Remote access handshake method and device based on double anti-quantum protection, equipment and medium

By supplementing the conventional quantum-resistant key exchange handshake in a VPN with a quantum-resistant signature verification step, and employing an open-source copper lock algorithm suite and a hybrid post-quantum key encapsulation mechanism, quantum-resistant protection of certificates is achieved. This fills the gap in certificate verification in existing VPN quantum-resistant schemes, reduces deployment costs, and maintains system compatibility.

CN121984679BActive Publication Date: 2026-06-16HANGZHOU FULANKE INFORMATION SECURITY TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU FULANKE INFORMATION SECURITY TECH CO LTD
Filing Date
2026-04-08
Publication Date
2026-06-16

Smart Images

  • Figure CN121984679B_ABST
    Figure CN121984679B_ABST
Patent Text Reader

Abstract

The application discloses a remote access handshake method and device based on double anti-quantum protection, equipment and medium, applied to a client, related to the field of encrypted communication, comprising: sending a connection request to a server, and setting a corresponding authentication protocol according to the quantum authentication identifier and anti-quantum authentication key exchange kit fed back by the server; performing handshake with the server based on the authentication protocol and the anti-quantum authentication key exchange kit, if the handshake is successful, sending a certificate anti-quantum authentication protocol request to the server, and analyzing the anti-quantum information fed back by the server, performing anti-quantum verification on the target certificate initially fed back by the server through the obtained preset anti-quantum signature algorithm, the anti-quantum public key of the server and the certificate signature value, and performing subsequent communication after the verification is passed; if the handshake fails, ending the communication between the server and the server. Therefore, after the completion of the conventional anti-quantum key exchange handshake, the anti-quantum signature verification can be supplemented, and double anti-quantum protection is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of encrypted communication, and in particular to a remote access handshake method, apparatus, device, and medium based on dual quantum-resistant protection. Background Technology

[0002] VPN (Virtual Private Network) is a widely used remote access technology that allows users to securely access internal corporate network resources via the internet. During VPN data transmission, data encryption and decryption are crucial for ensuring data security. VPNs typically use traditional Public Key Infrastructure (PKI) for identity authentication and key negotiation during the handshake phase, making it the mainstream technology in commercial scenarios. In some lightweight or private deployments, handshakes can also be achieved through pre-shared keys (PSKs) or certificate-free encryption technologies, eliminating the need for traditional PKI. However, regardless of the specific solution, neither can withstand the serious threats posed by the post-quantum algorithm revolution.

[0003] Currently, VPN quantum-resistant solutions mainly employ a hybrid quantum-resistant key exchange and quantum-resistant certificate approach. Both approaches have shortcomings: the hybrid quantum-resistant key exchange suite only protects the key exchange itself from quantum resistance, failing to provide quantum-resistant protection for the certificate, thus unable to achieve quantum resistance for the certificate. The quantum-resistant certificate approach, on the other hand, requires modifying the existing PKI system, including updating certificate format standards and related protocols to support new post-quantum cryptographic algorithm identifiers, key negotiation mechanisms, and digital signature schemes, resulting in high modification costs and difficult deployment. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a remote access handshake method, apparatus, device, and medium based on dual quantum-resistant protection. This method can supplement the conventional quantum-resistant key exchange handshake with quantum-resistant signature verification, achieving dual quantum-resistant protection. The specific solution is as follows:

[0005] In a first aspect, this application discloses a remote access handshake method based on dual quantum-resistant protection, applied to a client, comprising:

[0006] Send a connection request to the server and receive a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request from the server. Then, set the corresponding authentication protocol based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit.

[0007] Based on the authentication protocol and the quantum-resistant authentication key exchange suite, a handshake is performed with the server. If the handshake is successful, the target certificate fed back by the server is received, a quantum-resistant authentication protocol request for the certificate is sent to the server, and quantum-resistant information corresponding to the quantum-resistant authentication protocol request is received from the server. The quantum-resistant information includes a preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value.

[0008] The quantum-resistant information is parsed, and the target certificate is verified against quantum resistance using the preset quantum-resistant signature algorithm obtained from the parsing, the server-side quantum-resistant public key, and the certificate signature value. Subsequent communication is then carried out after the verification is successful.

[0009] If the handshake fails, communication with the server will end.

[0010] Optionally, the step of sending a connection request to the server and receiving a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request from the server, and then setting a corresponding authentication protocol based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit, includes:

[0011] A connection request is sent to the server so that the server generates a corresponding quantum authentication identifier upon receiving the connection request, and feeds back the quantum authentication identifier and the corresponding quantum-resistant authentication key exchange kit to the client.

[0012] The system receives the quantum authentication identifier corresponding to the connection request sent by the server and the quantum-resistant authentication key exchange suite, and sets the corresponding authentication protocol according to the quantum-resistant authentication key exchange suite.

[0013] Optionally, the process involves a handshake with the server based on the authentication protocol and the quantum-resistant authentication key exchange suite. If the handshake is successful, the process receives the target certificate from the server, sends a quantum-resistant authentication protocol request to the server, and receives quantum-resistant information corresponding to the quantum-resistant authentication protocol request from the server, including:

[0014] Determine the quantum-resistant key exchange algorithm corresponding to the quantum-resistant authentication key exchange suite, and perform a handshake with the server based on the quantum-resistant key exchange algorithm and the authentication protocol;

[0015] If the handshake is successful, the target certificate fed back by the server is received, and a certificate quantum-resistant authentication protocol request is sent to the server. After receiving the certificate quantum-resistant authentication protocol request, the server generates quantum-resistant information corresponding to the certificate quantum-resistant authentication protocol request and feeds back the quantum-resistant information to the client.

[0016] Receive the quantum-resistant information corresponding to the quantum-resistant authentication protocol request from the server.

[0017] Optionally, generating quantum-resistant information corresponding to the quantum-resistant authentication protocol request for the certificate and feeding back the quantum-resistant information to the client includes:

[0018] A server-side quantum-resistant key pair is generated based on a preset quantum-resistant signature algorithm, and the target certificate is hashed using a preset hash algorithm. Then, the certificate hash value obtained by hashing is signed using the server-side quantum-resistant private key in the key pair to obtain the certificate signature value.

[0019] The preset quantum-resistant signature algorithm, the certificate signature value, and the server-side quantum-resistant public key in the server-side quantum-resistant key pair are sent to the client as quantum-resistant information.

[0020] Optionally, the step of parsing the quantum-resistant information, and performing quantum-resistant verification on the target certificate using the pre-defined quantum-resistant signature algorithm obtained from the parsing, the server-side quantum-resistant public key, and the certificate signature value, and before proceeding with subsequent communication after successful verification, further includes:

[0021] If the anti-quantum information is not received from the server within the preset waiting time threshold, the handshake is determined to have failed, and the current communication connection with the server is disconnected.

[0022] Record the error message of this handshake failure and feed the error message back to the preset information processing node.

[0023] Optionally, the step of parsing the quantum-resistant information and performing quantum-resistant verification of the target certificate using the pre-defined quantum-resistant signature algorithm obtained from the parsing, the server-side quantum-resistant public key, and the certificate signature value includes:

[0024] The quantum-resistant information is parsed to obtain the preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value;

[0025] The target certificate is hashed using the preset hash algorithm to obtain a hash value to be compared, and the certificate signature value is restored using the preset quantum-resistant signature algorithm and the server-side quantum-resistant public key to obtain the certificate hash value.

[0026] A consistency comparison is performed between the certificate hash value and the hash value to be compared. If the certificate hash value is consistent with the hash value to be compared, the verification is successful.

[0027] If the certificate hash value and the hash value to be compared are inconsistent, the verification fails.

[0028] Optionally, the remote access handshake method based on dual quantum-resistant protection further includes:

[0029] If a target certificate quantum-resistant authentication protocol request is received from the server, a client-side quantum-resistant key pair is generated based on the preset quantum-resistant signature algorithm;

[0030] The local certificate hash value is obtained by performing a hash calculation on the local certificate using a preset hash algorithm, and then a quantum-resistant signature is obtained by performing a quantum-resistant signature on the local certificate hash value using the client quantum-resistant private key in the client quantum-resistant key pair.

[0031] The preset quantum-resistant signature algorithm, the local certificate signature value, and the client quantum-resistant public key in the client quantum-resistant key pair are sent to the server so that the server can perform quantum-resistant authentication.

[0032] Secondly, this application discloses a remote access handshake device based on dual quantum-resistant protection, applied to a client, comprising:

[0033] The protocol setting module is used to send a connection request to the server and receive a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request from the server. Then, it sets the corresponding authentication protocol based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit.

[0034] The information receiving module is used to handshake with the server based on the authentication protocol and the quantum-resistant authentication key exchange suite. If the handshake is successful, it receives the target certificate fed back by the server, sends a certificate quantum-resistant authentication protocol request to the server, and receives the quantum-resistant information corresponding to the certificate quantum-resistant authentication protocol request sent by the server. The quantum-resistant information includes a preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value.

[0035] The quantum verification module is used to parse the quantum-resistant information, and to perform quantum-resistant verification on the target certificate using the preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value obtained from the parsing, and to perform subsequent communication after the verification is successful.

[0036] The communication termination module is used to terminate communication with the server if the handshake fails.

[0037] Thirdly, this application discloses an electronic device, including:

[0038] Memory, used to store computer programs;

[0039] A processor is used to execute the computer program to implement the remote access handshake method based on dual quantum-resistant protection as described above.

[0040] Fourthly, this application discloses a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned remote access handshake method based on dual quantum-resistant protection.

[0041] In this application, a connection request is sent to a server, and a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request are received from the server. Then, a corresponding authentication protocol is set based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit. A handshake is performed with the server based on the authentication protocol and the quantum-resistant authentication key exchange kit. If the handshake is successful, the target certificate is received from the server, a quantum-resistant authentication protocol request is sent to the server, and quantum-resistant information corresponding to the quantum-resistant authentication protocol request is received from the server. The quantum-resistant information includes a preset quantum-resistant signature algorithm, a server-side quantum-resistant public key, and a certificate signature value. The quantum-resistant information is parsed, and the target certificate is quantum-resistant verified using the parsed preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value. Subsequent communication proceeds after successful verification. If the handshake fails, communication with the server ends.

[0042] Therefore, the method described in this application requires the client to send a connection request to the server, then receive the authentication identifier and quantum-resistant key exchange suite from the server. Based on these identifiers, the client sets the corresponding authentication protocol and then performs a handshake with the server according to the authentication protocol and the quantum-resistant key exchange suite. If the handshake fails, communication with the server ends directly. If the handshake succeeds, the client receives the target certificate from the server, sends a quantum-resistant authentication protocol request to the server, and parses the quantum-resistant information from the server. Based on the parsed preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value, the client performs quantum-resistant verification of the target certificate. Subsequent communication only proceeds after successful verification. This approach, by specifically supplementing the quantum-resistant signature verification step after the conventional quantum-resistant key exchange handshake, achieves a dual protection system combining quantum-resistant key exchange and quantum-resistant certificate verification, filling the gap in quantum-resistant certificate verification within conventional quantum-resistant key exchange algorithm suites. Therefore, it maintains compatibility with existing systems without requiring modifications to the existing PKI system or updates to certificate format standards and related protocols, effectively reducing deployment costs. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0044] Figure 1 This is a flowchart of a remote access handshake method based on dual quantum-resistant protection disclosed in this application;

[0045] Figure 2 This is a schematic diagram of the processing procedure of a remote access handshake method based on dual quantum protection disclosed in this application;

[0046] Figure 3 This is a schematic diagram of a remote access handshake device based on dual quantum-resistant protection disclosed in this application;

[0047] Figure 4 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0049] Currently, VPN quantum-resistant solutions mainly employ a hybrid quantum-resistant key exchange and quantum-resistant certificate approach. Both approaches have shortcomings: the hybrid quantum-resistant key exchange suite only protects the key exchange itself from quantum resistance, failing to provide quantum-resistant protection for the certificate, thus unable to achieve quantum resistance for the certificate. The quantum-resistant certificate approach, on the other hand, requires modifying the existing PKI system, including updating certificate format standards and related protocols to support new post-quantum cryptographic algorithm identifiers, key negotiation mechanisms, and digital signature schemes, resulting in high modification costs and difficult deployment.

[0050] To overcome the aforementioned technical problems, this application discloses a remote access handshake method, apparatus, device, and medium based on dual quantum-resistant protection. This method can supplement quantum-resistant signature verification after the conventional quantum-resistant key exchange handshake is completed, thereby achieving dual quantum-resistant protection.

[0051] See Figure 1 As shown, this embodiment of the invention discloses a remote access handshake method based on dual quantum-resistant protection, applied to a client, including:

[0052] Step S11: Send a connection request to the server and receive the quantum authentication identifier and quantum-resistant authentication key exchange kit corresponding to the connection request from the server. Then, set the corresponding authentication protocol based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit.

[0053] In this embodiment, as Figure 2 As shown, before the client sends a connection request to the server, the server must first configure the authentication method the client chooses, such as conventional authentication or quantum-resistant authentication. Furthermore, if conventional authentication is used, the TLS (Transport Layer Security) authentication protocol can be either TLS 1.2 or TLS 1.3. If quantum-resistant authentication is selected, TLS 1.3 must be used. The TLS 1.3 authentication protocol algorithm suite includes, but is not limited to, the following: , , , , wait.

[0054] Furthermore, if the server-side authentication method is configured as quantum-resistant authentication, then in addition to setting the TLS 1.3 protocol, a quantum-resistant key exchange algorithm suite also needs to be configured. The quantum-resistant key exchange algorithm suite used in this invention employs an open-source copper lock. The algorithm suite employs a hybrid quantum key encapsulation mechanism, simultaneously generating two shared keys, SM2 and ML-KEM768, during the TLS handshake. The final session key is generated jointly from both keys. This hybrid key encapsulation mechanism enables quantum resistance to key exchange during the TLS handshake process.

[0055] After configuration, the client can send a connection request to the server. Upon receiving the connection request, the server will respond with relevant information. Specifically, the client needs to send a connection request to the server so that the server can generate the corresponding quantum authentication identifier and send the quantum authentication identifier, the corresponding quantum-resistant key exchange suite, and the target certificate back to the client. That is, when the client connects to the server via socket, after receiving the client's connection request, the server first sends a "PQC" field indicating that the current authentication method is quantum-resistant via TCP (Transmission Control Protocol). In addition to this field, the server also sends the currently used algorithm suite and key exchange suite (such as SM2, MLKEM768) to the client.

[0056] Furthermore, the client needs to receive the quantum authentication identifier, quantum-resistant key exchange suite, and target certificate corresponding to the connection request sent by the server, and set the corresponding authentication protocol according to the quantum-resistant key exchange suite. For example... Figure 2 The client parses the TCP information returned by the server. Upon receiving the "PQC" quantum-resistant authentication identifier, it continues to parse the TCP information to obtain the quantum-resistant authentication key exchange suite. It should be noted that the quantum-resistant authentication key exchange suite includes the algorithm suite of the TLS protocol and the PQC key exchange suite with quantum resistance. Then, the corresponding authentication protocol needs to be set according to the algorithm suite in the quantum-resistant authentication key exchange suite.

[0057] Step S12: Based on the authentication protocol and the quantum-resistant authentication key exchange suite, perform a handshake with the server. If the handshake is successful, receive the target certificate fed back by the server, send a quantum-resistant authentication protocol request to the server, and receive the quantum-resistant information corresponding to the quantum-resistant authentication protocol request sent by the server. The quantum-resistant information includes a preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value.

[0058] In this embodiment, a handshake is required with the server based on the authentication protocol and the quantum-resistant authentication key exchange suite. Specifically, as follows: Figure 2 As shown, it is necessary to determine the quantum-resistant key exchange algorithm corresponding to the quantum-resistant authentication key exchange suite, and to perform a handshake with the server based on the quantum-resistant key exchange algorithm and the authentication protocol. If the handshake is successful, the client receives the target certificate from the server and sends a certificate quantum-resistant authentication protocol request to the server. That is, after the client and server complete the normal handshake, the client receives the server's target certificate, i.e., the signing certificate. If the current authentication method is quantum-resistant authentication, the client will send a certificate quantum-resistant authentication protocol request to the server to verify the quantum resistance of the server's certificate.

[0059] Furthermore, upon receiving a quantum-resistant certificate authentication protocol request, the server generates quantum-resistant information corresponding to the request and sends this information back to the client. Specifically, when the server receives the quantum-resistant certificate request, it uses the currently configured quantum-resistant signature algorithm, such as the commonly used ML-DSA (Module-Lattice-Based Digital Signature Algorithm). Mainstream quantum-resistant signature algorithms, such as FastFourier Transform over NTRU Lattice-Based Digital Signature Algorithm (FFT), or self-optimized algorithms, are used. First, an external quantum-resistant public-private key pair is generated. Second, the server certificate is hashed using algorithms including, but not limited to, commonly used algorithms such as MD5 (Message-Digest Algorithm) and SM3. Finally, the generated quantum-resistant private key is used to sign the hashed certificate information. After generating the quantum-resistant signature data for the certificate, the server sends the currently used preset quantum-resistant signature algorithm, the generated server-side quantum-resistant public key, and the certificate signature value to the client in an appropriate format, such as JSON (JavaScript Object Notation), through the tunnel generated during the handshake, according to the agreed protocol. It should be noted that conventional SSL (Secure Sockets Layer) handshakes use a hybrid key encapsulation mechanism, such as the Copper Lock algorithm suite (…). During the TLS handshake, two shared keys, SM2 and ML-KEM768, are generated simultaneously, and the final session key is generated jointly by the two keys.

[0060] Step S13: Parse the quantum-resistant information, and use the preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value obtained from the parsing to perform quantum-resistant verification on the target certificate, and proceed with subsequent communication after the verification is successful.

[0061] In this embodiment, after the client sends a certificate quantum-resistant authentication protocol request, it waits for the server to return the corresponding information. This can be divided into two specific scenarios. First, if no response is received from the server after a set time, the certificate quantum-resistant signature verification is considered to have failed, and the current connection is actively closed, while an error message is returned. Specifically, if no quantum-resistant information is received from the server within a preset waiting time threshold, the handshake is determined to have failed, the current communication connection with the server is closed, the error message of this handshake failure is recorded, and the error message is fed back to the preset information processing node.

[0062] Furthermore, in the second scenario, if quantum-resistant information is received from the server within a preset waiting time threshold, the target certificate needs to be hashed using a preset hash algorithm to obtain a comparison hash value. Then, the certificate signature value is restored using a preset quantum-resistant signature algorithm and the server's quantum-resistant public key to obtain the certificate hash value. Specifically, the returned quantum-resistant certificate information needs to be parsed. The parsed data includes the preset quantum-resistant signature algorithm used by the server, the server's quantum-resistant public key, and the certificate's quantum-resistant signature value. Then, the target server certificate saved after the successful handshake is hashed using the same hash algorithm to obtain the certificate hash value. Further, a consistency comparison needs to be performed between the certificate hash value and the comparison hash value. If the certificate hash value matches the comparison hash value, the verification passes; if they do not match, the verification fails. Specifically, a quantum-resistant signature verification is performed using a preset quantum-resistant signature algorithm, combined with the server's quantum-resistant public key, the quantum-resistant signature value, and the hash value. If the verification is successful, it indicates that the server certificate from the previous handshake was indeed the server's own certificate, and subsequent business operations can continue. If the quantum-resistant signature verification fails, it indicates that the server certificate in the previous handshake was not a genuine server certificate. The client then returns a quantum-resistant failure error message and actively disconnects the current tunnel.

[0063] Step S14: If the handshake fails, then terminate the communication with the server.

[0064] In this embodiment, after the client sends a connection request to the server, it needs to receive the authentication identifier and quantum-resistant key exchange suite from the server. Based on the authentication identifier and the quantum-resistant key exchange suite, the client sets the corresponding authentication protocol and then performs a handshake with the server according to the authentication protocol and the quantum-resistant key exchange suite. If the handshake fails, communication with the server ends directly. If the handshake succeeds, the client receives the target certificate from the server, sends a certificate quantum-resistant authentication protocol request to the server, and parses the quantum-resistant information from the server. Based on the parsed preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value, the client performs quantum-resistant verification of the target certificate. Subsequent communication proceeds only after successful verification. This allows for a dual protection system combining quantum-resistant key exchange and certificate verification, filling the gap in quantum-resistant certificate verification in conventional quantum-resistant key exchange algorithm suites. Therefore, it maintains compatibility with existing systems without modifying the existing PKI system or updating certificate format standards and related protocols, effectively reducing deployment costs.

[0065] In one preferred embodiment, in some cases, the server needs to perform quantum-resistant authentication on the client certificate. The specific steps are as follows: If a quantum-resistant authentication protocol request for the target certificate is received from the server, a quantum-resistant key pair for the client is generated based on a preset quantum-resistant signature algorithm; the local certificate is hashed using a preset hash algorithm to obtain the local certificate hash value, and the local certificate hash value is quantum-resistantly signed using the client quantum-resistant private key in the client quantum-resistant key pair to obtain the local certificate signature value; the preset quantum-resistant signature algorithm, the local certificate signature value, and the client quantum-resistant public key in the client quantum-resistant key pair are sent to the server so that the server can perform quantum-resistant authentication. That is, firstly, the server sends a quantum-resistant certificate authentication request to the client; secondly, after receiving the server's request, the client generates a quantum-resistant public-private key pair using the corresponding quantum-resistant signature algorithm and performs a quantum-resistant signature on the certificate information using the quantum-resistant private key; then, the quantum-resistant signature algorithm, the quantum-resistant public-private key pair, and the signature value are sent to the server; finally, the server verifies the quantum-resistant certificate information sent by the client using the corresponding quantum-resistant signature algorithm. If the signature verification passes, subsequent business can continue; if the signature verification fails, the tunnel will be disconnected and an error message will be returned.

[0066] See Figure 3 As shown, this embodiment of the invention discloses a remote access handshake device based on dual quantum-resistant protection, applied to a client, comprising:

[0067] The protocol setting module 11 is used to send a connection request to the server and receive a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request sent by the server, and then set the corresponding authentication protocol based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit.

[0068] The information receiving module 12 is used to perform a handshake with the server based on the authentication protocol and the quantum-resistant authentication key exchange suite. If the handshake is successful, it receives the target certificate fed back by the server, sends a certificate quantum-resistant authentication protocol request to the server, and receives the quantum-resistant information corresponding to the certificate quantum-resistant authentication protocol request sent by the server. The quantum-resistant information includes a preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value.

[0069] Quantum verification module 13 is used to parse the quantum-resistant information, and to perform quantum-resistant verification on the target certificate using the preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value obtained from the parsing, and to perform subsequent communication after the verification is successful;

[0070] The communication termination module 14 is used to terminate communication with the server if the handshake fails.

[0071] In this embodiment, after the client sends a connection request to the server, it needs to receive the authentication identifier and quantum-resistant key exchange suite from the server. Based on the authentication identifier and the quantum-resistant key exchange suite, the client sets the corresponding authentication protocol and then performs a handshake with the server according to the authentication protocol and the quantum-resistant key exchange suite. If the handshake fails, communication with the server ends directly. If the handshake succeeds, the client receives the target certificate from the server, sends a certificate quantum-resistant authentication protocol request to the server, and parses the quantum-resistant information from the server. Based on the parsed preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value, the client performs quantum-resistant verification of the target certificate. Subsequent communication proceeds only after successful verification. This allows for a dual protection system combining quantum-resistant key exchange and certificate verification, filling the gap in quantum-resistant certificate verification in conventional quantum-resistant key exchange algorithm suites. Therefore, it maintains compatibility with existing systems without modifying the existing PKI system or updating certificate format standards and related protocols, effectively reducing deployment costs.

[0072] In some embodiments, the protocol setting module 11 may specifically include:

[0073] A connection request sending unit is used to send a connection request to the server so that after receiving the connection request, the server generates a corresponding quantum authentication identifier and feeds back the quantum authentication identifier and the quantum-resistant authentication key exchange kit corresponding to the quantum authentication identifier to the client.

[0074] The protocol setting unit is used to receive the quantum authentication identifier corresponding to the connection request sent by the server and the quantum-resistant authentication key exchange suite, and to set the corresponding authentication protocol according to the quantum-resistant authentication key exchange suite.

[0075] In some embodiments, the information receiving module 12 may specifically include:

[0076] The communication handshake submodule is used to determine the quantum-resistant key exchange algorithm corresponding to the quantum-resistant authentication key exchange suite, and to perform a handshake with the server according to the quantum-resistant key exchange algorithm and the authentication protocol;

[0077] The authentication request sending submodule is used to receive the target certificate fed back by the server if the handshake is successful, send a certificate quantum-resistant authentication protocol request to the server, so that the server generates quantum-resistant information corresponding to the certificate quantum-resistant authentication protocol request after receiving the certificate quantum-resistant authentication protocol request, and feeds back the quantum-resistant information to the client;

[0078] The quantum-resistant information receiving submodule is used to receive the quantum-resistant information corresponding to the certificate quantum-resistant authentication protocol request fed back by the server.

[0079] In some embodiments, the authentication request sending submodule may specifically include:

[0080] The signature calculation unit is used to generate a server-side quantum-resistant key pair based on a preset quantum-resistant signature algorithm, perform hash calculation on the target certificate using a preset hash algorithm, and then sign the certificate hash value obtained by hash calculation using the server-side quantum-resistant private key in the key pair to obtain the certificate signature value.

[0081] The quantum-resistant information transmission unit sends the preset quantum-resistant signature algorithm, the certificate signature value, and the server-side quantum-resistant public key from the server-side quantum-resistant key pair as quantum-resistant information to the client.

[0082] In some embodiments, the remote access handshake device based on dual quantum-resistant protection may further include:

[0083] The connection disconnection unit is used to determine that the handshake has failed and disconnect the current communication connection with the server if the anti-quantum information is not received from the server within a preset waiting time threshold.

[0084] The error information feedback unit is used to record the error information of this handshake failure and feed the error information back to the preset information processing node.

[0085] In some embodiments, the quantum verification module 13 may specifically include:

[0086] The information parsing unit is used to parse the quantum-resistant information to obtain the preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value;

[0087] The signature restoration unit is used to perform hash calculation on the target certificate using the preset hash algorithm to obtain a hash value to be compared, and to restore the certificate signature value using the preset quantum-resistant signature algorithm and the server-side quantum-resistant public key to obtain the certificate hash value.

[0088] The first hash value comparison unit is used to perform a consistency comparison between the certificate hash value and the hash value to be compared. If the certificate hash value is consistent with the hash value to be compared, the verification is passed.

[0089] The second hash value comparison unit is used to verify if the certificate hash value and the hash value to be compared are inconsistent.

[0090] In some embodiments, the remote access handshake device based on dual quantum-resistant protection may further include:

[0091] A key pair generation unit is used to generate a client-side quantum-resistant key pair based on the preset quantum-resistant signature algorithm if a target certificate quantum-resistant authentication protocol request is received from the server.

[0092] The hash value signature unit is used to perform hash calculation on the local certificate using a preset hash algorithm to obtain the local certificate hash value corresponding to the local certificate, and to perform quantum-resistant signature on the local certificate hash value using the client quantum-resistant private key in the client quantum-resistant key pair to obtain the local certificate signature value.

[0093] The information sending unit is used to send the preset quantum-resistant signature algorithm, the local certificate signature value, and the client quantum-resistant public key in the client quantum-resistant key pair to the server so that the server can perform quantum-resistant authentication.

[0094] Furthermore, embodiments of this application also disclose an electronic device, Figure 4 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0095] Figure 4 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the remote access handshake method based on dual quantum-resistant protection disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0096] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0097] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0098] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the remote access handshake method based on dual quantum-resistant protection disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.

[0099] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned remote access handshake method based on dual quantum-resistant protection. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0100] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0101] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0102] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0103] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0104] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A remote access handshake method based on dual quantum-resistant protection, characterized in that, Applied to the client side, including: Send a connection request to the server and receive a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request from the server. Then, set the corresponding authentication protocol based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit. Based on the authentication protocol and the quantum-resistant authentication key exchange suite, a handshake is performed with the server. If the handshake is successful, the target certificate fed back by the server is received, a quantum-resistant authentication protocol request for the certificate is sent to the server, and quantum-resistant information corresponding to the quantum-resistant authentication protocol request is received from the server. The quantum-resistant information includes a preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value. The target certificate is a traditional certificate. The quantum-resistant information is parsed, and the target certificate is verified against quantum resistance using the preset quantum-resistant signature algorithm obtained from the parsing, the server-side quantum-resistant public key, and the certificate signature value. Subsequent communication is then carried out after the verification is successful. If the handshake fails, communication with the server will end.

2. The remote access handshake method based on dual quantum-resistant protection according to claim 1, characterized in that, The process involves sending a connection request to the server and receiving a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request from the server. Then, based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit, a corresponding authentication protocol is set, including: A connection request is sent to the server so that the server generates a corresponding quantum authentication identifier upon receiving the connection request, and feeds back the quantum authentication identifier and the corresponding quantum-resistant authentication key exchange kit to the client. The system receives the quantum authentication identifier corresponding to the connection request sent by the server and the quantum-resistant authentication key exchange suite, and sets the corresponding authentication protocol according to the quantum-resistant authentication key exchange suite.

3. The remote access handshake method based on dual quantum-resistant protection according to claim 2, characterized in that, The process involves a handshake with the server based on the authentication protocol and the quantum-resistant authentication key exchange suite. If the handshake is successful, the process receives the target certificate from the server, sends a quantum-resistant authentication protocol request to the server, and receives quantum-resistant information corresponding to the quantum-resistant authentication protocol request from the server, including: Determine the quantum-resistant key exchange algorithm corresponding to the quantum-resistant authentication key exchange suite, and perform a handshake with the server based on the quantum-resistant key exchange algorithm and the authentication protocol; If the handshake is successful, the target certificate fed back by the server is received, and a certificate quantum-resistant authentication protocol request is sent to the server. After receiving the certificate quantum-resistant authentication protocol request, the server generates quantum-resistant information corresponding to the certificate quantum-resistant authentication protocol request and feeds back the quantum-resistant information to the client. Receive the quantum-resistant information corresponding to the quantum-resistant authentication protocol request from the server.

4. The remote access handshake method based on dual quantum-resistant protection according to claim 3, characterized in that, The process of generating quantum-resistant information corresponding to the quantum-resistant authentication protocol request for the certificate and feeding back the quantum-resistant information to the client includes: A server-side quantum-resistant key pair is generated based on a preset quantum-resistant signature algorithm, and the target certificate is hashed using a preset hash algorithm. Then, the certificate hash value obtained by hashing is signed using the server-side quantum-resistant private key in the key pair to obtain the certificate signature value. The preset quantum-resistant signature algorithm, the certificate signature value, and the server-side quantum-resistant public key in the server-side quantum-resistant key pair are sent to the client as quantum-resistant information.

5. The remote access handshake method based on dual quantum-resistant protection according to claim 1, characterized in that, The step of parsing the quantum-resistant information, and performing quantum-resistant verification of the target certificate using the pre-defined quantum-resistant signature algorithm obtained from the parsing, the server-side quantum-resistant public key, and the certificate signature value, and before proceeding with subsequent communication after successful verification, further includes: If the anti-quantum information is not received from the server within the preset waiting time threshold, the handshake is determined to have failed, and the current communication connection with the server is disconnected. Record the error message of this handshake failure and feed the error message back to the preset information processing node.

6. The remote access handshake method based on dual quantum-resistant protection according to claim 4, characterized in that, The step of parsing the quantum-resistant information and performing quantum-resistant verification of the target certificate using the pre-defined quantum-resistant signature algorithm obtained from the parsing, the server-side quantum-resistant public key, and the certificate signature value includes: The quantum-resistant information is parsed to obtain the preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value; The target certificate is hashed using the preset hash algorithm to obtain a hash value to be compared, and the certificate signature value is restored using the preset quantum-resistant signature algorithm and the server-side quantum-resistant public key to obtain the certificate hash value. A consistency comparison is performed between the certificate hash value and the hash value to be compared. If the certificate hash value is consistent with the hash value to be compared, the verification is successful. If the certificate hash value and the hash value to be compared are inconsistent, the verification fails.

7. The remote access handshake method based on dual quantum-resistant protection according to any one of claims 1 to 6, characterized in that, Also includes: If a target certificate quantum-resistant authentication protocol request is received from the server, a client-side quantum-resistant key pair is generated based on the preset quantum-resistant signature algorithm; The local certificate hash value is obtained by performing a hash calculation on the local certificate using a preset hash algorithm, and then a quantum-resistant signature is obtained by performing a quantum-resistant signature on the local certificate hash value using the client quantum-resistant private key in the client quantum-resistant key pair. The preset quantum-resistant signature algorithm, the local certificate signature value, and the client quantum-resistant public key in the client quantum-resistant key pair are sent to the server so that the server can perform quantum-resistant authentication.

8. A remote access handshake device based on dual quantum-resistant protection, characterized in that, Applied to the client side, including: The protocol setting module is used to send a connection request to the server and receive a quantum authentication identifier and a quantum-resistant authentication key exchange kit corresponding to the connection request from the server. Then, it sets the corresponding authentication protocol based on the quantum authentication identifier and the quantum-resistant authentication key exchange kit. The information receiving module is used to handshake with the server based on the authentication protocol and the quantum-resistant authentication key exchange suite. If the handshake is successful, it receives the target certificate fed back by the server, sends a quantum-resistant authentication protocol request to the server, and receives quantum-resistant information corresponding to the quantum-resistant authentication protocol request sent by the server. The quantum-resistant information includes a preset quantum-resistant signature algorithm, the server's quantum-resistant public key, and the certificate signature value. The target certificate is a traditional certificate. The quantum verification module is used to parse the quantum-resistant information, and to perform quantum-resistant verification on the target certificate using the preset quantum-resistant signature algorithm, the server-side quantum-resistant public key, and the certificate signature value obtained from the parsing, and to perform subsequent communication after the verification is successful. The communication termination module is used to terminate communication with the server if the handshake fails.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the remote access handshake method based on dual quantum-resistant protection as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store a computer program, wherein the computer program, when executed by a processor, implements the remote access handshake method based on dual quantum-resistant protection as described in any one of claims 1 to 7.