify Sig1 and Sig2; Challenge response value: The original statement of this authentication, R2 (i.e., UserID||R1).

[0064] The assembly format can be a predefined TLV (tag-length-value) structure, JSON serialization, or simple binary concatenation (e.g., P=Sig1||Sig2||sim_SigCrt||R2).

[0065] The security processor calls the symmetric session key SesKey, temporarily generated for this session and stored in the SE's secure memory. A symmetric encryption algorithm matching the SesKey length is selected. For compliance requirements, the national standard SM4 algorithm is preferred; or for interoperability requirements, an AES (Advanced Encryption Standard) algorithm (such as AES-GCM or AES-CBC mode) is selected. The encryption operation C = Enc_SesKey(P) is performed. If an authentication encryption mode (such as SM4-GCM or AES-GCM) is selected, this operation will output both the ciphertext C and an authentication tag for integrity verification.

[0066] The encrypted output C (and optional Tag) constitutes the authentication response ciphertext, which can only be decrypted by an authentication server holding the same SesKey.

[0067] The Super SIM card sends the encrypted authentication response C to the authentication client via its local communication interface. Contextual information (such as the current session ID) can be attached. The authentication client receives the encrypted authentication response from the Super SIM card and, according to the application layer protocol agreed upon with the authentication server, encapsulates this encrypted response as the core payload into a network request (such as the body of an HTTP POST request). Simultaneously, it sends the network request containing the encrypted response to the authentication server's preset address via an established, secure transport layer connection. The authentication server receives the network request and parses out the encrypted authentication response C.

[0068] The authentication method provided in this application embodiment receives an encrypted composite certificate from the authentication server sent by the authentication client and verifies the encrypted composite certificate. After successful verification, multiple quantum random numbers are generated based on the QRNG module as session key components. Based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, the session key components are encrypted to generate key negotiation parameters, which are then sent to the authentication server via the authentication client. The challenge value forwarded by the authentication client from the authentication server is received, and the challenge response value corresponding to the challenge value is signed based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature. Based on the session key, the hybrid signature, the signature composite certificate of the Super SIM card, and the challenge response value are encrypted, and the encrypted authentication response ciphertext is sent to the authentication server via the authentication client. The session key is generated based on the key negotiation parameters, and the authentication response ciphertext is used for identity authentication. This application constructs a three-in-one security architecture that integrates quantum random source generation, dual-system algorithm fusion, and hardware-level key protection by using a super SIM card as the hardware carrier. While ensuring that the authentication process has quantum-resistant security and national cryptographic compliance, it enables users to have a convenient plug-and-play experience without having to carry additional dedicated hardware, thus solving the contradiction between security and portability in high-security scenarios.

[0069] Based on the above embodiments, the step of encrypting the session key components based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, and generating key negotiation parameters, includes: Based on the first quantum-resistant encryption public key, the first session key component is encrypted to obtain the first key negotiation parameters; Based on the first national cryptographic public key, the second session key component is encrypted to obtain the second key negotiation parameters.

[0070] After the Super SIM card successfully generates two quantum random session key components (q1 and q2), its security processor uses the verified cryptographic composite certificate (ser_EncCrt) from the authentication server to perform the following steps to generate securely transmit key negotiation parameters: 1) The Super SIM card's security processor parses the verified ser_EncCrt certificate data, accessing its public key information field conforming to the X.509 standard. Specifically, the processor locates and extracts the public key data with an algorithm identifier of a quantum-resistant algorithm (e.g., id-Kyber) from specific extensions or the main public key information field of the certificate. This public key is denoted as ser_KybPub, and its format conforms to the public key specification of quantum-resistant key encapsulation mechanisms (KEM) such as Kyber. Simultaneously, the processor locates and extracts the public key data with an algorithm identifier of a national cryptographic algorithm (e.g., id-SM2-Encryption) from the same certificate. This public key is denoted as ser_GmEPub, and its format conforms to the public key specification for encryption / key exchange using the SM2 algorithm.

[0071] 2) The processor calls the integrated quantum-resistant cryptographic algorithm coprocessor or software library to perform the Kyber key encapsulation operation. It inputs the public key (ser_KybPub) and the first session key component q1, and executes Q1=Kybe_Enc(ser_KybPub,q1). Internally, this algorithm utilizes ser_KybPub and randomness to generate an encapsulated ciphertext Q1 (i.e., the first key negotiation parameter). This ciphertext securely carries the information of q1, where Q1 is a ciphertext data block conforming to the Kyber algorithm output specification.

[0072] 3) The processor calls the national cryptographic algorithm coprocessor or software library to perform the SM2 public key encryption operation. It inputs the public key (ser_GmEPub) and the second session key component q2, and executes Q2=SM2_Enc(ser_GmEPub,q2). This algorithm uses ser_GmEPub to perform standard asymmetric encryption on q2, obtaining the second key negotiation parameter Q2, where Q2 is a ciphertext data block conforming to the SM2 encryption algorithm output specification.

[0073] After generating Q1 and Q2, the Super SIM card can send these two key negotiation parameters to the authentication server through the authentication client to complete the subsequent key negotiation.

[0074] This application's embodiments extract two sets of encryption public keys—one quantum-resistant and one based on national cryptographic standards—in parallel from a single encrypted composite certificate, and then encrypt the two independent quantum random session key components using corresponding algorithms. The quantum-resistant algorithm ensures the key negotiation's immunity to future quantum attacks, while the national cryptographic algorithm ensures current compliance.

[0075] Based on the above embodiments, the step of signing the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature includes: Based on the quantum-resistant signature private key, the challenge response value is signed to obtain the first signature; Based on the national cryptographic signature private key, the challenge response value is signed to obtain a second signature.

[0076] It should be understood that the hybrid signature includes a first signature and a second signature; the challenge response value is obtained by concatenating the user identification information with the challenge value.

[0077] After the Super SIM card obtains or constructs the challenge response value for this authentication session (e.g., R2=UserID||R1), the security processor within its security unit will execute the identity credential generation step: digitally signing R2 using two sets of private keys from different systems to generate a hybrid signature. This process is performed in an isolated hardware security environment and may include the following: 1) The message R2 to be signed is securely loaded into the internal secure RAM (Random Access Memory) of the secure unit (SE). The secure processor accesses the secure keystore within the SE, preparing to invoke two different signing private keys: Quantum-resistant signature private key: denoted as sim_DltPrv, its format conforms to the private key specifications of quantum-resistant signature algorithms such as Dilithium; The private key for the national cryptographic signature is denoted as sim_GmSPrv, and its format conforms to the private key specification of the national cryptographic SM2 signature algorithm.

[0078] 2) The processor invokes the integrated quantum-resistant signature algorithm coprocessor (or software module), inputting the private key (sim_DltPrv) and the message to be signed, R2, and executes Sig2 = Dlt_Sign(R2, sim_DltPrv). This algorithm uses sim_DltPrv and R2 to generate a digital signature Sig2, i.e., the first signature, based on a lattice cryptographic problem. Sig2 is a signature data block conforming to the Dilithium algorithm specification.

[0079] 3) The processor calls the integrated national cryptographic algorithm coprocessor (or software module), inputs the private key (sim_GmSPrv) and the message to be signed R2, and executes Sig1=SM2_Sign(R2,sim_GmSPrv). This algorithm uses sim_GmSPrv and R2 to generate a digital signature Sig1, i.e., the second signature, based on the elliptic curve discrete logarithm problem. Sig1 is an (r,s) pair conforming to the SM2 signature algorithm specification or its encoded form.

[0080] The security processor combines Sig1 and Sig2 into a single data structure, known as a hybrid signature. This can be represented as an ordered pair (Sig1, Sig2) or encoded as a composite data block. The generated hybrid signature is output, ready for use in subsequent authentication responses.

[0081] This application embodiment achieves superimposed security by applying a dual composite signature of quantum-resistant and national cryptographic standards to the same authentication statement, which increases the difficulty of forging or cracking identity credentials. At the same time, it can complete the transition from the current national cryptographic system to the future quantum-resistant system and provide continuous protection without changing the core hardware carrier.

[0082] Based on the above embodiments, the verification of the encrypted composite certificate includes: Request the pre-configured encrypted composite root certificate of the Super SIM cryptographic service platform from the authentication client; Extract the second quantum-resistant encryption public key and the second national cryptographic encryption public key from the encrypted composite root certificate; Based on the second quantum-resistant encryption public key, the signature value of the first quantum-resistant encryption public key in the encrypted composite certificate is verified; and based on the second national cryptographic encryption public key, the signature value of the first national cryptographic encryption public key in the encrypted composite certificate is verified; and, The validity period and certificate status information of the encrypted composite certificate are verified.

[0083] It should be understood that the encrypted composite root certificate is a special root certificate issued by the Super SIM cryptographic service platform itself, used to establish the apex of the entire system's encrypted trust chain. The dual public keys encapsulated in the encrypted composite root certificate (root_EncCrt) can include a quantum-resistant encryption root public key (root_KybPub) and a Chinese national cryptographic root public key (root_GmEPub). The quantum-resistant encryption root public key is used to verify the signature of the quantum-resistant encryption public key in the encrypted composite certificate; the Chinese national cryptographic root public key is used to verify the signature of the Chinese national cryptographic public key in the encrypted composite certificate.

[0084] The Super SIM card requests a pre-installed encrypted composite root certificate from the Super SIM cryptographic service platform from the authentication client. For example, after successfully receiving the encrypted composite certificate from the authentication client through its communication interface, the Super SIM card triggers a certificate verification process. The processing logic within the Super SIM card determines that the signature needs to be verified using the root certificate that issued the encrypted composite certificate. The Super SIM card proactively sends a specific request command to the authentication client via a local communication connection. This command contains explicit instruction codes to request the pre-installed encrypted composite root certificate from the Super SIM cryptographic service platform. Upon receiving the request command from the Super SIM card, the authentication client parses the command, accesses its own protected local storage area (such as the application's secure data area), reads the pre-stored encrypted composite root certificate, and returns the complete data of the read encrypted composite root certificate to the Super SIM card via the local communication connection. Accordingly, the Super SIM card successfully receives the encrypted composite root certificate from the authentication client.

[0085] The security processor within the Super SIM card first parses the encrypted composite root certificate (root_EncCrt), extracting two key root public keys from specific fields of its standard data structure (such as X.509 format): the second quantum-resistant encryption public key, i.e., the quantum-resistant encryption root public key of the Super SIM cryptographic service platform, denoted as root_KybPub; and the second national cryptographic encryption public key, i.e., the national cryptographic encryption root public key of the Super SIM cryptographic service platform, denoted as root_GmEPub. Simultaneously, it parses the encrypted composite certificate (ser_EncCrt), extracting two encapsulated business public keys to be verified and their corresponding digital signature values: the first quantum-resistant encryption public key, i.e., the quantum-resistant encryption public key of the authentication server, denoted as ser_KybPub, and its signature value Sig_serKyb; and the first national cryptographic encryption public key, i.e., the national cryptographic encryption public key of the authentication server, denoted as ser_GmEPub, and its signature value Sig_serGmE.

[0086] The verification process can be performed by a cryptographic coprocessor within the Security Unit (SE) of the Super SIM card, using the root public key of the same architecture to verify the signature of the corresponding architecture's service public key, and may include the following steps: 1) Quantum-resistant signature verification: Call a quantum-resistant signature verification algorithm (such as the Dilithium verification algorithm). The input parameters are: root_KybPub (verifier's public key), ser_KybPub (the message to be signed), and Sig_serKyb (the signature to be verified). Execute the operation: Dilithium_Verify(root_KybPub, ser_KybPub, Sig_serKyb). The output result is a boolean value: true (passed) or false (failed).

[0087] 2) National Cryptographic Signature Verification: Call the national cryptographic SM2 signature verification algorithm. The input parameters are: root_GmEPub (verifier's public key), ser_GmEPub (the message to be signed), and Sig_serGmE (the signature to be verified). The operation is: SM2_Verify(root_GmEPub, ser_GmEPub, Sig_serGmE). The output result is a boolean value: true (passed) or false (failed).

[0088] The Super SIM card's firmware logic collects the two independent verification results mentioned above. The Super SIM card only determines that the signature validity verification of the authentication server's encrypted composite certificate (ser_EncCrt) has passed if and only if both Dilithium_Verify and SM2_Verify return "true". Based on this, the Super SIM card can be certain that ser_KybPub was indeed issued by the Super SIM cryptographic service platform holding root_KybPrv, and that ser_GmEPub was indeed issued by the same platform holding root_GmEPrv, thus establishing the trustworthiness of ser_EncCrt as an encryption credential.

[0089] After completing the cryptographic signature verification of the encrypted composite certificate from the authentication server, or in parallel, the Super SIM card also needs to verify its validity period and certificate status information to ensure that the certificate is valid both temporally and administratively. For example, during validity period verification, the Super SIM card parses the standard structure of the ser_EncCrt certificate and extracts the "validity period" field. This field typically contains two timestamps: the effective time, i.e., the start time when the certificate becomes valid; and the expiration time, i.e., the time when the certificate automatically expires. The Super SIM card obtains the current timestamp from its internal secure clock module, which synchronizes with the network time via a security protocol when the device starts up and operates independently. If the current time is earlier than the effective time, the certificate is "not yet effective," and verification fails; if the current time is later than the expiration time, the certificate is "expired," and verification fails.

[0090] It should be understood that verifying the certificate status information of ser_EncCrt aims to confirm whether the certificate was actively revoked by the issuer (i.e., the Super SIM cryptographic service platform) before its natural expiration due to reasons such as private key leakage or identity change. For example, the distribution point information of the CRL (Certificate Revocation List) can be obtained from the encrypted composite certificate. Based on the CRL distribution point information, a CRL file signed by the issuer can be obtained; the signature validity of the CRL file can be verified; in the verified valid CRL file, the serial number of the encrypted composite certificate can be searched; if the serial number is not found, it is confirmed that the encrypted composite certificate has not been revoked. Alternatively, the OCSP responder address can be obtained from the encrypted composite certificate, and a status query request for the encrypted composite certificate can be sent to the OCSP (Online Certificate Status Protocol) responder address. The issuer's signed OCSP response can be received and verified; if the OCSP response indicates that the certificate status is normal, it is confirmed that the encrypted composite certificate has not been revoked.

[0091] This application embodiment utilizes a dual-root public key system of quantum resistance and national cryptographic standards to perform independent cryptographic verification of business certificates, ensuring the authenticity of the certificate issuance source and the forward-looking nature of the algorithm. At the same time, by checking the certificate validity period and revocation status, dynamic security management of the entire lifecycle of the certificate is achieved.

[0092] Figure 2 This is the second flowchart illustrating the authentication method provided in this application. This method is applied to the Super SIM cryptographic service platform, which integrates a quantum random source module and a hardware security module, such as... Figure 2 As shown, the method includes: Step 201: In response to the decryption request from the authentication server, extract the quantum-resistant encryption private key and the national cryptographic encryption private key from the hardware security module, decrypt the key negotiation parameters provided by the authentication server, and send the decrypted session key component to the authentication server.

[0093] It should be understood that the Super SIM cryptographic service platform provides a NIST-standard-based quantum-resistant cryptographic service API (Application Programming Interface), serving as the system's root of trust and key management hub. It offers a national cryptographic / quantum-resistant certificate issuance and hardware security module (HSM), encompassing key pair generation, signature / verification, and key encapsulation / decapsulation functions. Simultaneously, it manages the entire lifecycle of keys from generation and storage to distribution, update, and revocation. The platform relies on QRNG / QKD hardware to construct a quantum key source. All generated Dilithium quantum-resistant keys, Kyber quantum-resistant keys, and SM2 national cryptographic keys, as well as the random numbers required for cryptographic operations, are generated from this quantum source. The quality of the random numbers conforms to NIST SP 800-22 and GM / T 0062-2021 specifications, eliminating the risk of predictable keys from the source. It is also compatible with various cryptographic devices such as cloud server cryptographic machines and signature / verification servers, constructing a distributed cryptographic resource pool to provide efficient computing power support for national cryptographic and quantum-resistant algorithms for the authentication server. The platform exclusively stores the authentication server's dual-system private keys (Kyber encryption private key, SM2 encryption private key, Dilithium signing private key, and SM2 signing private key) through a hardware security module. Private key access never crosses the HSM boundary; decryption and signing operations are completed solely through key indexes. Furthermore, the platform integrates an OCSP certificate status query service, supporting real-time verification of certificate validity and revocation status. This provides collaborative support for signature verification and key negotiation for the authentication server, serving as a core infrastructure for ensuring the integrity of the system's trust chain and key security.

[0094] A hardware security module is a computing device that protects encryption keys throughout their entire lifecycle (generation, storage, use, and destruction) using a dedicated security chip, a physical tamper-proof casing, and robust access control mechanisms. Its design goal is to ensure that even if an attacker gains access to the physical device, they cannot extract the protected keys.

[0095] When the authentication server receives the key negotiation parameters (Q1 and Q2) from the Super SIM card, it cannot decrypt them on its own and needs to request the secure decryption service from the Super SIM cryptographic service platform. The platform responds to this request and performs the decryption process in a secure environment as follows: The authentication server sends a decryption request for key negotiation parameters to the Super SIM cryptographic service platform via a secure API interface. This request message may include: a request identifier (such as a unique session ID for tracking and replay protection), data to be decrypted (first key negotiation parameter Q1 and second key negotiation parameter Q2), and the server's identity credentials, used by the platform to verify whether the requester is a legitimate authentication server. The platform's front-end service gateway receives the request, first verifying the server's identity credentials and the validity of the request (such as signature and validity period). After successful verification, the request is forwarded to the security service engine.

[0096] The security service engine determines the key pair required for decryption based on the session ID or authentication server identifier in the request. The engine initiates an authenticated and authorized connection to the Hardware Security Module (HSM). This authorization is based on access control policies pre-configured within the HSM, ensuring that only the platform's core service components have the right to access the specific key.

[0097] The security service engine sends a command to the HSM to logically extract or prepare for use of two private keys hosted within it: a quantum-resistant encryption private key, identified as ser_KybPrv (a Kyber algorithm private key); and a Chinese national cryptographic encryption private key, identified as ser_GmEPrv (an SM2 encryption algorithm private key). It should be understood that the extraction operation does not involve reading the plaintext data of the private keys from the HSM, but rather refers to activating or marking these two keys within the HSM, preparing them for subsequent computation. The bits of the private keys are always physically protected by the HSM and are not exposed outside the HSM.

[0098] After receiving the decryption command and ciphertext data Q1 and Q2, HSM decrypts the ciphertext data Q1 and Q2, and the decrypted q1 and q2 are temporarily generated internally by HSM. HSM outputs these two plaintext results to the platform's security service engine through a secure channel, and at the same time, the temporary cache used by HSM for this operation is cleared.

[0099] The platform's security service engine encapsulates q1 and q2 into a response message, which is returned to the authentication server that initiated the request through a secure API channel.

[0100] Step 202: In response to the challenge value generation request from the authentication server, the quantum random source module is invoked to generate a quantum random number as the challenge value, and the challenge value is sent to the authentication server.

[0101] It should be understood that the quantum random source module is a dedicated hardware component integrated within the Super SIM cryptographic service platform that directly generates truly random numbers based on quantum physics processes. Specifically, the quantum random source module can be a quantum random number generator (QRNG) module or a quantum key distribution (QKD) module.

[0102] When the authentication process requires a user identity challenge, the authentication server does not generate the challenge value itself. Instead, it requests a challenge value with randomness from the Super SIM password service platform. For example, the challenge value can be generated in the following ways: The authentication server sends a challenge value generation request to the Super SIM cryptographic service platform via a secure API. This request may include an identifier for the current session to ensure the challenge value is bound to a specific session. The platform's service engine parses the request and instructs its integrated quantum random number source to generate a random number of a specified length (e.g., 256 bits). The quantum random source generates a raw random bit stream based on the inherent uncertainty of microscopic quantum processes. After subsequent processing (such as debiasing and amplification), this bit stream forms a quantum random number that meets the requirements of cryptographic applications. This random number is theoretically completely unpredictable and non-repeatable. The platform formally defines this generated quantum random number as the challenge value for this authentication session, denoted as R1, and returns R1 to the requesting authentication server via the secure API response. The response may include information about the association between the challenge value and the session. Upon receiving R1, the authentication server uses it as the core basis for this "challenge-response" authentication.

[0103] Step 203: In response to the encryption request from the authentication server, the challenge value is encrypted based on the session key provided by the authentication server, and the encrypted challenge value is sent to the authentication client via the authentication server.

[0104] The SuperSIM cryptographic service platform accepts the entrustment of the authentication server and uses the temporary session key provided by the authentication server to encrypt the quantum random challenge value previously generated, in order to assist the server in completing the secure distribution process.

[0105] In one embodiment, after obtaining the quantum random challenge value R1 and the session key SesKey for this session, the authentication server does not encrypt it itself, but instead sends an encryption request for the challenge value to the Super SIM cryptographic service platform. This request is transmitted through a secure API and contains at least two fields: 1) Session key (SesKey): a symmetric key derived by the server for this session; 2) Challenge value (R1): the plaintext quantum random number that needs to be encrypted.

[0106] The Super SIM cryptographic service platform's service engine receives encryption requests and first verifies the identity and authorization of the request source. Upon successful verification, the engine loads the SesKey and R1 from the encryption request into a secure temporary processing environment (such as a Trusted Execution Environment (TEE) or a secure memory area working with HSM). In this model, the platform is fully trusted by the authentication server and can temporarily hold the SesKey. The platform's cryptographic service module selects the appropriate symmetric encryption algorithm based on the SesKey's length and algorithm identifier (usually specified by the server in the request or pre-agreed upon by both parties). For example, it can choose the national standard SM4 algorithm to maintain full-chain compliance, or it can support the AES algorithm. The encryption operation is performed: E(R1) = Enc_SesKey(R1). If an authentication encryption mode (such as SM4-GCM) is used, this operation outputs both ciphertext and an authentication tag. The encryption process ensures the confidentiality and integrity of R1. After encryption, the platform generates response data, which is the encrypted challenge value E(R1). The platform returns E(R1) to the authentication server via a secure API. After returning a response, the platform immediately removes the plaintext copies of SesKey and R1 from secure memory.

[0107] After receiving E(R1), the authentication server does not need to decrypt it. Instead, it directly uses it as the challenge value ciphertext and sends it to the authentication client through the communication channel between the server and the authentication client.

[0108] Step 204: In response to the signature verification request from the authentication server, perform identity authentication based on the plaintext data of the authentication response provided by the authentication server.

[0109] The plaintext data of the authentication response is obtained by the authentication server decrypting the ciphertext of the authentication response received from the authentication client.

[0110] The verification process includes verifying the signature composite certificate and the mixed signature in the authentication response data and outputting a binary identity authentication decision result; wherein, the binary decision result is successful authentication if and only if the signature composite certificate is verified and all signatures in the mixed signature are verified.

[0111] In one embodiment, after the authentication server completes the decryption of the authentication response ciphertext and preliminary business verification, it delegates the final cryptographic decision-making for identity verification to the Super SIM cryptographic service platform. The platform, acting as the root of trust and adjudication center, performs the following complete authentication process: The authentication server sends a signature verification and identity authentication request to the Super SIM cryptographic service platform through a highly secure management API. This request message may carry the following information: 1) Request metadata: includes request ID, timestamp, and server identity identifier.

[0112] 2) Authentication response plaintext data packet: hybrid signature, including Sig1 (Chinese national cryptographic signature) and Sig2 (quantum resistant signature); signature composite certificate, i.e., the sim_SigCrt of the Super SIM card; challenge response value R2 (i.e., UserID||R1).

[0113] The platform's front-end gateway receives requests and verifies the server-side credentials and request integrity. Once verification is successful, the data is forwarded to the authentication adjudication engine.

[0114] The authentication adjudication engine first verifies the legitimacy of the sim_SigCrt, which is the foundation of trust for all subsequent verifications. Specifically, the engine invokes its own absolutely trusted platform signature composite root certificate (root_SigCrt); uses the national cryptographic signature root public key (root_GmSPub) in root_SigCrt to verify the signature of sim_GmSPub in sim_SigCrt; and uses the quantum-resistant signature root public key (root_DltPub) in root_SigCrt to verify the signature of sim_DltPub in sim_SigCrt. Additionally, it simultaneously checks the validity period of the sim_SigCrt and queries its revocation status in real time via the Online Status Protocol (OCSP). If any of the above verifications fails, the engine immediately terminates the process, generates an adjudication result of "Authentication Failed: Certificate Invalid" and returns it. If all verifications succeed, it proceeds to signature verification.

[0115] Assuming the certificate is valid, the authentication adjudication engine extracts the verified public keys sim_GmSPub and sim_DltPub from sim_SigCrt. It then calls the SM2 verification algorithm, inputting the public key sim_GmSPub, message R2, and signature Sig1, and executes result_sm2=SM2_Verify(R2,Sig1,sim_GmSPub). Simultaneously, it calls the Dilithium verification algorithm, inputting the public key sim_DltPub, message R2, and signature Sig2, and executes result_dlt=Dlt_Verify(R2,Sig2,sim_DltPub).

[0116] The authentication adjudication engine performs the final logical AND operation: final_verdict = (result_sm2 == TRUE) AND (result_dlt == TRUE). If final_verdict = TRUE: the authentication adjudication engine generates a final adjudication of "authentication successful," meaning the platform confirms that: the submitted certificate is authentic and valid; signatures Sig1 and Sig2 were indeed generated by the two private keys corresponding to the certificate; and the signature content is precisely the challenge response R2 for this authentication. The user's identity is verified by a dual cryptographic mechanism. If final_verdict = FALSE: the authentication adjudication engine generates a final adjudication of "authentication failed," and may append a reason code based on the specific values ​​of result_sm2 and result_dlt (e.g., invalid national cryptographic signature, invalid quantum-resistant signature).

[0117] The authentication adjudication engine encapsulates a concise and clear adjudication result (success / failure and optional reason code) into a response message, which is returned to the authentication server that initiated the request via a secure API channel. Upon receiving the adjudication, the authentication server performs subsequent business operations based on the result: if "successful," it generates a session token to authorize access; if "failed," it immediately terminates the session and records a security audit log.

[0118] The identity authentication method provided in this application ensures the security of the key lifecycle through a hardware security module, ensures the information theory security of the root of randomness through a quantum random source, and provides "plug-and-play" security empowerment for business systems through a centralized service interface that combines quantum resistance and national cryptographic dual system protection. Thus, while achieving a high level of security, it reduces the security complexity and deployment threshold of business systems.

[0119] Based on the above embodiments, the authentication response plaintext data includes a composite certificate of hybrid signature and Super SIM card signature, and the identity authentication based on the authentication response plaintext data provided by the authentication server includes: Verify the signature composite certificate; After successful verification, the first quantum-resistant signature public key and the first national cryptographic signature public key are extracted from the signature composite certificate; Based on the first quantum-resistant signature public key, the first signature in the hybrid signature is verified; The second signature in the hybrid signature is verified based on the first national cryptographic signature public key.

[0120] The signature composite certificate undergoes signature validity verification, validity period verification, and status validity verification. It should be understood that the purpose of verifying the signature composite certificate is to establish an absolutely trustworthy initial anchor point for the entire identity authentication process. By triple-checking the certificate's signature, validity period, and revocation status, the system confirms that the received certificate is not only issued by a legitimate authority but has also not been revoked within its validity period, thereby ensuring the authenticity and timeliness of the public key extracted for signature verification. This step is a logical prerequisite for subsequent cryptographic operations (such as verifying user signatures), and its essence is to establish the legitimacy of the verification behavior by verifying the legitimacy of the credentials.

[0121] The authentication server calls the Super SIM cryptographic service platform, uses SesKey to decrypt the ciphertext, obtains the plaintext parameters (Sig1, Sig2, R2, sim_SignCrt), and then calls the platform to verify the signature composite certificate and mixed signature: Verification challenge value: Check if R2 is consistent. If R2≠USerID||R1, the verification fails and the session is terminated.

[0122] Verify the SIM-side dual-algorithm signature certificate: After R2 verification passes, the authentication server forwards the composite signature certificate and signature value to the Super SIM cryptographic service platform for certificate verification. If the composite signature certificate verification passes, then SIM-side dual-signature verification is performed. Extract the SM2 national cryptographic signature public key sim_GmSPub from sim_SignCrt and verify it with Sig1: SM2_Verify(R2, Sig1, sim_GmSPub); Extract the Dilithium quantum-resistant signature public key sim_DltPub from sim_SignCrt and verify it using Sig2: Dlt_Verify(R2, Sig2, sim_DltPub).

[0123] If both signatures pass, the system returns "Verification successful"; otherwise, it returns "Verification failed".

[0124] This application's embodiments first verify the authenticity and validity of the identity credential (certificate) itself, and then extract a trusted public key from it to verify the user's behavior (signature). This design ensures the completeness of the verification logic; that is, verification of the credential holder's behavior is only meaningful if the credential is legitimate, thereby eliminating the possibility of attacks using forged or invalid credentials. Simultaneously, relying on the correspondence between national cryptographic public keys verifying national cryptographic signatures and quantum-resistant public keys verifying quantum-resistant signatures, it efficiently and reliably completes dual cryptographic verification of the user's identity.

[0125] Based on the above embodiments, the verification of the signature composite certificate includes: Extract the second quantum-resistant signature public key and the second national cryptographic signature public key from the pre-stored signature composite root certificate; Based on the second quantum-resistant signature public key, the signature value of the first quantum-resistant signature public key is verified; and based on the second national cryptographic signature public key, the signature value of the first national cryptographic signature public key is verified; and, The validity period and certificate status information of the signature composite certificate are verified.

[0126] After the R2 verification is successful, the authentication server forwards the signature composite certificate and signature value to the Super SIM cryptographic service platform, where the platform performs certificate verification. The verifier loads the pre-stored signed composite root certificate (i.e., the root_SigCrt self-signed by the Super SIM cryptographic service platform) from its protected secure storage, parses the root_SigCrt, and extracts the two root public keys from its specific fields: The second quantum-resistant signature public key: that is, the platform's quantum-resistant signature root public key, denoted as root_DltPub.

[0127] The second national cryptographic signature public key: that is, the platform's national cryptographic signature root public key, denoted as root_GmSPub.

[0128] Simultaneously, sim_SigCrt is parsed to extract the two business public keys encapsulated within it and their corresponding digital signature values: the first quantum-resistant signature public key: sim_DltPub and its signature Sig_simDlt; the first national cryptographic signature public key: sim_GmSPub and its signature Sig_simGmS.

[0129] Call the Dilithium signature verification algorithm, input root_DltPub (verifier's public key), sim_DltPub (the message being signed), and Sig_simDlt (the signature to be verified), execute Dlt_Verify(root_DltPub, sim_DltPub, Sig_simDlt), and the result is V_dlt.

[0130] Call the SM2 signature verification algorithm, input root_GmSPub (verifier's public key), sim_GmSPub (the message to be signed), and Sig_simGmS (the signature to be verified), execute SM2_Verify(root_GmSPub, sim_GmSPub, Sig_simGmS), and the result is V_gms.

[0131] This verification step requires both V_dlt==TRUE and V_gms==TRUE to be satisfied simultaneously. If either fails, the certificate verification will terminate and return "Invalid signature".

[0132] After successful cryptographic signature verification, the certificate's management status is checked. Specifically, the notBefore (effective time) and notAfter (expiration time) fields are extracted from sim_SigCrt. The current trusted system time is obtained, and it is checked whether the following condition is met: notBefore ≤ current time ≤ notAfter. If not, the certificate has expired or has not yet become effective, and verification fails. Simultaneously, the Certificate Revocation List Distribution Point (CRL) or Online Certificate Status Protocol (OCSP) responder address is obtained from the extended fields of sim_SigCrt. By querying the CRL or OCSP service, the status information regarding the sim_SigCrt serial number issued by the platform is obtained. Its status is confirmed to be "good" rather than "revoked". If the status is revoked or a valid status cannot be obtained, verification fails.

[0133] The signature composite certificate (sim_SigCrt) is considered successfully verified when all three criteria—signature validity verification, validity period verification, and revocation status verification—are met. Once verified, the sim_DltPub and sim_GmSPub extracted from this certificate are considered trusted public keys and can be used for subsequent verification of user mixed signatures.

[0134] This application embodiment uses two root public keys to verify the authenticity of the issuance of the two public keys in the certificate, ensuring the integrity and correctness of the trust chain from the cryptographic root. At the same time, by adding checks on the validity period and revocation status, it eliminates security vulnerabilities caused by the certificate becoming invalid due to time or management.

[0135] Based on the above embodiments, the step of extracting the quantum-resistant encryption private key and the national cryptographic encryption private key from the hardware security module, and decrypting the key negotiation parameters provided by the authentication server, includes: Based on the quantum-resistant encryption private key, the first key negotiation parameter in the key negotiation parameters is decrypted to obtain the first session key component; Based on the national cryptographic encryption private key, the second key negotiation parameter in the key negotiation parameters is decrypted to obtain the second session key component.

[0136] The HSM in the Super SIM cryptographic service platform receives a decryption command from the upper-layer service, along with two key negotiation parameters to be decrypted: the first key negotiation parameter (Q1), a packaged ciphertext conforming to the Kyber algorithm specification; and the second key negotiation parameter (Q2), an encrypted ciphertext conforming to the SM2 encryption algorithm specification. Based on the command authorization, the HSM logically activates the corresponding two private keys in its internal secure storage area: a quantum-resistant encryption private key (ser_KybPrv), a Kyber private key paired with the public key ser_KybPub used to generate Q1; and a Chinese national cryptographic encryption private key (ser_GmEPrv), an SM2 encryption private key paired with the public key ser_GmEPub used to generate Q2.

[0137] The HSM's internal secure cryptographic processor executes the following two decryption operations in parallel or sequentially, with all calculations performed within the tamper-proof chip: Quantum-resistant KEM decapsulation: Call the Kyber decryption algorithm and use ser_KybPrv to decapsulate Q1. Calculate q1=Kyber_Dec(ser_KybPrv,Q1). This operation recovers the shared secret (i.e., the first session key component q1) encapsulated in Q1.

[0138] National Cryptographic Asymmetric Decryption: Call the SM2 decryption algorithm, use ser_GmEPrv to decrypt Q2, calculate q2=SM2_Dec(ser_GmEPrv,Q2), this operation recovers the plaintext encrypted in Q2 (i.e. the second session key component q2).

[0139] The embodiments of this application use both quantum-resistant private keys and national cryptographic private keys to independently decrypt the two types of ciphertext, successfully restoring the key components protected by the dual-system encryption, and achieving synergistic protection of quantum-resistant security and national cryptographic compliance in the key recovery process.

[0140] Based on the above embodiments, the identity authentication method further includes: Based on the random number source generated by the quantum random source module, quantum-resistant key pairs and national cryptographic key pairs are generated; the quantum-resistant key pairs include quantum-resistant signature key pairs and quantum-resistant encryption key pairs; the national cryptographic key pairs include national cryptographic signature key pairs and national cryptographic encryption key pairs. For the signature scenario, the quantum-resistant signature public key in the quantum-resistant signature key pair and the national cryptographic signature public key in the national cryptographic signature key pair are encapsulated in a single certificate carrier, and the quantum-resistant signature public key is signed based on the quantum-resistant signature root private key, and the national cryptographic signature public key is signed based on the national cryptographic signature root private key to generate a signature composite certificate. For encryption scenarios, the quantum-resistant encryption public key in the quantum-resistant encryption key pair and the national cryptographic encryption public key in the national cryptographic encryption key pair are encapsulated in a single certificate carrier. The quantum-resistant encryption public key is signed based on the quantum-resistant encryption root private key, and the national cryptographic encryption public key is signed based on the national cryptographic encryption root private key to generate an encrypted composite certificate.

[0141] The Super SIM cryptographic service platform uses a QRNG / QKD quantum key source as its core (compliant with NIST SP 800-22 and GM / T 0062-2021 randomness standards) to generate dual-system composite certificates for various roles in the system (such as the Super SIM card, authentication server, and the platform itself): a signature composite certificate (containing two types of public key information: Dilithium quantum-resistant signature and SM2 national cryptographic signature) and an encryption composite certificate (containing two types of public key information: Kyber quantum-resistant encryption and SM2 national cryptographic encryption). All keys (Dilithium quantum-resistant signature key, Kyber quantum-resistant encryption key, and SM2 national cryptographic key) are generated based on this quantum key source, thereby improving the quality of key random numbers and eliminating predictable risks from the source. The signature composite certificate conforms to the NIST FIPS 204 and GM / T0015-2021 specifications, while the encryption composite certificate conforms to the NIST FIPS 203 and GM / T 0015-2012 specifications. Both types of certificates include fields such as public key, issuer information, validity period, serial number, and signature algorithm OID / CRL distribution point. The specific generation method is as follows: (1) Generation of composite signature certificates: The Super SIM cryptographic service platform generates composite signature certificates for both the Super SIM card and the Super SIM cryptographic service platform side. The composite signature certificate is a single certificate carrier that simultaneously carries the Dilithium quantum-resistant signature public key and the SM2 national cryptographic signature public key. The two types of public keys are signed by the root private key corresponding to the Super SIM cryptographic service platform to form a unified signature trust certificate. The specific generation categories are shown in the table below: The certificate issuance logic mainly includes: 1) Super SIM card signature composite certificate: The public keys (sim_DltPub, sim_GmSPub) are encapsulated in the same signature certificate carrier sim_SigCrt, where sim_DltPub is signed by the platform root_DltPrv (Dilithium signature root private key), and sim_GmSPub is signed by the platform root_GmSPrv (SM2 signature root private key).

[0142] 2) Super SIM cryptographic service platform signature root certificate: The public keys (root_DltPub, root_GmSPub) are self-signed by root_DltPrv and root_GmSPrv respectively, and are jointly encapsulated in the same signature certificate carrier to form the top-level trust root root_SigCrt, ensuring the integrity of the signature verification chain.

[0143] (2) Generation of Encryption Composite Certificates: Encryption certificates are single certificate files that encapsulate both the Kyber quantum-resistant encryption public key and the SM2 national cryptographic encryption public key. The two public keys are signed by the root private key corresponding to the Super SIM cryptographic service platform to form a unified encryption trust credential. The specific generation categories are shown in the table below: The certificate issuance logic mainly includes: (1) Encryption composite certificate of the authentication server: The public key (ser_KybPub, ser_GmEPub) is encapsulated in the same encryption certificate carrier ser_EncCrt, where ser_KybPub is signed by the platform root_KybPrv (Kyber encryption root private key) and ser_GmEPub is signed by the platform root_GmEPrv (SM2 encryption root private key).

[0144] (2) Super SIM cryptographic service platform encryption root certificate: The public keys (root_KybPub, root_GmEPub) are self-signed by root_KybPrv and root_GmEPrv respectively, and are jointly encapsulated in the same encryption certificate carrier to form the top-level trust root root_EncCrt, which ensures the security of the key negotiation link.

[0145] During the authentication phase, various private keys such as (sim_DltPrv, sim_GmSPrv) are stored in the SE secure area of ​​the Super SIM card; the ser-side (i.e., authentication server-side) private keys (ser_KybPrv, ser_GmEPrv) can be accessed through the Super SIM cryptographic service platform based on key indexes and are stored in the HSM on the Super SIM cryptographic service platform. The Super SIM card, authentication client, and authentication server each have the following pre-configured keys: Super SIM card: The signature composite certificate sim_SigCrt and the signature composite root certificate root_SigCrt of the Super SIM cryptographic service platform are pre-installed at the factory, eliminating the need for users to manually import them and ensuring a plug-and-play operating experience; Authentication client: Pre-installed encrypted composite certificate ser_EncCrt of the authentication server and encrypted composite root certificate root_EncCrt of the Super SIM cryptographic service platform, used for certificate chain validity verification in the initial stage of authentication; The authentication server generates a dual encryption key pair and certificate for the Ser side through the Super SIM cryptographic service platform: a national cryptographic encryption key pair (ser_GmEPub, ser_GmEPrv), a quantum-resistant encryption key pair (ser_KybPub, ser_KybPrv), and an encrypted composite certificate (ser_EncCrt) for the authentication server. The private keys (ser_KybPrv, ser_GmEPrv) are stored in the Super SIM cryptographic service platform HSM and are available for the authentication server to access through a key index.

[0146] Public keys and certificates (sim_DltPub, sim_GmSPub, ser_EncCrt, etc.) are transmitted as needed during the authentication interaction process, and the transmission process is protected by session key encryption. Temporary parameters (Q1, Q2, SesKey, R1, R2, Sig1, Sig2, Token) are dynamically generated during the session, temporarily stored in memory, and destroyed after the session ends. They are transmitted as needed during the authentication interaction process, and the transmission process is protected by session key encryption.

[0147] This application's embodiments construct a scenario-based composite certificate system by using a quantum random source as a common entropy basis to simultaneously generate and structurally encapsulate signature and encryption key pairs that are both quantum-resistant and based on national cryptographic standards. This design not only ensures the unpredictability of all keys from a physical source, but also maintains the compactness of the certificate structure by integrating dual-algorithm public keys into a single certificate and having them independently signed by the corresponding root private key. This achieves parallel dual-track trust chain and scenario-based separation of functions, thereby natively realizing a deep integration of quantum-resistant security and national cryptographic compliance at the key management level.

[0148] Figure 3 This is the third flowchart illustrating the identity authentication method provided in this application. This method is applied to the authentication client, such as... Figure 3 As shown, the method includes: Step 301: In response to the user's login request, send the encrypted composite certificate from the authentication server to the Super SIM card; Step 302: Receive the key negotiation parameters sent by the Super SIM card, and send the key negotiation parameters to the authentication server; the key negotiation parameters are generated based on the encrypted composite certificate; Step 303: Receive the challenge value sent by the authentication server, and send the challenge response value of the challenge value to the Super SIM card; Step 304: Receive the encrypted authentication response sent by the Super SIM card, and send the encrypted authentication response to the authentication server; the encrypted authentication response is used for identity authentication. Step 305: Receive the login token sent by the authentication server and display it to the user.

[0149] The authentication client (such as a mobile app) acts as a trusted communication proxy and user interface. Its complete identity authentication relay process is implemented as follows: Users open the authentication client app on their smartphones and enter their account (such as username). The user clicks the "Login" button, and the authentication client app responds to the login request and begins the authentication process.

[0150] 1) The authentication client first sends a login request containing the user's identifier to the authentication server via the network (e.g., HTTPS). Simultaneously (or after receiving a response from the server), the authentication client reads the pre-installed encrypted composite certificate (ser_EncCrt) from its secure local storage. Through the smart card interface provided by the operating system, it establishes a local connection with the Super SIM card inserted in the same phone and sends the complete ser_EncCrt certificate data to the Super SIM card.

[0151] 2) After the Super SIM card verifies the certificate locally and generates key negotiation parameters (Q1, Q2), it returns Q1 and Q2 to the authentication client through the local interface. The authentication client receives these two parameters and encapsulates them into a network request according to the application layer protocol agreed upon with the authentication server (such as JSON format). This request is then sent back to the authentication server via the established TLS connection.

[0152] 3) After generating and encrypting the challenge value, the authentication server sends the ciphertext challenge value to the authentication client. The authentication client receives this ciphertext and immediately forwards it verbatim to the Super SIM card for decryption. After decryption, the Super SIM card returns the plaintext challenge value R1 to the authentication client. The authentication client prompts the user for confirmation on the interface (e.g., displaying "Login..."), and automatically or manually obtains the currently logged-in user identifier UserID, executes business logic, and constructs the challenge response value R2 = UserID || R1. The authentication client sends the constructed R2 to the Super SIM card, requesting it to sign R2.

[0153] 4) The Super SIM card generates a hybrid signature, encrypts it with the session key to form an authentication response ciphertext, and returns it to the authentication client. The authentication client receives this authentication response ciphertext, uses it as its core payload, encapsulates it into a network request, and sends it to the authentication server through a secure channel.

[0154] 5) The authentication client awaits the final response from the authentication server. If authentication is successful, the server returns a login token and a success command. The authentication client receives the token. The client displays a "Login successful" message to the user on the interface and securely stores the token for subsequent access to protected resources. If authentication fails, the client receives an error message and prompts the user with "Authentication failed."

[0155] The authentication method provided in this application positions the authentication client as a secure relay and user interaction hub, responsible for the reliable forwarding of trusted data and user-friendly interaction during the authentication process. All core cryptographic operations and key security responsibilities are delegated to the Super SIM card and backend service platform. This design eliminates the need for the client to handle complex cryptographic logic, store sensitive keys, or decrypt core ciphertext. Therefore, without sacrificing the end-user experience (plug and play), it reduces the client's vulnerability to attacks, achieving a balance between high security and ease of use on mobile terminals.

[0156] Based on the above embodiments, sending the challenge response value of the challenge value to the Super SIM card includes: Send the decryption request for the challenge value to the Super SIM card; The system receives the decrypted challenge value sent by the Super SIM card and initiates a user confirmation operation; the user confirmation operation includes prompting the user to enter a personal identification code (PIN) and verifying the entered PIN. After the user confirms the operation, the challenge response value is determined based on the decrypted challenge value and user identification information.

[0157] After receiving the cryptographic challenge value from the server, the authentication client's responsibility is to coordinate with the user and the Super SIM card to securely construct the challenge response value for signing. This process is implemented as follows: The authentication client receives the ciphertext challenge value from the authentication server over the network, which is E(R1) encrypted using the session key. Instead of attempting decryption, the authentication client sends a challenge value decryption request to the Super SIM card through the local communication interface, sending E(R1) along with the request data.

[0158] The SuperSIM card decrypts E(R1) using the session key within the Secure Element (SE) to obtain the plaintext challenge value R1, which it then returns to the authentication client. The authentication client receives R1 from the SuperSIM card. Simultaneously, the authentication client obtains or reads the currently logged-in user's user identification information (UserID), such as username, account, or employee number, from the interface or local cache.

[0159] To ensure the operation is performed by the genuine user, the authentication client initiates a user confirmation process before constructing the final response. The authentication client displays a security dialog box prompting the user to enter their Personal Identification Number (PIN), which is pre-set by the user in the authentication client or when bound to the Super SIM card. After the user enters the PIN, the authentication client verifies it. Verification methods can be: local verification, comparing the hash value of the entered PIN with a locally stored secure hash value; or delegated verification, sending the PIN to the Super SIM card for internal security verification and returning the result. The process continues only after successful PIN verification; if PIN verification fails, the authentication client terminates the authentication process and reports the error to the user and server.

[0160] After successful user confirmation (PIN verification), the authentication client executes its core business logic: determining the challenge response value. The authentication client concatenates the UserID with the decrypted R1 (|| is the concatenation operator) to construct R2 = UserID||R1. This step strongly binds the user's identity to a unique challenge value specific to this session, ensuring that the signature cannot be reused for other users or other sessions. The constructed R2 is the challenge response value, representing the statement that "UserID has confirmed and responded to challenge R1." The authentication client sends R2 to the SuperSIM card, requesting it to digitally sign R2 using its securely stored private key.

[0161] This application embodiment constructs an identity-bound response value by calling the hardware decryption challenge value and combining it with local PIN verification, thus achieving dual protection of hardware security and user confirmation. This ensures the reliability of challenge processing and effectively eliminates the risks of replay and impersonation through identity binding.

[0162] Figure 4 This is the fourth flowchart illustrating the identity authentication method provided in this application. This method is applied to the authentication server, such as... Figure 4 As shown, the method includes: Step 401: Receive the key negotiation parameters forwarded by the authentication client, and send the key negotiation parameters to the Super SIM cryptographic service platform for decryption to obtain the session key component; the key negotiation parameters are generated based on the encrypted composite certificate of the authentication server. Step 402: Send a challenge value generation request to the Super SIM Password Service Platform to obtain the challenge value returned by the Super SIM Password Service Platform; Step 403: Send the challenge value and the session key generated based on the session key component to the Super SIM cryptographic service platform to request the Super SIM cryptographic service platform to encrypt the challenge value and send the encrypted challenge value to the authentication client; Step 404: Receive the ciphertext of the authentication response sent by the authentication client, decrypt the ciphertext of the authentication response, and send the decrypted plaintext authentication response data to the Super SIM Password Service Platform; the ciphertext of the authentication response is used for identity authentication. Step 405: After receiving the successful verification result sent by the Super SIM Password Service Platform, generate a login token based on the session key and send the login token to the authentication client.

[0163] The authentication server does not handle core cryptographic operations. Instead, it acts as a driver of business processes, a coordinator of resources, and an executor of final business decisions. Its complete identity authentication process is implemented as follows: 1) The authentication server receives a login request from the authentication client, triggering a new session. The authentication server receives the key negotiation parameters, i.e., ciphertexts Q1 and Q2, forwarded by the client. The authentication server does not decrypt the parameters itself, but immediately constructs a decryption request for the key negotiation parameters and sends Q1 and Q2 to the Super SIM cryptographic service platform through a secure management API.

[0164] 2) The platform completes decryption within the HSM and returns the two obtained session key components q1 and q2 to the authentication server. The authentication server, in secure memory, uses a standard key derivation function (KDF, such as based on SM3 or HKDF) to derive the unique symmetric session key SesKey for this session, taking q1 and q2 as input.

[0165] 3) The authentication server needs to issue a challenge to the user. To do this, it sends a "challenge value generation request" to the Super SIM password service platform. The platform calls its quantum random source (QRNG / QKD) to generate a high-strength quantum random number, which is then returned to the authentication server as the challenge value R1.

[0166] 4) The authentication server holds R1 and the SesKey. At this point, the authentication server chooses to delegate the encryption work to the platform to simplify its logic (or utilize platform hardware acceleration). The authentication server sends a "challenge value encryption request" to the platform, providing R1 and the SesKey. The platform uses the SesKey to encrypt R1, generating the challenge value ciphertext E(R1), and returns it to the authentication server. The authentication server then sends E(R1) to the authentication client via the established TLS connection.

[0167] 5) The authentication server waits for and receives the ciphertext authentication response forwarded by the client. The authentication server uses a locally derived SesKey to decrypt the ciphertext, restoring the plaintext data packet, which includes: a hybrid signature (Sig1, Sig2), a Super SIM card signature composite certificate (sim_SigCrt), and a challenge response value (R2). The authentication server first performs a business logic verification on R2, confirming that it is equal to UserID||R1. After successful verification, the authentication server sends the decrypted authentication response plaintext data (especially the hybrid signature and certificate) to the Super SIM cryptographic service platform via a secure API, initiating a "signature verification request."

[0168] 6) The authentication server awaits the platform's verification result. The platform will verify the certificate and dual signature and return a binary decision result ("success" or "failure"). If the decision is "success": the authentication server fully trusts this result. Based on the SesKey of this session, it generates a time-sensitive login token (e.g., 30 minutes) and returns the token to the authentication client, authorizing the user to access. If the decision is "failure": the authentication server immediately terminates the session, logs the security information, and returns an error message to the client.

[0169] The authentication method provided in this application entrusts all cryptographic security operations, such as key negotiation, challenge generation, data encryption, and authentication, to a trusted Super SIM cryptographic service platform. This allows the authentication server to focus on business process coordination and logic control, reducing the complexity of the server's own security implementation and operational risks. It enables the server to integrate and drive a future security authentication protocol that combines quantum-resistant and national cryptographic systems with simple and efficient business logic, achieving a balance between business agility and cutting-edge security.

[0170] Based on the above embodiments, the step of decrypting the ciphertext of the authentication response and sending the decrypted plaintext authentication response data to the Super SIM cryptographic service platform includes: Based on the session key, the ciphertext of the authentication response is decrypted to obtain the plaintext data of the authentication response; the plaintext data of the authentication response includes a hybrid signature, a composite certificate of the Super SIM card signature, and a challenge response value; The challenge response value is verified based on the challenge value and user identification information; After successful verification, the hybrid signature and the signature composite certificate are sent to the Super SIM cryptographic service platform.

[0171] After receiving the final authentication response ciphertext from the client, the authentication server does not forward it directly. Instead, it performs a series of decryption, verification, and filtering operations to prepare it for submission to the Super SIM cryptographic service platform for final verification. The specific implementation of this process is as follows: The authentication server receives the ciphertext authentication response from the authentication client over the network. This ciphertext is data encrypted by the Super SIM card using the session key SesKey. The authentication server, in secure memory, uses the session key derived for this session, SesKey, to call the appropriate symmetric decryption algorithm (such as SM4 or AES) to decrypt the received ciphertext. Successful decryption yields the plaintext authentication response data packet, which contains three core parts: a hybrid signature, including a quantum-resistant signature Sig2 and a Chinese national cryptographic signature Sig1; a signature composite certificate, namely the Super SIM card's sim_SigCrt; and a challenge response value R2 (in the format UserID||R1).

[0172] The authentication server retrieves the challenge value R1 previously issued in this session and the target user identifier UserID being authenticated in this session from the local session context. It concatenates these two values ​​to generate the expected challenge response value: Expected_R2 = UserID || R1. The authentication server then compares the decrypted R2 byte-by-byte with Expected_R2. If R2 equals Expected_R2: verification is successful, indicating that the client's response indeed addresses the challenge and target user for this session, effectively mitigating replay attacks and identity obfuscation attacks, and the process continues. If R2 does not equal Expected_R2: verification fails, the authentication server immediately terminates the authentication process, returns a "challenge response mismatch" error, and does not need to request further signature verification from the platform.

[0173] After the R2 service verification passes, the authentication server needs to delegate the cryptographic verification work to the platform. The authentication server constructs a "signature verification request" to be submitted to the Super SIM cryptographic service platform. The payload of this request is carefully selected and includes: a mixed signature (Sig1, Sig2) and a composite signature certificate (sim_SigCrt).

[0174] This application embodiment adopts a layered processing approach of business verification first and password verification later, which enables the server to quickly filter invalid requests and submit only valid authentication data to the password platform for core verification, thereby improving processing efficiency and optimizing the division of security responsibilities.

[0175] To further explain the identity authentication method proposed in this application, please refer to the following embodiments.

[0176] In one embodiment, this application specifically proposes a secure encrypted identity authentication system based on super SIM and quantum-resistant cryptography.

[0177] This application's embodiments construct a dual identity authentication system using a Super SIM card as a portable key carrier. It integrates enhanced quantum key technology with a "quantum-resistant + national cryptographic" dual signature mechanism, providing a highly secure and portable identity authentication solution. Through security upgrades, it achieves a forward-looking technological layout to address the security threats posed by quantum computing, while simultaneously strengthening the stability and reliability of the existing security system. The Super SIM cryptographic service platform, as the core of trust, generates enhanced keys based on a QRNG / QKD quantum key source. All keys (including Dilithium quantum-resistant signature keys, Kyber quantum-resistant encryption keys, and SM2 national cryptographic keys) are generated from this quantum key source, improving the quality of random numbers required for key generation and cryptographic operations, thus eliminating predictable risks in keys and cryptographic operations at the source. The platform issues two types of core certificates for the Super SIM card, the authentication server, and itself: a quantum-resistant system (Kyber encryption, Dilithium signature) and a national cryptographic system (SM2 encryption / signature), forming a triple-protection security architecture of "QRNG + national cryptographic + quantum-resistant".

[0178] The system uses the Super SIM card as a portable and trusted key carrier, securely storing the dual-system private keys (sim_DltPrv / sim_GmSPrv, etc.) in its SE hardware isolation area. This achieves "portable and plug-and-play" keys while ensuring the physical isolation and security of the private keys. During the authentication phase, after the user initiates a request, the authentication server issues an encrypted certificate (containing Kyber+SM2 dual-system encryption information). After receiving the certificate and verifying its validity, the Super SIM card generates a quantum random number conforming to the NISTSP800-22 randomness standard based on its built-in QRNG module. The random number is then encrypted using both the Kyber quantum-resistant algorithm and the SM2 national cryptographic algorithm to complete the session key negotiation. After synchronizing the key components, the authentication server generates a session key through a key derivation algorithm, constructs an edge-cloud secure encrypted channel, and sends the challenge value to the Super SIM card in ciphertext. After receiving the challenge value, the Super SIM card constructs a composite challenge by combining the user information, and uses the dual-system private key to generate a hybrid signature of Chinese national cryptography SM2 and quantum-resistant Dilithium. This signature is then encrypted with the session key and transmitted to the authentication server. The authentication server calls the Super SIM cryptographic service platform to complete the dual signature verification. Once the verification is successful, the user's identity is confirmed and login is completed.

[0179] This authentication mode, which uses a super SIM card as the carrier, quantum-enhanced keys as the security foundation, and dual signatures as the core, leverages the terminal integration features of the super SIM card to make keys portable and easy to use. It also strengthens end-to-end security by using enhanced keys generated by QRNG / QKD quantum key sources. The dual signature mechanism not only has the ability to resist quantum attacks, but also achieves a security upgrade of the identity authentication system through the collaboration of Kyber and SM2 algorithms. It effectively solves the technical pain points of traditional solutions, such as insecure key storage, lack of quantum protection, and high risk of identity forgery. It is suitable for identity authentication scenarios with high requirements for both security and portability, such as mobile payment and remote work.

[0180] refer to Figure 5 The identity authentication system is designed with a core concept of "QRNG + Chinese cryptographic standards + quantum-resistant" triple protection, constructing a closed loop for identity authentication that synergistically strengthens resistance to quantum attacks and the security system. The overall architecture is based on a dual-system certificate (quantum-resistant certificate + Chinese cryptographic standard certificate). The signature certificate integrates Dilithium quantum-resistant signature and SM2 Chinese cryptographic standard signature public key information, while the encryption certificate integrates Kyber quantum-resistant encryption and SM2 Chinese cryptographic standard encryption public key information. The authentication client uses a super SIM card to achieve secure storage of the dual-system private keys and hardware-level algorithm computation. A built-in QRNG chip provides high-quality quantum random number key components and cryptographic operation parameters. The super SIM cryptographic service platform integrates certificate issuance, quantum-enhanced key management, and dual-signature verification. Both the Chinese cryptographic standard and quantum-resistant algorithm keys are derived from quantum random numbers generated by the platform's QRNG / QKD technology, ensuring "quantum-level true randomness" of the keys from the source, forming a full-process security mechanism of "certificate issuance - key negotiation - signature challenge - verification and authorization."

[0181] In one embodiment, this application specifically proposes a secure encrypted identity authentication method based on SuperSIM and quantum-resistant cryptography. (See reference...) Figure 6 This method mainly includes: 1. Initiation of an authentication request, including: S1-S2: The user opens the client and sends a login request to the authentication server through the authentication client.

[0182] S3: Send the Ser-side dual-algorithm encryption certificate built into the authentication client to the Super SIM card: the encryption composite certificate of the authentication server (ser_EncCrt, containing certificate chain information, which internally encapsulates the Kyber quantum-resistant encryption public key ser_KybPub and the SM2 national cryptographic encryption public key ser_GmEPub).

[0183] 2. Quantum-resistant key negotiation (using QRNG to generate random numbers to ensure key randomness), including: S4: Verify the Super SIM card certificate and generate Q1 and Q2 key parameters: Verify the Ser-side dual-algorithm encryption certificate: 1) Certificate chain verification: The SIM card requests the pre-installed Super SIM cryptographic service platform's national cryptographic encryption root certificate root_EncCrt from the authentication client, extracts the national cryptographic encryption public key (root_GmEPub) and the quantum-resistant Kyber encryption public key (root_KybPub), and verifies the signature values ​​corresponding to the two types of public keys in the Ser-side national cryptographic SM2 encryption composite certificate (ser_EncCrt) to check whether the certificate was issued by the Super SIM cryptographic service platform. 2) Validity and revocation status: Check the certificate validity period and confirm that the certificate has not been revoked through CRL (Certificate Revocation List) or OCSP (Online Certificate Status Protocol). Only after successful verification can the next step be proceeded; otherwise, the client will prompt the user with "Authentication server untrusted" and terminate the session.

[0184] Generating quantum random numbers and calculating Seskey: The Super SIM card generates quantum random numbers q1 and q2 based on the built-in QRNG module as session key components; based on the two key components, a session key SesKey is generated through a key derivation algorithm, which serves as the symmetric key for subsequent encrypted transmission channels.

[0185] Hybrid encryption using Chinese national cryptographic algorithm and quantum-resistant algorithm (using QRNG to generate random numbers to ensure the randomness of the encryption process): 1) Quantum-resistant Kyber algorithm encryption encapsulation: Extract the Kyber quantum-resistant encryption public key ser_KybPub from the Ser-side encrypted composite certificate (ser_EncCrt), and calculate Q1=Kybe_Enc(ser_KybPub, q1); 2) Chinese national cryptographic encryption: Extract the SM2 Chinese national cryptographic encryption public key ser_GmEPub from the Ser-side encrypted composite certificate (ser_EncCrt), and calculate: Q2=SM2_Enc(ser_GmEPub, q2).

[0186] S5-S6: The Super SIM card forwards key negotiation parameters (Q1, Q2) to the Ser through the authentication client.

[0187] 3. The Ser side synchronizes the session key and issues the challenge value, including: S7-S8: The authentication server calls the Super SIM cryptographic service platform API interface to decrypt and obtain q1 and q2. The Super SIM cryptographic service platform retrieves the Ser-side quantum-resistant Kyber encryption private key ser_KybPrv from the HSM (the private key never leaves the HSM and is only decrypted internally), and calculates q1=Kyber_Dec(ser_KybPrv, Q1). The Super SIM cryptographic service platform retrieves the Ser-side national cryptographic encryption private key ser_GmEPrv from the HSM, and calculates q2=SM2_Dec(ser_GmEPrv, Q2).

[0188] The Super SIM cryptographic service platform returns the q1 and q2 parameters to the authentication server. S9-S10: The authentication server generates the challenge value R1 and the session key SesKey, establishing a secure encrypted channel.

[0189] Generate challenge value: The authentication server calls the Super SIM cryptographic service platform QRNG / QKD to generate a quantum random number R1 as the challenge value; Generate a session key and establish a secure encrypted channel: The authentication server generates a session key SesKey based on the (q1, q2) key components using a key derivation algorithm, and sends SesKey and R1 to the Super SIM cryptographic service platform; The Super SIM cryptographic service platform encrypts the transmitted data R1 and uses SesKey as the encryption key to encrypt the data using the SM4 encryption algorithm.

[0190] S11: The authentication server transmits the encrypted challenge value R1 to the authentication client.

[0191] 4. Generate a hybrid signature combining Chinese national cryptography and quantum resistance (using QRNG to generate random numbers to ensure the randomness of the signature process), including: S12-S13: The authentication client receives the challenge value ciphertext and requests the Super SIM card to decrypt it to obtain R1. It then requests the user to confirm and enter the login parameters and PIN code.

[0192] S14: After the user's PIN code is verified, the authentication client constructs R2=USerID||R1 (|| is a concatenation operation) and requests the Super SIM card to call the private key for signing.

[0193] S15-17: The Super SIM card extracts the national cryptographic SM2 signature private key (sim_GmSPrv) and the quantum-resistant Dilithium signature private key (sim_DltPrv) from the SE security zone, generates a hybrid signature (the signing process uses a QRNG chip to generate quantum random numbers to ensure randomness), and transmits the relevant parameters in ciphertext to the authentication server through the authentication client: Quantum-resistant Delithium signature (Sig2): Sig2 = Dlt_Sign(R2, sim_DltPrv) is calculated using the Dilithium-P7 parameters; SM2 signature (Sig1): Sign R2 using the SM2 signature private key (sim_GmSPrv), i.e., Sig1 = SM2_Sign(R2, sim_GmSPrv).

[0194] The parameters (Sig1, Sig2, SIM end-signature composite certificate sim_SignCrt, R2) are encrypted and transmitted using the session key SesKey.

[0195] 5. Signature verification, including: S18-S22: The authentication server calls the Super SIM cryptographic service platform, uses SesKey to decrypt the ciphertext, obtains the plaintext parameters (Sig1, Sig2, R2, sim_SignCrt), and calls the platform to verify the signature composite certificate and mixed signature: Verification challenge value: Check if R2 is consistent. If R2≠USerID||R1, the verification fails and the session is terminated.

[0196] Verify the dual-algorithm signature certificate on the SIM side: After the R2 verification is successful, the Ser will forward the SIM-side signature composite certificate and signature value to the Super SIM cryptographic service platform for certificate verification. 1) Certificate Chain Verification: The Super SIM Cryptographic Service Platform calls the platform's signature root certificate (root_SigCrt) to extract the national cryptographic signature public key (root_GmSPub) and the quantum-resistant Dilithium signature public key (root_DltPub) respectively. It then verifies the signature values ​​corresponding to the two types of public keys in the Sim-side national cryptographic SM2 signature composite certificate (sim_SigCrt) to confirm that the certificate was issued by the Super SIM Cryptographic Service Platform. 2) Validity and Revocation Status: Check the certificate validity period and confirm that the certificate has not been revoked via CRL or OCSP. After successful verification, the SuperSIM cryptographic service platform will perform dual signature verification.

[0197] Verify the dual signature on the SIM side: Extract the SM2 national cryptographic signature public key sim_GmSPub from sim_SignCrt, and verify Sig1: SM2_Verify(R2,Sig1,sim_GmSPub); Extract the Dilithium quantum-resistant signature public key sim_DltPub from sim_SignCrt, and verify Sig2: Dlt_Verify(R2,Sig2,sim_DltPub).

[0198] S22: If both signatures pass, return "Verification successful"; otherwise, return "Verification failed".

[0199] 5. Login verification, including: S23-25: After successful verification, the Ser generates a login token (containing UserID, valid for 30 minutes) based on the SesKey and issues it through the authentication client. The client prompts the user "Login successful"; if verification fails, it prompts "Authentication failed, please try again".

[0200] This application employs a super SIM card with an integrated QRNG chip as the mobile terminal security hardware carrier. The server uses QRNG / QKD as a quantum random source, providing quantum-level true random numbers for key generation and encryption signature operations of the national cryptographic algorithm and quantum-resistant cryptography, ensuring randomness and hardware-level security throughout the process. Simultaneously, the super SIM card possesses inherent portability with the mobile terminal and relies on the SE / TEE hardware isolation zone for secure storage and computation of private keys. Furthermore, during encryption, quantum random numbers are used to fragment the national cryptographic encryption key and the quantum-resistant encryption key, generating multiple key components. Through the collaborative encryption logic of "national cryptographic key fragmentation + quantum-resistant key fragmentation," the authentication data is protected by both national cryptographic and quantum-resistant algorithms. Even when facing quantum computing threats, the security of any algorithm's fragmented key ensures the security of the overall encrypted data. Additionally, a composite challenge and dual-signature (quantum-resistant signature + national cryptographic signature) collaborative mechanism is designed to perform hybrid signature and dual verification of user identity, achieving authentication process security where "security of any algorithm eliminates the risk of replay attacks and identity forgery." In addition, a hybrid certificate system is adopted, which integrates the public key of the national cryptographic algorithm and the public key of the quantum-resistant algorithm, and includes the certificate signature of the national cryptographic algorithm and the quantum-resistant algorithm. Compared with the traditional dual certificate system, it not only reduces the overall size of the certificate, but also avoids the risk of a single certificate being forged through the redundancy of the dual algorithm signature. The identity authentication device provided in this application is described below. The identity authentication device described below can be referred to in correspondence with the identity authentication method described above.

[0201] refer to Figure 7 The identity authentication device provided in this application includes: The encrypted composite certificate receiving module 701 is used to receive the encrypted composite certificate from the authentication server sent by the authentication client and to verify the encrypted composite certificate. The session key component generation module 702 is used to generate multiple quantum random numbers as session key components based on the QRNG module after successful verification; The key negotiation parameter generation module 703 is used to encrypt the session key component based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, generate key negotiation parameters, and send the key negotiation parameters to the authentication server through the authentication client. The hybrid signature generation module 704 is used to receive the challenge value forwarded by the authentication client from the authentication server, and to sign the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit, thereby generating a hybrid signature; The authentication response ciphertext sending module 705 is used to encrypt the hybrid signature, the signature composite certificate of the Super SIM card, and the challenge response value based on the session key, and send the encrypted authentication response ciphertext to the authentication server via the authentication client; the session key is generated based on the key negotiation parameters, and the authentication response ciphertext is used for identity authentication.

[0202] refer to Figure 8 The identity authentication device provided in this application includes: The first decryption module 801 is used to respond to the decryption request from the authentication server, extract the quantum-resistant encryption private key and the national cryptographic encryption private key from the hardware security module, decrypt the key negotiation parameters provided by the authentication server, and send the decrypted session key component to the authentication server. The challenge value generation module 802 is used to respond to the challenge value generation request from the authentication server, call the quantum random source module to generate a quantum random number as the challenge value, and send the challenge value to the authentication server; The challenge value sending module 803 is used to respond to the encryption request from the authentication server, encrypt the challenge value based on the session key provided by the authentication server, and send the encrypted challenge value to the authentication client via the authentication server; The identity authentication module 804 is used to respond to the signature verification request of the authentication server and perform identity authentication based on the plaintext authentication response data provided by the authentication server; the plaintext authentication response data is obtained by the authentication server decrypting the ciphertext authentication response received from the authentication client.

[0203] refer to Figure 9 The identity authentication device provided in this application includes: The login response module 901 is used to respond to the user's login request by sending the encrypted composite certificate from the authentication server to the Super SIM card; The key negotiation parameter receiving module 902 is used to receive the key negotiation parameters sent by the Super SIM card and send the key negotiation parameters to the authentication server; the key negotiation parameters are generated based on the encrypted composite certificate. The challenge value receiving module 903 is used to receive the challenge value sent by the authentication server and send the challenge response value of the challenge value to the super SIM card; The authentication response ciphertext receiving module 904 is used to receive the authentication response ciphertext sent by the Super SIM card and send the authentication response ciphertext to the authentication server; the authentication response ciphertext is used for identity authentication. The login token receiving module 905 is used to receive the login token sent by the authentication server and display it to the user.

[0204] refer to Figure 10 The identity authentication device provided in this application includes: The second decryption module 1001 is used to receive the key negotiation parameters forwarded by the authentication client, and send the key negotiation parameters to the Super SIM cryptographic service platform for decryption to obtain the session key component; the key negotiation parameters are generated based on the encrypted composite certificate of the authentication server. The challenge value generation request sending module 1002 is used to send a challenge value generation request to the Super SIM password service platform in order to obtain the challenge value returned by the Super SIM password service platform; The challenge value encryption module 1003 is used to send the challenge value and the session key generated based on the session key component to the Super SIM cryptographic service platform to request the Super SIM cryptographic service platform to encrypt the challenge value and send the encrypted challenge value to the authentication client. The authentication response plaintext data sending module 1004 is used to receive the authentication response ciphertext sent by the authentication client, decrypt the authentication response ciphertext, and send the decrypted authentication response plaintext data to the Super SIM cryptographic service platform; the authentication response ciphertext is used for identity authentication. The login token generation module 1005 is used to generate a login token based on the session key after receiving the verification success result sent by the Super SIM password service platform, and send the login token to the authentication client.

[0205] Figure 11 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 11 As shown, the electronic device may include a processor 1110, a communications interface 1120, a memory 1130, and a communication bus 1140, wherein the processor 1110, the communications interface 1120, and the memory 1130 communicate with each other through the communication bus 1140. The processor 1110 can call logical instructions in the memory 1130 to execute an authentication method.

[0206] Furthermore, the logical instructions in the aforementioned memory 1130 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0207] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to perform the authentication methods provided by the above methods.

[0208] In another aspect, this application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the authentication methods provided by the methods described above.

[0209] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0210] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0211] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. An identity authentication method, characterized in that, Applied to a Super SIM card, which integrates a security unit and a quantum random number generator (QRNG) module, the authentication method includes: Receive the encrypted composite certificate from the authentication server sent by the authentication client, and verify the encrypted composite certificate; After successful verification, multiple quantum random numbers are generated based on the QRNG module as session key components; Based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, the session key components are encrypted respectively to generate key negotiation parameters, and the key negotiation parameters are sent to the authentication server through the authentication client. The authentication server receives the challenge value forwarded by the authentication client and signs the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature. Based on the session key, the hybrid signature, the signature composite certificate of the Super SIM card, and the challenge response value are encrypted, and the encrypted authentication response ciphertext is sent to the authentication server via the authentication client; the session key is generated based on the key negotiation parameters, and the authentication response ciphertext is used for identity authentication.

2. The identity authentication method according to claim 1, characterized in that, The session key components include a first session key component and a second session key component; the process of encrypting the session key components based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, and generating key negotiation parameters, includes: Based on the first quantum-resistant encryption public key, the first session key component is encrypted to obtain the first key negotiation parameters; Based on the first national cryptographic public key, the second session key component is encrypted to obtain the second key negotiation parameters; The key negotiation parameters include the first key negotiation parameters and the second key negotiation parameters.

3. The identity authentication method according to claim 1, characterized in that, The process of signing the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit to generate a hybrid signature includes: Based on the quantum-resistant signature private key, the challenge response value is signed to obtain the first signature; Based on the national cryptographic signature private key, the challenge response value is signed to obtain a second signature; The hybrid signature includes the first signature and the second signature; the challenge response value is obtained by concatenating the user identification information with the challenge value.

4. The identity authentication method according to claim 1, characterized in that, The verification of the encrypted composite certificate includes: Request the pre-configured encrypted composite root certificate of the Super SIM cryptographic service platform from the authentication client; Extract the second quantum-resistant encryption public key and the second national cryptographic encryption public key from the encrypted composite root certificate; Based on the second quantum-resistant encryption public key, the signature value of the first quantum-resistant encryption public key in the encrypted composite certificate is verified; and based on the second national cryptographic encryption public key, the signature value of the first national cryptographic encryption public key in the encrypted composite certificate is verified; and, The validity period and certificate status information of the encrypted composite certificate are verified.

5. An identity authentication method, characterized in that, Applied to a Super SIM cryptographic service platform, which integrates a quantum random source module and a hardware security module, the authentication method includes: In response to the decryption request from the authentication server, the anti-quantum encryption private key and the national cryptographic encryption private key are extracted from the hardware security module, the key negotiation parameters provided by the authentication server are decrypted, and the decrypted session key component is sent to the authentication server. In response to the challenge value generation request from the authentication server, the quantum random source module is invoked to generate a quantum random number as the challenge value, and the challenge value is sent to the authentication server. In response to the encryption request from the authentication server, the challenge value is encrypted based on the session key provided by the authentication server, and the encrypted challenge value is sent to the authentication client via the authentication server. In response to the signature verification request from the authentication server, identity authentication is performed based on the plaintext authentication response data provided by the authentication server; the plaintext authentication response data is obtained by the authentication server decrypting the ciphertext authentication response received from the authentication client.

6. The identity authentication method according to claim 5, characterized in that, The authentication response plaintext data includes a composite certificate of hybrid signature and Super SIM card signature. The identity authentication based on the authentication response plaintext data provided by the authentication server includes: Verify the signature composite certificate; After successful verification, the first quantum-resistant signature public key and the first national cryptographic signature public key are extracted from the signature composite certificate; Based on the first quantum-resistant signature public key, the first signature in the hybrid signature is verified; Based on the first national cryptographic signature public key, the second signature in the hybrid signature is verified; If both the first and second signature verification results pass, then the user's identity authentication is successful.

7. The identity authentication method according to claim 6, characterized in that, The verification of the signature composite certificate includes: Extract the second quantum-resistant signature public key and the second national cryptographic signature public key from the pre-stored signature composite root certificate; Based on the second quantum-resistant signature public key, the signature value of the first quantum-resistant signature public key is verified; and based on the second national cryptographic signature public key, the signature value of the first national cryptographic signature public key is verified; and, The validity period and certificate status information of the signature composite certificate are verified.

8. The identity authentication method according to claim 5, characterized in that, The step of extracting the quantum-resistant encryption private key and the national cryptographic encryption private key from the hardware security module, and decrypting the key negotiation parameters provided by the authentication server, includes: Based on the quantum-resistant encryption private key, the first key negotiation parameter in the key negotiation parameters is decrypted to obtain the first session key component; Based on the national cryptographic encryption private key, the second key negotiation parameter in the key negotiation parameters is decrypted to obtain the second session key component.

9. The identity authentication method according to claim 5, characterized in that, The identity authentication method further includes: Based on the random number source generated by the quantum random source module, quantum-resistant key pairs and national cryptographic key pairs are generated; the quantum-resistant key pairs include quantum-resistant signature key pairs and quantum-resistant encryption key pairs; the national cryptographic key pairs include national cryptographic signature key pairs and national cryptographic encryption key pairs. For the signature scenario, the quantum-resistant signature public key in the quantum-resistant signature key pair and the national cryptographic signature public key in the national cryptographic signature key pair are encapsulated in a single certificate carrier, and the quantum-resistant signature public key is signed based on the quantum-resistant signature root private key, and the national cryptographic signature public key is signed based on the national cryptographic signature root private key to generate a signature composite certificate. For encryption scenarios, the quantum-resistant encryption public key in the quantum-resistant encryption key pair and the national cryptographic encryption public key in the national cryptographic encryption key pair are encapsulated in a single certificate carrier. The quantum-resistant encryption public key is signed based on the quantum-resistant encryption root private key, and the national cryptographic encryption public key is signed based on the national cryptographic encryption root private key to generate an encrypted composite certificate.

10. An identity authentication method, characterized in that, The authentication method, applied to an authentication client, includes: In response to the user's login request, the encrypted composite certificate from the authentication server is sent to the Super SIM card; The system receives key negotiation parameters sent by the Super SIM card and sends the key negotiation parameters to the authentication server; the key negotiation parameters are generated based on the encrypted composite certificate. Receive the challenge value sent by the authentication server, and send the challenge response value of the challenge value to the Super SIM card; The system receives the encrypted authentication response sent by the Super SIM card and sends the encrypted authentication response to the authentication server; the encrypted authentication response is used for identity authentication. Receive the login token sent by the authentication server and display it to the user.

11. The identity authentication method according to claim 10, characterized in that, Sending the challenge response value of the challenge value to the Super SIM card includes: Send the decryption request for the challenge value to the Super SIM card; The system receives the decrypted challenge value sent by the Super SIM card and initiates a user confirmation operation; the user confirmation operation includes prompting the user to enter a personal identification code (PIN) and verifying the entered PIN. After the user confirms the operation, the challenge response value is determined based on the decrypted challenge value and user identification information.

12. An identity authentication method, characterized in that, Applied to the authentication server, the identity authentication method includes: The system receives key negotiation parameters forwarded by the authentication client, sends the key negotiation parameters to the Super SIM cryptographic service platform for decryption, and obtains the session key component; the key negotiation parameters are generated based on the encrypted composite certificate of the authentication server. Send a challenge value generation request to the Super SIM Password Service Platform to obtain the challenge value returned by the Super SIM Password Service Platform; The challenge value and the session key generated based on the session key component are sent to the Super SIM cryptographic service platform to request the Super SIM cryptographic service platform to encrypt the challenge value and send the encrypted challenge value to the authentication client. The system receives the ciphertext authentication response sent by the authentication client, decrypts the ciphertext authentication response, and sends the decrypted plaintext authentication response data to the Super SIM Password Service Platform; the ciphertext authentication response is used for identity authentication. After receiving the successful verification result from the Super SIM Password Service Platform, a login token is generated based on the session key, and the login token is sent to the authentication client.

13. The identity authentication method according to claim 12, characterized in that, The step of decrypting the ciphertext of the authentication response and sending the decrypted plaintext authentication response data to the Super SIM cryptographic service platform includes: Based on the session key, the ciphertext of the authentication response is decrypted to obtain the plaintext data of the authentication response; the plaintext data of the authentication response includes a hybrid signature, a composite certificate of the Super SIM card signature, and a challenge response value; The challenge response value is verified based on the challenge value and user identification information; After successful verification, the hybrid signature and the signature composite certificate are sent to the Super SIM cryptographic service platform.

14. An identity authentication device, characterized in that, include: An encrypted composite certificate receiving module is used to receive an encrypted composite certificate from the authentication server sent by the authentication client and to verify the encrypted composite certificate. The session key component generation module is used to generate multiple quantum random numbers as session key components based on the QRNG module after successful verification. The key negotiation parameter generation module is used to encrypt the session key component based on the first quantum-resistant encryption public key and the first national cryptographic encryption public key extracted from the encrypted composite certificate, generate key negotiation parameters, and send the key negotiation parameters to the authentication server through the authentication client; The hybrid signature generation module is used to receive the challenge value forwarded by the authentication client from the authentication server, and to sign the challenge response value corresponding to the challenge value based on the quantum-resistant signature private key and the national cryptographic signature private key stored in the security unit, thereby generating a hybrid signature; The authentication response ciphertext sending module is used to encrypt the hybrid signature, the signature composite certificate of the Super SIM card, and the challenge response value based on the session key, and send the encrypted authentication response ciphertext to the authentication server via the authentication client; the session key is generated based on the key negotiation parameters, and the authentication response ciphertext is used for identity authentication.

15. An identity authentication device, characterized in that, include: The first decryption module is used to respond to the decryption request from the authentication server, extract the quantum-resistant encryption private key and the national cryptographic encryption private key from the hardware security module, decrypt the key negotiation parameters provided by the authentication server, and send the decrypted session key component to the authentication server. The challenge value generation module is used to respond to the challenge value generation request from the authentication server by calling the quantum random source module to generate a quantum random number as the challenge value, and sending the challenge value to the authentication server. The challenge value sending module is used to respond to the encryption request from the authentication server, encrypt the challenge value based on the session key provided by the authentication server, and send the encrypted challenge value to the authentication client via the authentication server; The identity authentication module is used to respond to the signature verification request from the authentication server and perform identity authentication based on the plaintext data of the authentication response provided by the authentication server. The plaintext authentication response data is obtained by the authentication server decrypting the ciphertext authentication response received from the authentication client.

16. An identity authentication device, characterized in that, include: The login response module is used to respond to the user's login request by sending the encrypted composite certificate from the authentication server to the Super SIM card; The key negotiation parameter receiving module is used to receive the key negotiation parameters sent by the Super SIM card and send the key negotiation parameters to the authentication server; the key negotiation parameters are generated based on the encrypted composite certificate. The challenge value receiving module is used to receive the challenge value sent by the authentication server and send the challenge response value of the challenge value to the super SIM card; The authentication response ciphertext receiving module is used to receive the authentication response ciphertext sent by the Super SIM card and send the authentication response ciphertext to the authentication server. The encrypted authentication response is used for identity authentication; The login token receiving module is used to receive the login token sent by the authentication server and display it to the user.

17. An identity authentication device, characterized in that, include: The second decryption module is used to receive the key negotiation parameters forwarded by the authentication client, and send the key negotiation parameters to the Super SIM cryptographic service platform for decryption to obtain the session key component; The key negotiation parameters are generated based on the encrypted composite certificate of the authentication server; The challenge value generation request sending module is used to send a challenge value generation request to the Super SIM password service platform in order to obtain the challenge value returned by the Super SIM password service platform; The challenge value encryption module is used to send the challenge value and the session key generated based on the session key component to the Super SIM cryptographic service platform to request the Super SIM cryptographic service platform to encrypt the challenge value and send the encrypted challenge value to the authentication client; The authentication response plaintext data sending module is used to receive the authentication response ciphertext sent by the authentication client, decrypt the authentication response ciphertext, and send the decrypted authentication response plaintext data to the Super SIM cryptographic service platform; The encrypted authentication response is used for identity authentication; The login token generation module is used to generate a login token based on the session key after receiving the verification success result sent by the Super SIM password service platform, and send the login token to the authentication client.

18. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the authentication method as described in any one of claims 1 to 13.

19. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the authentication method as described in any one of claims 1 to 13.

20. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the authentication method as described in any one of claims 1 to 13.