Authentication method based on dual quantum random number protection, client, and system

Through the dual quantum random number protection method, the client and the authentication side obtain the quantum random number respectively and fuse the encrypted certificate private key information, solving the confidentiality and monitoring problems of traditional authentication solutions and realizing a high-security authentication process.

WO2025148510A1PCT designated stage expired Publication Date: 2025-07-17CHINA TELECOM QUANTUM TECH CO LTD

Patent Information

Application Number
PCT/CN2024/131636
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-11
Filing Date
2024-11-12
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Traditional authentication solutions cannot meet the user's high confidentiality requirements, user information is easily cracked and cannot self-identify whether it is monitored.

Method used

The dual quantum random number protection method is adopted, and the quantum random number is obtained by the client and the authentication end respectively and decrypted using the preset quantum random number protection factor. After fusing, it is used to encrypt the certificate private key information, generate an authentication request and send it to the authentication end for authentication.

Benefits of technology

It improves the confidentiality of the authentication process, increases the difficulty of attacks, and ensures the security of the quantum random number dispatching process and the physical non-listening nature of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024131636_17072025_PF_FP_ABST
    Figure CN2024131636_17072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses an authentication method based on dual quantum random number protection, a client, and a system. The method comprises: requesting a quantum random number from an authentication end and receiving a first quantum random number returned by the authentication end, wherein the first quantum random number is obtained by the authentication end applying for a quantum random number from a quantum random number distribution apparatus and decrypting same using a preset quantum random number protection factor; applying to the quantum random number distribution apparatus to obtain a quantum random number and decrypting same using a preset quantum random number protection factor, so as to obtain a second quantum random number; fusing the first quantum random number and the second quantum random number to obtain a third quantum random number; by using the third quantum random number and a cryptographic algorithm, encrypting read certificate private key information, so as to obtain an authentication request; and sending the authentication request to the authentication end for authentication. The present application can enhance the confidentiality of authentication processes.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication method, client and system based on double quantum random number protection

[0001] This application claims priority to a Chinese patent application filed with the Patent Office of China on January 11, 2024, with application number 202410046217.X and entitled “Authentication method, client and system based on double quantum random number protection,” the entire contents of which are incorporated herein by reference. Technical Field

[0002] The present application relates to the field of quantum communication technology, and in particular to an authentication method, client, and system based on double quantum random number protection. Background Art

[0003] With users' increasing demands for high data confidentiality and high data transmission rates, and the continuous development of quantum technology, traditional authentication solutions are unable to meet users' high confidentiality requirements. The main problems are as follows:

[0004] (1) User information is transparent or encrypted in a simple way during the authentication process, which makes it easy to crack and poses a security risk;

[0005] (2) Physically, traditional authentication processes cannot self-identify whether they are being monitored.

[0006] In related technologies, patent application publication number CN108173649A proposes that when two clients perform message authentication, a shared key seed is obtained through a quantum network service station on the network side. Message authentication code generation and comparative authentication are performed on the user side, ensuring the security of data transmission. Patent application publication number CN113852460A proposes that a secure access client and a secure access server conduct a session over an SSL VPN channel and synchronize working key parameter information. A working key is generated based on the working key parameter information and a preset key generation algorithm. The secure access client and the secure access server obtain a quantum key from a quantum key server based on a session identifier. The secure access client and the secure access server each perform a calculation on the working key and the quantum key using a preset fusion algorithm to obtain a new working key. The new working key is used for encrypted transmission of service data, and the security of the existing working key is enhanced by fusing the working key with the quantum key. Patent application publication number CN114268441A proposes that two clients use a preset key generation algorithm to generate a first shared key factor, and a second shared key factor based on a correlated XOR value provided by a server. The two key factors are then subjected to security enhancement to produce an encryption key. The encryption key is then used for data encryption communication, achieving a close integration of quantum key and internet encryption. Patent application publication number CN114584298A proposes using a handshake protocol to generate a first key factor; generating a second key factor based on a preset random number; enhancing the security of the two key factors to produce an encryption key; and using the encryption key to establish a quantum-secure SSL connection for secure data transmission.

[0007] Summary of the Invention

[0008] The technical problem to be solved by this application is how to improve the confidentiality of the authentication process.

[0009] This application solves the above technical problems through the following technical means:

[0010] In a first aspect, the present application proposes an authentication method based on double quantum random number protection, which is applied to a client and includes:

[0011] Requesting a quantum random number from an authentication terminal and receiving a first quantum random number returned by the authentication terminal, wherein the first quantum random number is obtained by the authentication terminal applying for a quantum random number from a quantum random number distribution device and decrypting the quantum random number using a preset quantum random number protection factor;

[0012] Applying to the quantum random number distribution device to obtain a quantum random number and decrypting it using a preset quantum random number protection factor to obtain a second quantum random number;

[0013] Fusing the first quantum random number and the second quantum random number to obtain a third quantum random number;

[0014] Using the third quantum random number, a cryptographic algorithm is used to encrypt the read certificate private key information to obtain an authentication request;

[0015] The authentication request is sent to the authentication end for authentication.

[0016] Furthermore, requesting a quantum random number from the authentication end and receiving a first quantum random number returned by the authentication end includes:

[0017] Performing secure socket layer protocol negotiation with the authentication end to establish a connection;

[0018] Sending a random number acquisition request to the authentication end, so that the authentication end applies to the quantum random number distribution device to obtain a quantum random number and decrypts it using a quantum random number protection factor preset by the authentication end to obtain a first quantum random number;

[0019] Receive the first quantum random number and timestamp returned by the authentication end.

[0020] Furthermore, applying to the quantum random number distribution device to obtain a quantum random number and decrypting the second quantum random number using a preset quantum random number protection factor includes:

[0021] Sending a random number acquisition request to the quantum random number distribution device;

[0022] Receive the quantum random number returned by the quantum random number distribution device, and decrypt it using a preset quantum random number protection factor to obtain the second quantum random number, wherein the quantum random number protection factor is a charging key preset in the client by the quantum random number distribution device.

[0023] Furthermore, before applying to the quantum random number distribution device for obtaining a quantum random number and decrypting using a preset quantum random number protection factor to obtain a second quantum random number, the method further includes:

[0024] Receiving a charging key ciphertext issued by the quantum random number distribution device, wherein the charging key ciphertext is obtained by encrypting the charging key using the basic key;

[0025] The charging key ciphertext is decrypted using a basic key preset by the client to obtain a charging key, and the charging key is stored in a quantum user identification card as the quantum random number protection factor.

[0026] Furthermore, the fusing of the first quantum random number and the second quantum random number to obtain a third quantum random number includes:

[0027] The first quantum random number and the second quantum random number are concatenated to obtain the third quantum random number.

[0028] Furthermore, the method further comprises:

[0029] When an abnormality occurs in the encryption device on the client side, the quantum random number protection factor and basic key preset by the client are cleared.

[0030] Furthermore, the method of using the third quantum random number to encrypt the read certificate private key information using a cryptographic algorithm to obtain an authentication request includes:

[0031] Read the certificate private key information, which includes a password and a private key;

[0032] Encrypting the password using the first algorithm in combination with the third quantum random number to obtain a first password authentication code;

[0033] encrypting the private key using the second algorithm in combination with the third quantum random number to obtain a signature value;

[0034] The authentication request is generated based on the first password authentication code, the signature value, the third quantum random number, a timestamp when the first quantum random number returned by the authentication end is received, and a user name.

[0035] Furthermore, after sending the authentication request to the authentication end for authentication, the method further includes:

[0036] When both password authentication and certificate authentication are passed by the authentication terminal, an authentication pass message sent by the authentication terminal is received, wherein when the authentication terminal performs password authentication, the first algorithm value and the public key of the password are read from the database according to the user name, and a second password authentication code is calculated according to the third quantum random number and the first algorithm value of the password using the first algorithm, and a password authentication pass message is generated when the first password authentication code and the second password authentication code are compared and found to be consistent; when the authentication terminal performs certificate authentication, the second algorithm is used in combination with the public key, the third quantum random number and the signature value to perform signature verification, and a certificate authentication pass message is generated when the signature verification is successful.

[0037] In a second aspect, the present application proposes a client, comprising:

[0038] a first quantum random number request module, configured to request a quantum random number from an authentication end and receive a first quantum random number returned by the authentication end, wherein the first quantum random number is obtained by the authentication end applying to a quantum random number distribution device and decrypting the quantum random number using a preset quantum random number protection factor;

[0039] A second quantum random number request module is configured to apply to the quantum random number distribution device for obtaining a quantum random number and decrypt the second quantum random number using a preset quantum random number protection factor;

[0040] A random number fusion module, configured to fuse the first quantum random number and the second quantum random number to obtain a third quantum random number;

[0041] an authentication request generation module, configured to encrypt the read certificate private key information using the third quantum random number and a cryptographic algorithm to obtain an authentication request;

[0042] The authentication module is used to send the authentication request to the authentication end for authentication.

[0043] Furthermore, the client is also provided with a quantum user identification card and a cryptographic component. The quantum user identification card is pre-installed with a charging key as the quantum random number protection factor, and the cryptographic component is pre-installed with a basic key.

[0044] Furthermore, the client is also connected to a key destruction module, which is used to reset the injection key in the quantum user identification card and the basic key in the cryptographic component to zero when the encryption device is abnormal.

[0045] In a third aspect, the present application proposes an authentication system based on double quantum random number protection, the system comprising a client, an authentication end, and a quantum random number distribution device, the client negotiating with the authentication end to establish a connection via a secure socket layer protocol, and both the client and the authentication end are connected to the quantum random number distribution device; the client is used to execute the authentication method based on double quantum random number protection as described above.

[0046] In a fourth aspect, the present application proposes a computing and processing device, comprising: a memory storing computer-readable code; and one or more processors. When the computer-readable code is executed by the one or more processors, the computing and processing device executes the authentication method based on double quantum random number protection as described above.

[0047] In a fifth aspect, the present application proposes a computer program, which includes a computer-readable code. When the computer-readable code is run on a computing processing device, it causes the computing processing device to execute any one of the authentication methods based on double quantum random number protection as described above.

[0048] In a sixth aspect, the present application proposes a computer-readable medium in which the computer program described above is stored.

[0049] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0051] FIG1 is a flow chart of an authentication method based on dual quantum random number protection proposed in an embodiment of the present application;

[0052] FIG2 is a diagram showing a key protection system hierarchy according to an embodiment of the present application;

[0053] FIG3 is a diagram of a dual quantum random number fusion cryptography according to an embodiment of the present application;

[0054] FIG4 is a schematic diagram of the structure of a client proposed in an embodiment of the present application;

[0055] Figure 5 is a key interaction diagram of an authentication system based on dual quantum random number protection proposed in an embodiment of the present application

[0056] FIG6 is a schematic diagram of the structure of a computing and processing device proposed in an embodiment of the present application;

[0057] FIG7 is a schematic structural diagram of a storage unit for program code proposed in an embodiment of the present application. DETAILED DESCRIPTION

[0058] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0059] As shown in FIG1 , the first embodiment of the present application discloses an authentication method based on double quantum random number protection, which is applied to a client and includes the following steps:

[0060] S10, requesting a quantum random number from an authentication terminal and receiving a first quantum random number returned by the authentication terminal, where the first quantum random number is obtained by the authentication terminal applying to a quantum random number distribution device and decrypting the quantum random number using a preset quantum random number protection factor;

[0061] S20, applying to the quantum random number distribution device to obtain a quantum random number and decrypting it using a preset quantum random number protection factor to obtain a second quantum random number;

[0062] It should be noted that the client and the authentication end obtain the quantum random number encrypted and protected by the quantum random number protection factor by the quantum random number distribution device, and decrypt it using the quantum random number protection factor preset on each end, ensuring the security of the quantum random number distribution process.

[0063] Moreover, the authentication end and the client are both connected to two different quantum distribution systems. The authentication end and the client obtain quantum random numbers separately, which are unrelated to each other, increasing the difficulty for attackers and improving the security of the system, increasing the difficulty of attacks on the physical level.

[0064] S30, fusing the first quantum random number and the second quantum random number to obtain a third quantum random number;

[0065] S40: Using the third quantum random number, adopting a cryptographic algorithm to encrypt the read certificate private key information to obtain an authentication request;

[0066] S50: Send the authentication request to the authentication end for authentication.

[0067] This embodiment fuses the dual quantum random numbers obtained by the authentication end and the client respectively, and uses the third quantum random number obtained by the fusion for encryption authentication, thereby improving the confidentiality of the authentication process.

[0068] In one embodiment, step S10: requesting a quantum random number from an authentication end and receiving a first quantum random number returned by the authentication end, includes the following steps:

[0069] S11, performing Secure Sockets Layer protocol negotiation with the authentication end to establish a connection;

[0070] It's important to note that the Secure Sockets Layer (SSL) protocol is a cryptographically secure transport protocol used to protect data transmission over the internet. It provides applications with security features such as encryption, authentication, and integrity protection. It boasts strong encryption, wide applicability, cross-platform security, and high CA (certification authority) support.

[0071] S12. Sending a random number acquisition request to the authentication end, so that the authentication end applies to the quantum random number distribution device to obtain a quantum random number and decrypts it using a quantum random number protection factor preset by the authentication end to obtain a first quantum random number;

[0072] S13: Receive the first quantum random number and timestamp returned by the authentication end for anti-replay.

[0073] It should be noted that the quantum key distribution method in this embodiment distributes quantum random numbers. The quantum key distribution method is a secure communication method that uses the principles of quantum mechanics to exchange secret keys. It is based on the irreversibility theorem in quantum physics and ensures the security of the key and prevents it from being eavesdropped.

[0074] In one embodiment, step S20: applying to the quantum random number distribution device to obtain a quantum random number and decrypting the second quantum random number using a preset quantum random number protection factor specifically includes the following steps:

[0075] Sending a random number acquisition request to the quantum random number distribution device;

[0076] Receive the quantum random number returned by the quantum random number distribution device, and decrypt it using a preset quantum random number protection factor to obtain the second quantum random number, wherein the quantum random number protection factor is a charging key preset in the client by the quantum random number distribution device.

[0077] In one embodiment, before the step S20 of applying to the quantum random number distribution device for obtaining a quantum random number and decrypting the second quantum random number using a preset quantum random number protection factor, the method further includes the following steps:

[0078] Receiving a charging key ciphertext issued by the quantum random number distribution device, wherein the charging key ciphertext is obtained by encrypting the charging key using the basic key;

[0079] The charging key ciphertext is decrypted using a basic key preset by the client to obtain a charging key, and the charging key is stored in a quantum user identification card as the quantum random number protection factor.

[0080] The quantum user identification card, also known as the quantum SIM card, has a three-layer quantum random number protection system, as shown in Figure 2. The basic key, as a root key pre-installed in the quantum distributor, is used to protect the charging key. The charging key is distributed by the quantum key distribution device and stored in the quantum SIM card, which is used to protect the quantum random number. The quantum random number is a random number distributed by the quantum key distribution device, which is obtained online and can be used immediately.

[0081] In one embodiment, the method further comprises:

[0082] When an abnormality occurs in the encryption device on the client side, the quantum random number protection factor and basic key preset by the client are cleared.

[0083] It should be noted that when the encryption device is forcibly disassembled or attacked, it is determined that the encryption device is abnormal, and the charging key and the basic key are reset to zero to ensure key security.

[0084] In one embodiment, the step S30 of fusing the first quantum random number and the second quantum random number to obtain a third quantum random number includes:

[0085] The first quantum random number and the second quantum random number are concatenated to obtain the third quantum random number.

[0086] In one embodiment, step S40: using the third quantum random number and a cryptographic algorithm to encrypt the read certificate private key information to obtain an authentication request includes the following steps:

[0087] S41. Read the certificate private key information, where the certificate private key information includes a password and a private key.

[0088] S42. Encrypt the password using the first algorithm in combination with the third quantum random number to obtain a first password authentication code;

[0089] S43. Encrypt the private key using the second algorithm combined with the third quantum random number to obtain a signature value;

[0090] S44. Generate the authentication request based on the first password authentication code, the signature value, the third quantum random number, the timestamp of receiving the first quantum random number returned by the authentication terminal, and the user name.

[0091] Specifically, the dual quantum random number fusion cryptographic diagram is shown in Figure 3. The first algorithm can be the SM3 algorithm, and the second algorithm can be the SM2 algorithm. Both the SM3 algorithm and the SM2 algorithm are cryptographic algorithms. This embodiment uses algorithm SM3 (SM3 (password) | QRNG_S_R) to calculate the password authentication code (PASS_CODE_R), and uses algorithm SM2 (private key, QRNG_S_R) to obtain the signature value (SIGN_CODE). PASS_CODE_R, SIHGN_CODE, QRNG_S_R, TIME, and user name are used as parameters to send an authentication request to the authentication terminal. By integrating quantum random numbers with cryptographic algorithms, encryption protection of user information is achieved, rather than simply performing an XOR combination on random numbers.

[0092] It should be noted that the cryptographic algorithm used is China's national commercial cryptographic algorithm for encrypting and authenticating communication data. This algorithm, with independent intellectual property rights and high security, ensures data confidentiality and integrity by encrypting and authenticating communication data, preventing data tampering or forgery.

[0093] In one embodiment, after the step S50 of sending the authentication request to the authentication end for authentication, the method further includes:

[0094] When both password authentication and certificate authentication are passed by the authentication end, an authentication pass message sent by the authentication end is received, wherein when the authentication end performs password authentication, the SM3 value and public key of the password are read from the database according to the user name, and the second password authentication code is calculated according to the third quantum random number and the SM3 value of the password using the SM3 algorithm, and the password authentication pass message is generated when the first password authentication code and the second password authentication code are compared and found to be consistent; when the authentication end performs certificate authentication, the SM2 algorithm is used in combination with the public key, the third quantum random number and the signature value to perform signature verification, and a certificate authentication pass message is generated when the signature verification is successful.

[0095] In addition, as shown in FIG4 , the second embodiment of the present application discloses a client, which includes:

[0096] A first quantum random number request module 10 is configured to request a quantum random number from an authentication end and receive a first quantum random number returned by the authentication end, wherein the first quantum random number is obtained by the authentication end applying to a quantum random number distribution device and decrypting the quantum random number using a preset quantum random number protection factor;

[0097] A second quantum random number request module 20 is configured to request a quantum random number from the quantum random number distribution device and decrypt the second quantum random number using a preset quantum random number protection factor;

[0098] A random number fusion module 30 is configured to fuse the first quantum random number and the second quantum random number to obtain a third quantum random number;

[0099] an authentication request generating module 40 for encrypting the read certificate private key information using the third quantum random number and a cryptographic algorithm to obtain an authentication request;

[0100] The authentication module 50 is configured to send the authentication request to the authentication end for authentication.

[0101] In one embodiment, a quantum SIM card and a cryptographic component are provided in the encryption device on the client side. The quantum SIM card is pre-installed with a charging key as the quantum random number protection factor. The cryptographic component is pre-installed with a basic key. The basic key is used to protect the charging key, and the charging key is used to protect the quantum random number.

[0102] In this embodiment, encryption devices are provided on both the authentication end and the client, which are responsible for allocating quantum random numbers to both ends.

[0103] Specifically, the cryptographic component provides the required cryptographic algorithm support for the encryption device and stores the basic key in its secure storage area; the quantum SIM card stores the charging key, which is used to decrypt the quantum random number distributed by the quantum distributor.

[0104] In one embodiment, the client is further connected to a key destruction module, which is used to reset the charging key in the quantum SIM card and the basic key in the cryptographic component to zero when the encryption device is abnormal.

[0105] Among them, the key destruction module is an independent hardware physical module. When the encryption device is forcibly disassembled or attacked, the module is triggered to reset the charging key in the quantum SIM card to zero and the basic key in the cryptographic component to zero to ensure key security.

[0106] Specifically, the random number acquisition process is as follows:

[0107] (1) The encryption device pre-sets the basic key in the cryptographic component;

[0108] (2) Pre-filling the key into the quantum SIM card through the quantum key distribution device;

[0109] (3) During the authentication process, both parties request quantum random numbers from the quantum distributor and obtain random number ciphertext;

[0110] (4) The quantum SIM card decrypts the quantum number ciphertext and obtains the quantum random number;

[0111] (5) Encryption protection of user information is achieved by integrating quantum random numbers through cryptographic algorithms.

[0112] During the above process, if the key destruction mechanism is triggered, the quantum key protection factor in the QT secure eSIM card will be set to zero, and the basic key in the cryptographic component will be set to zero to ensure key security.

[0113] In one embodiment, the first quantum random number request module 10 specifically includes:

[0114] A connection establishing unit, configured to perform SSL negotiation with the authentication end to establish a connection;

[0115] a first random number requesting unit, configured to send a random number acquisition request to the authentication end, so that the authentication end applies to the quantum random number distribution device for obtaining a quantum random number and decrypts the quantum random number using a quantum random number protection factor preset by the authentication end to obtain a first quantum random number;

[0116] The first random number receiving unit is configured to receive the first quantum random number and timestamp returned by the authentication end.

[0117] In one embodiment, the second quantum random number request module 20 includes:

[0118] A second random number requesting unit, configured to send a random number acquisition request to the quantum random number distribution device;

[0119] The second random number receiving unit is configured to receive the quantum random number returned by the quantum random number distribution device, and decrypt the quantum random number using a preset quantum random number protection factor to obtain the second quantum random number, wherein the quantum random number protection factor is a charging key preset in the client by the quantum random number distribution device.

[0120] In one embodiment, the client further includes a quantum random number protection factor pre-injection module, which is configured to:

[0121] Receiving a charging key ciphertext issued by the quantum random number distribution device, wherein the charging key ciphertext is obtained by encrypting the charging key using the basic key;

[0122] The charging key ciphertext is decrypted using the basic key preset by the client to obtain the charging key, and the charging key is stored in the quantum SIM card as the quantum random number protection factor.

[0123] In one embodiment, the random number fusion module 30 is specifically configured to concatenate the first quantum random number and the second quantum random number to obtain the third quantum random number.

[0124] In one embodiment, the authentication request generation module 40 specifically includes:

[0125] An information reading unit, configured to read certificate private key information, wherein the certificate private key information includes a password and a private key;

[0126] a password authentication unit, configured to encrypt the password using an SM3 algorithm in combination with the third quantum random number to obtain a first password authentication code;

[0127] a signature value calculation unit, configured to encrypt the private key using the SM2 algorithm in combination with the third quantum random number to obtain a signature value;

[0128] An authentication request generating unit is configured to generate the authentication request based on the first password authentication code, the signature value, the third quantum random number, a timestamp when the first quantum random number returned by the authentication terminal is received, and a user name.

[0129] Specifically, this embodiment uses algorithm SM3 (SM3 (password) | QRNG_S_R) to calculate the password authentication code (PASS_CODE_R) and algorithm SM2 (private key, QRNG_S_R) to obtain the signature value (SIGN_CODE). An authentication request is then sent to the authentication client using PASS_CODE_R, SIHGN_CODE, QRNG_S_R, TIME, and the username as parameters. QRNG_S_R is the concatenated third quantum random number.

[0130] The embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one place or distributed across multiple network elements. Some or all of the modules may be selected based on actual needs to achieve the objectives of the embodiments. Persons of ordinary skill in the art will be able to understand and implement the embodiments without inventive effort.

[0131] It should be noted that other embodiments or implementation methods of the client described in this application can refer to the first embodiment of the method described above, and will not be repeated here.

[0132] In addition, as shown in Figure 5, the third embodiment of the present application discloses an authentication system based on dual quantum random number protection, which includes a client, an authentication end and a quantum random number distribution device. The client and the authentication end perform password SSL negotiation to establish a connection, and both the client and the authentication end are connected to the quantum random number distribution device; the client is used to execute the authentication method based on dual quantum random number protection as described in the first embodiment above.

[0133] Specifically, the workflow of the authentication system based on dual quantum random number protection proposed in this embodiment includes:

[0134] (1) Initialize the quantum generator;

[0135] (2) The quantum generator presets the quantum random number protection factor into the quantum SIM card through the quantum random number distribution device;

[0136] (3) The authentication end and the client each apply for a quantum random number from the quantum random number distribution device;

[0137] (4) The client authenticates based on two-factor authentication and quantum random number (QRNG):

[0138] 4-1) The client and the authentication end negotiate a password SSL (GMSSL) to establish a connection;

[0139] 4-2) The client obtains a challenge code from the authenticator. The authenticator applies to the quantum random number distributor for a QRNG, decrypts it using the quantum random number protection factor, obtains a 32-byte QRNG (QRNG_S), and returns it to the client along with a timestamp (TIME).

[0140] 4-3) The client applies for a quantum random number from the quantum random number distribution device in the same way as in 4-2), and similarly obtains a 32-byte QRNG (QRNG_R). It concatenates QRNG_S and QRNG_R to obtain QRNG_S_R.

[0141] 4-4) The client obtains the certificate private key information by reading the USB shield or SIM card;

[0142] 4-5) Use algorithm SM3 (SM3 (password) | QRNG_S_R) to calculate the password authentication code (PASS_CODE_R), use algorithm SM2 (private key, QRNG_S_R) to obtain the signature value (SIGN_CODE), and send an authentication request to the authenticator using PASS_CODE_R, SIHGN_CODE, QRNG_S_R, TIME, and username as parameters;

[0143] 4-6) The authentication end first performs TIME verification for anti-replay, and reads the password SM3 value and public key from the database according to the username

[0144] 4-7) Based on the password sm3 value read in 4-5), combined with the QRNG_S_R in the client request, the password authentication code (PASS_CODE_S) is calculated using the algorithm for calculating the password authentication code in S4, and PASS_CODE_R is compared with PASS_CODE_S. If the two are equal, the password authentication is successful;

[0145] 4-8) Based on the public key read in S5, combined with the QRNG_S_R and SIHGN_CODE in the client request, the signature is verified using algorithm SM2 (public key, QRNG_S_R, SIHGN_CODE). If the signature verification is successful, the certificate authentication is successful;

[0146] 4-9) After both password authentication and certificate authentication are verified, the final authentication is passed.

[0147] The various component embodiments of the present application can be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof. It will be appreciated by those skilled in the art that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the computing processing equipment according to the embodiment of the present application. The application can also be implemented as a device or apparatus program (for example, a computer program and a computer program product) for performing a part or all of the methods described herein. Such a program implementing the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0148] For example, FIG6 illustrates a computing device that can implement the methods according to the present application. The computing device typically includes a processor 1010 and a computer program product or computer-readable medium in the form of a memory 1020. Memory 1020 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, a hard disk, or ROM. Memory 1020 has storage space 1030 for program code 1031 for executing any of the method steps described above. For example, storage space 1030 for program code can include individual program codes 1031 for implementing various steps in the method described above. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards, or floppy disks. Such computer program products are typically portable or fixed storage units, as described with reference to FIG7 . This storage unit can have storage segments, storage space, and the like arranged similarly to memory 1020 in the computing device of FIG6 . The program code can, for example, be compressed in a suitable form. Typically, the storage unit includes computer-readable codes 1031 ′, ie, codes that can be read by a processor such as 1010 , which, when executed by a computing device, cause the computing device to perform the steps of the method described above.

[0149] References herein to "one embodiment," "an embodiment," or "one or more embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Furthermore, please note that instances of the phrase "in one embodiment" do not necessarily all refer to the same embodiment.

[0150] In the description provided herein, a large number of specific details are described. However, it is understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.

[0151] In the claims, any reference signs placed between brackets shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application may be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.

[0152] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An authentication method based on double quantum random number protection, wherein, The method is applied to a client and includes: Requesting a quantum random number from an authentication end and receiving a first quantum random number returned by the authentication end, where the first quantum random number is obtained by the authentication end applying for a quantum random number from a quantum random number distribution device and decrypting it using a preset quantum random number protection factor; Applying for a quantum random number from the quantum random number distribution device and decrypting it using a preset quantum random number protection factor to obtain a second quantum random number; Fusing the first quantum random number and the second quantum random number to obtain a third quantum random number; Using the third quantum random number to encrypt the read certificate private key information using a cryptographic algorithm to obtain an authentication request; Sending the authentication request to the authentication end for authentication.

2. The authentication method based on dual quantum random number protection according to claim 1, wherein, The requesting a quantum random number from an authentication end and receiving a first quantum random number returned by the authentication end includes: Negotiating a Secure Sockets Layer protocol with the authentication end to establish a connection; Sending a random number acquisition request to the authentication end, so that the authentication end applies for a quantum random number from the quantum random number distribution device and decrypts it using a preset quantum random number protection factor of the authentication end to obtain a first quantum random number; Receiving the first quantum random number and a timestamp returned by the authentication end.

3. The authentication method based on dual quantum random number protection as described in claim 1, wherein, Applying for a quantum random number from the quantum random number distribution device and decrypting it using a preset quantum random number protection factor to obtain a second quantum random number includes: Sending a random number acquisition request to the quantum random number distribution device; Receiving the quantum random number returned by the quantum random number distribution device and decrypting it using a preset quantum random number protection factor to obtain the second quantum random number, where the quantum random number protection factor is a charging key preset by the quantum random number distribution device in the client.

4. The authentication method based on double quantum random number protection according to claim 1, wherein, Before applying for a quantum random number from the quantum random number distribution device and decrypting it using a preset quantum random number protection factor to obtain a second quantum random number, the method further includes: Receiving a ciphertext of the charging key sent by the quantum random number distribution device, where the ciphertext of the charging key is obtained by encrypting the charging key using a basic key; Decrypting the ciphertext of the charging key using a basic key preset in the client to obtain the charging key, and storing the charging key in a quantum user identification card as the quantum random number protection factor.

5. The authentication method based on dual quantum random number protection according to claim 1, wherein, The fusing the first quantum random number and the second quantum random number to obtain a third quantum random number includes: Concatenating the first quantum random number and the second quantum random number to obtain the third quantum random number.

6. The authentication method based on dual quantum random number protection according to claim 1, wherein, The method further includes: When an abnormality occurs in the encryption device on the client side, clearing the preset quantum random number protection factor and basic key on the client.

7. The authentication method based on dual quantum random number protection according to claim 1, wherein The using the third quantum random number to encrypt the read certificate private key information using a cryptographic algorithm to obtain an authentication request includes: Reading the certificate private key information, where the certificate private key information includes a password and a private key; Encrypting the password using a first algorithm in combination with the third quantum random number to obtain a first password authentication code; Encrypt the private key using the second algorithm in combination with the third quantum random number to obtain a signature value; Generate the authentication request based on the first password authentication code, the signature value, the third quantum random number, the timestamp when receiving the first quantum random number returned by the authentication end, and the username.

8. The authentication method based on double quantum random number protection according to claim 7, wherein, After sending the authentication request to the authentication end for authentication, the method further includes: When both the password authentication and the certificate authentication at the authentication end pass, receive the authentication passed message sent by the authentication end. When the authentication end performs password authentication, read the first algorithm value of the password and the public key from the database according to the username, and calculate the second password authentication code using the first algorithm based on the third quantum random number and the first algorithm value of the password. Generate a password authentication passed message when the first password authentication code and the second password authentication code are compared and found to be consistent; when the authentication end performs certificate authentication, use the second algorithm to perform signature verification in combination with the public key, the third quantum random number, and the signature value, and generate a certificate authentication passed message when the signature verification is successful.

9. A client, wherein, The client includes: A first quantum random number request module, configured to request a quantum random number from the authentication end and receive the first quantum random number returned by the authentication end. The first quantum random number is obtained by the authentication end applying for a quantum random number from the quantum random number distribution device and decrypting it using a preset quantum random number protection factor; A second quantum random number request module, configured to apply for a quantum random number from the quantum random number distribution device and decrypt it using a preset quantum random number protection factor to obtain a second quantum random number; A random number fusion module, configured to fuse the first quantum random number and the second quantum random number to obtain a third quantum random number; An authentication request generation module, configured to use the third quantum random number to encrypt the read certificate private key information using a cryptographic algorithm to obtain an authentication request; An authentication module, configured to send the authentication request to the authentication end for authentication.

10. The client according to claim 9, wherein A quantum user identity card and a password component are further provided in the client. A charging key is preset in the quantum user identity card as the quantum random number protection factor, and a basic key is preset in the password component.

11. The client according to claim 10, wherein, The client is further connected to a key destruction module, which is configured to set the charging key in the quantum user identity card to zero and set the basic key in the password component to zero when the encryption device is abnormal.

12. An authentication system based on double quantum random number protection, wherein, The system includes a client, an authentication end, and a quantum random number distribution device. The client negotiates and establishes a connection with the authentication end through a secure socket layer protocol. Both the client and the authentication end are connected to the quantum random number distribution device; the client is configured to execute the authentication method based on dual quantum random number protection according to any one of claims 1-8.

13. A computing and processing device, characterized in that, Includes: A memory, which stores computer-readable code; One or more processors, when the computer-readable code is executed by the one or more processors, the computing device executes the authentication method based on dual quantum random number protection according to any one of claims 1-8.

14. A computer program, comprising computer-readable code which, when run on a computing processing device, causes the computing processing device to execute the authentication method based on dual quantum random number protection according to any one of claims 1-8.

15. A computer-readable medium storing the computer program as claimed in claim 14.

Citation Information

Patent Citations

  • Bidirectional authentication method and device

    CN113596046A

  • Authentication data processing method, device, system, equipment and medium

    CN116073989A

  • Quantum encryption authentication fusion method, device and system

    CN116170139A

  • Authentication method, client and system based on dual quantum random number protection

    CN117955708A

  • Bracket for Fixing Solar Panel

    KR102468084B1

Cited By

  • Remote access handshake method, device and equipment based on double anti-quantum protection and medium

    CN121984679A