Quantum encryption-based meta-universe terminal identity authentication method, device and equipment
By combining offline quantum key refilling and secure chip anchoring with quantum TF cards and PQC algorithms, a dual security system is designed, which solves the problem that traditional encryption algorithms are easily cracked, and achieves high security and compliance of identity authentication in the government metaverse, ensuring the security of data interaction.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ANHUI TELECOMM PLANNING & DESIGNING
- Filing Date
- 2026-02-28
- Publication Date
- 2026-06-16
AI Technical Summary
Traditional encryption algorithms are vulnerable to brute-force attacks and man-in-the-middle attacks, which quantum computers can easily crack. Existing identity authentication methods cannot meet the high security requirements of the e-government world, especially in immersive terminals such as VR headsets and AR glasses, where the security of identity authentication and session encryption is difficult to guarantee.
The technology adopts offline quantum key refilling and secure chip anchoring, combines quantum TF card and PQC algorithm to generate key pairs, and realizes full life cycle management of keys through SHA-3 algorithm and verifiable destruction protocol. It designs a dual security system of user quantum-resistant signature and device quantum key authentication to ensure strong binding between identity and device.
It effectively prevents the misuse of devices and identity information, achieves strong binding between user identity and devices, ensures the security and compliance of data interaction in the government metaverse, resists quantum computing attacks, and meets the encryption requirements of highly sensitive government data.
Smart Images

Figure CN122226338A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity authentication technology, and more specifically, to a metaverse terminal identity authentication method, apparatus, and device based on quantum encryption. Background Technology
[0002] With the rapid development of information technology, cybersecurity issues have become increasingly prominent, and user authentication has become a core element in ensuring information security. While traditional symmetric and asymmetric encryption algorithms offer some degree of security, they are vulnerable to brute-force attacks and man-in-the-middle attacks, leading to identity theft and information leaks. Furthermore, with the development of quantum computers, Shor's algorithm can easily crack these mainstream asymmetric encryption algorithms, posing a significant risk of complete failure to traditional encryption systems and severely threatening systems and services that rely on such algorithms.
[0003] As an emerging virtual interaction scenario, the metaverse relies on immersive terminals such as VR headsets, AR glasses, and holographic devices as core entry points for users. Its security requirements for identity authentication and session encryption far exceed those of traditional scenarios. Especially against the backdrop of digital government evolving towards immersive services, the e-government metaverse is becoming a new form of government service, involving specific business processes such as highly sensitive government data transmission and electronic signatures. This places even stricter demands on the security and compliance of identity authentication, which traditional authentication methods can no longer meet.
[0004] To address the identity authentication problem in the metaverse, several technical solutions have emerged, but none can meet the high security requirements of the government metaverse. For example, invention patent CN116186656A discloses a metaverse identity authentication method, device, equipment, and storage medium. Its core technology is based on traditional cryptography, using digital filters and blockchain identity tags to obtain and verify another user's identification information and scenario information, solving the problem of virtual identity authentication in multiple scenarios. However, this solution does not involve the application of quantum encryption in identity authentication, cannot resist quantum computing attacks, and focuses on consumer-level interaction scenarios, failing to consider the high sensitivity of government data, thus failing to meet the needs of the government metaverse. Another invention patent, CN121356813A, discloses a metaverse-based identity authentication method, device, and medium. It employs revocable mathematical vectors and biometric authentication. While mentioning encapsulating revocable mathematical vectors with quantum-secure keys, it fails to specify the technical implementation paths for quantum key generation, storage, and use. Quantum encryption technology remains conceptual, lacking substantial technical support and failing to fully leverage its high-security characteristics. Consequently, it cannot meet the high-security authentication and data encryption requirements of the government metaverse. Therefore, there is an urgent need to provide a metaverse-based terminal identity authentication method, device, storage medium, and program product to solve the aforementioned problems. Summary of the Invention
[0005] To address the aforementioned technical challenges, this invention provides a metaverse terminal identity authentication method, device, and equipment based on quantum encryption. It employs offline quantum key refilling and secure chip anchoring to achieve strong binding between identity and device. Considering VR applications and government needs, it utilizes quantum TF cards, upgrades the PQC algorithm to generate key pairs, and incorporates a dual security system to prevent misuse. Session keys are used to encrypt highly sensitive government data to ensure compliance. The SHA-3 algorithm and a verifiable destruction protocol are combined to clear session keys, achieving full lifecycle management of keys and ensuring secure data interaction.
[0006] To achieve the above objectives, the technical solution of the present invention is as follows:
[0007] The metaverse terminal authentication method based on quantum encryption includes the following steps:
[0008] S1. Offline charging of quantum key to quantum TF card. And obtain the corresponding index. Quantum key Perform multi-point secure storage, record and inject timestamps, and index them. The timestamp of the filling is encrypted and stored in the quantum TF card;
[0009] S2. Adapt the PQC algorithm to the security chip SE of the terminal device and generate a PQC key pair. Encrypt and store the PQC private key in the security chip SE. Upload the user's identity information to the government authentication center server in encryption. Generate a binding request containing information related to the user, device, and key, sign and upload it. After the government authentication center server verifies the request, a strong binding relationship is established between the two. If the verification fails, login is prohibited.
[0010] S3. The user initiates an authentication request to the government authentication center server through the terminal device, receives the random challenge generated by the server and performs HMAC operation, unlocks the security chip SE, performs PQC signature on the operation result and uploads it for verification. If the verification is successful, the session request is allowed to be established; if the verification fails, the login is prohibited.
[0011] S4. The terminal device requests the session key from the quantum distribution network node or the quantum cryptographic resource pool. Session key via quantum key After encryption, the key is simultaneously sent to the terminal device and the government authentication center server. The terminal device then decrypts the key to obtain the session key. Then destroy the locally stored quantum key. ;
[0012] S5, terminal devices, and the government metaverse system communicate via session keys. Data is transmitted in encrypted form, and the session key is destroyed via a verifiable key destruction protocol after the session ends. Completely destroy.
[0013] As a preferred embodiment of the present invention, S1 specifically comprises:
[0014] S101. Users use quantum TF cards to offline refill the keys cached in the quantum distribution network node / quantum cryptographic resource pool at the key refilling machine to obtain quantum keys. and its corresponding key index number The quantum TF card supports the SM4 algorithm and has a key length of 128 bits. It is a 32-bit unsigned integer;
[0015] S102, Transfer the quantum key The quantum cryptography resource is stored in the quantum distribution network node / quantum cryptography resource pool, the government authentication center server, and the quantum TF card, and the filling timestamp is recorded. The timestamp adopts the Unix timestamp format.
[0016] S103, Transfer the quantum key Key index number The filling timestamp is stored in the quantum TF card, and the storage method is encrypted storage, using the AES-256 encryption algorithm;
[0017] S104. By combining time difference hash value with digital feature extraction, a dynamic and variable encoding algorithm selection mechanism is constructed to make the session identifier generation process resistant to analysis and cracking. The time difference hash value adopts the SHA-256 algorithm, and the digital features are extracted using the PCA principal component analysis algorithm.
[0018] As a preferred embodiment of the present invention, S2 specifically comprises:
[0019] S201. Upgrade the PQC algorithm hardware and software using the existing security chip SE on the terminal device, generate a PQC key pair, and transfer the PQC private key. The PQC public key is encrypted and stored in the secure chip SE. Preparing to upload to the government certification center, the PQC algorithm to be selected is the SPHINCS-256 algorithm;
[0020] S202. Users register their identity through terminal devices. The registration information is transmitted to the government authentication center server through quantum key encryption. The registration information includes name, ID number, contact number, etc.
[0021] S203, Generate a hash containing the user's ID card number. ,chip , , The request is bound to a timestamp and uses a PQC private key. After signing the request, it is uploaded to the government authentication center server. The signing algorithm is SM2.
[0022] S204, The government authentication center server verifies the user's identity. The system verifies the reuse status and batch validity. If the verification passes, the user is allowed to enter S3; otherwise, login is prohibited. The verification period is 30 days.
[0023] As a preferred embodiment of the present invention, S3 specifically comprises:
[0024] S301. Users wearing VR headsets or other immersive government service terminals access the government service metaverse client and send a message to the authentication center server. and chips ;
[0025] S302. The government authentication center server generates a random challenge, which includes a random number, a timestamp, and a validity period. The random number generator uses the ChaCha20 algorithm, the timestamp uses the Unix timestamp format, and the validity period is 60 seconds.
[0026] S303, The device reads the quantum key from the quantum TF card. Perform HMAC operation and generate the result. The HMAC algorithm used is SHA-256.
[0027] S304. The user enters a PIN code or biometric signature to unlock the security chip SE. The security chip SE uses the PQC private key. Sign the calculation result;
[0028] S305. The device sends the response result to the government authentication center server. The authentication center server uses the pre-registered PQC public key. Verification is performed; if verification fails, login is denied; if verification succeeds, a session request is allowed to enter S4.
[0029] As a preferred embodiment of the present invention, S4 includes the following steps:
[0030] S401. The user equipment terminal requests the quantum distribution network node / quantum cryptographic resource pool to issue the session key generated in real time. Quantum keys are used for device terminals and government authentication center servers. right Encryption protection is implemented during distribution. The key length is 256 bits;
[0031] S402, Equipment According to Find the corresponding one in the quantum TF card. Decryption and immediately destroy the relevant equipment. Key;
[0032] S403. By bidirectionally generating and exchanging encrypted hash digests between the quantum key server and external devices, a mutually verifiable key destruction mechanism is constructed to ensure the credibility and non-repudiation of the key destruction process. The hash algorithm selected is SHA-512.
[0033] As a preferred embodiment of the present invention, S5 includes the following steps:
[0034] S501, user equipment and systems in the government metaverse transmit data;
[0035] S502, Communication data uses a key Encrypt the transmission;
[0036] S503. When the session ends, the key is cleared by comparing the bidirectional hash digest through the verifiable destruction protocol of the verification layer key, thus fundamentally eliminating the risk of key residue after the session ends. The hash algorithm selected is SHA-3.
[0037] This invention also provides a metaverse terminal identity authentication device based on quantum encryption, comprising:
[0038] The quantum key injection module is used to inject quantum keys offline into quantum TF cards. And obtain the corresponding index. Quantum key Perform multi-point secure storage, record and inject timestamps, and index them. The timestamp of the filling is encrypted and stored in the quantum TF card;
[0039] The identity device binding module is used to adapt the PQC algorithm to the security chip SE of the terminal device and generate a PQC key pair. The PQC private key is encrypted and stored in the security chip SE. The user's identity information is encrypted and uploaded to the government authentication center server. A binding request containing user, device and key information is generated, signed and uploaded. The module receives the verification result from the government authentication center server. If the verification is successful, a strong binding relationship between the user's identity and the terminal device is established. If the verification fails, the user is prohibited from logging in.
[0040] The authentication session establishment module is used to receive authentication requests initiated by users through terminal devices, forward the requests to the government authentication center server, receive random challenges generated by the server and perform HMAC operations, unlock the security chip SE, perform PQC signature on the operation results and upload them to the server for verification, receive the verification results, and allow the session establishment request if the verification is successful, and prohibit login if the verification fails.
[0041] The session key distribution module is used to request session keys from quantum distribution network nodes / quantum cryptographic resource pools. Receive via quantum key Encrypted session key It also synchronizes with the terminal device and the government authentication center server, controlling the terminal device to decrypt and obtain the session key. Then destroy the locally stored quantum key. ;
[0042] The data transmission and key destruction module is used to control the communication between terminal devices and the government metaverse system via session keys. Data is transmitted in encrypted form, and the session key is destroyed via a verifiable key destruction protocol after the session ends. Completely destroy.
[0043] The present invention also provides an electronic device, including: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions, which, when called and executed by the processor, implement the above-described metaverse terminal identity authentication method.
[0044] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described metaverse terminal identity authentication method.
[0045] The present invention also provides a computer program product, the computer program product comprising a computer program, which, when executed by a processor, implements the above-described metaverse terminal identity authentication method.
[0046] The beneficial technical effects of this invention are:
[0047] Based on quantum key distribution and PQC technology, a strong binding between identity and device is achieved by using offline quantum key filling and secure chip anchoring. Combining the hardware form of VR headsets and the security requirements of government affairs, quantum TF cards are selected as key carriers, and it is explained that they are more suitable for the lightweight and high-security access requirements of government metaverse immersive devices compared to other carriers.
[0048] By upgrading the PQC algorithm through hardware or software, user devices can autonomously generate PQC key pairs, encrypt and store the PQC private key in a secure chip, and upload the PQC public key to the government certification center. This prevents key leakage and illegal use from the key management level, and strengthens the foundation for a strong bond between devices and users.
[0049] The design incorporates a dual security system of user quantum-resistant signatures and device quantum key authentication to achieve trusted recording of user identity, device information, PQC signature, and key index. This further ensures a strong binding between user identity and device at the authentication level, effectively preventing the misuse of device and identity information. Attached Figure Description
[0050] Figure 1 This is a diagram of the generator structure of the present invention.
[0051] Figure 2 This is a structural diagram of the discriminator of the present invention. Detailed Implementation
[0052] In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, the specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0053] Combination Figure 1-2 The present invention provides the following embodiments:
[0054] The metaverse terminal authentication method based on quantum encryption includes the following steps:
[0055] S1. Offline charging of quantum key to quantum TF card. And obtain the corresponding index. Quantum key Perform multi-point secure storage, record and inject timestamps, and index them. The timestamp of the filling is encrypted and stored in the quantum TF card;
[0056] S2. Adapt the PQC algorithm to the security chip SE of the terminal device and generate a PQC key pair. Encrypt and store the PQC private key in the security chip SE. Upload the user's identity information to the government authentication center server in encryption. Generate a binding request containing information related to the user, device, and key, sign and upload it. After the government authentication center server verifies the request, a strong binding relationship is established between the two. If the verification fails, login is prohibited.
[0057] S3. The user initiates an authentication request to the government authentication center server through the terminal device, receives the random challenge generated by the server and performs HMAC operation, unlocks the security chip SE, performs PQC signature on the operation result and uploads it for verification. If the verification is successful, the session request is allowed to be established; if the verification fails, the login is prohibited.
[0058] S4. The terminal device requests the session key from the quantum distribution network node or the quantum cryptographic resource pool. Session key via quantum key After encryption, the key is simultaneously sent to the terminal device and the government authentication center server. The terminal device then decrypts the key to obtain the session key. Then destroy the locally stored quantum key. ;
[0059] S5, terminal devices, and the government metaverse system communicate via session keys. Data is transmitted in encrypted form, and the session key is destroyed via a verifiable key destruction protocol after the session ends. Completely destroy.
[0060] As a preferred embodiment of the present invention, S1 specifically comprises:
[0061] S101. Users use quantum TF cards to offline refill the keys cached in the quantum distribution network node / quantum cryptographic resource pool at the key refilling machine to obtain quantum keys. and its corresponding key index number The quantum TF card supports the SM4 algorithm and has a key length of 128 bits. It is a 32-bit unsigned integer;
[0062] S102, Transfer the quantum key The quantum cryptography resource is stored in the quantum distribution network node / quantum cryptography resource pool, the government authentication center server, and the quantum TF card, and the filling timestamp is recorded. The timestamp adopts the Unix timestamp format.
[0063] S103, Transfer the quantum key Key index number The filling timestamp is stored in the quantum TF card, and the storage method is encrypted storage, using the AES-256 encryption algorithm;
[0064] S104. By combining time difference hash value with digital feature extraction, a dynamic and variable encoding algorithm selection mechanism is constructed to make the session identifier generation process resistant to analysis and cracking. The time difference hash value adopts the SHA-256 algorithm, and the digital features are extracted using the PCA principal component analysis algorithm.
[0065] Offline refilling avoids the risk of eavesdropping during key transmission. The quantum TF card supports the SM4 algorithm and a 128-bit key length, meeting the encryption compliance requirements of government scenarios, and uses a 32-bit unsigned integer format. It enables unique key identification and fast indexing; three independent storage points provide key redundancy protection to prevent key loss due to single node failure; Unix timestamps provide timing basis for key validity verification; AES-256 encrypted storage. The addition of timestamps prevents core parameters from being tampered with or stolen, and avoids identity theft caused by forged key indexes. The dynamic encoding mechanism, which combines SHA-256 hashing and PCA feature extraction, enables the session identifier generation rules to change dynamically with time difference and key characteristics, breaking the limitations of fixed encoding, effectively resisting analysis and cracking attacks, and laying a solid foundation for key security for subsequent identity authentication and sessions.
[0066] As a preferred embodiment of the present invention, S2 specifically comprises:
[0067] S201. Upgrade the PQC algorithm hardware and software using the existing security chip SE on the terminal device, generate a PQC key pair, and transfer the PQC private key. The PQC public key is encrypted and stored in the secure chip SE. Preparing to upload to the government certification center, the PQC algorithm to be selected is the SPHINCS-256 algorithm;
[0068] S202. Users register their identity through terminal devices. The registration information is transmitted to the government authentication center server through quantum key encryption. The registration information includes name, ID number, contact number, etc.
[0069] S203, Generate a hash containing the user's ID card number. ,chip , , The request is bound to a timestamp and uses a PQC private key. After signing the request, it is uploaded to the government authentication center server. The signing algorithm is SM2.
[0070] S204, The government authentication center server verifies the user's identity. The system verifies the reuse status and batch validity. If the verification passes, the user is allowed to enter S3; otherwise, login is prohibited. The verification period is 30 days.
[0071] Upgrading the PQC algorithm based on the existing security chip SE in the terminal device requires no new hardware, balancing security and cost-effectiveness. The SPHINCS-256 quantum-resistant algorithm can resist quantum computing attacks, and the hardware isolation characteristics of the security chip SE can prevent… Unauthorized reading and tampering; quantum key encryption for transmitting registered sensitive information prevents information leakage during transmission, meeting government data privacy protection requirements; SM2 algorithm combined with Signing the binding request ensures its integrity and non-repudiation, preventing forged binding requests; a 30-day verification period enables dynamic validation of the binding relationship, allowing for timely detection. Issues such as reuse and abnormal binding are addressed, along with verification. The validity of the key can prevent illegal misuse and achieve a strong binding between users, devices, and keys.
[0072] As a preferred embodiment of the present invention, S3 specifically comprises:
[0073] S301. Users wearing VR headsets or other immersive government service terminals access the government service metaverse client and send a message to the authentication center server. and chips ;
[0074] S302. The government authentication center server generates a random challenge, which includes a random number, a timestamp, and a validity period. The random number generator uses the ChaCha20 algorithm, the timestamp uses the Unix timestamp format, and the validity period is 60 seconds.
[0075] S303, The device reads the quantum key from the quantum TF card. Perform HMAC operation and generate the result. The HMAC algorithm used is SHA-256.
[0076] S304. The user enters a PIN code or biometric signature to unlock the security chip SE. The security chip SE uses the PQC private key. Sign the calculation result;
[0077] S305. The device sends the response result to the government authentication center server. The authentication center server uses the pre-registered PQC public key. Verification is performed; if verification fails, login is denied; if verification succeeds, a session request is allowed to enter S4.
[0078] Sending the UserID and chip UID can initially identify the legitimacy of the user and device without transmitting sensitive keys, reducing the risk of information leakage; the ChaCha20 algorithm generates high-strength random numbers, combined with a 60-second validity period and a Unix timestamp, ensuring the uniqueness and timeliness of the challenge, preventing the challenge information from being reused and forged; HMAC-SHA-256 operations are combined with... It can verify whether the device holds a legitimate key, achieving initial verification of the device's legitimacy; PIN code or biometric unlocking mechanisms enable secondary verification of user identity, preventing unauthorized access after the device is stolen. , The signature further binds the user, device, and key legitimacy; The reverse verification of the response results ensures that the results have not been tampered with or forged, achieving triple verification of user, device, and key to prevent unauthorized login.
[0079] As a preferred embodiment of the present invention, S4 includes the following steps:
[0080] S401. The user equipment terminal requests the quantum distribution network node / quantum cryptographic resource pool to issue the session key generated in real time. Quantum keys are used for device terminals and government authentication center servers. right Encryption protection is implemented during distribution. The key length is 256 bits;
[0081] S402, Equipment According to Find the corresponding one in the quantum TF card. Decryption and immediately destroy the relevant equipment. Key;
[0082] S403. By bidirectionally generating and exchanging encrypted hash digests between the quantum key server and external devices, a mutually verifiable key destruction mechanism is constructed to ensure the credibility and non-repudiation of the key destruction process. The hash algorithm selected is SHA-512.
[0083] Real-time generation Achieving one key per session, with a 256-bit key length enhancing encryption strength, meets the high security requirements of government data. Encryption protection This ensures that the session key transmission process is not eavesdropped on or intercepted; Quickly match corresponding To ensure efficient decryption, the data is destroyed immediately after decryption. ,accomplish Single-use design avoids the risk of leakage caused by long-term storage and eliminates the hidden dangers of key reuse; the SHA-512 algorithm generates a high-strength hash digest, enabling bidirectional generation, exchange, and comparison to verify that both parties have completed the process. Destroy the keys to prevent key residues, ensure the destruction process is trustworthy and non-repudiable, and improve key lifecycle management.
[0084] As a preferred embodiment of the present invention, S5 includes the following steps:
[0085] S501, user equipment and systems in the government metaverse transmit data;
[0086] S502, Communication data uses a key Encrypt the transmission;
[0087] S503. When the session ends, the key is cleared by comparing the bidirectional hash digest through the verifiable destruction protocol of the verification layer key, thus fundamentally eliminating the risk of key residue after the session ends. The hash algorithm selected is SHA-3.
[0088] As a dedicated session key, it encrypts highly sensitive business data within the government metaverse, ensuring the confidentiality and integrity of data transmission and preventing eavesdropping, tampering, and leakage, thus meeting government data security compliance requirements. The SHA-3 algorithm possesses excellent anti-cracking and anti-hash collision characteristics. Combined with a verifiable destruction protocol and bidirectional hash comparison, it can be confirmed that both the user device and the government metaverse system have been completely erased. This avoids security risks caused by residual keys after the session ends, enables closed-loop management of session keys throughout their entire lifecycle, and ensures the security of the entire process of government data interaction.
[0089] This invention also provides a metaverse terminal identity authentication device based on quantum encryption, comprising:
[0090] The quantum key injection module is used to inject quantum keys offline into quantum TF cards. And obtain the corresponding index. Quantum key Perform multi-point secure storage, record and inject timestamps, and index them. The timestamp of the filling is encrypted and stored in the quantum TF card;
[0091] The identity device binding module is used to adapt the PQC algorithm to the security chip SE of the terminal device and generate a PQC key pair. The PQC private key is encrypted and stored in the security chip SE. The user's identity information is encrypted and uploaded to the government authentication center server. A binding request containing user, device and key information is generated, signed and uploaded. The module receives the verification result from the government authentication center server. If the verification is successful, a strong binding relationship between the user's identity and the terminal device is established. If the verification fails, the user is prohibited from logging in.
[0092] The authentication session establishment module is used to receive authentication requests initiated by users through terminal devices, forward the requests to the government authentication center server, receive random challenges generated by the server and perform HMAC operations, unlock the security chip SE, perform PQC signature on the operation results and upload them to the server for verification, receive the verification results, and allow the session establishment request if the verification is successful, and prohibit login if the verification fails.
[0093] The session key distribution module is used to request session keys from quantum distribution network nodes / quantum cryptographic resource pools. Receive via quantum key Encrypted session key It also synchronizes with the terminal device and the government authentication center server, controlling the terminal device to decrypt and obtain the session key. Then destroy the locally stored quantum key. ;
[0094] The data transmission and key destruction module is used to control the communication between terminal devices and the government metaverse system via session keys. Data is transmitted in encrypted form, and the session key is destroyed via a verifiable key destruction protocol after the session ends. Completely destroy.
[0095] The present invention also provides an electronic device, including: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions, which, when called and executed by the processor, implement the above-described metaverse terminal identity authentication method.
[0096] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described metaverse terminal identity authentication method.
[0097] The present invention also provides a computer program product, the computer program product comprising a computer program, which, when executed by a processor, implements the above-described metaverse terminal identity authentication method.
[0098] As one application of the present invention, the specific details are as follows:
[0099] Step 1: User equipment performs quantum key injection.
[0100] Users access the key filling machine via a quantum TF card to perform offline filling operations on the keys cached in the quantum distribution network node / quantum cryptographic resource pool, thereby obtaining quantum keys. and its corresponding key index number The quantum TF card is compatible with the SM4 block encryption algorithm. The key length is , for Unsigned integers, .
[0101] quantum key The keys are stored independently in three locations: a quantum distribution network node / quantum cryptographic resource pool, a government authentication center server, and a quantum TF card; the key filling timestamp is also recorded. , Uses Unix timestamp format. , To fill the instantaneous time.
[0102] Will and splicing process ( The concatenated data is encrypted using the AES-256 encryption algorithm, and the ciphertext result is obtained. ,in For AES root key, As the initial vector, and the ciphertext Stored in a quantum TF card.
[0103] Calculate the time difference hash value ,in The hash algorithm chosen is SHA-256, representing the time difference between two adjacent sessions; the original feature matrix associated with the key is... Perform principal component analysis (PCA) to extract core numerical features. Construct a dynamic coding algorithm selection mechanism ,Will and Input parameter substitution mechanism This enables dynamic matching of the session identifier generation algorithm, making the generation process resistant to analysis and cracking.
[0104] Step 2: Binding User Identity and Terminal Device
[0105] The hardware and software of the SPHINCS-256 quantum-resistant cryptographic algorithm were upgraded on the security chip SE built into the terminal device, and PQC asymmetric key pairs were generated through the security chip SE. ;PQC private key The PQC public key is stored internally in the security chip (SE) using hardware encryption. The parameters to be uploaded are stored locally on the terminal.
[0106] Users submit identity registration information through terminal devices. , Using quantum key distribution right Perform encryption operations The encrypted registration information is then transmitted to the government authentication center server.
[0107] Generate an identity device binding request:
[0108] ,in The hash value of the user's ID number. The SE (Security Component) is the unique device identifier for the security chip.
[0109] Using the SM2 elliptic curve signature algorithm, through right Perform signature calculation ,Will and After splicing ( Upload to the government certification center server.
[0110] The government authentication center server verifies the user's real identity, Verification of reuse and batch validity is conducted, with a verification cycle of... If the verification is successful, proceed to step 3; if the verification fails, a login prohibition command will be sent to the terminal.
[0111] Step 3: The user logs into the government affairs metaverse client using their terminal device and establishes a session request.
[0112] Users wearing VR headsets or other immersive government service terminals access the government service metaverse client and upload their user identity hash value to the government service authentication center server. Unique Identifier for Security Chip (SE) Initiate an identity authentication request.
[0113] The government authentication center server generates random numbers based on the ChaCha20 stream encryption algorithm. , To create a truly random seed for the server, construct a random challenge. ,in To generate a timestamp for the challenge, effectively verify the duration. ;Will Distribute to user terminals.
[0114] The user terminal reads the quantum key from the quantum TF card. The HMAC-SHA256 algorithm is used to... Perform message authentication code calculation and generate the calculation result. .
[0115] Users unlock the security chip SE by entering a PIN code or biometric information; the chip then calls its built-in... ,right Perform SPHINCS-256 quantum-resistant signature operations to generate signature results. .
[0116] The user terminal will and splicing into response results The data is then uploaded to the government certification center server; the server retrieves the pre-stored data. Perform signature verification If the verification fails, the terminal is prohibited from logging in; if the verification succeeds, the terminal is allowed to initiate a session request and proceed to step 4.
[0117] Step 4: Session Key Issuance
[0118] The user terminal initiates a session key distribution request to the quantum distribution network node / quantum cryptography resource pool, and the node / resource pool generates the session key in real time. , The key length is 256 bits; quantum key distribution is used. right Implement encryption protection and ciphertext The data is simultaneously distributed to user terminals and the government authentication center server.
[0119] User terminal through Match the corresponding quantum key in the quantum TF card , for ciphertext Perform decryption operation Obtain the session key After decryption, immediately send a quantum key destruction command to each storage module of the terminal. Thoroughly clean the inside of the device .
[0120] Quantum key server generates random data User terminal generates random data Both parties used the SHA-512 hash algorithm to generate encrypted hash digests. , They also exchange digest values bidirectionally; and establish a mutual verification mechanism. The credibility and non-repudiation of the key destruction process are verified by digest comparison.
[0121] Step 5: End the session and destroy the key.
[0122] The user terminal establishes a communication link with the government metaverse system to perform business data interaction and transmission. The original transmitted data is denoted as... .
[0123] Employing the SM4 block cipher algorithm with a session key For encryption keys, the original data Perform encryption operations Only ciphertext is transmitted in the communication link. This ensures the confidentiality of data transmission.
[0124] After the session terminates, the authentication layer key can be activated to verify the destruction protocol; the user terminal and the government metaverse system respectively verify the key. Perform the SHA-3 hash algorithm to generate a bidirectional hash digest. , ;right and A consistency check is performed. If the check passes, both parties simultaneously execute the key destruction command. Completely remove from devices and servers This eliminates the risk of key residue.
[0125] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A quantum encryption-based meta-universe terminal identity authentication method, characterized in that, Includes the following steps: S1, quantum TF card offline quantum key filling and get the corresponding index , quantum key Multi-point secure storage, record filling timestamp and index and filling timestamp encrypted storage in quantum TF card; S2. Adapt the PQC algorithm to the security chip SE of the terminal device and generate a PQC key pair. Encrypt and store the PQC private key in the security chip SE. User identity information is encrypted and uploaded to the government authentication center server. A binding request containing user, device, and key information is generated, signed, and uploaded. Once the government authentication center server verifies the request, a strong binding relationship is established between the two. If the verification fails, login is prohibited. S3. The user initiates an authentication request to the government authentication center server through the terminal device, receives the random challenge generated by the server and performs HMAC operation, unlocks the security chip SE, performs PQC signature on the operation result and uploads it for verification. If the verification is successful, the session request is allowed to be established; if the verification fails, the login is prohibited. S4, the terminal equipment requests the quantum distribution network node or the quantum cryptography resource pool to issue a session key , the session key After the quantum key is encrypted, it is synchronized and issued to the terminal equipment and the government authentication center server, and the terminal equipment decrypts to obtain the session key Destroy the locally stored quantum key ; S5, the terminal device and the government affair meta-universe system pass the session key through the session key encrypted transmission data, after the session ends, the session key is destroyed through a verifiable key destruction protocol completely destroyed.
2. The quantum encryption-based meta-universe terminal identity authentication method according to claim 1, characterized in that, S1 specifically refers to: S101. Users use quantum TF cards to offline refill the keys cached in the quantum distribution network node / quantum cryptographic resource pool at the key refilling machine to obtain quantum keys. and its corresponding key index number The quantum TF card supports the SM4 algorithm and has a key length of 128 bits. It is a 32-bit unsigned integer; S102, Transfer the quantum key The quantum cryptography resource is stored in the quantum distribution network node / quantum cryptography resource pool, the government authentication center server, and the quantum TF card, and the filling timestamp is recorded. The timestamp adopts the Unix timestamp format. S103, Transfer the quantum key Key index number The filling timestamp is stored in the quantum TF card, and the storage method is encrypted storage, using the AES-256 encryption algorithm; S104. By combining time difference hash value with digital feature extraction, a dynamic and variable encoding algorithm selection mechanism is constructed to make the session identifier generation process resistant to analysis and cracking. The time difference hash value adopts the SHA-256 algorithm, and the digital features are extracted using the PCA principal component analysis algorithm.
3. The metaverse terminal identity authentication method based on quantum encryption according to claim 1, characterized in that, S2 specifically refers to: S201. Upgrade the PQC algorithm hardware and software using the existing security chip SE on the terminal device, generate a PQC key pair, and transfer the PQC private key. The PQC public key is encrypted and stored in the secure chip SE. Preparing to upload to the government certification center, the PQC algorithm to be selected is the SPHINCS-256 algorithm; S202. Users register their identity through terminal devices. The registration information is transmitted to the government authentication center server through quantum key encryption. The registration information includes name, ID number, contact number, etc. S203, Generate a hash containing the user's ID card number. ,chip , , The request is bound to a timestamp and uses a PQC private key. After signing the request, it is uploaded to the government authentication center server. The signing algorithm is SM2. S204, The government authentication center server verifies the user's identity. The system verifies the reuse status and batch validity. If the verification passes, the user is allowed to enter S3; otherwise, login is prohibited. The verification period is 30 days.
4. The metaverse terminal identity authentication method based on quantum encryption according to claim 1, characterized in that, S3 specifically refers to: S301. Users wearing VR headsets or other immersive government service terminals enter the government service metaverse client and send a message to the authentication center server. and chips ; S302. The government authentication center server generates a random challenge, which includes a random number, a timestamp, and a validity period. The random number generator uses the ChaCha20 algorithm, the timestamp uses the Unix timestamp format, and the validity period is 60 seconds. S303, The device reads the quantum key from the quantum TF card. Perform HMAC operation and generate the result. The HMAC algorithm used is SHA-256. S304. The user enters a PIN code or biometric signature to unlock the security chip SE. The security chip SE uses the PQC private key. Sign the calculation result; S305. The device sends the response result to the government authentication center server. The authentication center server uses the pre-registered PQC public key. Verification is performed; if verification fails, login is denied; if verification succeeds, a session request is allowed to enter S4.
5. The metaverse terminal identity authentication method based on quantum encryption according to claim 4, characterized in that, S4 includes the following steps: S401. The user equipment terminal requests the quantum distribution network node / quantum cryptographic resource pool to issue the session key generated in real time. Quantum keys are used for device terminals and government authentication center servers. right Encryption protection is implemented during distribution. The key length is 256 bits; S402, Equipment according to Find the corresponding one in the quantum TF card. Decryption and immediately destroy the relevant equipment. Key; S403. By bidirectionally generating and exchanging encrypted hash digests between the quantum key server and external devices, a mutually verifiable key destruction mechanism is constructed to ensure the credibility and non-repudiation of the key destruction process. The hash algorithm selected is SHA-512.
6. The metaverse terminal identity authentication method based on quantum encryption according to claim 1, characterized in that, S5 includes the following steps: S501, user equipment and systems in the government metaverse transmit data; S502, Communication data uses a key Encrypt the transmission; S503. When the session ends, the key is cleared by comparing the bidirectional hash digest through the verifiable destruction protocol of the verification layer key, thus fundamentally eliminating the risk of key residue after the session ends. The hash algorithm selected is SHA-3.
7. A metaverse terminal identity authentication device based on quantum encryption, characterized in that, include: The quantum key injection module is used to inject quantum keys offline into quantum TF cards. And obtain the corresponding index. Quantum key Perform multi-point secure storage, record and inject timestamps, and index them. The timestamp of the filling is encrypted and stored in the quantum TF card; The identity device binding module is used to adapt the PQC algorithm to the security chip SE of the terminal device and generate a PQC key pair, and to encrypt and store the PQC private key in the security chip SE. After encrypting the user's identity information, it is uploaded to the government authentication center server. A binding request containing information related to the user, device, and key is generated, signed, and uploaded. The verification result is received from the government authentication center server. If the verification is successful, a strong binding relationship between the user's identity and the terminal device is established. If the verification fails, the user is prohibited from logging in. The authentication session establishment module is used to receive authentication requests initiated by users through terminal devices, forward the requests to the government authentication center server, receive random challenges generated by the server and perform HMAC operations, unlock the security chip SE, perform PQC signature on the operation results and upload them to the server for verification, receive the verification results, and allow the session establishment request if the verification is successful, and prohibit login if the verification fails. The session key distribution module is used to request session keys from quantum distribution network nodes / quantum cryptographic resource pools. Receive via quantum key Encrypted session key It also synchronizes with the terminal device and the government authentication center server, controlling the terminal device to decrypt and obtain the session key. Then destroy the locally stored quantum key. ; The data transmission and key destruction module is used to control the communication between terminal devices and the government metaverse system via session keys. Data is transmitted in encrypted form, and the session key is destroyed via a verifiable key destruction protocol after the session ends. Completely destroy.
8. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions, which, when called and executed by the processor, implement the metaverse terminal identity authentication method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the metaverse terminal identity authentication method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the metaverse terminal identity authentication method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Metacosm identity authentication method, apparatus and device, and storage medium
CN116186656A
Identity authentication method and device based on element universe and medium
CN121356813A