Quantum-resistant security enhancement method for transport layer security protocol
By using post-quantum cryptography algorithms and quantum key distribution technology to generate handshake keys resistant to quantum computing attacks between terminals and network devices, the security problem of transport layer security protocols under quantum computing attacks is solved, and efficient and low-cost quantum computing-resistant communication is achieved.
Patent Information
- Application Number
- PCT/CN2024/118627
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-25
- Filing Date
- 2024-09-12
- Publication Date
- 2026-01-29
AI Technical Summary
Existing transport layer security protocols lack effective quantum resistance against quantum computing attacks, especially the TLS 1.3 protocol, which is at risk of being quickly cracked by quantum computing. Furthermore, existing post-quantum cryptography algorithms and quantum key distribution technologies each have their limitations and high costs.
By using post-quantum cryptography algorithms to encrypt quantum keys and key identifiers between terminals and network devices, combining this with random number generation to create a master key, and using quantum key distribution technology to generate a handshake key resistant to quantum computing attacks, communication security is enhanced.
It effectively resists quantum computing attacks, enhances the security of network communication between terminals and network devices, ensures the integrity and confidentiality of data transmission, and improves the ability to resist quantum computing while reducing costs.
Smart Images

Figure CN2024118627_29012026_PF_FP_ABST
Abstract
Description
Anti-quantum security enhancement method of transport layer security protocol
[0001] Priority information
[0002] The present application claims priority to and the benefit of the filing date of Chinese Patent Application No. 202411007785.5, filed July 25, 2024, and is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application relates to the technical field of network security, and in particular to an anti-quantum security enhancement method of a transport layer security protocol of a communication network. BACKGROUND
[0004] The leap in computing power represented by quantum computing has a significant impact on related algorithms in classical cryptography in terms of security. Understandably, with the advent of large-scale quantum computers, there will be some impact on key agreement, encryption, signature, and other applications in classical cryptography. Therefore, providing a cryptographic technology that can resist quantum computing attacks has become a pressing problem.
[0005] SUMMARY
[0006] The present application provides an anti-quantum security enhancement method of a transport layer security protocol of a communication network.
[0007] The present application provides an anti-quantum security enhancement method of a transport layer security protocol of a communication network.
[0008] obtaining a first quantum key and a quantum key identifier from a service node to which the terminal is connected;
[0009] performing post-quantum cryptographic encryption processing on the quantum key identifier, and sending a first encryption result of the post-quantum cryptographic encryption processing to the network device;
[0010] performing decryption processing on a second encryption result received from the network device to obtain a second decryption result, the second encryption result being obtained according to the first encryption result;
[0011] obtaining a first terminal handshake key and a first network device handshake key according to the first encryption result and the second decryption result;
[0012] generating a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result, and the second decryption result, to encrypt communication between the terminal and the network device.
[0013] Thus, in the communication process of the terminal and the network device, the terminal and the network device obtain the quantum key and the quantum key identifier, and encrypt the quantum key identifier by using a post-quantum cryptographic algorithm to generate an anti-quantum key capable of resisting quantum computing attacks. The post-quantum cryptographic algorithm is a series of encryption algorithms designed to resist quantum computing attacks. At the same time, the terminal and the network device exchange random numbers randomly generated by each other to generate a master key, and derive the first terminal handshake key and the first network device handshake key from the master key. The terminal and the network device fuse the quantum key, the terminal handshake key, the network device handshake key, and the anti-quantum key for use in communication between the terminal and the network device. In this way, the anti-quantum computing attack capability of the network communication between the terminal and the network device is enhanced.
[0014] In some embodiments, the service node to which the terminal accesses acquires the first quantum key and the quantum key identifier, including:
[0015] The cryptographic module of the terminal is replenished with a plurality of keys by the service node.
[0016] A quantum key application is sent to the service node, and one of the plurality of keys replenished to the cryptographic module is randomly used as a protection key to protect the quantum key application.
[0017] A quantum key encryption result obtained by the service node by encrypting the first quantum key and the quantum key identifier according to the protection key is received, the first quantum key is generated by a first network node accessing the service node and distributed to the service node, and the quantum key identifier is obtained by the first network node by marking the first quantum key according to the identification code of the first network node and distributed to the service node.
[0018] The first quantum key and the quantum key identifier are obtained by decrypting the quantum key encryption result.
[0019] Thus, the service node is used to charge the cryptographic module with a key, and then a quantum key application is sent to the service node, which is encrypted by using a randomly used key in the cryptographic module as a protection key. Then, the receiving service node performs encryption processing on the first quantum key and the quantum key identifier according to the protection key to obtain a quantum key encryption result, the first quantum key is generated by a first network node of the access service node and distributed to the service node, and the quantum key identifier is marked by the first network node according to the identification code of the first network node and distributed to the service node. The quantum key encryption result is decrypted to obtain the first quantum key and the quantum key identifier. In this way, the first quantum key and the quantum key identifier are obtained, the first quantum key can be used to generate a key with quantum computing attack resistance, and the quantum key identifier is helpful for using and managing the quantum key.
[0020] In some embodiments, the quantum key identifier is post-quantum cryptographic encryption processing, and the first encryption result of the post-quantum cryptographic encryption processing is sent to the network device, comprising:
[0021] The quantum key identifier and the first random number generated randomly are spliced to obtain a first handshake message;
[0022] The first handshake message and the first handshake random number in the first encryption result are processed to generate a second handshake message;
[0023] The second handshake message is post-quantum cryptographic derivation processing to generate a first handshake key;
[0024] The second handshake message is post-quantum cryptographic encryption processing to generate a first encrypted message in the first encryption result;
[0025] The quantum key identifier and the first handshake random number are spliced to obtain a first verification message;
[0026] The first verification message is post-quantum cryptographic signature processing to generate a first signature message in the first encryption result;
[0027] The first encryption result is sent to the network device.
[0028] Thus, the quantum key identifier is spliced with the first random number generated at random to obtain a first handshake message. Then, the first handshake message is XORed with the first handshake random number in the first encryption result to generate a second handshake message in the first encryption result. Then, the second handshake message is subjected to post-quantum password derivation processing to generate a first handshake key, and the second handshake message is subjected to post-quantum password encryption processing to generate a first encrypted message in the first encryption result. The quantum key identifier is spliced with the first handshake random number to obtain a first verification message, and the first verification message is subjected to post-quantum password signature processing to generate a first signature message in the first encryption result, which is used to verify the authenticity and integrity of the data. Finally, the first encryption result is sent to the network device. By splicing the quantum key identifier with the first random number, the confidentiality of the quantum key identifier is increased, and the quantum key identifier and its derivative are processed using a post-quantum password algorithm to combine quantum key distribution technology and post-quantum password technology to increase the complexity of the quantum key identifier.
[0029] In some embodiments, the received second encryption result sent by the network device is decrypted to obtain a second decryption result, comprising:
[0030] The second encryption result sent by the network device is received, which is obtained by the network device by encrypting the first decryption result, and the first decryption result is obtained by the network device by decrypting the first encryption result;
[0031] The second encryption result is decrypted to obtain a second decryption result, which includes a second handshake random number, a fourth handshake message and a second signature message.
[0032] Thus, the second encryption result sent by the network device is received, which is obtained by the network device by encrypting the first decryption result, and the first decryption result is obtained by the network device by decrypting the first encryption result. The second encryption result is decrypted to obtain a second decryption result, which includes a second handshake random number, a fourth handshake message and a second signature message. In this way, the terminal determines the availability of the channel for communication with the network device and obtains the key information of the network device, which can be combined with the related key information of the terminal to generate a higher security key.
[0033] In some embodiments, the method further comprises:
[0034] The second handshake key is obtained according to the fourth handshake message;
[0035] The third handshake message and the quantum key identifier are obtained according to the fourth handshake message and the second handshake random number.
[0036] Thus, the second handshake key is obtained according to the fourth handshake message. Then, the third handshake message and the quantum key identifier are obtained according to the fourth handshake message and the second handshake random number. The second handshake key is thus obtained for subsequent key generation to obtain a key with good anti-quantum computing attack capability.
[0037] In some embodiments, the method further comprises:
[0038] obtaining a second verification message according to the second signed message;
[0039] performing a post-quantum cryptographic signature verification process on the second signed message to confirm the correctness of the second verification message, the second verification message being obtained by concatenating the quantum key identifier and the second handshake random number.
[0040] Thus, the second verification message is obtained according to the second signed message, and the post-quantum cryptographic signature verification process is performed on the second signed message. The post-quantum cryptographic signature verification process is performed on the second signed message to ensure that the terminal can verify the identity of the network device and the integrity of the data, thereby providing security assurance for subsequent data transmission.
[0041] In some embodiments, the first encryption result includes the first handshake random number, the second decryption result includes the second handshake random number, and the first terminal handshake key and the first network device handshake key are obtained according to the first encryption result and the second decryption result, comprising:
[0042] generating a master key according to the first handshake random number and the second handshake random number;
[0043] deriving the first terminal handshake key and the first network device handshake key according to the master key.
[0044] Thus, the master key is generated according to the first handshake random number in the first encryption result and the second handshake random number in the second decryption result. Then, the first terminal handshake key and the first network device handshake key are derived according to the generated master key. The master key is generated by using the randomly generated random number, and the first terminal handshake key and the first network device handshake key are generated by using the cryptographic algorithm to derive the master key for subsequent key derivation.
[0045] In some embodiments, the second terminal handshake key and the second network device handshake key are generated according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result, and the second decryption result to encrypt the communication between the terminal and the network device, comprising:
[0046] generate a second terminal handshake key according to the first quantum key, the first terminal handshake key, the first handshake key, and the second handshake key;
[0047] generate a second network device handshake key according to the first quantum key, the first network device handshake key, the first handshake key, and the second handshake key;
[0048] encrypt communication between the terminal and the network device according to the second terminal handshake key and the second network device handshake key.
[0049] Thus, a second terminal key is generated according to the first terminal handshake key, the first quantum key, the first handshake key, and the second handshake key. Then, a second network device key is generated according to the first network device handshake key, the first quantum key, the first handshake key, and the second handshake key. The communication between the terminal and the network device is encrypted by using the generated second terminal key and the second network device key, so that the ability of resisting quantum computing attacks of the communication between the network devices is enhanced by using the keys generated by combining the quantum key distribution technology and the post-quantum cryptography technology, and the data transmitted in the communication process is protected.
[0050] The embodiment of the application provides an anti-quantum security enhancement method of a transport layer security protocol of a communication network, the communication network comprising a terminal and a network device, the method being used for the network device, and the method comprising the following steps:
[0051] receiving a first encryption result of post-quantum cryptography encryption processing of a quantum key identifier by the terminal, the quantum key identifier being obtained by the terminal from a password service node accessed by the terminal;
[0052] decrypting the first encryption result to obtain a first decryption result;
[0053] performing post-quantum cryptography encryption processing on the first decryption result to obtain a second encryption result;
[0054] obtaining a first terminal handshake key and a first network device handshake key according to the first decryption result and the second encryption result;
[0055] generating a second terminal handshake key and a second network device handshake key according to a second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result, and the second encryption result, so as to encrypt communication between the terminal and the network device.
[0056] Thus, in the communication process of the terminal and the network device, the terminal and the network device obtain the quantum key, and perform encryption processing on the quantum key by using a post-quantum cryptography algorithm to generate an anti-quantum key capable of resisting quantum computing attacks. The post-quantum cryptography algorithm is a series of encryption algorithms designed to resist quantum computing attacks. At the same time, the terminal and the network device exchange random numbers randomly generated by each other to generate a master key, and derive the first terminal handshake key and the first network device handshake key from the master key. The terminal and the network device fuse the quantum key, the terminal handshake key, the network device handshake key, and the anti-quantum key for use in communication between the terminal and the network device. In this way, the anti-quantum computing attack capability of the network communication between the terminal and the network device is enhanced.
[0057] In some embodiments, the method further comprises:
[0058] accessing the second network node through a pre-established channel;
[0059] loading a security certificate of the terminal or a security certificate of the network device.
[0060] Thus, before data transmission with the terminal, the second network node is accessed through a pre-established channel, which can protect data during data transmission and reduce the risk of unauthorized access. Then, the security certificate of the terminal or the security certificate of the network device is loaded. After the security certificate is loaded, it will be used to establish and maintain a secure communication channel, enhancing the security of data during transmission.
[0061] In some embodiments, the first decryption result includes a second handshake message and a first handshake random number, and the method further comprises:
[0062] obtaining a first handshake message according to the second handshake message and the first handshake random number;
[0063] obtaining the quantum key identifier according to the first handshake message.
[0064] Thus, the first handshake message is obtained according to the second handshake message and the first handshake random number, and the quantum key identifier is obtained according to the first handshake message. In this way, the quantum key identifier is obtained, which can be used to apply for a quantum key.
[0065] In some embodiments, the first decryption result includes a first signature message, and the method further comprises:
[0066] obtaining a first verification message according to the first signature message;
[0067] performing post-quantum cryptographic signature verification on the first signature message to confirm that a correct first verification message is obtained, the first verification message being concatenated from a first handshake random number and the quantum key identifier;
[0068] in a case where the obtained quantum key identifier is correct, obtaining the second quantum key from the second network node accessing the network device.
[0069] In this way, the first signature message is subjected to post-quantum cryptographic signature verification to confirm that a correct first verification message is received, ensuring the integrity of data and the legitimacy of the source. When the received first verification message is correct, i.e., the received quantum key identifier is correct, the network node accessing the network device applies for obtaining a second quantum key through the quantum key identifier. In this way, it is ensured that the obtained second quantum key matches the first quantum key of the first network device, and the quantum key is used to generate a higher-security key.
[0070] In certain embodiments, the post-quantum cryptographic encryption processing on the first decryption result to obtain a second encryption result comprises:
[0071] concatenating the quantum key identifier and a second random number generated at random to obtain a third handshake message;
[0072] processing the third handshake message and the second handshake random number in the second encryption result to generate a fourth handshake message;
[0073] performing post-quantum cryptographic derivation processing on the fourth handshake message to generate a second handshake key;
[0074] performing post-quantum cryptographic encryption processing on the fourth handshake message to generate a second encryption message in the second encryption result;
[0075] concatenating the quantum key identifier and the second handshake random number to obtain a second verification message;
[0076] performing post-quantum cryptographic signature processing on the second verification message to generate a second signature message in the second encryption result;
[0077] sending the second encryption result to the terminal.
[0078] Thus, the quantum key identifier and the second random number generated randomly are spliced to obtain a third handshake message. Then, the third handshake message and the second handshake random number in the second encryption result are XORed to generate a fourth handshake message in the second encryption result. Next, the fourth handshake message is subjected to post-quantum password derivation processing to generate a second handshake key, and the fourth handshake message is subjected to post-quantum password encryption processing to generate a second encrypted message in the second encryption result. The quantum key identifier and the second handshake random number are spliced to obtain a second verification message. Finally, the second verification message is subjected to post-quantum password signature processing to generate a second signature message in the second encryption result. The second encryption result is sent to the terminal. The confidentiality of the quantum key identifier is increased by splicing the quantum key identifier and the second random number, and the complexity of the quantum key identifier is increased by using the post-quantum password algorithm to encrypt the quantum key identifier and its derivative in combination with the quantum key distribution technology and the post-quantum password technology.
[0079] In some embodiments, the first decryption result includes a first handshake random number, the second encryption result includes a second handshake random number, and the first terminal handshake key and the first network device handshake key are obtained according to the first decryption result and the second encryption result, including:
[0080] A master key is generated according to the first handshake random number and the second handshake random number;
[0081] The first terminal handshake key and the first network device handshake key are derived according to the master key.
[0082] Thus, a master key is generated according to the first handshake random number in the first decryption result and the second handshake random number in the second encryption result. Next, the first terminal handshake key and the first network device handshake key are derived according to the generated master key. The master key is generated by using a randomly generated random number, and the first terminal handshake key and the first network device handshake key are derived from the master key by using a cryptographic algorithm for subsequent key derivation.
[0083] In some embodiments, the first decryption result includes a second handshake message, and the second terminal handshake key and the second network device handshake key are generated according to the second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result, and the second encryption result to encrypt the communication between the terminal and the network device, including:
[0084] The second handshake message is subjected to post-quantum password derivation processing to generate a first handshake key;
[0085] generate a second terminal handshake key according to the second quantum key, the first terminal handshake key, the first handshake key, and the second handshake key;
[0086] generate a second network device handshake key according to the second quantum key, the first network device handshake key, the first handshake key, and the second handshake key;
[0087] encrypt communication between the terminal and the network device according to the second terminal handshake key and the second network device handshake key.
[0088] Thus, the second handshake message is subjected to post-quantum cryptographic derivation processing to generate a first handshake key. A second terminal key is generated according to the first terminal handshake key, the second quantum key, the first handshake key, and the second handshake key. Then, a second network device key is generated according to the first network device handshake key, the second quantum key, the first handshake key, and the second handshake key. The communication between the terminal and the network device is encrypted by using the generated second terminal key and the second network device key, so that the ability of the communication between the network devices to resist quantum computing attacks is enhanced by using the keys generated by combining the quantum key distribution technology and the post-quantum cryptography technology, and the data transmitted in the communication process is protected.
[0089] The embodiment of the application provides a terminal used in an Internet Transport Layer Security protocol-based communication network, the communication network further comprising a network device, and the terminal is configured to:
[0090] obtain a first quantum key and a quantum key identifier from a service node to which the terminal accesses;
[0091] perform post-quantum cryptographic encryption processing on the quantum key identifier, and send a first encryption result of the post-quantum cryptographic encryption processing to the network device;
[0092] perform decryption processing on a second encryption result received and sent by the network device to obtain a second decryption result;
[0093] obtain a first terminal handshake key and a first network device handshake key according to the first encryption result and the second decryption result;
[0094] generate a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result, and the second decryption result, so as to encrypt communication between the terminal and the network device.
[0095] Thus, in the communication process of the terminal and the network device, the terminal and the network device obtain the quantum key, and use the post-quantum cryptography algorithm to encrypt the quantum key to generate the anti-quantum key capable of resisting quantum computing attacks. The post-quantum cryptography algorithm is a series of encryption algorithms designed to resist quantum computing attacks. At the same time, the terminal and the network device exchange the random numbers randomly generated by each other to generate a master key, and then derive the first terminal handshake key and the first network device handshake key from the master key. The terminal and the network device then fuse the quantum key, the terminal handshake key, the network device handshake key, and the anti-quantum key for use in communication between the terminal and the network device. In this way, the anti-quantum computing attack capability of the network communication between the terminal and the network device is enhanced.
[0096] The embodiment of the application provides a network device for a communication network based on an Internet transmission layer security protocol, the communication network further comprising a terminal, and the network device is configured to:
[0097] receive a first encryption result of post-quantum cryptography encryption processing of a quantum key identifier by the terminal, the quantum key identifier being obtained by the terminal from an accessed cryptographic service node;
[0098] decrypt the first encryption result to obtain a first decryption result;
[0099] perform post-quantum cryptography encryption processing on the first decryption result to obtain a second encryption result;
[0100] obtain a first terminal handshake key and a first network device handshake key according to the first decryption result and the second encryption result;
[0101] generate a second terminal handshake key and a second network device handshake key according to a second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result, and the second encryption result, to encrypt the communication of the terminal and the network device.
[0102] Thus, in the communication process of the terminal and the network device, the terminal and the network device obtain the quantum key, and use the post-quantum cryptography algorithm to encrypt the quantum key to generate the anti-quantum key capable of resisting quantum computing attacks. The post-quantum cryptography algorithm is a series of encryption algorithms designed to resist quantum computing attacks. At the same time, the terminal and the network device exchange the random numbers randomly generated by each other to generate a master key, and then derive the first terminal handshake key and the first network device handshake key from the master key. The terminal and the network device then fuse the quantum key, the terminal handshake key, the network device handshake key, and the anti-quantum key for use in communication between the terminal and the network device. In this way, the anti-quantum computing attack capability of the network communication between the terminal and the network device is enhanced.
[0103] The embodiment of the present application provides a communication system based on an Internet transmission layer security protocol, the communication system comprising the terminal as described above, the network device as described above and a quantum key distribution network, the quantum key distribution network being configured to distribute a quantum key to the terminal or the network device.
[0104] The embodiment of the present application provides a terminal, the terminal comprising one or more processors and a memory, the memory storing a computer program, the computer program being executed by the processor to implement the method as described above.
[0105] The embodiment of the present application provides a network device, the network device comprising one or more processors and a memory, the memory storing a computer program, the computer program being executed by the processor to implement the method as described above.
[0106] The embodiment of the present application provides a computer readable storage medium, the computer readable storage medium storing a computer program, the computer program being executed by the processor to implement the method as described above.
[0107] Additional aspects and advantages of the present application will be made apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0108] The above and / or additional aspects and advantages of the present application will become apparent and be readily appreciated from the following description, including the accompanying drawings, wherein:
[0109] Wherein:
[0110] Fig. 1 is one of flow schematic diagrams of the method of the embodiment of the present application;
[0111] Fig. 2 is an architecture diagram of the method of the embodiment of the present application;
[0112] Fig. 3 is a signaling diagram of the method of the embodiment of the present application;
[0113] Fig. 4 is another of flow schematic diagrams of the method of the embodiment of the present application;
[0114] Fig. 5 is a third of flow schematic diagrams of the method of the embodiment of the present application;
[0115] Fig. 6 is a fourth of flow schematic diagrams of the method of the embodiment of the present application;
[0116] Fig. 7 is a fifth of flow schematic diagrams of the method of the embodiment of the present application;
[0117] Fig. 8 is a sixth of flow schematic diagrams of the method of the embodiment of the present application;
[0118] Fig. 9 is a flowchart of a method of the embodiment of the present application;
[0119] Fig. 10 is a flowchart of a method of the embodiment of the present application;
[0120] Fig. 11 is a flowchart of a method of the embodiment of the present application;
[0121] Fig. 12 is a flowchart of a method of the embodiment of the present application;
[0122] Fig. 13 is a flowchart of a method of the embodiment of the present application;
[0123] Fig. 14 is a flowchart of a method of the embodiment of the present application;
[0124] Fig. 15 is a flowchart of a method of the embodiment of the present application;
[0125] Fig. 16 is a flowchart of a method of the embodiment of the present application;
[0126] Fig. 17 is a flowchart of a method of the embodiment of the present application. DETAILED DESCRIPTION
[0127] The embodiments of the present application are described in detail below with reference to the accompanying drawings. Examples of the embodiments are shown in the drawings, wherein the same or similar components are denoted by the same or similar reference numerals throughout. The embodiments described below by reference to the drawings are exemplary and are for the purpose of explanation only, and are not to be understood as limiting the embodiments of the present application.
[0128] The leap of computing power represented by quantum computing has a great impact on related algorithms in classical cryptography in terms of security. That is, quantum computing poses a more direct and urgent threat to the cracking of classical cryptography. For example, Shor's quantum algorithm can solve complex mathematical problems such as large integer factorization and discrete logarithm solving in polynomial time, and quickly crack widely used public key cryptography algorithms such as RSA, ECC, DSA, and ElGamal. Understandably, with the implementation of large quantum computers, there will be some impact on key agreement, encryption, signature, and other applications in classical cryptography.
[0129] The Internet transport layer is also threatened by quantum computing attacks. Although the original Transport Layer Security (TLS) 1.3 based on Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange and Elliptic Curve Digital Signature Algorithm (ECDSA) has good security and forward secrecy, can resist active attacks and passive listening, but still lacks the ability to resist quantum computing attacks. TLS 1.3 is the most widely used cryptographic protocol for secure access, secure remote access, and web security.
[0130] Currently, the international response to quantum computing threats is mainly divided into two categories: "classic against quantum - post-quantum cryptographic algorithms" and "quantum against quantum - quantum cryptographic technology". Post-quantum cryptographic algorithms (PQC) are designed based on mathematical difficult problems that known quantum algorithms cannot solve in polynomial time, and their security relies on computational complexity. However, from a development perspective, the mathematical problems on which post-quantum cryptographic algorithms depend still have questions about whether they will remain difficult to solve in the future, whether the algorithm's security will remain effective in the long term, and whether they will still be immune to new quantum attacks. These all indicate that post-quantum cryptographic algorithms have certain fragility and uncertainty factors. Quantum key distribution technology (QKD) is based on the quantum physical implementation principle of single quantum indivisibility and quantum state cloning, and achieves the goal of classical cryptography. Quantum key distribution technology refers to a method and process by which both parties communicate quantum states to achieve information theory secure key generation and distribution. Quantum key distribution technology has good resistance to quantum computing attacks, but the cost of quantum key distribution technology is relatively high. Both post-quantum cryptographic algorithms and quantum key distribution technology have the ability to resist quantum computing attacks, but each has its limitations, so providing a relatively low-cost cryptographic technology with high security that can resist quantum computing attacks has become a pressing problem.
[0131] Based on the above problems, referring to FIG. 1, the application embodiment provides a quantum-resistant security enhancement method for a transport layer security protocol of a communication network, the communication network comprising a terminal and a network device, the method being used for the terminal, and the method comprising:
[0132] 011: obtaining a first quantum key and a quantum key identifier from a service node of the terminal;
[0133] 012: performing post-quantum cryptographic encryption processing on the quantum key identifier, and sending a first encrypted result of the post-quantum cryptographic encryption processing to the network device;
[0134] 013: performing decryption processing on a second encrypted result received from the network device to obtain a second decrypted result, the second encrypted result being obtained according to the first encrypted result;
[0135] 014: obtaining a first terminal handshake key and a first network device handshake key according to the first encrypted result and the second decrypted result;
[0136] 015: generating a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encrypted result, and the second decrypted result, to encrypt communication between the terminal and the network device.
[0137] The application also provides a terminal, including a memory and a processor. The method of the application can be implemented by the terminal of the application. Specifically, the memory stores a computer program, and the processor is configured to obtain a first quantum key and a quantum key identifier from a service node of the terminal, perform post-quantum cryptographic encryption processing on the quantum key identifier, and send a first encrypted result of the post-quantum cryptographic encryption processing to the network device. The processor is also configured to perform decryption processing on a second encrypted result received from the network device to obtain a second decrypted result, the second encrypted result being obtained according to the first encrypted result, obtain a first terminal handshake key and a first network device handshake key according to the first encrypted result and the second decrypted result, and generate a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encrypted result, and the second decrypted result, to encrypt communication between the terminal and the network device.
[0138] The embodiment of the application further provides a terminal. The method of the embodiment of the application can be implemented by the terminal of the embodiment of the application. Specifically, the terminal comprises an acquisition module, an encryption module, a decryption module and a derivation module. The acquisition module is configured to acquire a first quantum key and a quantum key identifier from a service node of the terminal. The encryption module is configured to perform post-quantum cryptographic encryption processing on the quantum key identifier, and send a first encryption result of the post-quantum cryptographic encryption processing to a network device. The decryption module is configured to perform decryption processing on a second encryption result received from the network device to obtain a second decryption result, the second encryption result being obtained according to the first encryption result. The derivation module is configured to obtain a first terminal handshake key and a first network device handshake key according to the first encryption result and the second decryption result. The derivation module is further configured to generate a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result and the second decryption result, so as to encrypt the communication between the terminal and the network device.
[0139] The application provides a communication system based on an Internet transport layer security protocol, the communication system comprising the terminal, the network device and the quantum key distribution network of the above-mentioned embodiment, and the quantum key distribution network is configured to distribute quantum keys to the terminal or the network device. Specifically, the quantum key distribution network comprises a network node and a quantum network link control center, the network node is configured to store quantum keys in the quantum key distribution network. The quantum network link center can establish quantum key distribution and relay links between network nodes according to the names of the network nodes, and the relay links are used for data transfer and other functions. The quantum key distribution network is used to implement quantum key generation, quantum key relay, quantum key provision and other services.
[0140] Referring to FIG. 2, in some embodiments, the terminal and the network device communicate through a TLS record layer encrypted channel, such as performing a TLS handshake protocol, the TLS record layer encrypted channel refers to an encrypted communication channel established between the terminal and the network device, which is used to transmit application layer data, and the TLS handshake protocol is a key part of the TLS 1.3 protocol, which is used in the initial stage of establishing secure communication between the client and the server. The terminal accesses a service node, which is a relay station used by the client to connect to the network node, and the service node is used to charge the terminal with a key and to relay and store the quantum key. When the terminal applies for a quantum key, the network node generates a quantum key through a quantum key distribution network and sends it to the service node, and the service node sends the quantum key to the terminal. When the terminal applies successfully and obtains the quantum key distributed by the network node, the quantum network link control center synchronously controls the network node involved in the network device to generate a quantum key, but does not immediately send it to the network device, but needs the network device to apply for a quantum key and distribute it successfully. The above-mentioned correspondence between the terminal, the network device and the network node is provided by the management platform.
[0141] It should be noted that the embodiments of the present application take the FIPS 203 Module-Lattice-based Key-Encapsulation Mechanism Standard as the PQC key encapsulation algorithm, and take the FIPS 204 Module-Lattice-Based Digital Signature Standard as the PQC digital signature algorithm as an example for explanation and description. The following description of the operations related to the PQC algorithm is based on the above FIPS standard. Of course, in other embodiments, other algorithms such as the NewHope algorithm, the Sidh algorithm, and the HQC algorithm can also be used as the related algorithm of PQC.
[0142] Specifically, in the embodiments of the present application, the terminal sends a quantum key application, obtains a first quantum key and a quantum key identifier from a service node accessed by the terminal, the first quantum key and the quantum key identifier can be used to generate a key with quantum computing attack resistance, and the quantum key identifier is helpful for using and managing the quantum key. After obtaining the first quantum key and the quantum key identifier, the terminal performs a post-quantum cryptography encryption process on the quantum key identifier, and sends the first encryption result of the post-quantum cryptography encryption process to the network device. By performing the post-quantum cryptography encryption process on the quantum key identifier, the quantum key distribution technology is combined with the post-quantum cryptography technology to improve the complexity of the key, and the encryption result is sent to the network device for sharing to make the communication data of the terminal and the network device consistent in the communication network.
[0143] Then, the network device receives the first encryption result sent by the terminal, decrypts the first encryption result to obtain a first decryption result. The network device further encrypts the first decryption result by using the post-quantum cryptography to obtain a second encryption result. After obtaining the second encryption result, the network device sends the second encryption result to the terminal, so that the terminal can also share the network device information and the generated key. The network device further obtains a first terminal handshake key and a first network device key according to the first decryption result and the second encryption result, and generates a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result and the second encryption result, so as to encrypt the communication between the terminal and the network device.
[0144] Meanwhile, the terminal receives the second encryption result sent by the network device, and decrypts the second encryption result to obtain a second decryption result. The terminal further obtains a first terminal handshake key and a first network device key according to the first encryption result and the second decryption result, and generates a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result and the second encryption result, so as to encrypt the communication between the terminal and the network device.
[0145] The method of the embodiment of the application is described below by using an example. In the example of the application, the client is a terminal, the secure access gateway is a network device, the cryptography service node is a service node, the quantum network node is a network node, the client hello message is a first encryption result, and the second encryption result contains a server hello message. Referring to FIG. 3, the client receives a first quantum key QK_UUID1 and a quantum key identifier UUID_QK sent by the cryptography service node. The quantum key identifier UUID_QK is helpful for managing and using the first quantum key QK_UUID1. After obtaining the first quantum key QK_UUID1 and the quantum key identifier UUID_QK, the client encrypts the quantum key identifier UUID_QK by using the post-quantum cryptography, and sends the client hello message encrypted by using the post-quantum cryptography to the network device.
[0146] Then, the secure access gateway receives the client hello message sent by the client, performs post-quantum cryptography decryption processing on the client hello message to obtain a first decryption result. The secure access gateway further performs post-quantum cryptography encryption processing on the first decryption result to obtain a server hello message. After obtaining the server hello message, the secure access gateway sends the server hello message to the client. The secure access gateway obtains the client_handshake_traffic_secret, that is, the first terminal handshake key, and the server_handshake_traffic_secret, that is, the first network device handshake key, according to related information in the first decryption result and related information in the server hello message. The secure access gateway further generates the client_handshake_traffic_secret2, that is, the second terminal handshake key, and the server_handshake_traffic_secret2, that is, the second network device handshake key, according to the second quantum key, the server_handshake_traffic_secret, the client_handshake_traffic_secret, the first decryption result, and the server hello message, so as to encrypt the communication between the client and the secure access gateway and protect the communication data.
[0147] Meanwhile, the client receives the server hello message sent by the secure access gateway, and decrypts the server hello message to obtain a second decryption result. Subsequently, the client obtains a client_handshake_traffic_secret, i.e., the first terminal handshake key, and a server_handshake_traffic_secret, i.e., the first network device handshake key, according to the client hello message and the second decryption result. The client generates a client_handshake_traffic_secret2, i.e., the second terminal handshake key, and a server_handshake_traffic_secret2, i.e., the second network device handshake key, according to the first quantum key, the server_handshake_traffic_secret, the client_handshake_traffic_secret, the related keys in the client hello message, and the second decryption result, to encrypt the communication between the client and the secure access gateway, and protect the communication data. In this way, even if the threat brought by the quantum computer is faced, the TLS handshake between the client and the secure access gateway can still provide secure data transmission. By using the post-quantum cryptography algorithm and the quantum key distribution technology, the communication can be more securely resistant to the threat brought by the quantum computer.
[0148] In summary, in the communication network, the anti-quantum security enhancement method of the transport layer security protocol, the communication system, the terminal, and the network device, for the communication process of the terminal and the network device, the terminal and the network device apply for obtaining a quantum key and a quantum key identifier, and encrypt the quantum key identifier by using a post-quantum cryptography algorithm to generate an anti-quantum key that can resist quantum computing attacks. The post-quantum cryptography algorithm is a series of encryption algorithms designed to resist quantum computing attacks. Meanwhile, the terminal and the network device exchange random numbers randomly generated by each other to generate a master key, and derive the first terminal handshake key and the first network device handshake key from the master key. The terminal and the network device fuse the quantum key, the terminal handshake key, the network device handshake key, and the anti-quantum key for use in the communication between the terminal and the network device. In this way, the anti-quantum computing attack ability of the network communication between the terminal and the network device is enhanced.
[0149] Referring to FIG. 4, in some embodiments, step 011 (obtaining a first quantum key and a quantum key identifier from a service node of an access terminal) includes:
[0150] 0111: charging a plurality of keys to a cryptographic module of the terminal by using the service node;
[0151] 0112: sending a quantum key application to the service node, and randomly using one of the plurality of keys filled into the cryptographic module as a protection key to protect the quantum key application;
[0152] 0113: receiving a quantum key encryption result obtained by the service node encrypting a first quantum key and a quantum key identifier according to the protection key, the first quantum key being generated by a first network node accessing the service node and distributed to the service node, and the quantum key identifier being obtained by the first network node marking the first quantum key according to an identification code of the first network node and distributed to the service node;
[0153] 0114: decrypting the quantum key encryption result to obtain the first quantum key and the quantum key identifier.
[0154] In some embodiments, the filling module is configured to fill the cryptographic module with keys by the service node, the application module is configured to send a quantum key application to the service node, and the quantum key application is protected by the service node using a key of the cryptographic module as a protection key, the receiving module is configured to receive a quantum key encryption result obtained by the service node encrypting a first quantum key and a quantum key identifier according to the protection key, the first quantum key being generated by a first network node accessing the service node and distributed to the service node, and the quantum key identifier being obtained by the first network node marking the first quantum key according to an identification code of the first network node and distributed to the service node. The decryption module is configured to decrypt the quantum key encryption result to obtain the first quantum key and the quantum key identifier.
[0155] In some embodiments, the processor is further configured to fill the cryptographic module with keys by the service node, and send a quantum key application to the service node, and the quantum key application is protected by the service node using a key of the cryptographic module as a protection key. Furthermore, the processor is configured to receive a first quantum key and a quantum key identifier distributed by the service node according to the quantum key application, the first quantum key being generated by a first network node accessing the service node and distributed to the service node, and the quantum key identifier being obtained by the first network node marking the first quantum key according to an identification code of the first network node and distributed to the service node, and the distribution of the first quantum key and the quantum key identifier is encrypted by the protection key to protect the first quantum key and the quantum key identifier.
[0156] Specifically, the terminal uses the service node to key-in the cryptographic module, so that the cryptographic module has sufficient keys and will not affect use. The terminal sends a quantum key application to the service node, and the quantum key application is encrypted and protected by using a randomly used key in the cryptographic module as a protection key. Subsequently, the terminal receives a quantum key encryption result obtained by the service node performing encryption processing on a first quantum key and a quantum key identifier according to the protection key, the first quantum key is generated by a first network node of the access service node and distributed to the service node, and the quantum key identifier is obtained by the first network node according to an identification code of the first network node to mark the first quantum key and distributed to the service node. The terminal further performs decryption processing on the quantum key encryption result to obtain the first quantum key and the quantum key identifier. In this way, the first quantum key and the quantum key identifier are obtained, the first quantum key can be used to generate a key with quantum computing attack resistance, and the quantum key identifier is helpful for use and management of the quantum key.
[0157] In the above example, the personal cryptographic module is a cryptographic module, please refer to Fig. 3 again, the client uses the cryptographic service node to pre-share key-in the personal cryptographic module, and the total capacity is 1Mbit key (size is 128bit), the personal cryptographic module used in this embodiment is a smart cryptographic key (HSM), and other personal cryptographic modules such as virtual security module (VSM) can be used in other schemes. Then, the client sends a quantum key application to the cryptographic service node, and uses a randomly used key in the smart cryptographic key as a protection key. One protection method is that the client uses SM3 algorithm to perform hash operation on key ID and application content, then the cryptographic service node uses the protection key to calculate HMAC (Hash-based Message Authentication Code) to ensure the integrity and authenticity of the data, and HMAC is a method of using hash function and key to provide data integrity and source authentication.
[0158] After the quantum key is applied successfully, the client receives the quantum key encryption result obtained by the password service node based on the protection key for encrypting the first quantum key QK_UUID1 and the quantum key identifier UUID_QK. The first quantum key QK_UUID1 is generated by the first quantum network node of the access password service node and distributed to the password service node. The quantum key identifier UUID_QK is obtained by the first quantum network node based on its unique universal identifier for marking the first quantum key and distributed to the password service node. The client then decrypts the quantum key encryption result based on the protection key to obtain the first quantum key QK_UUID1 and the quantum key identifier UUID_QK. This ensures the security of the quantum key application process. By using a random key and a hash function, the client can ensure the integrity and authenticity of the application content during transmission. In this way, the first quantum key and the quantum key identifier are obtained. The first quantum key can be used to generate a key with quantum computing attack resistance. The quantum key identifier helps to use and manage the quantum key.
[0159] Referring to FIG. 5, in some embodiments, step 012 (post-quantum cryptographic encryption processing of the quantum key, and sending the first encryption result processed by the post-quantum cryptographic encryption to the network device) includes:
[0160] 0121: Splicing the quantum key identifier and the first random number generated randomly to obtain the first handshake message;
[0161] 0122: Processing the first handshake message and the first handshake random number in the first encryption result to generate the second handshake message;
[0162] 0123: Post-quantum cryptographic derivation processing of the second handshake message to generate the first handshake key;
[0163] 0124: Post-quantum cryptographic encryption processing of the second handshake message to generate the first encryption message in the first encryption result;
[0164] 0125: Splicing the quantum key identifier and the first handshake random number to obtain the first verification message;
[0165] 0126: Post-quantum cryptographic signature processing of the first verification message to generate the first signature message in the first encryption result;
[0166] 0127: Sending the first encryption result to the network device.
[0167] In some embodiments, the splicing module is configured to splice the quantum key identifier and a first random number generated randomly to obtain a first handshake message. The processing module is configured to process the first handshake message and a first handshake random number in the first encryption result to generate a second handshake message. The derivation module is configured to perform post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key. The encryption module is configured to perform post-quantum cryptographic encryption processing on the second handshake message to generate a first encrypted message in the first encryption result. The splicing module is further configured to splice the quantum key identifier and the first handshake random number to obtain a first verification message. The signature module is configured to perform post-quantum cryptographic signature processing on the first verification message to generate a first signature message in the first encryption result. The sending module is configured to send the first encryption result to the network device.
[0168] In some embodiments, the processor is further configured to splice the quantum key identifier and a first random number generated randomly to obtain a first handshake message, process the first handshake message and a first handshake random number in the first encryption result to generate a second handshake message, and perform post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key. In addition, the processor is further configured to perform post-quantum cryptographic encryption processing on the second handshake message to generate a first encrypted message in the first encryption result, splice the quantum key identifier and the first handshake random number to obtain a first verification message, perform post-quantum cryptographic signature processing on the first verification message to generate a first signature message in the first encryption result, and send the first encryption result to the network device.
[0169] Specifically, the terminal splices the quantum key identifier and a first random number generated randomly to obtain a first handshake message, which increases the complexity of the quantum key identifier. Then, the terminal processes the first handshake message and a first handshake random number in the first encryption result to generate a second handshake message. The terminal further performs post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key, which has the ability to resist quantum computing attacks. Then, the terminal performs post-quantum cryptographic encryption processing on the second handshake message to generate a first encrypted message in the first encryption result. The terminal further splices the quantum key identifier and the first handshake random number to obtain a first verification message. Finally, the terminal performs post-quantum cryptographic signature processing on the first verification message to generate a first signature message in the first encryption result and sends the first encryption result to the network device, and the first signature message is used to ensure the integrity and authenticity of the message, and any unauthorized access and tampering will be detected. In this way, the confidentiality of the quantum key identifier is increased by splicing with the first random number, and the quantum key identifier and its derivative are processed using post-quantum cryptographic algorithms to combine quantum key distribution technology with post-quantum cryptographic technology to increase the complexity of the quantum key identifier.
[0170] In the foregoing example, the client combines the PQC post-quantum cryptographic algorithm with the ECDHA key exchange and ECDSA signature of the classical PKI system, and combines the PQC key encapsulation and PQC digital signature algorithm with the QKD quantum key distribution and other anti-quantum means. The client hello message is the first encryption result, the Certificate Authorities is used to list the certificate authorities trusted by the client, the DN is a string used to uniquely identify the certificate holder, including organization, geographic location, country, and other information. Please refer to FIG. 3 again, the client initiates the TLS handshake, when having the post-quantum cryptography (PQC) certificate, the DN name of the CA (certificate authority) issuing the PQC certificate is added in the extension of the type “Certificate Authorities”. Two types of extensions are expanded: the pqc_key_share and the pqc_signature, the content of the pqc_key_share includes the algorithm ID, algorithm parameters, and key encapsulation information of the PQC key encapsulation.
[0171] The content of the pqc_signature includes the algorithm ID, algorithm parameters, and digital signature information of the PQC digital signature.
[0172] When not having the post-quantum cryptography certificate, the client does not add the DN name of the CA (certificate authority) issuing the PQC certificate in the extension of the type “Certificate Authorities”, and the secure access gateway also does not process. When not having the PQC certificate, the client and the secure access gateway end can import the PQC signature public key and the encryption public key of the other party in an offline manner, and through this method, it is ensured that the communication between the client and the secure access gateway is established on the basis of mutual trust. Then, the pqc_key_share and the pqc_signature type of extension are added on the basis of the original TLS 1.3 protocol client hello message.
[0173] Then, the client concatenates the quantum key identifier UUID QK and a first random number r1 (128 bits) generated by the client to obtain a first handshake message m1. Subsequently, the client XORs the first handshake message m1 and the first handshake random number R1 in the client hello message to generate a second handshake message m2. Next, the client runs the G function of the PQC algorithm to obtain a first handshake key K1, taking the second handshake message m2 as the encrypted message m in the PQC key encapsulation algorithm, and encapsulates the information as the extension_data content of the pqc_key_share. The second handshake message m2 is then post-quantum cryptography encrypted to generate the first encrypted message in the client hello message. The client concatenates the quantum key identifier UUID QK and the first handshake random number R1 to obtain a first verification message, and takes the first verification message as the signed message M in the PQC signature algorithm to generate the first signature message M1 in the client hello message, and the signature information is taken as the extension_data content of the pqc_signature. Finally, the client sends the client hello message to the secure access gateway. In this way, the client increases the confidentiality of the quantum key identifier by concatenating the quantum key identifier UUID QK and the first random number generated by the client, and processes the quantum key identifier UUID QK and its derivatives using the post-quantum cryptography algorithm to combine the quantum key distribution technology and the post-quantum cryptography technology to increase the complexity of the quantum key identifier.
[0174] Referring to FIG. 6, in some embodiments, step 013 (decrypting the received second encrypted result sent by the network device to obtain a second decrypted result, the second encrypted result being obtained according to the first encrypted result) comprises:
[0175] 0131: receiving the second encrypted result sent by the network device, the second encrypted result being obtained by the network device performing post-quantum cryptography encryption on the first decrypted result, the first decrypted result being obtained by the network device decrypting the first encrypted result;
[0176] 0132: decrypting the second encrypted result to obtain a second decrypted result, the second decrypted result comprising a second handshake random number, a fourth handshake message, and a second signature message.
[0177] In some embodiments, the receiving module is further configured to receive a second encryption result sent by the network device, the second encryption result being obtained by the network device from post-quantum cryptographic encryption processing on a first decryption result, the first decryption result being obtained by the network device from decryption processing on the first encryption result, and the decryption module is further configured to obtain a second decryption result from decryption processing on the second encryption result, the second decryption result comprising the second handshake random number, the fourth handshake message, and the second signature message.
[0178] In some embodiments, the processor is further configured to receive a second encryption result sent by the network device, the second encryption result being obtained by the network device from post-quantum cryptographic encryption processing on a first decryption result, the first decryption result being obtained by the network device from decryption processing on the first encryption result, and obtain a second decryption result from decryption processing on the second encryption result, the second decryption result comprising the second handshake random number, the fourth handshake message, and the second signature message.
[0179] Specifically, the terminal receives a second encryption result sent by the network device, the second encryption result being obtained by the network device from post-quantum cryptographic encryption processing on a first decryption result, the first decryption result being obtained by the network device from decryption processing on the first encryption result. Then, the terminal obtains a second decryption result from decryption processing on the second encryption result, the second decryption result comprising the second handshake random number, the fourth handshake message, and the second signature message. In this way, the terminal determines the availability of the channel for communication with the network device and obtains the key information of the network device, which can be combined with the relevant key information of the terminal to generate a higher-security key.
[0180] Continuing with the above example, the server hello message is the second encryption result, please refer to FIG. 3 again, the client receives a server hello message sent by the secure access gateway, the server hello message being obtained by the secure access gateway from encryption processing on a first decryption result, the first decryption result being obtained by the secure access gateway from decryption processing on the client hello message. Then, the client obtains a second decryption result from decryption processing on the server hello message, the second decryption result comprising the second handshake random number R2, the fourth handshake message m4, and the second signature message M2. In this way, the client determines the availability of the channel for communication with the secure access gateway and obtains the key information of the secure access gateway, which can be combined with the relevant key information of the client to generate a higher-security key.
[0181] Please refer to FIG. 7, in some embodiments, the method further comprises:
[0182] 016: obtaining a second handshake key according to the fourth handshake message;
[0183] 017: obtaining the third handshake message and the quantum key identifier from the fourth handshake message and the second handshake random number.
[0184] In some embodiments, the deriving module is configured to obtain the second handshake key from the fourth handshake message, and obtain the third handshake message and the quantum key identifier from the fourth handshake message and the second handshake random number.
[0185] In some embodiments, the processor is further configured to obtain the second handshake key from the fourth handshake message, and obtain the third handshake message and the quantum key identifier from the fourth handshake message and the second handshake random number.
[0186] In particular, the terminal obtains the second handshake key from the fourth handshake message. Then, the terminal obtains the third handshake message and the quantum key identifier from the fourth handshake message and the second handshake random number. The second handshake key is obtained for subsequent key generation to obtain a key with good resistance to quantum computing attacks.
[0187] Continuing with the above example, referring again to FIG. 3, the client obtains the second handshake key K2 from the fourth handshake message m4. Then, the client obtains the third handshake message m3 from the fourth handshake message m4 and the second handshake random number R2 by XOR operation, and obtains the quantum key identifier UUID QK from the third handshake message m3. The client obtains the second handshake key K2 for subsequent key generation to obtain a key with good resistance to quantum computing attacks.
[0188] Referring to FIG. 8, in some embodiments, the method further comprises:
[0189] 018: obtaining the second verification message from the second signed message;
[0190] 019: performing post-quantum cryptographic signature verification on the second signed message to confirm the correctness of the second verification message, the second verification message being obtained by concatenating the quantum key identifier and the second handshake random number.
[0191] In some embodiments, the processing module is configured to obtain the second verification message from the second signed message, and the signature verification module is configured to perform post-quantum cryptographic signature verification on the second signed message to confirm the correctness of the second verification message, the second verification message being obtained by concatenating the quantum key identifier and the second handshake random number.
[0192] In some embodiments, the processor is further configured to obtain the second verification message from the second signed message, and perform post-quantum cryptographic signature verification on the second signed message to confirm the correctness of the second verification message, the second verification message being obtained by concatenating the quantum key identifier and the second handshake random number.
[0193] Specifically, the terminal obtains the second verification message according to the second signed message, and performs post-quantum cryptographic signature verification on the second signed message to confirm the correctness of the second verification message. Through the signature verification process, the terminal can confirm the identity of the network device and the integrity of the data, providing security for subsequent data transmission.
[0194] With reference to the above example, please refer to FIG. 3 again. The client obtains the second verification message according to the second signed message, and performs post-quantum cryptographic signature verification on the second signed message M2 to confirm the correctness of the second verification message, i.e., to confirm that the correct quantum key identifier UUID_QK and the second handshake random number R2 are received. Through this process, the client and the secure access gateway achieve secure data exchange and communication, ensuring the confidentiality, integrity, and authenticity of the data.
[0195] Please refer to FIG. 9. In some embodiments, the first encrypted result includes the first handshake random number, and the second decrypted result includes the second handshake random number. Step 014 (obtaining the first terminal handshake key and the first network device handshake key according to the first encrypted result and the second decrypted result) includes:
[0196] 0141: generating a master key according to the first handshake random number and the second handshake random number;
[0197] 0142: deriving the first terminal handshake key and the first network device handshake key according to the master key.
[0198] In some embodiments, the derivation module is further configured to generate a master key according to the first handshake random number and the second handshake random number, and derive the first terminal handshake key and the first network device handshake key according to the master key.
[0199] In some embodiments, the processor is further configured to generate a master key according to the first handshake random number and the second handshake random number, and derive the first terminal handshake key and the first network device handshake key according to the master key.
[0200] Specifically, the terminal generates a master key according to the first handshake random number and the second handshake random number, and then derives the first terminal handshake key and the first network device handshake key according to the master key. The terminal generates a master key by using a randomly generated random number, and then derives the first terminal handshake key and the first network device handshake key from the master key using a cryptographic algorithm for subsequent key derivation.
[0201] Please refer to FIG. 3 again, the client generates the master secret key according to the first handshake random number R1 and the second handshake random number R2, and then calculates the first terminal handshake key client_handshake_traffic_secret and the first network device handshake key server_handshake_traffic_secret according to the TLS 1.3 protocol specification.
[0202] In this way, the client generates the master secret key by using the randomly generated random number, and then derives the first terminal handshake key client_handshake_traffic_secret and the first network device handshake key server_handshake_traffic_secret from the master secret key by using the cryptographic algorithm for subsequent key derivation.
[0203] Please refer to FIG. 10, in some embodiments, the step 015 (generating the second terminal handshake key and the second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result and the second decryption result, so as to encrypt the communication between the terminal and the network device) comprises:
[0204] 0151: generating the second terminal handshake key according to the first quantum key, the first terminal handshake key, the first handshake key and the second handshake key;
[0205] 0152: generating the second network device handshake key according to the first quantum key, the first network device handshake key, the first handshake key and the second handshake key;
[0206] 0153: encrypting the communication between the terminal and the network device according to the second terminal handshake key and the second network device handshake key.
[0207] In some embodiments, the derivation module is further configured to generate the second terminal handshake key according to the first quantum key, the first terminal handshake key, the first handshake key and the second handshake key, and to generate the second network device handshake key according to the first quantum key, the first network device handshake key, the first handshake key and the second handshake key. The encryption module is further configured to encrypt the communication between the terminal and the network device according to the second terminal handshake key and the second network device handshake key.
[0208] In some embodiments, the processor is further configured to generate a second terminal handshake key based on the first quantum key, the first terminal handshake key, the first handshake key, and the second handshake key, and generate a second network device handshake key based on the first quantum key, the first network device handshake key, the first handshake key, and the second handshake key, and encrypt communication between the terminal and the network device based on the second terminal handshake key and the second network device handshake key.
[0209] Specifically, the terminal generates a second terminal handshake key based on the first quantum key, the first terminal handshake key, the first handshake key, and the second handshake key. Then, the terminal generates a second network device handshake key based on the first quantum key, the first network device handshake key, the first handshake key, and the second handshake key. Finally, the terminal encrypts communication between the terminal and the network device based on the second terminal handshake key and the second network device handshake key. In this way, the ability of the communication between the network devices to resist quantum computing attacks is enhanced by using the keys generated by combining the quantum key distribution technology and the post-quantum cryptography technology, and the data transmitted in the communication process is protected.
[0210] In the foregoing example, the client generates a first terminal key client_handshake_traffic_secret based on the first terminal handshake key client_handshake_traffic_secret, the first quantum key QK_UUID1, and the first handshake key K1. The client generates a first network device key server_handshake_traffic_secret based on the first network device handshake key server_handshake_traffic_secret, the first quantum key QK_UUID1, and the first handshake key K1. The client and the secure access gateway use the generated first terminal key and the first network device key to encrypt the communication between the terminal and the network device. In this way, the ability of the network device to resist quantum computing attacks is enhanced by using the key generated by combining the quantum key distribution technology and the post-quantum cryptography technology, and the data transmitted in the communication process is protected. After generating the first terminal key and the first network device key, the client and the secure access gateway perform subsequent handshake messages under the protection of the first terminal key client_handshake_traffic_secret and the first network device key server_handshake_traffic_secret and the derived write_key and write_iv according to the TLS 1.3 protocol specification. When the PQC certificate is available, the client adds the PQC signature certificate and the PQC encryption certificate in the client Certificate message. The authentication range of the CertificateVerify and Finished messages of the client and the secure access gateway covers the above newly added PQC related messages. The client and the gateway finally generate a client application traffic key client_application_traffic_secret and a gateway application traffic key server_application_traffic_secret and the derived write_key and write_iv and other keys for application data protection of the record layer protocol. The client application traffic key client_application_traffic_secret and the gateway application traffic key server_application_traffic_secret are used to encrypt the application data sent by the client, to ensure the confidentiality and integrity of the data in the transmission process.
[0211] Referring to FIG. 11, the embodiment of the application provides a method for anti-quantum security enhancement of a transport layer security protocol of a communication network, the communication network comprising a terminal and a network device, the method being used for the network device, and the method comprising:
[0212] 021: receiving a first encryption result of a quantum key identifier encrypted by the terminal by using post-quantum cryptography, the quantum key identifier being obtained by the terminal from a cryptographic service node accessed by the terminal;
[0213] 022: decrypting the first encryption result to obtain a first decryption result;
[0214] 023: encrypting the first decryption result by using post-quantum cryptography to obtain a second encryption result;
[0215] 024: obtaining a first terminal handshake key and a first network device handshake key according to the first decryption result and the second encryption result;
[0216] 025: generating a second terminal handshake key and a second network device handshake key according to a second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result and the second encryption result, so as to encrypt the communication between the terminal and the network device.
[0217] The application also provides a network device comprising a memory and a processor. The method of the application can be implemented by the network device of the application. Specifically, the memory stores a computer program, and the processor is configured to receive a first encryption result of a first quantum key encrypted by a terminal by using post-quantum cryptography, the first quantum key being obtained by the terminal from a cryptographic service node accessed by the terminal. The processor is also configured to decrypt the first encryption result to obtain a first decryption result, and encrypt the first decryption result by using post-quantum cryptography to obtain a second encryption result. The processor is further configured to obtain a first terminal handshake key and a first network device handshake key according to the first decryption result and the second encryption result, and generate a second terminal handshake key and a second network device handshake key according to a second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result and the second encryption result, so as to encrypt the communication between the terminal and the network device.
[0218] The method of the embodiments of the present application can be implemented by the network device of the embodiments of the present application. Specifically, the network device comprises a receiving module, a decryption module, an encryption module, and a derivation module. The receiving module is configured to receive a first encryption result of post-quantum cryptographic encryption processing of a terminal on a first quantum key, the first quantum key being obtained by the terminal from a cryptographic service node accessed by the terminal. The decryption module is configured to perform decryption processing on the first encryption result to obtain a first decryption result. The encryption module is configured to perform post-quantum cryptographic encryption processing on the first decryption result to obtain a second encryption result. The derivation module is configured to obtain a first terminal handshake key and a first network device handshake key according to the first decryption result and the second encryption result, and generate a second terminal handshake key and a second network device handshake key according to a second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result, and the second encryption result, so as to encrypt communication between the terminal and the network device.
[0219] Specifically, in the embodiments of the present application, the terminal sends a quantum key application, obtains a first quantum key and a quantum key identifier from a service node accessed by the terminal, the first quantum key and the quantum key identifier can be used to generate a key with quantum computing attack resistance, and the quantum key identifier is helpful for use and management of the quantum key. After obtaining the first quantum key and the quantum key identifier, the terminal performs post-quantum cryptographic encryption processing on the quantum key identifier, and sends a first encryption result of the post-quantum cryptographic encryption processing to the network device. By performing post-quantum cryptographic encryption processing on the quantum key identifier, the quantum key distribution technology is combined with the post-quantum cryptographic technology to improve the complexity of the key, and the encryption result is sent to the network device for sharing, so that the communication data of the terminal and the network device in the communication network remains consistent.
[0220] Then, after receiving the first encryption result sent by the terminal, the network device performs decryption processing on the first encryption result to obtain a first decryption result. The network device then performs post-quantum cryptographic encryption processing on the first decryption result to obtain a second encryption result. After obtaining the second encryption result, the network device sends the second encryption result to the terminal so that the terminal can also share the network device information and the generated key. The network device then obtains a first terminal handshake key and a first network device key according to the first decryption result and the second encryption result, and generates a second terminal handshake key and a second network device handshake key according to a second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result, and the second encryption result, so as to encrypt communication between the terminal and the network device.
[0221] Meanwhile, the terminal receives the second encryption result sent by the network device, and decrypts the second encryption result to obtain a second decryption result. The terminal obtains a first terminal handshake key and a first network device key according to the first encryption result and the second decryption result, and generates a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result and the second encryption result, so as to encrypt the communication between the terminal and the network device.
[0222] In this way, in the communication process between the terminal and the network device, the terminal and the network device apply for obtaining a quantum key and a quantum key identifier, and encrypt the quantum key identifier by using a post-quantum cryptography algorithm to generate an anti-quantum key capable of resisting quantum computing attacks. The post-quantum cryptography algorithm is a series of encryption algorithms designed to resist quantum computing attacks. Meanwhile, the terminal and the network device exchange the random numbers randomly generated by each other to generate a master key, and derive the first terminal handshake key and the first network device handshake key from the master key. The terminal and the network device further fuse the quantum key, the terminal handshake key, the network device handshake key and the anti-quantum key for use in the communication between the terminal and the network device. In this way, the anti-quantum computing attack capability of the network communication between the terminal and the network device is enhanced.
[0223] Continuing the above example, please refer to FIG. 3 again, the client receives the first quantum key QK_UUID1 and the quantum key identifier UUID_QK sent by the cryptography service node, and the quantum key identifier UUID_QK helps to manage and use the first quantum key QK_UUID1. After obtaining the first quantum key QK_UUID1 and the quantum key identifier UUID_QK, the client encrypts the quantum key identifier UUID_QK by using a post-quantum cryptography algorithm, and sends the post-quantum cryptography encrypted client hello message to the network device.
[0224] Then, the secure access gateway receives the client hello message sent by the client, and performs quantum cryptography decryption on the client hello message to obtain a first decryption result. The secure access gateway further performs post-quantum cryptography encryption on the first decryption result to obtain a server hello message. After obtaining the server hello message, the secure access gateway sends the server hello message to the client. The secure access gateway obtains the client_handshake_traffic_secret, i.e., the first terminal handshake key, and the server_handshake_traffic_secret, i.e., the first network device handshake key, according to relevant information in the first decryption result and relevant information in the server hello message. The secure access gateway further generates the client_handshake_traffic_secret2, i.e., the second terminal handshake key, and the server_handshake_traffic_secret2, i.e., the second network device handshake key, according to the second quantum key, the server_handshake_traffic_secret, the client_handshake_traffic_secret, the first decryption result, and the server hello message, to encrypt the communication between the client and the secure access gateway and protect the communication data.
[0225] Meanwhile, the client receives the server hello message sent by the secure access gateway, and performs decryption on the server hello message to obtain a second decryption result. Subsequently, the client obtains the client_handshake_traffic_secret, i.e., the first terminal handshake key, and the server_handshake_traffic_secret, i.e., the first network device handshake key, according to the client hello message and the second decryption result. The client further generates the client_handshake_traffic_secret2, i.e., the second terminal handshake key, and the server_handshake_traffic_secret2, i.e., the second network device handshake key, according to the first quantum key, the server_handshake_traffic_secret, the client_handshake_traffic_secret, relevant keys in the client hello message, and the second decryption result, to encrypt the communication between the client and the secure access gateway and protect the communication data.
[0226] In this way, even in the face of the threat posed by quantum computers, the TLS handshake between the client and the secure access gateway can still provide secure data transmission. By using post-quantum cryptography algorithms and quantum key distribution techniques, communication can be more secure against the threat posed by quantum computers.
[0227] Referring to FIG. 12, in some embodiments, the method further comprises:
[0228] 026: accessing the second network node through the pre-established channel;
[0229] 027: loading the security certificate of the terminal or the security certificate of the network device.
[0230] In some embodiments, the access module is configured to access the second network node through the pre-established channel, and the loading module is configured to load the security certificate of the terminal or the security certificate of the network device.
[0231] In some embodiments, the processor is further configured to access the second network node through the pre-established channel, and load the security certificate of the terminal or the security certificate of the network device.
[0232] Specifically, before data transmission with the terminal, the network device accesses the second network node through the pre-established channel, which can protect data during data transmission and reduce the risk of unauthorized access. Then, the network device loads the security certificate of the network device or the security certificate of the terminal, which will be used to establish and maintain a secure communication channel after loading, enhancing the security of data during transmission.
[0233] Referring back to FIG. 3, before data transmission with the client, the secure access gateway accesses the second quantum network node that is closest in physical distance and has completed authorization through a trusted channel, which refers to a mechanism or protocol that provides a secure communication path between two communication entities. One way to establish is that the secure access gateway and the second quantum network node are inside the same cabinet and are directly connected by shielded network cables. This channel ensures the confidentiality, integrity, and availability of data during transmission, preventing unauthorized access, tampering, or eavesdropping. At the same time, through offline import, the secure access gateway and the client load the public key of the key pair of the post-quantum cryptography algorithm of the other party, or the certificate of the post-quantum cryptography algorithm of itself issued by the certificate system, which includes encryption certificates and signature certificates. Offline import means that the transmission of keys or certificates will not pass through the Internet or other network paths that may be monitored or attacked, ensuring the security of the transmission process. In this way, the secure access gateway accesses the second quantum network node through a trusted channel and loads security certificates through offline import, ensuring the confidentiality of network device data and reducing the risk of data leakage.
[0234] Please refer to Figure 13. In some implementations, the first decryption result includes the second handshake message and the first handshake random number. The method further includes:
[0235] 028: Obtain the first handshake message based on the second handshake message and the first handshake random number;
[0236] 029: Obtain the quantum key identifier based on the first handshake message.
[0237] In some implementations, the derived module is further configured to obtain the first handshake message based on the second handshake message and the first handshake random number, and the processing module is configured to obtain the quantum key identifier based on the first handshake message.
[0238] In some implementations, the processor is further configured to obtain the first handshake message based on the second handshake message and the first handshake random number, and to obtain the quantum key identifier based on the first handshake message.
[0239] Specifically, the network device obtains the first handshake message based on the second handshake message and the first handshake random number, and then obtains the quantum key identifier based on the first handshake message. This quantum key identifier, obtained in this way, can be used to apply for the second quantum key.
[0240] Continuing with the example above, please refer to Figure 3 again. The secure access gateway XORs the second handshake message m2 with the first handshake random number R1 to obtain the first handshake message, and then obtains the quantum key identifier UUID_QK based on the first handshake message. The quantum key identifier UUID_QK is obtained in this way, and this quantum key identifier UUID_QK can be used to apply for quantum keys.
[0241] Please refer to Figure 14. In some embodiments, the first decryption result includes a first signature message, and the method further includes:
[0242] 030: Obtain the first verification message based on the first signature message;
[0243] 031: Perform post-quantum cryptographic verification on the first signed message to confirm that the correct first verification message has been obtained. The first verification message is composed of the first handshake random number and the quantum key identifier.
[0244] 032: If the obtained quantum key identifier is correct, obtain the second quantum key from the network node of the access network device.
[0245] In some implementations, the processing module is used to obtain a first verification message based on the first signature message, the verification module is used to perform post-quantum cryptographic verification processing on the first signature message to confirm that the correct first verification message has been obtained, the first verification message is composed of a first handshake random number and a quantum key identifier, and the acquisition module is used to obtain a second quantum key from the network node of the access network device if the quantum key identifier is correct.
[0246] In some implementations, the processor is further configured to obtain a first verification message based on the first signature message, and perform post-quantum cryptographic verification processing on the first signature message to confirm that the correct first verification message has been obtained. The first verification message is composed of a first handshake random number and a quantum key identifier. If the quantum key identifier is correct, the processor is configured to obtain a second quantum key from the network node of the access network device.
[0247] Specifically, the network device performs post-quantum cryptographic verification on the first signed message to confirm that it has received the correct first verification message, ensuring the integrity and legitimacy of the data source. When the received first verification message is correct, i.e., the received quantum key identifier is correct, the network device requests a second quantum key from the network nodes accessing the network device using the quantum key identifier. This ensures that the obtained second quantum key matches the first quantum key of the first network device, and this quantum key is used to generate a more secure key.
[0248] Continuing the example above, the secure access gateway performs post-quantum cryptographic verification processing on the first signature message M1 to confirm that it has received the correct first verification message, i.e., it has confirmed that it has received the correct quantum key identifier UUID_QK and the first handshake random number R1. When the received first verification message is correct, i.e., the received quantum key identifier UUID_QK is correct, the network device requests a second quantum key QK_UUID2 from the second quantum network node accessing the secure access gateway using the quantum key identifier UUID_QK. This ensures that the obtained second quantum key QK_UUID2 matches the terminal's first quantum key, which is used to generate a more secure key.
[0249] Please refer to Figure 15. In some embodiments, step 023 (performing post-quantum cryptographic encryption on the first decryption result to obtain the second encryption result) includes:
[0250] 0231: The third handshake message is obtained by concatenating the quantum key identifier with a randomly generated second random number;
[0251] 0232: Process the second handshake random number in the third handshake message and the second encryption result to generate the fourth handshake message;
[0252] 0233: Perform post-quantum cryptographic derivation processing on the fourth handshake message to generate the second handshake key;
[0253] 0234: Perform post-quantum cryptographic encryption on the fourth handshake message to generate the second encrypted message in the second encryption result;
[0254] 0235: The second verification message is obtained by concatenating the quantum key identifier and the second handshake random number;
[0255] 0236: Perform post-quantum cryptographic signing processing on the second verification message to generate the second signature message in the second encryption result;
[0256] 0237: Send the second encryption result to the terminal.
[0257] In some implementations, the concatenation module concatenates the quantum key identifier with a randomly generated second random number to obtain a third handshake message. The processing module processes the third handshake message and the second handshake random number from the second encryption result to generate a fourth handshake message. The derivation module performs post-quantum cryptographic derivation processing on the fourth handshake message to generate a second handshake key. The encryption module performs post-quantum cryptographic encryption processing on the fourth handshake message to generate a second encrypted message from the second encryption result. The concatenation module also concatenates the quantum key identifier with the second handshake random number to obtain a second verification message. The signing module performs post-quantum cryptographic signing processing on the second verification message to generate a second signed message from the second encryption result. The sending module sends the second encryption result to the terminal.
[0258] In some embodiments, the processor is further configured to concatenate the quantum key identifier with a randomly generated second random number to obtain a third handshake message, process the third handshake message and the second handshake random number in the second encryption result to generate a fourth handshake message, and perform post-quantum cryptographic derivation processing on the fourth handshake message to generate a second handshake key. Furthermore, the processor is also configured to perform post-quantum cryptographic encryption processing on the fourth handshake message to generate a second encrypted message in the second encryption result, concatenate the quantum key identifier with the second handshake random number to obtain a second verification message, perform post-quantum cryptographic signature processing on the second verification message to generate a second signature message in the second encryption result, and send the second encryption result to the terminal.
[0259] Specifically, the network device concatenates the quantum key identifier with a randomly generated second random number to obtain the third handshake message. Then, the network device XORs the third handshake message with the second handshake random number from the second encryption result to generate the fourth handshake message in the second encryption result. Next, the network device performs post-quantum cryptographic derivation processing on the fourth handshake message to generate the second handshake key, and then performs post-quantum cryptographic encryption processing on the fourth handshake message to generate the second encrypted message in the second encryption result. The network device then concatenates the quantum key identifier with the second handshake random number to obtain the second verification message. Finally, the network device performs post-quantum cryptographic signature processing on the second verification message to generate the second signature message in the second encryption result. The second encryption result is then sent to the terminal. Concatenating with the second random number increases the confidentiality of the quantum key identifier, and the use of post-quantum cryptographic algorithms to encrypt the quantum key identifier and its derivatives combines quantum key distribution technology with post-quantum cryptography to increase the complexity of the quantum key identifier.
[0260] Continuing the example above, the secure access gateway integrates the PQC post-quantum cryptography algorithm with the classic PKI system's ECDHA key exchange and ECDSA signature, organically combining PQC key encapsulation and PQC digital signature algorithms with quantum-resistant methods such as QKD quantum key distribution. The second encryption result includes a server hello message. `Certificate Authorities` lists the certificate authorities trusted by the client, and `DN` is a string used to uniquely identify the certificate holder, including information such as organization, geographical location, and country. Referring again to Figure 3, when a post-quantum cryptography (PQC) certificate is available, the secure access gateway adds the DN name of the CA (Certificate Authority) that issued the PQC certificate to the "Certificate Authorities" extension. Two types of extensions are available: `pqc_key_share` and `pqc_signature`.
[0261] The pqc_key_share contains the algorithm ID, algorithm parameters, and key encapsulation information for PQC key encapsulation.
[0262] The pqc_signature contains the algorithm ID, algorithm parameters, and digital signature information for the PQC digital signature.
[0263] When a post-quantum cryptography certificate is unavailable, the client does not include the Certificate Authority (CA) name (DN) that issued the PQC certificate in the "Certificate Authorities" extension, and the secure access gateway does not process this information either. When a PQC certificate is unavailable, the client and secure access gateway can import each other's PQC signing and encryption public keys offline. This method ensures that communication between the client and secure access gateway is based on mutual trust. Subsequently, extensions of type pqc_key_share and pqc_signature are added to the existing TLS 1.3 server hello message.
[0264] Then, the secure access gateway concatenates the quantum key identifier UUID_QK with a first random number r2 (128 bits) randomly generated by the secure access gateway to obtain the third handshake message m3. Next, the secure access gateway XORs the third handshake message m3 with the second handshake random number R2 from the server hello message to generate the fourth handshake message m4. Then, the secure access gateway uses the fourth handshake message m4 as the encrypted message m in the PQC key encapsulation algorithm, runs the G function of the PQC algorithm to obtain the second handshake key K2, and uses the encapsulation information as the extension_data content of pqc_key_share. The fourth handshake message m4 is then subjected to post-quantum cryptographic encryption to generate the second encrypted message in the server hello message. The secure access gateway concatenates the quantum key identifier UUID_QK with the second handshake random number R2 to obtain the second verification message, and uses the second verification message as M in the PQC signature algorithm for PQC signature protection to generate the second signed message M2 in the server hello message. The signature information is used as the extension_data content of pqc_signature. Finally, the secure access gateway sends a server hello message to the client. In this way, the secure access gateway increases the confidentiality of the quantum key identifier (UUID_QK) by concatenating it with a randomly generated second random number r2, and further increases the complexity of the quantum key identifier by processing it and its derivatives using post-quantum cryptography algorithms, combining quantum key distribution technology with post-quantum cryptography.
[0265] Please refer to Figure 16. In some embodiments, the first decryption result includes a first handshake random number, and the second encryption result includes a second handshake random number. Step 024 (obtaining the first terminal handshake key and the first network device handshake key based on the first decryption result and the second encryption result) includes:
[0266] 0241: Generate the master key based on the first handshake random number and the second handshake random number;
[0267] 0242: Obtain the first terminal handshake key and the first network device handshake key by deriving from the master key.
[0268] In some implementations, the derivation module is also used to generate a master key based on the first handshake random number and the second handshake random number, and to derive a first terminal handshake key and a first network device handshake key based on the master key.
[0269] In some implementations, the processor is further configured to generate a master key based on a first handshake random number and a second handshake random number, and to derive a first terminal handshake key and a first network device handshake key based on the master key.
[0270] Specifically, the secure access gateway generates a master key based on the first handshake random number in the first decryption result and the second handshake random number in the second encryption result. Then, the secure access gateway derives a first terminal handshake key and a first network device handshake key from the generated master key. In this way, the master key is generated using randomly generated random numbers, and then cryptographic algorithms are used to derive the first terminal handshake key and the first network device handshake key from the master key for subsequent key derivation.
[0271] Continuing with the example above, please refer to Figure 3 again. The secure access gateway generates a master key based on the first handshake random number R1 and the second handshake random number R2. Then, according to the TLS 1.3 protocol specification, it calculates the first terminal handshake key `client_handshake_traffic_secret` and the first network device handshake key `server_handshake_traffic_secret`. The secure access gateway generates the master key using randomly generated random numbers, and then uses cryptographic algorithms to derive the first terminal handshake key `client_handshake_traffic_secret` and the first network device handshake key `server_handshake_traffic_secret` from the master key for subsequent key derivation.
[0272] Referring to Figure 17, in some embodiments, the first decryption result includes a second handshake message. Step 025 (generating a second terminal handshake key and a second network device handshake key based on the second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result, and the second encryption result to encrypt communication between the terminal and the network device) includes:
[0273] 0251: Perform post-quantum cryptographic derivation processing on the second handshake message to generate the first handshake key;
[0274] 0252: Generate the second terminal handshake key based on the second quantum key, the first terminal handshake key, the first handshake key, and the second handshake key;
[0275] 0253: Generate the second network device handshake key based on the second quantum key, the first network device handshake key, the first handshake key, and the second handshake key;
[0276] 0254: Encrypt the communication between the terminal and the network device based on the second terminal handshake key and the second network device handshake key.
[0277] In some embodiments, the derivation module is further configured to perform post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key, and to generate a second terminal handshake key based on the second quantum key, the first terminal handshake key, the first handshake key, and the second handshake key, and to generate a second network device handshake key based on the second quantum key, the first network device handshake key, the first handshake key, and the second handshake key. The communication module is configured to encrypt the communication between the terminal and the network device based on the second terminal handshake key and the second network device handshake key.
[0278] In some embodiments, the processor is further configured to perform post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key, and generate a second terminal handshake key based on the second quantum key, the first terminal handshake key, the first handshake key, and the second handshake key, and generate a second network device handshake key based on the second quantum key, the first network device handshake key, the first handshake key, and the second handshake key, and encrypt the communication between the terminal and the network device based on the second terminal handshake key and the second network device handshake key.
[0279] Specifically, first, the network device performs post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key. Then, the network device generates a second terminal key based on the first terminal handshake key, the second quantum key, the first handshake key, and the second handshake key. Next, the network device generates a second network device key based on the first network device handshake key, the second quantum key, the first handshake key, and the second handshake key. The network device then uses the generated second terminal key and second network device key to encrypt the communication between the terminal and the network device. This method, by using a key generated combining quantum key distribution technology and post-quantum cryptography, enhances the resistance of communication between network devices to quantum computing attacks, protecting the data transmitted during the communication process.
[0280] Continuing the example above, firstly, the secure access gateway performs post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key K1. Then, the secure access gateway generates a second terminal key, client_handshake_traffic_secret2, based on the first terminal handshake key client_handshake_traffic_secret, the first quantum key QK_UUID1, the first handshake key K1, and the second handshake key K2. Next, the client generates a second network device key, server_handshake_traffic_secret2, based on the first network device handshake key server_handshake_traffic_secret, the first quantum key QK_UUID1, the first handshake key K1, and the second handshake key K2. The generated second terminal key and second network device key are then used to encrypt the communication between the terminal and the network device. This method, by using a key generated combining quantum key distribution and post-quantum cryptography, enhances the resistance of communication between network devices to quantum computing attacks, protecting the data transmitted during the communication process. After generating the second terminal key and the second network device key, the client and the secure access gateway conduct subsequent handshake messages according to the TLS 1.3 protocol specification, protected by the second terminal key `client_handshake_traffic_secret2` and the second network device key `server_handshake_traffic_secret2`, and their derived `write_key` and `write_iv`. If a PQC certificate is available, the client adds a PQC signing certificate and a PQC encryption certificate to its `Certificate` message. The authentication scope of the `CertificateVerify` and `Finished` messages between the client and the secure access gateway covers the newly added PQC-related messages. Finally, the client and gateway generate the client application traffic key `client_application_traffic_secret` and the gateway application traffic key `server_application_traffic_secret`, along with their derived `write_key` and `write_iv` keys, for application data protection in the record layer protocol. The client application traffic key `client_application_traffic_secret` and the gateway application traffic key `server_application_traffic_secret` are used to encrypt the application data sent by the client, ensuring the confidentiality and integrity of the data during transmission.
[0281] This application also provides a computer-readable storage medium containing a computer program. When the computer program is executed by one or more processors, it causes the one or more processors to perform the voice interaction method of this application.
[0282] It is understood that a computer program includes computer program code. Computer program code can be in the form of source code, object code, executable files, or some intermediate form. Computer-readable storage media can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, external hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media, etc.
[0283] In this specification, the terms "specifically," "furthermore," "particularly," "understandably," etc., refer to specific features, structures, materials, or characteristics described in connection with embodiments or examples that are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0284] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this application pertain.
[0285] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.
Claims
1. A method of quantum-resistant enhancement of a transport layer security protocol of a communication network, characterized in that, The communication network comprises a terminal and a network device, the method is used for the terminal, and the method comprises the following steps: Obtaining a first quantum key and a quantum key identifier from a service node accessed by the terminal; Encrypting the quantum key identifier by using post-quantum cryptography, and sending a first encryption result of the post-quantum cryptography to the network device; Decrypting a second encryption result received from the network device to obtain a second decryption result, wherein the second encryption result is obtained according to the first encryption result; Obtaining a first terminal handshake key and a first network device handshake key according to the first encryption result and the second decryption result; Generating a second terminal handshake key and a second network device handshake key according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result and the second decryption result, so as to encrypt the communication between the terminal and the network device.
2. The method of claim 1, wherein, The step of obtaining a first quantum key and a quantum key identifier from a service node accessed by the terminal comprises the following steps: Recharging a plurality of keys into a cryptographic module of the terminal by using the service node; Sending a quantum key application to the service node, and randomly using one of the plurality of keys recharged into the cryptographic module as a protection key to protect the quantum key application; Receiving a quantum key encryption result obtained by encrypting the first quantum key and the quantum key identifier according to the protection key by the service node, wherein the first quantum key is generated by a first network node accessing the service node and distributed to the service node, and the quantum key identifier is obtained by marking the first quantum key according to an identification code of the first network node and distributed to the service node; Decrypting the quantum key encryption result to obtain the first quantum key and the quantum key identifier.
3. The method of claim 2, wherein, The step of encrypting the quantum key identifier by using post-quantum cryptography, and sending a first encryption result of the post-quantum cryptography to the network device comprises the following steps: Splicing the quantum key identifier and a first random number generated randomly to obtain a first handshake message; Processing the first handshake message and a first handshake random number in the first encryption result to generate a second handshake message; Deriving the second handshake message by using post-quantum cryptography to generate a first handshake key; Encrypting the second handshake message by using post-quantum cryptography to generate a first encryption message in the first encryption result; Splicing the quantum key identifier and the first handshake random number to obtain a first verification message; and signing the first verification message by using post-quantum cryptography to generate a first signature message in the first encryption result; Sending the first encryption result to the network device.
4. The method of claim 3, wherein, The step of decrypting a second encryption result received from the network device to obtain a second decryption result comprises the following steps: receive the second encryption result sent by the network device, the second encryption result being obtained by performing post-quantum cryptographic encryption processing on a first decryption result by the network device, the first decryption result being obtained by performing decryption processing on the first encryption result by the network device; perform decryption processing on the second encryption result to obtain a second decryption result, the second decryption result comprising a second handshake random number, a fourth handshake message and a second signature message.
5. The method of claim 4, wherein, The method further comprises: obtain a second handshake key according to the fourth handshake message; obtain a third handshake message and a quantum key identifier according to the fourth handshake message and the second handshake random number.
6. The method of claim 4, wherein, The method further comprises: obtain a second verification message according to the second signature message; perform post-quantum cryptographic signature verification processing on the second signature message to confirm the correctness of the second verification message, the second verification message being obtained by concatenating the quantum key identifier and the second handshake random number.
7. The method of claim 5, wherein, The first encryption result comprises a first handshake random number, and the second decryption result comprises a second handshake random number, and the first terminal handshake key and the first network device handshake key are obtained according to the first encryption result and the second decryption result, comprising: generating a master key according to the first handshake random number and the second handshake random number; deriving the first terminal handshake key and the first network device handshake key according to the master key.
8. The method of claim 7, wherein, The second terminal handshake key and the second network device handshake key are generated according to the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result and the second decryption result to encrypt the communication between the terminal and the network device, comprising: generating a second terminal handshake key according to the first quantum key, the first terminal handshake key, the first handshake key and the second handshake key; generating a second network device handshake key according to the first quantum key, the first network device handshake key, the first handshake key and the second handshake key; encrypting the communication between the terminal and the network device according to the second terminal handshake key and the second network device handshake key.
9. A method of quantum-resistant enhancement of a transport layer security protocol of a communication network, c h a r a c t e r i s e d b y The communication network comprises a terminal and a network device, and the method is used for the network device, and the method comprises: receiving a first encryption result of a quantum key identifier processed by the terminal by post-quantum cryptography, the quantum key identifier being obtained by the terminal from an accessed cryptographic service node; performing decryption processing on the first encryption result to obtain a first decryption result; performing post-quantum cryptographic encryption processing on the first decryption result to obtain a second encryption result; obtaining a first terminal handshake key and a first network device handshake key according to the first decryption result and the second encryption result; generating a second terminal handshake key and a second network device handshake key according to a second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result and the second encryption result to encrypt the communication between the terminal and the network device.
10. The method of claim 9, wherein, The method further comprises: Access the second network node through a pre-established channel; Load a security certificate of the terminal or a security certificate of the network device.
11. The method of claim 9, wherein, The first decryption result includes a second handshake message and a first handshake random number, and the method further includes: Obtaining a first handshake message according to the second handshake message and the first handshake random number; Obtaining the quantum key identifier according to the first handshake message.
12. The method of claim 10, wherein, The first decryption result includes a first signature message, and the method further includes: Obtaining a first verification message according to the first signature message; Performing post-quantum cryptographic signature verification processing on the first signature message to confirm that the correct first verification message is obtained, wherein the first verification message is concatenated from the first handshake random number and the quantum key identifier; If the obtained quantum key identifier is correct, obtaining the second quantum key from the second network node accessing the network device.
13. The method of claim 11, wherein, The post-quantum cryptographic encryption processing on the first decryption result to obtain a second encryption result includes: Concatenating the quantum key identifier and a randomly generated second random number to obtain a third handshake message; Processing the third handshake message and a second handshake random number in the second encryption result to generate a fourth handshake message; Performing post-quantum cryptographic derivation processing on the fourth handshake message to generate a second handshake key; Performing post-quantum cryptographic encryption processing on the fourth handshake message to generate a second encryption message in the second encryption result; Concatenating the quantum key identifier and the second handshake random number to obtain a second verification message; Performing post-quantum cryptographic signature processing on the second verification message to generate a second signature message in the second encryption result; Sending the second encryption result to the terminal.
14. The method of claim 13, wherein, The first decryption result includes a first handshake random number, and the second encryption result includes a second handshake random number, and the first terminal handshake key and the first network device handshake key obtained according to the first decryption result and the second encryption result include: Generating a master key according to the first handshake random number and the second handshake random number; Deriving the first terminal handshake key and the first network device handshake key according to the master key.
15. The method of claim 14, wherein, The first decryption result includes a second handshake message, and the second terminal handshake key and the second network device handshake key generated according to the second quantum key, the first terminal handshake key, the first network device handshake key, the first decryption result, and the second encryption result to encrypt the communication between the terminal and the network device include: Performing post-quantum cryptographic derivation processing on the second handshake message to generate a first handshake key; Generating a second terminal handshake key according to the second quantum key, the first terminal handshake key, the first handshake key, and the second handshake key; Generating a second network device handshake key according to the second quantum key, the first network device handshake key, the first handshake key, and the second handshake key; Encrypting the communication between the terminal and the network device according to the second terminal handshake key and the second network device handshake key.
Citation Information
Patent Citations
Quantum key distribution method and system for authentication based on post-quantum cryptography algorithm
CN112152817A
Data encryption transmission method and system, equipment and storage medium
CN113612612A
Secure transmission method and system based on quantum key encapsulation and negotiation after mixing
CN114629646A
Quantum key transmission method, device and system
CN116633530A
Forward secrecy qsl
US20230353349A1
Cited By
Systems and methods for protecting tokens using a unified containerized framework
US20260212033A1