Certificate-Based Security Using Post-Quantum Cryptography

The hybrid handshake protocol combines conventional and post-quantum cryptography certificates to establish a secure communication link resistant to quantum computer attacks, addressing the vulnerability of existing cryptographic methods.

JP7695021B2Active Publication Date: 2025-06-18INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023525111
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-11-02
Filing Date
2021-10-28
Publication Date
2025-06-18
Estimated Expiration
2041-10-28

AI Technical Summary

Technical Problem

Conventional cryptographic algorithms such as RSA and ECC are vulnerable to being broken by large-scale quantum computers, posing a risk to the security of current encrypted communication and data storage systems.

Method used

A hybrid handshake protocol that uses two certificates cryptographically bound to each other: a conventional cryptographic method (TC) certificate and a lattice-based post-quantum cryptography (PQC) certificate, ensuring secure communication by requiring PQC verification data to be authenticated before TC verification data.

Benefits of technology

The hybrid protocol establishes a secure communication link resistant to quantum computer attacks, ensuring backward compatibility with existing protocols and protecting against malicious attempts to break either the PQC or TC methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007695021000001
    Figure 0007695021000001
  • Figure 0007695021000002
    Figure 0007695021000002
  • Figure 0007695021000003
    Figure 0007695021000003
Patent Text Reader

Abstract

Establish secure communication by sending a server certificate message, the certificate message including a first certificate associated with a first encryption algorithm and a second certificate associated with a second encryption algorithm, the first certificate and the second certificate being bound to each other; signing a first message associated with the client-server communication using a first private key associated with the first certificate; and signing a second message associated with the client-server communication using a second private key associated with the second certificate, the second message including the signed first message; and sending a server certificate verification message including the signed first message and the signed second message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to the establishment of secure network communications. In particular, this disclosure relates to a communications handshake that uses a combination of multiple certificates and encryption algorithms.

Background Art

[0002] The emergence of large-scale quantum computing systems has raised the possibility that the use of Shor's algorithm and such quantum devices could endanger conventional cryptographic algorithms such as RSA (Rivest-Shamir-Adleman), elliptic curve cryptography (ECC), or similar technologies. Furthermore, such means of endangering conventional cryptographic algorithms are currently unusable, but if such systems become available, the security of current encrypted communication and data storage systems will be at risk. When conventional cryptographic methods become insufficient, security protocols are needed to protect communication and data both now and in the future. Legacy communication and data storage protocols must be enhanced to provide this additional protection without disrupting current protocols.

Summary of the Invention

[0003] A summary is presented below to provide a basic understanding of one or more embodiments of the present disclosure. This summary is not intended to identify key or important elements, nor to define the scope of any particular embodiment or the scope of any claims. Its sole purpose is to present concepts in a simplified form as a prelude to the more detailed description that follows. In one or more embodiments described herein, a device, system, computer-implemented method, apparatus, or computer program product, or a combination thereof, enables the establishment of a secure network communication channel using certificates.

[0004] Aspects of the present invention include transmitting a server certificate message, where the certificate message includes a first certificate associated with a first encryption algorithm and a second certificate associated with a second encryption algorithm, and the first certificate and the second certificate are bound to each other; signing a first message associated with client-server communication using a first private key associated with the first certificate; signing a second message associated with client-server communication using a second private key associated with the second certificate, where the second message includes the signed first message; and transmitting a server certificate verification message including the signed first message and the signed second message, which are associated with establishing secure communication. The present invention discloses a method, a system, and a computer-readable medium related thereto.

[0005] Through a more detailed description of some embodiments of the present disclosure in the accompanying drawings, the above and other objects, features, and advantages of the present disclosure will become more apparent. The same reference numerals generally refer to the same components in the embodiments of the present disclosure.

Brief Description of the Drawings

[0006]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Modes for Carrying Out the Invention

[0007] Some embodiments will be described in more detail with reference to the accompanying drawings that illustrate embodiments of the present disclosure. However, the present disclosure can be implemented in various ways and should not be construed as limited to the embodiments disclosed herein.

[0008] In one embodiment, one or more components of a system can use hardware and / or software, or both, to solve problems of a highly technical nature (e.g., communication protocols, sending and receiving messages, verifying the identity of entities, authenticating digital certificates, authenticating digital signatures, etc.). These solutions are not abstract and cannot be performed as a series of mental activities by a human, for example, due to the processing power required to facilitate the establishment of a secure client-server communication link. Further, some of the processes performed can be executed by a dedicated computer to perform the specified tasks related to securing communications. For example, a dedicated computer can be used to perform tasks related to communication security handshake protocols and the like.

[0009] Aspects of the present invention relate to establishing secure communication by receiving a client hello message from a client device, sending a server hello message, sending a server certificate message, where the certificate message includes a first certificate associated with a first encryption algorithm and a second certificate associated with a second encryption algorithm, the first certificate and the second certificate being bound to each other, signing a first message associated with client-server communication using a first private key associated with the first certificate, signing a second message associated with client-server communication using a second private key associated with the second certificate, where the second message includes the signed first message, sending a server certificate verification message including the signed first message and the signed second message, receiving a client certificate message in response to the server hello message by one or more server computer processors, where the client certificate message includes a third certificate associated with the first encryption algorithm and a fourth certificate associated with the second encryption algorithm, the third certificate and the fourth certificate being bound to each other, receiving a client certificate verification message by one or more server computer processors, where the client certificate verification message includes a third message associated with client-server communication signed using a third private key associated with the third certificate and a fourth message associated with client-server communication signed using a fourth private key associated with the fourth certificate, the fourth message including the third message, receiving a client completion message from the client device, and sending a server completion message in response to receiving the client completion message, and disclose a method, system, and computer-readable medium related thereto.

[0010] The disclosed embodiments provide the advantage of linking two certificates, one based on a conventional cryptographic method and one based on a lattice or post-quantum cryptography (PQC) method, in a way that guarantees a secure communication link established through the two certificates as long as both the PQC method and the TC method are not broken by malicious actors.

[0011] Conventional cryptographic methods (TC) based on RSA or ECC are vulnerable to being broken by the use of large-scale quantum computers. RSA and ECC are based on the use of large prime numbers that are multiplied together to produce a result. A large-scale quantum computer using Shor's algorithm could easily invalidate encryption algorithms based on the use of factors, such as RSA or ECC.

[0012] Internet communication between computing entities involves an initial "handshake" between the entities. The initial unencrypted communication of the entities takes place during the handshake that introduces the entities to each other. Through the handshake, the entities exchange unencrypted information necessary to establish the attributes of subsequent communication. The attributes include the exchange of information necessary to establish the encryption protocol used for encrypting and decrypting data, as well as the exchange of information necessary for the entities to verify each other's identities, including public keys.

[0013] Common communication handshakes, such as the Transport Layer Security (TLS) handshake, rely on public key certificates, such as x.509 certificates, that are authenticated by secure digital signatures based on RSA, ECC, or similar conventional factor-based cryptographic public key infrastructures. There is a risk that a malicious actor could access the handshake communication, break the TC of one of the parties, and then impersonate that party using a forged private key.

[0014] Lattice-based encryption algorithms use a pair of public and private keys generated using lattice or array-based mathematical techniques. Such algorithms are considered to be resistant to being broken by the use of quantum computers. Such algorithms are regarded as post-quantum cryptography (PQC) algorithms.

[0015] Since the legacy TLS protocol is based on the use of TC, simply replacing TC with PQC may cause backward compatibility problems in global Internet communications. A backward-compatible communication link protocol that is resistant to being broken by the use of quantum computers is needed. The disclosed method prevents this by using two certificates that are cryptographically bound to each other, namely, a TC factor-based certificate and a PQC lattice-based certificate. Each of the two certificates is issued by a certification authority (CA) trusted by the entity. Malicious actors cannot break lattice-based encryption with a quantum computer. A hybrid handshake protocol based on a combination of TC certificates cryptographically bound to PQC certificates enables the establishment of communication links between networked entities in a post-quantum world.

[0016] In the term TLS, each of the server's certificate and the certificate verification message contains two sets of certificate chains and two sets of verification data, respectively. The message is composed of two messages, each of which simplifies processing and enables the use of current TLS message processing logic. The disclosed embodiments enable secure communication by requiring that the PQC verification data be authenticated before the TC verification data can be authenticated. PQC must be broken before TC can be attacked. Malicious actors must break both PQC and TC in order to succeed in attacking the communication link.

[0017] The TLS handshake begins with the client device sending a client hello message to the server. The handshake proceeds with the server responding to the client hello message by sending a server hello message. The exchange of hello messages includes the negotiation of the encryption protocol to be used, as well as the exchange of random numbers generated by the client and server to be used for the subsequent encrypted data exchange. As an example, the client hello message includes the version of TLS used by the client, the compression method to be used, the options for the cipher suites supported by the client for the communication, and a random string to be used for the encrypted data exchange. The client hello message can include one or more extensions, such as encryption extensions for encrypting the TLS handshake data according to the hello message. The server hello message can include the server's selection of a cipher suite from the provided options, and a different random number to be used for the encryption of the communication.

[0018] Thereafter, the server sends a TLS certificate message to the client. The TLS certificate message includes two certificate chains embedded in the message, one certificate chain is based on TC and one certificate chain is based on PQC. Each of the two certificate chains can include a series of certificates starting from the server's end-entity certificate including one or more intermediate certificates and ending with a root certificate. The root certificate is issued and signed by a certificate authority trusted by the entity. In one embodiment, each of the certificate chains includes a single certificate.

[0019] Upon receiving the server certificate message, the client device decrypts the two certificate chains and authenticates each certificate chain independently. The client verifies that the expiration date of each certificate in each of the two certificate chains has not passed, or that each certificate has not been revoked, that the domain name of the certificate matches the domain of the server, that the digital signature of each certificate in each chain is valid, and that the root certificate of each chain was issued by a CA trusted by the client.

[0020] In one embodiment, the client authenticates the signature of the server's end-entity certificate using the public key of the CA. In one embodiment, the client authenticates the signature of the end-entity certificate using the public key from the intermediate certificate and authenticates the signature of the root certificate and the signature of the intermediate certificate using the public key of the CA root certificate.

[0021] In the case of the TC certificate chain, the public key and digital signature are based on a pair of TC public and private keys. In the case of the PQC certificate chain, the signature and public key are based on a pair of public and private keys derived using a PQC algorithm.

[0022] PQC algorithms include lattice-based encryption methods including CRYSTALS-DILITHIUM, FALCON, RAINBOW, CLASSIC McELIECE, CRYSTALS-KYBER, NTRU, SABER, and other lattice-based algorithms. (Note: The terms "CRYSTALS-DILITHIUM", "FALCON", "RAINBOW", "CLASSIC McELIECE", "CRYSTALS-KYBER", "NTRU", and "SABER" may be the subject of trademark rights in various jurisdictions around the world and are used herein only with respect to the products or services properly indicated by such trademarks to the extent that such trademark rights may exist.)

[0023] In one embodiment, the server creates a certificate verification message for the client. The certificate verification message helps prove that the server owns the PQC private key and the TC private key associated with each of the PQC certificate and the TC certificate. The certificate verification message includes two messages. The first message includes the current transcript of the messages exchanged so far between the client and the server, and this transcript is signed using the server's PQC private key. The second message includes the current transcript of the exchanged messages with the first message added by the server, and the added transcript is signed using the server's TC private key that generates a conventional server certificate verification message. The server combines the first certificate verification message and the second certificate verification message and sends the combination to the client as a single certificate verification message.

[0024] The client receives the combined certificate verification message and separates the two messages. The client owns the current messaging transcript and the server's PQC public key from the process of authenticating the server's PQC certificate. The client uses the current messaging transcript and the server's PQC public key to verify the PQC digital signature of the PQC certificate verification part of the server certificate verification message. The client uses the message transcript including the signed first message content provided in the PQC part of the combined server certificate verification message to verify the TC signature of the TC part of the combined server certificate message. The client uses the added messaging transcript and the server's TC public key obtained during the process of authenticating the server's TC certificate.

[0025] In one embodiment, the method further binds a TC certificate and a PQC certificate. The method creates a PQC certificate and a TC certificate having the same subject name, issuer name, and subject alternative name. The method sets the TC constraints to be the same as the PQC constraints, except for the serial number of the public key and the signatures of the two certificates. In this embodiment, the method sets the serial number or extension of the TC to be equal to the hash (SHA1, SHA256, or other hash function) of the PQC certificate data. The binding value set as the output of the hash function cannot be broken using a large-scale quantum computer or a conventional non-quantum computer. In this embodiment, the client authenticates that the TC serial number or extension contains the hash of the PQC certificate data at the time of use, and that all other TC certificate data attributes and PQC certificate data attributes match.

[0026] In one embodiment, mutual entity authentication is desirable as indicated by a certificate request message sent from a server to a client. In response to the certificate request message, the client sends a certificate message including each of the client's TC certificate and PQC certificate. The client then generates and sends a combined certificate verification message. This includes creating a first certificate verification message by signing the current message transcript using the client's PQC private key, then adding the first certificate verification message to the current messaging transcript, and signing the added transcript using the client's TC private key.

[0027] In one embodiment, the exchange of client hello messages and server hello messages does not lead to the use of PQC certificates. This is because the client does not support their use. In this embodiment, the method passes only the TC certificate and the TC certificate verification part of the message. In this embodiment, the method provides backward compatibility during any period in which not all network entities have migrated to the use of PQC-based protocols.

[0028] Figure 1 is a schematic diagram of exemplary network resources associated with implementing the disclosed invention. The present invention may be implemented in any processor of the disclosed elements that processes an instruction stream. As shown, networked client device 110 wirelessly connects to server subsystem 102. Client device 104 wirelessly connects to server subsystem 102 via network 114. Client devices 104, 110 include a communication security program (not shown) along with sufficient computing resources (processor, memory, network communication hardware) to execute the program. The communication handshake between client devices 104, 110 and server subsystem 102 can include the use of the disclosed embodiments to enable secure communication between verified entities and the exchange of encrypted data. As shown in FIG. 1, server subsystem 102 includes server computer 150. FIG. 1 is a block diagram of the components of server computer 150 within networked computer system 1000 according to an embodiment of the present invention. It should be understood that FIG. 1 simply provides an illustration of one implementation form and does not imply any limitation regarding the environment in which different embodiments can be implemented. Many changes can be made to the illustrated environment.

[0029] Server computer 150 can include a processor 154, a memory 158, a persistent storage 170, a communication unit 152, an input / output (I / O) interface 156, and a communication fabric 140. Communication fabric 140 provides communication among cache 162, memory 158, persistent storage 170, communication unit 152, and input / output (I / O) interface 156. Communication fabric 140 may be implemented in any architecture designed to pass data or control information or both among processors (such as microprocessors, communication and network processors, etc.), system memory, peripheral devices, and any other hardware components within the system. For example, communication fabric 140 may be implemented with one or more buses.

[0030] Memory 158 and persistent storage 170 are computer-readable storage media. In this embodiment, memory 158 includes random access memory (RAM) 160. Generally, memory 158 can include any suitable volatile or non-volatile computer-readable storage media. Cache 162 is a high-speed memory that improves the performance of processor 154 by holding recently accessed data and data near recently accessed data from memory 158.

[0031] Program instructions and data used to implement embodiments of the present invention, for example, communication security program 175, are stored in persistent storage 170 for execution by, access to, or both, one or more of the respective processors 154 of server computer 150 via cache 162. In this embodiment, persistent storage 170 includes a magnetic hard disk drive. Instead of or in addition to the magnetic hard disk drive, persistent storage 170 can include a solid state hard drive, a semiconductor storage device, a read only memory (ROM), an erasable programmable read only memory (EPROM), a flash memory, or any other computer readable storage medium capable of storing program instructions or digital information.

[0032] The medium used by persistent storage 170 may be removable. For example, a removable hard drive can be used for persistent storage 170. Other examples include optical disks and magnetic disks, thumb drives, and smart cards that are inserted into a drive for transfer to another computer readable storage medium that is also part of persistent storage 170.

[0033] In these examples, communication unit 152 provides communication with other data processing systems or devices including the resources of client computing devices 104, 110. In these examples, communication unit 152 includes one or more network interface cards. Communication unit 152 can provide communication using either or both physical and wireless communication links. Software distribution programs and other programs and data used in implementations of the present invention can be downloaded through communication unit 152 to persistent storage 170 of server computer 150.

[0034] The I / O interface 156 enables the input and output of data with other devices that can be connected to the server computer 150. For example, the I / O interface 156 can provide a connection to an external device 190 such as a keyboard, keypad, touch screen, microphone, digital camera, or other suitable input device, or a combination thereof. The external device 190 can include, for example, a portable computer-readable storage medium such as a thumb drive, portable optical or magnetic disk, and memory card. Software and data used to implement embodiments of the present invention, such as the communication security program 175 of the server computer 150, can be stored on such a portable computer-readable storage medium and loaded into the persistent storage 170 via the I / O interface 156. The I / O interface 156 is also connected to a display 180.

[0035] The display 180 provides a mechanism for displaying data to the user and can be, for example, a computer monitor. The display 180 can also function as a touch screen, such as the display of a tablet computer.

[0036] Figure 2 is a flowchart 200 showing exemplary operations associated with the implementation of the present disclosure. After the program starts, at block 210, the server's communication security program 175 receives a client hello message that includes client information regarding the supported TLS protocol, options for the cipher suite, and a random number generated by the client.

[0037] At block 220, the server transmits a server hello message that indicates the server's selection of a cipher suite from the provided options and includes a random number generated by the server.

[0038] At block 230, the server sends a server certificate message. The server certificate message includes two certificates or certificate chains. The certificate or certificate chain includes a first certificate or certificate chain signed using a first digital signature associated with a first server private key from a PQC algorithm, and a second certificate or certificate chain signed using a second digital signature associated with a second server private key from a TC encryption algorithm.

[0039] At block 240, the server's communication security program 175 signs a first message using the first server PQC private key. The first message includes a transcript of client-server messaging.

[0040] At block 250, the server's communication security program 175 signs a second message using the second server TC private key. The second message includes the current client-server messaging transcript with the first message appended.

[0041] At block 260, the server's communication security program 175 combines the first message and the second message into a single server certificate verification message and sends the combined message to the client.

[0042] At block 270, the communication security program 175 receives a client completion message from the client. The client completion message includes the cryptographic hash of all previous client-server messaging encrypted using the agreed-upon encryption algorithm.

[0043] At block 280, the communication security program 175 sends a server completion message that includes the cryptographic hash of all previous client-server messaging traffic from the handshake protocol.

[0044] It should be understood that the TLS handshake protocol can include additional messages between the client and the server related to the exchange of information necessary to generate encryption / decryption keys for data and for other purposes.

[0045] Schematic diagram 300 of FIG. 3 shows messaging traffic between client 310 and server 320 according to an embodiment of the present invention. As shown, client 310 sends a client hello message 315 to server 320. Server 320 responds by sending a server hello message 325, a server certificate message 330, and a server certificate verification message 340. Each of the server certificate message 330 and the server certificate verification message 340 includes two separate messages. The server certificate message 330 includes a server PQC certificate message 332 and a server TC certificate message 334. The server certificate verification message 340 includes a first message 342 that includes a messaging transcript signed using the server PQC private key, and the second message 344 includes a messaging transcript to which the first message is added and that is signed using the server TC private key.

[0046] Figure 3 includes messages associated with mutual authentication, including client certificate message 360 and client certificate verification message 370. Similar to the server, client certificate message 360 includes two messages, namely, client PQC certificate message 362 and client TC certificate message 364. Client certificate verification message 370 also includes two messages. One message 372 includes a messaging transcript, signed using the client's PQC private key, and the other message 374 includes a messaging transcript added to include a message signed using the client's PQC private key, and this message is signed using the client's TC private key. Item 380 generally indicates additional client-server messaging traffic related to the communication handshake between the client and the server, including client completion messages and server completion messages.

[0047] This disclosure includes a detailed description of cloud computing, but it should be understood that the implementation of the teachings described herein is not limited to a cloud computing environment. Rather, embodiments of the present invention can be implemented with any other type of computing environment that is currently known or developed in the future.

[0048] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model can include at least five characteristics, at least three service models, and at least four deployment models.

[0049] The characteristics are as follows.

[0050] On - demand self - service: Cloud consumers can provision computing capabilities such as server time and network storage automatically as needed, without the need for human interaction with the service provider.

[0051] Broad network access: The capabilities are available over a network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0052] Resource pooling: To accommodate multiple consumers using a multi - tenant model, the provider's computing resources are pooled, and different physical and virtual resources are dynamically assigned and re - assigned as required. Consumers generally have a sense of location independence in that they cannot control or know the exact location of the resources provided, but can specify a location at a higher level of abstraction (e.g., country, state, or data center).

[0053] Rapid elasticity: The capabilities can be provisioned quickly and elastically, and in some cases automatically, to scale out rapidly and released quickly to scale in. To the consumer, the capabilities available for provisioning often appear to be unlimited, and any amount can be purchased at any time.

[0054] Measured service: The cloud system automatically controls and optimizes resource use by leveraging some form of metering capability appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts) at some level of abstraction. It can monitor, control, and report resource usage, providing transparency to both the provider and consumer of the utilized service.

[0055] The service model is as follows.

[0056] Software as a Service (SaaS): The functionality provided to consumers is to use the provider's applications that run on cloud infrastructure. The applications are accessible from various client devices through a thin-client interface such as a web browser (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or individual application functionality, except for limited user-specific application configurations.

[0057] Platform as a Service (PaaS): The functionality provided to consumers is to deploy consumer-created or consumer-acquired applications created using programming languages and tools supported by the provider on cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, or storage, but can control the deployed applications and, in some cases, the application-hosting environment configuration.

[0058] Infrastructure as a Service (IaaS): The functionality provided to consumers is to provision processing, storage, network, and other basic computing resources, and consumers can deploy and run any software that may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but can control the operating system, storage, deployed applications, and, in some cases, perform limited control of selected networking components (e.g., host firewalls).

[0059] The deployment models are as follows.

[0060] Private cloud: This cloud infrastructure is operated only for an organization. It may be managed by the organization or a third party and may exist on-premises or off-premises.

[0061] Community cloud: This cloud infrastructure is shared by several organizations and supports a specific community with common concerns (e.g., missions, security requirements, policies, and compliance matters). It may be managed by the organization or a third party and may exist on-premises or off-premises.

[0062] Public cloud: This cloud infrastructure can be used by the general public or large industry groups and is owned by an organization that sells cloud services.

[0063] Hybrid cloud: This cloud infrastructure is a composite of two or more clouds (private, community, or public), and those clouds remain distinct entities but are joined together by standardized or proprietary technologies (e.g., cloud bursting for load balancing between clouds) that enable data and application portability.

[0064] Cloud computing environments are service-oriented, focusing on statelessness, loose coupling, modularity, and semantic interoperability. At the core of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0065] Next, referring to FIG. 4, an exemplary cloud computing environment 50 is shown. As illustrated, cloud computing environment 50 includes one or more cloud computing nodes 10 that can communicate with a local computing device used by a cloud consumer, such as, for example, a personal digital assistant (PDA) or cellular phone 54A, a desktop computer 54B, a laptop computer 54C, or an automotive computer system 54N, or a combination thereof. The nodes 10 can communicate with each other. The nodes 10 can be physically or virtually grouped (not shown) in one or more networks, such as the private cloud, community cloud, public cloud, or hybrid cloud, or a combination thereof, described above. Thereby, cloud computing environment 50 can provide infrastructure, platform, or software, or a combination thereof, as a service such that a cloud consumer need not maintain resources on a local computing device therefor. The types of computing devices 54A - 54N shown in FIG. 4 are merely exemplary, and it is understood that cloud computing nodes 10 and cloud computing environment 50 can communicate with any type of computerized device via any type of network or network addressable connection (e.g., using a web browser) or both.

[0066] Next, referring to FIG. 5, a set of functional abstraction layers provided by cloud computing environment 50 (FIG. 4) is shown. It should be understood in advance that the components, layers, and functions shown in FIG. 5 are merely exemplary and that embodiments of the present invention are not limited thereto. As illustrated, the following layers and corresponding functions are provided.

[0067] The hardware and software layer 60 includes hardware components and software components. Examples of hardware components include mainframe 61, reduced instruction set computer (RISC) architecture-based server 62, server 63, blade server 64, storage device 65, and network and networking components 66. In some embodiments, examples of software components include network application server software 67 and database software 68.

[0068] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 71, virtual storage 72, virtual network 73 including a virtual private network, virtual applications and operating systems 74, and virtual clients 75.

[0069] In one example, the management layer 80 can provide the following functions. Resource provisioning 81 performs dynamic procurement of computing resources and other resources used to execute tasks within a cloud computing environment. Metering and pricing 82 performs cost tracking when resources are utilized within a cloud computing environment and issues invoices or processes invoices for consumption of these resources. In one example, these resources can include application software licenses. Security performs authentication of cloud consumers and tasks and protection of data and other resources. The user portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 performs cloud computing resource allocation and management such that the required service levels are met. Planning and fulfillment of service level agreements (SLAs) 85 performs advance arrangement and procurement of cloud computing resources for which future requirements are predicted to comply with the SLA.

[0070] The workload layer 90 provides examples of functions that can utilize a cloud computing environment for that purpose. Examples of workloads and functions that can be provided from this layer include mapping and navigation 91, software development and lifecycle management 92, virtual classroom education delivery 93, data analysis processing 94, transaction processing 95, and communication security program 175.

[0071] The present invention may be a system, method, or computer program product, or a combination thereof, at any possible integrated technical detail level. The present invention may be advantageously implemented in any system (alone or in parallel) that processes an instruction stream. The computer program product may include one or more computer-readable storage media having computer-readable program instructions for causing a processor to execute aspects of the present invention.

[0072] A computer-readable storage medium may be a tangible device that can hold and store instructions for use by an instruction-executing device. The computer-readable storage medium may be, for example, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof, but is not limited thereto. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory sticks, floppy (R) disks, mechanically encoded devices such as punch cards or raised structures in grooves in which instructions are recorded, and any suitable combination thereof. As used herein, a computer-readable storage medium or computer-readable storage device should not be construed to be a transient signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through an electrical wire.

[0073] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or can be downloaded from an external computer or an external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network can include a copper transmission cable, an optical transmission fiber, a wireless transmission, a router, a firewall, a switch, a gateway computer, or an edge server, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers those computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.

[0074] The computer-readable program instructions for carrying out the operations of the present invention may be source code or object code written in any combination of one or more programming languages, including assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or object-oriented programming languages such as Smalltalk(R), C++, and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, in order to carry out aspects of the present invention, an electronic circuit, including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may execute the computer-readable program instructions by utilizing state information of the computer-readable program instructions to personalize the electronic circuit.

[0075] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0076] These computer-readable program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which are executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more blocks of the flowchart or block diagram or both. These computer-readable program instructions may be stored in a computer-readable storage medium that includes instructions for implementing the aspects of the functions / acts specified in one or more blocks of the flowchart or block diagram or both, such that the computer-readable storage medium forms a product including instructions that, when executed by a computer, programmable data processing apparatus, or other device, or a combination thereof, cause the device to function in a particular manner.

[0077] The computer-readable program instructions may be loaded onto a computer, other programmable apparatus, or other device to produce a process that is executed by the computer, other programmable data processing apparatus, or other device such that the instructions, when executed by the computer, other programmable apparatus, or other device, implement the functions / acts specified in one or more blocks of the flowchart or block diagram or both by causing a series of operational steps to be performed on the computer, other programmable apparatus, or other device.

[0078] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, segment, or portion of instructions that include one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions described in the blocks may occur out of the order described in the figures. For example, two blocks shown in succession may, in fact, be executed substantially simultaneously, or the blocks may sometimes be executed in the reverse order depending on the functions involved. It should also be noted that each block in the block diagram or flowchart diagram, or a combination of blocks in the block diagram or flowchart diagram or both, can be implemented by a dedicated hardware-based system that performs the specified function or operation, or a combination of dedicated hardware and computer instructions.

[0079] References to "one embodiment," "an embodiment," "exemplary embodiment," etc., in this specification indicate that the embodiment described may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes that particular feature, structure, or characteristic. Further, such expressions do not necessarily refer to the same embodiment. Moreover, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments, whether or not explicitly described.

[0080] The terms used in this specification are for the purpose of describing particular embodiments only and are not intended to limit the present invention. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. The terms "comprising" or "including" or both, as used herein, specify the presence of the stated function, integer, step, operation, element, or component, or a combination thereof, but do not preclude the presence or addition of one or more other functions, integers, steps, operations, elements, components, or groups thereof, or a combination thereof.

[0081] The description of various embodiments of the present disclosure is presented for purposes of illustration, but is not intended to be exhaustive or to limit the present invention to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the present invention. The terms used herein are chosen in order to best explain the principles of an embodiment, the practical application, or technical improvements in the marketplace as compared to the technology seen in the marketplace, or to enable others of ordinary skill in the art to understand the embodiments disclosed herein.

Claims

1. A computer-implemented method for establishing secure network communication, wherein one or more server computer processors transmit a server certificate message in response to a client hello message, the server certificate message including a first certificate associated with a first encryption algorithm and a second certificate associated with a second encryption algorithm, the first certificate and the second certificate being bound to each other, said transmitting; wherein the one or more server computer processors sign a first message associated with client-server communication using a first private key associated with the first certificate; wherein the one or more server computer processors sign a second message associated with the client-server communication using a second private key associated with the second certificate, the second message including the first message, said signing; wherein the one or more server computer processors transmit a server certificate verification message including the first message and the second message in response to receiving the client hello message; A computer-implemented method comprising:

2. The computer-implemented method according to claim 1, wherein the first encryption algorithm includes a lattice-based encryption algorithm.

3. The computer-implemented method according to claim 1 or 2, wherein the first message includes a transcript of client-server messaging.

4. The computer-implemented method according to any one of claims 1 to 3, wherein the first certificate and the second certificate have the same subject name.

5. The computer-implemented method according to any one of claims 1 to 4, wherein the attribute of the second certificate includes the hash value of the first certificate.

6. The computer-implemented method according to any one of claims 1 to 5, further comprising transmitting, by the one or more server computer processors, a server hello message in response to the client hello message.

7. Receiving, by the one or more server computer processors, a client certificate message in response to the server hello message, the client certificate message including a third certificate associated with the first encryption algorithm and a fourth certificate associated with the second encryption algorithm, the third certificate and the fourth certificate being bound to each other; Receiving, by the one or more server computer processors, a client certificate verification message, the client certificate verification message including a third message associated with the client-server communication signed using a third private key associated with the third certificate and a fourth message associated with the client-server communication signed using a fourth private key associated with the fourth certificate, the fourth message including the third message; The computer-implemented method according to claim 6, further comprising.

8. The method further comprising transmitting, by the one or more server computer processors, data encrypted using the first encryption algorithm. The computer-implemented method according to any one of claims 1 to 7.

9. A computer program for establishing secure network communication, Program instructions for sending a server certificate message in response to a client hello message, wherein the server certificate message includes a first certificate associated with a first encryption algorithm and a second certificate associated with a second encryption algorithm, and the first certificate and the second certificate are bound to each other, the program instructions, Program instructions for signing a first message associated with client-server communication using a first private key associated with the first certificate, Program instructions for signing a second message associated with the client-server communication using a second private key associated with the second certificate, wherein the second message includes the first message, the program instructions, Program instructions for sending a server certificate verification message including the first message and the second message in response to receipt of the client hello message A computer program comprising.

10. The computer program according to claim 9, wherein the first encryption algorithm includes a lattice-based encryption algorithm.

11. The computer program according to claim 9 or 10, wherein the first message includes a transcript of client-server messaging.

12. The computer program according to any one of claims 9 to 11, wherein the first certificate and the second certificate have the same subject name.

13. The computer program according to any one of claims 9 to 12, wherein the attributes of the second certificate include the hash value of the first certificate.

14. The computer program according to any one of claims 9 to 13, wherein the program instructions further include program instructions for sending a server hello message in response to the client hello message.

15. The program instructions Program instructions for receiving a client certificate message in response to the server hello message, wherein the client certificate message includes a third certificate associated with the first encryption algorithm and a fourth certificate associated with the second encryption algorithm, and the third certificate and the fourth certificate are bound to each other; the program instructions Program instructions for receiving a client certificate verification message, wherein the client certificate verification message includes a third message associated with client-server communication signed using a third private key associated with the third certificate and a fourth message associated with the client-server communication signed using a fourth private key associated with the fourth certificate, and the fourth message includes the third message; the program instructions The computer program according to claim 14, further comprising:

16. The computer program according to any one of claims 9 to 15, wherein the program instructions further include program instructions for sending data encrypted using the first encryption algorithm.

17. A computer system for establishing secure network communication, comprising: One or more computer processors; One or more computer-readable storage devices; Program instructions stored in the one or more computer-readable storage devices for execution by the one or more computer processors; and the stored program instructions being, program instructions for sending a server certificate message in response to a client hello message, the server certificate message including a first certificate associated with a first encryption algorithm and a second certificate associated with a second encryption algorithm, the first certificate and the second certificate being bound to each other, the program instructions, program instructions for signing a first message associated with client-server communication using a first private key associated with the first certificate, program instructions for signing a second message associated with the client-server communication using a second private key associated with the second certificate, the second message including the first message, the program instructions, program instructions for sending a server certificate verification message including the first message and the second message in response to receipt of the client hello message A computer system comprising.

18. The computer system according to claim 17, wherein the first encryption algorithm includes a lattice-based encryption algorithm.

19. The computer system according to claim 17 or 18, wherein the first message includes a transcript of client-server messaging.

20. The computer system according to any one of claims 17 to 19, wherein the first certificate and the second certificate have the same subject name.

21. The computer system according to any one of claims 17 to 20, wherein the attributes of the second certificate include a hash value of the first certificate.

22. The computer system according to any one of claims 17 to 21, wherein the stored program instructions further include program instructions for sending a server hello message in response to the client hello message.

23. The stored program instructions are program instructions for receiving a client certificate message in response to the server hello message, the client certificate message including a third certificate associated with the first encryption algorithm and a fourth certificate associated with the second encryption algorithm, the third certificate and the fourth certificate being bound to each other; and the program instructions program instructions for receiving a client certificate verification message, the client certificate verification message including a third message associated with client-server communication, signed using a third private key associated with the third certificate, and a fourth message associated with the client-server communication, signed using a fourth private key associated with the fourth certificate, the fourth message including the third message; and the program instructions The computer system according to claim 22, further comprising

Citation Information

Patent Citations

  • Using Digital Certificates with Multiple Cryptosystems

    JP2019509652A