Quantum-resistant security enhancement method for central authentication service protocol

By distributing quantum keys between terminals and servers and using post-quantum cryptography algorithms to process authentication information, the security problem of central authentication service protocols in existing technologies under quantum computing attacks is solved, realizing the ability to resist quantum computing attacks in the communication process and the security of data transmission.

WO2026045824A1PCT designated stage Publication Date: 2026-03-05CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing classical cryptographic algorithms lack resistance to quantum computing attacks, threatening the security of the central authentication service protocol and making it unable to effectively defend against quantum computing attacks.

Method used

The security of the communication process is enhanced by employing quantum key distribution technology and post-quantum cryptography algorithms. This is achieved by distributing quantum keys between the terminal and the server and using post-quantum cryptography algorithms to process authentication information, generate and verify ticket request information, thereby ensuring the communication process's resistance to quantum computing attacks.

Benefits of technology

It improves the resistance to quantum computing attacks in the communication process of terminal accessing server resources, ensures the security and integrity of data transmission, simplifies the process of obtaining service tickets, and has good resistance to quantum computing attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025111971_05032026_PF_FP_ABST
    Figure CN2025111971_05032026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present application is a quantum-resistant security enhancement method for a central authentication service protocol of a communication network. The method comprises: when a resource in a server is accessed for the first time, sending a first resource access request to a server; receiving a login ticket and a login form which are obtained by the server on the basis of the first resource access request; on the basis of the login ticket, acquiring a first quantum key; on the basis of the login form, acquiring authentication information of a terminal; on the basis of the first quantum key and a post-quantum cryptographic algorithm, processing the authentication information to obtain ticket request information, and sending the ticket request information to the server; receiving a service ticket generated by the server; and sending to the server a second resource access request generated on the basis of the service ticket, and on the basis of the second resource access request, the server confirming access permission for a corresponding resource, such that the terminal performs resource access to the server. A terminal and a server use a post-quantum cryptographic algorithm and quantum key distribution technology to perform encrypted communication, thereby significantly enhancing the ability to resist quantum computing attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Quantum-resistant security enhancement methods for central authentication service protocols

[0001] This application claims priority to Chinese Patent Application No. 202411191726.8, filed on August 28, 2024, entitled “Method for Enhancing Quantum Security Against Central Authentication Service Protocols”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of network security, and more specifically, to a method for enhancing the quantum-resistant security of a central authentication service protocol for a communication network. Background Technology

[0003] The leap in computing power, exemplified by quantum computing, has significantly impacted the security of algorithms in classical cryptography. Understandably, the realization of large-scale quantum computers will affect applications in classical cryptography such as key negotiation, encryption, and signature. Therefore, providing cryptographic techniques resistant to quantum computing attacks has become an urgent problem to solve. Summary of the Invention

[0004] This application provides a method for enhancing the quantum-resistant security of a central authentication service protocol for communication networks.

[0005] In a first aspect, embodiments of this application provide a method for enhancing the quantum security of a central authentication service protocol in a communication network, the communication network including a terminal and a server, the method being used on the terminal, the method comprising:

[0006] In the case of the first access to a resource on the server, a first resource access request is sent to the server;

[0007] Receive the login ticket and login form obtained by the server based on the first resource access request;

[0008] The first quantum key is obtained from the first network node accessing the terminal based on the login ticket;

[0009] Obtain the terminal's authentication information based on the login form;

[0010] The authentication information is processed according to the first quantum key and the post-quantum cryptography algorithm to obtain ticket request information, and the ticket request information is sent to the server;

[0011] Receive the service ticket generated by the server based on the ticket request information;

[0012] The terminal sends a second resource access request generated based on the service ticket to the server. The server confirms the access permissions of the resource corresponding to the second resource access request based on the second resource access request, so that the terminal can access the server's resources.

[0013] Thus, during the initial communication process of a terminal requesting access to resources on the server, the terminal uses the login ticket received from the server to request a quantum key from the first network node accessing the terminal. The quantum key and a post-quantum cryptography algorithm are then used to encrypt the authentication information generated from the login form received from the server, generating a ticket request message resistant to quantum computing attacks. The post-quantum cryptography algorithm includes a series of encryption algorithms designed to resist quantum computing attacks, and the quantum key has strong resistance to quantum computing attacks. Next, the server generates a service ticket based on the ticket request message sent by the terminal and sends the service ticket to the terminal. Then, the terminal generates a resource access request based on the service ticket to access resources on the server. Finally, the server verifies the correctness of the service ticket to determine whether the terminal can access the resource corresponding to the resource access request. In this way, quantum key distribution technology and a post-quantum cryptography algorithm enhance the resistance to quantum computing attacks during the terminal's communication process for requesting access to server resources.

[0014] In some embodiments, the method further includes:

[0015] Send the terminal's post-quantum public key to the server.

[0016] In this way, the terminal sends its post-quantum public key to the server. The server then obtains the terminal's post-quantum public key, which is used for subsequent signing and verification processes. The post-quantum public key has strong resistance to quantum computing attacks, ensuring that the transmitted data is well-protected against such attacks.

[0017] In some implementations, obtaining the first quantum key from the first network node accessing the terminal based on the login ticket includes:

[0018] The service node is used to fill the cryptographic module of the terminal with multiple keys;

[0019] A quantum key request is sent to the service node based on the login ticket. The quantum key request is protected by a protection key, which is one of multiple keys randomly used from those injected into the cryptographic module.

[0020] The service node receives the quantum key encryption result obtained by encrypting the first quantum key according to the protection key, and the first quantum key is distributed to the service node by the first network node connected to the service node.

[0021] The first quantum key is obtained by decrypting the quantum key encryption result.

[0022] In this way, the terminal uses the service node to fill its cryptographic module with multiple keys. Next, based on the authorization code received from the server, the terminal sends a quantum key request to the service node. This quantum key request is protected by a protection key, which is randomly selected from the multiple keys filled into the cryptographic module. Then, the terminal receives the quantum key encryption result obtained by the service node encrypting the first quantum key using the protection key. The first quantum key is generated and distributed to the service node by the first network node connected to the service node. Finally, the terminal decrypts the quantum key encryption result to obtain the first quantum key. Thus, the terminal obtains the first quantum key, which has good resistance to quantum computing attacks and can protect the communication between the terminal and the server.

[0023] In some embodiments, the step of processing the authentication information based on the first quantum key and a post-quantum cryptography algorithm to obtain ticket request information, and sending the ticket request information to the server, includes:

[0024] The authentication information is encrypted using the first quantum key to obtain encrypted authentication information.

[0025] A temporary public key signature message is obtained by performing post-quantum signature processing on the temporary public key in the temporary key pair randomly generated by the terminal.

[0026] The encrypted authentication information, the temporary public key signature message, the temporary public key, the login ticket, and the resource information corresponding to the resource access request of the first resource are sent to the server as ticket request information.

[0027] Thus, the terminal encrypts the authentication information using the first quantum key to obtain encrypted authentication information. Next, the terminal performs post-quantum signature processing on the temporary public key in the randomly generated temporary key pair to obtain a temporary public key signature message. Finally, the terminal sends the encrypted authentication information, the temporary public key signature message, the temporary public key, the login ticket, and the resource information corresponding to the first resource access request as ticket request information to the server. In this way, the terminal obtains encrypted authentication information by encrypting the authentication information using the first quantum key, giving the authentication information strong resistance to quantum computing attacks. Furthermore, signing the temporary public key with the post-quantum public key ensures the integrity and authenticity of the temporary public key during transmission.

[0028] In some implementations, sending a second resource access request generated based on the service ticket to the server includes:

[0029] The resource information and the verification random number randomly generated by the terminal are concatenated to obtain the verification concatenation body.

[0030] The verification concatenation is signed using the temporary private key in the temporary key pair to obtain a verification signature message.

[0031] The verification message, the service ticket, and the resource information are sent to the server as a second resource access request. The verification message includes the verification signature message and the verification random number.

[0032] Thus, the terminal concatenates the resource information and a randomly generated verification random number to obtain a verification concatenation. Next, the terminal performs post-quantum signature processing on the verification concatenation using the temporary private key from the temporary key pair to obtain a verification signature message. Finally, the terminal sends the verification message, service ticket, and resource information as a second resource access request to the server. The verification message includes the verification signature message and the verification random number. In this way, the terminal uses a post-quantum signature algorithm to sign the verification concatenation obtained by concatenating the resource information and the randomly generated verification random number to obtain the verification signature message. This ensures that the second resource access request has strong quantum resistance during communication between the terminal and the server, preventing unauthorized access to communication data.

[0033] In some embodiments, the method further includes:

[0034] The server receives a ticket authorization ticket sent by the server, which is generated by the server based on the ticket request information.

[0035] Thus, the terminal receives the ticket authorization ticket sent by the server, which is generated by the server based on the ticket request information. The terminal then obtains the ticket authorization ticket, which allows it to simplify the process of acquiring service tickets.

[0036] In some embodiments, the method further includes:

[0037] When accessing resources on the server for the first time, a ticket authorization ticket is sent to the server.

[0038] Receive the follow-up service ticket generated based on the ticket authorization ticket sent by the server;

[0039] The terminal sends a third resource access request generated based on the subsequent service ticket to the server. The server confirms the access permissions of the subsequent resources corresponding to the third resource access request based on the third resource access request, so that the terminal can access the subsequent resources in the server.

[0040] Thus, when accessing resources on the server for the first time, the terminal sends a ticket authorization ticket to the server. Next, the terminal receives a subsequent service ticket generated from the ticket authorization ticket by the server. Finally, the terminal sends a third resource access request generated from the subsequent service ticket to the server. The server confirms the access permissions for the subsequent resource corresponding to the third resource access request, enabling the terminal to access the subsequent resource on the server. In this way, when accessing resources on the server for the first time, the terminal uses the obtained ticket authorization ticket to obtain a subsequent service ticket from the server, thereby accessing the required resource, simplifying the process of obtaining the subsequent service ticket. Furthermore, because the ticket service ticket is quantum resistant, the communication process of obtaining the subsequent service ticket based on the ticket authorization ticket has good resistance to quantum computing attacks.

[0041] Secondly, embodiments of this application provide a method for enhancing the quantum security of a central authentication service protocol in a communication network, the communication network including a terminal and a server, the method being used on the server, the method comprising:

[0042] Receive a first resource access request sent by the terminal, wherein the first resource access request is generated by the terminal when it first accesses a resource in the server;

[0043] The second quantum key and quantum key identifier are obtained from the second network node connected to the server;

[0044] Send a login ticket and a login form to the terminal. The login ticket is the quantum key identifier, and the login form is generated by the server based on the first resource access request.

[0045] The system receives a ticket request message sent by the terminal, which is obtained by processing authentication information based on a first quantum key and a post-quantum cryptography algorithm. The first quantum key is obtained by the terminal based on the login ticket, and the authentication information is obtained by the terminal based on the login form.

[0046] A service ticket is generated based on the ticket request information, and the service ticket is sent to the terminal.

[0047] The system receives a second resource access request generated by the terminal based on the service ticket, confirms the access permissions of the resource corresponding to the second resource access request, and enables the terminal to access the server for resources.

[0048] Thus, during the initial communication process of a terminal requesting access to resources on the server, the terminal uses the login ticket received from the server to request a quantum key from the first network node accessing the terminal. The quantum key and a post-quantum cryptography algorithm are then used to encrypt the authentication information generated from the login form received from the server, generating a ticket request message resistant to quantum computing attacks. The post-quantum cryptography algorithm includes a series of encryption algorithms designed to resist quantum computing attacks, and the quantum key has strong resistance to quantum computing attacks. Next, the server generates a service ticket based on the ticket request message sent by the terminal and sends the service ticket to the terminal. Then, the terminal generates a resource access request based on the service ticket to access resources on the server. Finally, the server verifies the correctness of the service ticket to determine whether the terminal can access the resource corresponding to the resource access request. In this way, quantum key distribution technology and a post-quantum cryptography algorithm enhance the resistance to quantum computing attacks during the terminal's communication process for requesting access to server resources.

[0049] In some embodiments, the method further includes:

[0050] Receive the terminal's post-quantum public key sent by the terminal.

[0051] In this way, the server receives the terminal's own post-quantum public key. The server then obtains the terminal's post-quantum public key and can decrypt the communication data sent by the terminal based on it. Post-quantum public keys have strong resistance to quantum computing attacks, enabling data protected by them to be well-protected against such attacks.

[0052] In some implementations, obtaining the second quantum key and quantum key identifier from a second network node connected to the server includes:

[0053] Upon receiving the first resource access request, a quantum key application is sent to the second network node connected to the server;

[0054] The system receives the second quantum key and the quantum key identifier sent by the second network node. The second quantum key is obtained by the second network node based on the quantum key application, and the quantum key identifier is obtained by the second network node by identifying the second quantum key based on the identification code of the second network node.

[0055] Thus, upon receiving a first resource access request, the server sends a quantum key request to the second network node accessing the server. Next, the server receives a second quantum key and a quantum key identifier from the second network node. The second quantum key was obtained by the second network node according to the quantum key request, and the quantum key identifier was obtained by the second network node by identifying the second quantum key using its own identification code. In this way, the server obtains the second quantum key and the quantum key identifier. The second quantum key has strong resistance to quantum computing attacks and can be used to provide strong confidentiality for communication between the terminal and the server. The quantum key identifier facilitates the management and use of the quantum key. Using the quantum key identifier as a login ticket provides strong confidentiality.

[0056] In some implementations, the ticket request information includes encrypted authentication information, a temporary public key signature message, a login ticket, and a temporary public key; the method further includes:

[0057] Confirm the usage status of the second quantum key corresponding to the login ticket;

[0058] If the second quantum key is not used, the encrypted authentication information is decrypted using the second quantum key to obtain the authentication information;

[0059] The temporary public key signature message is verified using the post-quantum public key to determine the correctness of the temporary public key;

[0060] Upon obtaining the authentication information, the second quantum key is deleted to ensure that the second quantum key is not reusable;

[0061] The temporary public key is divided into a first temporary public key and a second temporary public key.

[0062] Thus, the server first verifies the usage of the second quantum key corresponding to the login ticket. If the second quantum key is not in use, the server decrypts the encrypted authentication information using it to obtain the authentication information. Next, the server verifies the signature of the temporary public key using the subsequent quantum public key to confirm the correctness of the temporary public key. Upon obtaining the authentication information, the server deletes the second quantum key to ensure it cannot be reused. Furthermore, the server divides the temporary public key into a first temporary public key and a second temporary public key. This ensures the security of the authentication process and prevents unauthorized access by confirming that the quantum key corresponding to the login ticket has not been used for previous logins. And by deleting the second quantum key after obtaining the authentication information, the server ensures that a used quantum key cannot be reused. Additionally, the server divides the temporary public key into a first temporary public key and a second temporary public key for subsequent processes to reduce potential security risks.

[0063] In some implementations, the ticket request information includes resource information, and the step of generating a service ticket based on the ticket request information and sending the service ticket to the terminal includes:

[0064] Generate a temporary ticket authorization ticket based on the resource information;

[0065] A first temporary service ticket is generated based on the temporary ticket authorization ticket;

[0066] The temporary public key and the ticket authorization ticket attribute value in the first temporary service ticket are concatenated to obtain a temporary concatenation body. The ticket authorization ticket attribute value is used to store relevant information related to the temporary ticket authorization ticket.

[0067] The temporary concatenation is processed with a post-quantum signature based on the server’s second post-quantum private key to obtain a service ticket signature message.

[0068] The service ticket signature message and the first temporary public key are stored in the first temporary service ticket to obtain the second temporary service ticket;

[0069] The second temporary service ticket is signed using the server's second classic public key to obtain a service ticket, and the service ticket is sent to the terminal.

[0070] Cache the second temporary public key and delete the first temporary public key.

[0071] Thus, the server generates a temporary authorization ticket based on the resource information. Next, the server generates a first temporary service ticket based on the temporary authorization ticket. Then, the server concatenates the temporary public key and the authorization ticket attribute values ​​from the first temporary service ticket to obtain a temporary concatenation. The authorization ticket attribute values ​​are used to store relevant information related to the temporary authorization ticket. The server then performs post-quantum signature processing on the temporary concatenation using its second post-quantum private key to obtain a service ticket signature message. The service ticket signature message and the first temporary public key are stored in the first temporary service ticket to obtain a second temporary service ticket. Finally, the server signs the second temporary service ticket using its second classical public key to obtain the service ticket and sends it to the terminal. Furthermore, the server caches the second temporary public key and deletes the first temporary public key. In this way, the server generates a first temporary service ticket and uses post-quantum signature algorithms and classical signature algorithms to sign and protect the first temporary service ticket, giving the signed service ticket good confidentiality and quantum resistance. Furthermore, the server caches a portion of the temporary public key locally and deletes the other portion to reduce potential security risks and maintain the integrity of the public key.

[0072] In some implementations, receiving the second resource access request generated by the terminal based on the service ticket, and confirming the access permissions of the resource corresponding to the second resource access request, so that the terminal can access the server, includes:

[0073] The terminal receives a second resource access request generated based on the service ticket. The second resource access request includes a verification message, the service ticket, and the resource information. The verification message includes a verification signature message and a verification random number.

[0074] The verification signature message is processed using the server's second classic private key to confirm the validity of the service ticket;

[0075] The second temporary public key and the received first temporary public key are combined to obtain the temporary public key;

[0076] The service ticket signature message is verified using the server’s second post-quantum public key to confirm that the ticket authorization ticket corresponding to the ticket authorization ticket attribute value is valid.

[0077] The authentication information is verified using the temporary public key; if the authentication information is correct, the terminal is allowed to access resources of the server.

[0078] Thus, the server receives a second resource access request generated by the terminal based on a service ticket. This request includes a verification message, a service ticket, and resource information. The verification message includes a verification signature message and a verification random number. Next, the server verifies the verification signature message using its second classical private key to confirm the validity of the service ticket. Then, the server synthesizes the second temporary public key and the received first temporary public key to obtain a temporary public key. The server then verifies the service ticket signature message using its second post-quantum public key to confirm the validity of the authorization ticket corresponding to the ticket's attribute value. Finally, the server verifies the correctness of the authentication information using the temporary public key; if the authentication information is correct, the terminal is allowed to access the server's resources. In this way, by verifying the validity of the service ticket in the second resource access request and verifying the service ticket signature message using the synthesized temporary public key to confirm the validity of the authorization ticket, the server can ensure the authenticity of the terminal's identity, providing strong security and quantum security for resource access requests, thus helping to protect data and communication security.

[0079] In some embodiments, the method further includes:

[0080] The temporary ticket authorization ticket is signed using the server's second classic public key to obtain a classic signed ticket authorization ticket.

[0081] The temporary ticket authorization ticket is processed by post-quantum signature processing using the server's second post-quantum public key to obtain a post-quantum signature ticket authorization ticket.

[0082] The classic signature ticket authorization ticket and the post-quantum signature ticket authorization ticket are stored in the temporary ticket authorization ticket to obtain the ticket authorization ticket;

[0083] The authorized ticket is sent to the terminal.

[0084] Thus, the server signs the temporary ticket authorization ticket using its second classical public key to obtain a classically signed ticket authorization ticket. Next, the server performs a post-quantum signature process on the temporary ticket authorization ticket using its second post-quantum public key to obtain a post-quantum signed ticket authorization ticket. Then, the server stores both the classically signed and post-quantum signed ticket authorization tickets within the temporary ticket authorization ticket, resulting in the final ticket authorization ticket. Finally, the server sends the final ticket authorization ticket to the terminal. This process, by signing the temporary ticket authorization ticket using both classical and post-quantum signature algorithms, and then storing these two tickets within the temporary ticket authorization ticket, provides the final ticket authorization ticket with strong quantum resistance and confidentiality.

[0085] In some embodiments, the method further includes:

[0086] In cases where access to resources on the server is not the first time, the terminal sends a ticket authorization ticket.

[0087] A follow-up service ticket is generated based on the authorized ticket, and the follow-up service ticket is sent to the terminal.

[0088] The server receives a third resource access request generated based on the subsequent service ticket from the terminal, confirms the access permissions of the subsequent resources corresponding to the third resource access request, and enables the terminal to access the subsequent resources of the server.

[0089] Thus, when accessing server resources for the first time, the server receives a ticket authorization ticket sent by the terminal. Next, the server generates a subsequent service ticket based on the ticket authorization ticket and sends it to the terminal. Finally, the server receives a third resource access request generated by the terminal based on the subsequent service ticket, confirms the access permissions for the corresponding subsequent resources, and enables the terminal to access those resources. This method, where the server generates subsequent service tickets based on the received ticket authorization ticket to allow the terminal to access server resources for the first time, greatly simplifies the process of obtaining service tickets for the terminal, while also providing good quantum resistance and confidentiality.

[0090] In some implementations, generating a follow-up service ticket based on the authorized ticket and sending the follow-up service ticket to the terminal includes:

[0091] The ticket authorization ticket is verified using the second classical public key and the second post-quantum public key to confirm its correctness.

[0092] If the authorization ticket is confirmed to be correct, a follow-up service ticket is sent to the terminal.

[0093] Thus, the server verifies the signature of the authorization ticket using the second classical public key and the second post-quantum public key to confirm its correctness. Upon confirming the ticket's correctness, the server sends subsequent service tickets to the terminal. In this way, by verifying the signature of the authorization ticket, confirming its correctness, generating and distributing subsequent service tickets, and verifying the terminal's identity, the security of resources on the server is ensured.

[0094] Thirdly, embodiments of this application provide a computing processing device, comprising: a memory storing computer-readable code; and one or more processors, wherein when the computer-readable code is executed by the one or more processors, the computing processing device executes a quantum-resistant security enhancement method for a central authentication service protocol of a communication network as described in the first and second aspects above.

[0095] Fourthly, embodiments of this application provide a computer program including computer-readable code, which, when executed on a computing processing device, causes the computing processing device to execute a quantum-resistant security enhancement method for a central authentication service protocol of a communication network as described in the first and second aspects above.

[0096] Fifthly, this application proposes a computer-readable medium storing the computer program as described in the fourth aspect above.

[0097] Additional aspects and advantages of embodiments of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of embodiments of this application. Attached Figure Description

[0098] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, wherein:

[0099] Figure 1 is a flowchart illustrating one of the quantum-resistant security enhancement methods for a central authentication service protocol in a communication network proposed in an embodiment of this application.

[0100] Figure 2 is an architecture diagram of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in an embodiment of this application;

[0101] Figure 3 is a signaling diagram of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in an embodiment of this application;

[0102] Figure 4 is a second schematic flowchart of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in an embodiment of this application;

[0103] Figure 5 is a third flowchart illustrating a quantum-resistant security enhancement method for a central authentication service protocol in a communication network, as proposed in an embodiment of this application.

[0104] Figure 6 is a fourth flowchart illustrating a quantum-resistant security enhancement method for a central authentication service protocol in a communication network proposed in an embodiment of this application.

[0105] Figure 7 is a fifth flowchart illustrating a quantum-resistant security enhancement method for a central authentication service protocol in a communication network, as proposed in an embodiment of this application.

[0106] Figure 8 is a flowchart of the sixth embodiment of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in this application.

[0107] Figure 9 is a flowchart of the seventh method for enhancing the quantum security of a central authentication service protocol for a communication network according to an embodiment of this application;

[0108] Figure 10 is the eighth flowchart illustrating a quantum-resistant security enhancement method for a central authentication service protocol in a communication network according to an embodiment of this application.

[0109] Figure 11 is a flowchart of the ninth embodiment of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in this application.

[0110] Figure 12 is a flowchart of the tenth embodiment of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in this application.

[0111] Figure 13 is an eleventh flowchart illustrating a quantum-resistant security enhancement method for a central authentication service protocol in a communication network according to an embodiment of this application.

[0112] Figure 14 is a schematic flowchart of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in an embodiment of this application.

[0113] Figure 15 is a flowchart of the method for enhancing the quantum security of a central authentication service protocol for a communication network according to an embodiment of this application.

[0114] Figure 16 is a schematic flowchart of the fourteenth of the embodiments of this application of a method for enhancing the quantum security of a central authentication service protocol for a communication network;

[0115] Figure 17 is a flowchart of the fifteenth embodiment of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in this application.

[0116] Figure 18 is a schematic flowchart of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in an embodiment of this application.

[0117] Figure 19 is a schematic diagram of the structure of a computing device for a quantum-resistant security enhancement method of a central authentication service protocol for a communication network proposed in an embodiment of this application;

[0118] Figure 20 is a schematic diagram of the computer program structure of a quantum-resistant security enhancement method for a central authentication service protocol of a communication network proposed in an embodiment of this application. Detailed Implementation

[0119] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the embodiments of this application, and should not be construed as limiting the embodiments of this application.

[0120] The leap in computing power, exemplified by quantum computing, has significantly impacted the security of algorithms in classical cryptography. In other words, quantum computing poses a more direct and pressing threat to classical cryptography. Classical algorithms such as the Diffie-Hellman algorithm, RSA algorithm, and elliptic curve cryptography (ECC) face greater security risks because the number theory problems they are based on, such as large prime number factorization and discrete logarithms, are no longer difficult in the quantum era. Understandably, the realization of large-scale quantum computers will have some impact on applications of classical cryptography, such as key negotiation, encryption, and signatures.

[0121] Thus, the security of the Internet, which uses classical cryptographic algorithms to protect communication processes, is heavily threatened by quantum computing attacks. For example, the Central Authentication Service (CAS) protocol, a simple yet powerful ticket-based protocol, provides a centralized authentication service, simplifying the user authentication process and improving system security and user experience. The CAS Client, as part of the client application, is deployed alongside the protected client application to handle authentication and authorization interactions with the CAS server. In related technologies, the interaction flow between the CAS Client and the CAS Server is as follows:

[0122] For each resource access request to a protected resource, the CAS Client analyzes whether the request contains a Service Ticket (ST). If not, it means the current user is not logged in. The client then redirects the resource access request to the specified authentication server login address, passing the resource address (Service) corresponding to the request. Next, the user enters authentication information. If login is successful, the CAS Server randomly generates a unique, unforgeable Service Ticket (ST) of a sufficient length and caches it for future verification. The system then automatically redirects to the address of the resource address (Service) and sets a Ticket Granted Cookie (TGC) for the client browser. After receiving the resource address (Service) and the newly generated Service Ticket, the CAS Server verifies the user's identity to ensure the legitimacy of the Service Ticket (ST).

[0123] In the interaction process between the CAS Client and the CAS Server described above, classic authentication techniques are used to authenticate and protect the communication data during the interaction. These classic authentication techniques use classic public-key encryption algorithms such as RSA and ECC. However, this means that the central authentication service protocol is not resistant to quantum computing attacks, posing a significant security risk when facing such attacks.

[0124] Currently, international technologies for addressing quantum computing attacks mainly fall into two categories: one focuses on scenarios where (symmetric) key negotiation is performed using asymmetric algorithms, followed by encrypted transmission using symmetric algorithms. This involves researching the use of quantum key distribution (QKD) networks for symmetric key negotiation to protect key security. The other category researches post-quantum cryptography (PQC) algorithms to directly replace existing asymmetric algorithms. Quantum key distribution technology utilizes quantum mechanics principles to generate keys that cannot be intercepted by third parties, ensuring the security of key transmission. It is particularly suitable for key exchange scenarios and can replace existing asymmetric key negotiation algorithms, such as RSA or ECC, to improve key security. However, quantum key distribution technology cannot currently completely replace all applications of asymmetric algorithms. For example, in scenarios involving signature verification, integrity protection, and non-repudiation, asymmetric algorithms are still required.

[0125] Post-quantum cryptography algorithms are asymmetric cryptographic algorithms designed based on new mathematical problems, aiming to resist the potential threats posed by quantum computers. NIST has published the first batch of four proposed standardized post-quantum cryptographic algorithms: Kyber, Dilithium, Falcon, and SPHINCS+. These algorithms cover multiple technical approaches to reduce the risk of a single technique being compromised. Theoretically, post-quantum cryptography algorithms can replace all asymmetric algorithms and are more universal. However, the security of post-quantum cryptography algorithms still depends on the complexity of the computational problem, and they may face new methods of breaking them in the future or become insecure as computing power increases. Furthermore, post-quantum cryptography standards have not yet been officially published, and the production and certification of related products will take time; therefore, their large-scale application will require a considerable period.

[0126] Both post-quantum cryptography algorithms and quantum key distribution technologies have the ability to resist quantum computing attacks, but each has its limitations. Therefore, providing a relatively low-cost and highly secure cryptographic technology that can resist quantum computing attacks has become an urgent problem to be solved.

[0127] Based on the above problems, please refer to Figure 1. This application provides a method for enhancing the quantum security of a central authentication service protocol in a communication network. The communication network includes a terminal and a server. The method is used on the terminal and includes:

[0128] 011: When accessing a resource on the server for the first time, send a first resource access request to the server;

[0129] 012: Receive the login ticket and login form obtained by the server based on the first resource access request;

[0130] 013: Obtain the first quantum key from the first network node of the access terminal based on the login ticket;

[0131] 014: Obtain the terminal's authentication information based on the login form;

[0132] 015: Process the authentication information using the first quantum key and the post-quantum cryptography algorithm to obtain the ticket request information, and then send the ticket request information to the server;

[0133] 016: Receive the service ticket generated by the server based on the ticket request information;

[0134] 017: Send a second resource access request generated based on the service ticket to the server. The server confirms the access permissions of the resource corresponding to the second resource access request, so that the terminal can access the server's resources.

[0135] This application also provides a terminal, including a memory and a processor. The method of this application can be implemented by the terminal of this application. Specifically, the memory stores a computer program, and the processor is used to send a first resource access request to the server upon first access to resources on the server; receive a login ticket and login form obtained by the server based on the first resource access request; and obtain a first quantum key from a first network node accessing the terminal based on the login ticket. The processor is also used to obtain the terminal's authentication information based on the login form; process the authentication information based on the first quantum key and a post-quantum cryptography algorithm to obtain ticket request information, and send the ticket request information to the server; and receive a service ticket generated by the server based on the ticket request information and send a second resource access request generated based on the service ticket to the server.

[0136] This application also provides a terminal security enhancement device. The method of this application can be implemented by the terminal security enhancement device of this application. Specifically, the terminal security enhancement device includes a sending module, a receiving module, an acquisition module, a processing module, and a receiving module. The sending module is used to send a first resource access request to the server when accessing resources in the server for the first time. The receiving module is used to receive a login ticket and a login form obtained by the server based on the first resource access request. The acquisition module is used to obtain a first quantum key from a first network node of the access terminal based on the login ticket, and obtain the terminal's authentication information based on the login form. The processing module is used to process the authentication information based on the first quantum key and a post-quantum cryptography algorithm to obtain ticket request information, and send the ticket request information to the server. The receiving module is used to receive a service ticket generated by the server based on the ticket request information. The sending module sends a second resource access request generated based on the service ticket to the server.

[0137] This application provides a communication system based on a central authentication service protocol. The communication system includes a terminal, a server, and a quantum key distribution network as described in the above embodiments. The quantum key distribution network is configured to distribute quantum keys to the terminal or the server.

[0138] Specifically, the terminal is the user terminal of the CAS protocol, representing the user who needs to access relevant resources in a CAS application scenario. The server includes an authentication server and a resource server. The authentication server is used in the CAS application scenario to process authentication requests and issue tokens authorizing access to relevant resources. The resource server and the authentication server can be the same server or different servers. Whether the servers are the same or different has no substantial impact on the quantum-resistant enhancement method of this application. In practical applications, the choice between the same server and different servers depends on specific needs, security considerations, and budget. In the embodiments described in this application, the resource server and the authentication server are deployed in different locations on the same server.

[0139] A quantum key distribution network (QKDC) consists of network nodes and a quantum network link control center. Network nodes are used to store and distribute quantum keys. The quantum network link control center establishes quantum key distribution and relay links between network nodes based on their names. These links are used for data transfer and other functions. The QKDC provides services such as quantum key generation, quantum key relay, and quantum key provision.

[0140] Referring to Figure 2, in some implementations, when a terminal sends a resource access request to the resource server for the first time, the resource server redirects the terminal to the authentication server. Through ticket requests and responses between the client and the authentication server, the client obtains a service ticket issued by the authentication server to initiate a resource access request to the resource server. After receiving the service ticket sent by the client, the resource server sends the service ticket to the authentication server so that the authentication server can authenticate the user based on the service ticket, thereby allowing access to the resource corresponding to the resource access request. The terminal accesses a service node, which is a relay station used by the terminal to connect to network nodes, and is used to supply keys to the terminal and relay and store quantum keys. When the terminal sends a quantum key request, the network node sends the quantum key generated by the quantum key distribution network to the service node accessing the terminal, and the service node then sends the quantum key to the terminal. The simplified process of the terminal and the authentication server obtaining the quantum key is as follows: First, the authentication server sends a quantum key request to the second network node accessing the server. Then, the second network node distributes the quantum key generated according to the quantum key request to the server. Simultaneously, the quantum network link control center enables the first network node of the access terminal to generate a quantum key. However, this quantum key is not immediately distributed to the access terminal but is first stored in the network node. The correspondence between the aforementioned terminal, authentication server, service node, and network node is provided by the management and control platform.

[0141] It should be noted that this application uses the FIPS203 Module-Lattice-based Key-Encapsulation Mechanism Standard as the PQC key encapsulation algorithm and the FIPS204 Module-Lattice-Based Digital Signature Standard as the PQC digital signature algorithm for explanation and illustration. All subsequent descriptions of PQC algorithm-related operations refer to the aforementioned FIPS standards. Of course, in other embodiments, other algorithms such as the NewHope algorithm, Sidh algorithm, and HQC algorithm can also be used as PQC algorithms. It should also be noted that the embodiments of this application pertain to the Central Authentication Service (CAS) protocol, hereinafter referred to as the CAS protocol.

[0142] Specifically, login forms typically include username and password input fields to collect user authentication information. Authentication information includes the username and password entered by the user.

[0143] In the case of initial access to resources on the server, the terminal sends a first resource access request to the server. Since this is the terminal's first access, it does not have a service ticket. Therefore, the server obtains a second quantum key and a quantum key identifier from the second network node accessing the server. The server then returns the quantum key identifier as a login ticket, along with the login form generated based on the first resource access request, to the terminal.

[0144] After receiving the login ticket and login form from the server, the terminal sends a quantum key request to the first network node accessing the terminal based on the login ticket to obtain the first quantum key. The terminal also obtains its authentication information based on the login form. Subsequently, the terminal performs a series of processing steps on the authentication information using the first quantum key and a post-quantum cryptography algorithm to obtain ticket request information, which it then sends to the server.

[0145] After receiving the ticket request information from the terminal, the server generates a service ticket based on the ticket request information and then returns the service ticket to the terminal.

[0146] After receiving the service ticket, the terminal can generate a second resource access request based on the service ticket and send the second resource access request to the server.

[0147] After receiving the second resource access request, the server, having processed the service ticket carried in the request, allows the terminal to access the resource on the server corresponding to the second resource access request.

[0148] The following example illustrates the method of this application. In the embodiment described in this application, the terminal is a user terminal of the CAS protocol, representing a user who needs to access relevant resources in a CAS application scenario. The server is a CAS protocol server, including an authentication server and a resource server. The authentication server is used in the CAS application scenario to process authentication requests and issue tokens authorizing access to relevant resources. The resource server is used to provide the accessed resources and their services.

[0149] The network nodes are quantum network nodes. They store and provide generated quantum keys to the server via a trusted channel, or to the client via a key service node. The service nodes are key service nodes, which connect to the quantum network nodes and provide pre-shared key filling and quantum key services to the client.

[0150] Referring to Figure 3, in the case of the user's first access to resources on the server, the client sends a first resource access request to the resource server. Since this is the user's first access to the resource server, the client does not have a service ticket, and the resource server redirects the user to the authentication server. The authentication server obtains the second quantum key QK_UUID-2 and the quantum key identifier UUID_QK from the second quantum network node accessing the server. It then returns the quantum key identifier UUID_QK as a login ticket, along with the login form generated based on the first resource access request, to the client.

[0151] After receiving the login ticket and login form from the authentication server, the user terminal sends a quantum key request to the first quantum network node accessing the user terminal based on the login ticket to obtain the first quantum key QK_UUID-1. The user terminal also retrieves the authentication information entered in the login form. Subsequently, the user terminal performs a series of processing steps on the authentication information using the first quantum key QK_UUID-1 and a post-quantum cryptography algorithm to obtain ticket request information, which is then sent to the authentication server.

[0152] After receiving the ticket request information from the client, the authentication server generates a service ticket (ST) based on the ticket request information. The service ticket (ST) is then returned to the client.

[0153] After receiving the Service Ticket (ST), the client can generate a second resource access request based on the Service Ticket (ST) and send the second resource access request to the resource server.

[0154] After receiving the second resource access request, the resource server submits the second resource access request to the authentication server because the second resource access request carries a service ticket (ST). After the authentication server completes the verification process, it allows the user client to access the resource on the resource server corresponding to the second resource access request.

[0155] In summary, in the quantum-resistant security enhancement method, communication system, terminal, and server of the central authentication service protocol in the communication network according to the embodiments of this application, for the communication process of the terminal's initial request to access resources in the server, the terminal uses the login ticket received from the server to request a quantum key from the first network node accessing the terminal. The quantum key and a post-quantum cryptography algorithm are then used to encrypt the authentication information generated from the login form received from the server, generating a ticket request information resistant to quantum computing attacks. The post-quantum cryptography algorithm includes a series of encryption algorithms designed to resist quantum computing attacks, and the quantum key has good resistance to quantum computing attacks. Next, the server generates a service ticket based on the ticket request information sent by the terminal and sends the service ticket to the terminal. Then, the terminal generates a resource access request based on the service ticket to access resources in the server. Finally, the server verifies the correctness of the service ticket to determine whether the terminal can access the resource corresponding to the resource access request. Thus, the quantum key distribution technology and the post-quantum cryptography algorithm enhance the resistance to quantum computing attacks in the communication process of the terminal requesting access to server resources.

[0156] Please refer to Figure 4. In some embodiments, the method further includes:

[0157] 018: Send the terminal's post-quantum public key to the server.

[0158] In some implementations, the sending module is used to send the terminal's post-quantum public key to the server.

[0159] In some implementations, the processor is also used to send the terminal's post-quantum public key to the server.

[0160] Specifically, the terminal sends its post-quantum public key to the server. The server then obtains the terminal's post-quantum public key, which is used for subsequent signing and verification processes. This post-quantum public key has strong resistance to quantum computing attacks, ensuring that the transmitted data is well-protected against such attacks.

[0161] Continuing with the example above, the post-quantum public key is the PQC public key. Please refer to Figure 3 again. Before the user sends the first resource access request to the authentication server, the user registers its own PQC public key with the authentication server.

[0162] In this way, the authentication server obtains the user's PQC public key, which is used for subsequent signing and verification processes. The PQC public key has good resistance to quantum computing attacks, enabling the transmitted data to have good resistance to quantum computing attacks.

[0163] Please refer to Figure 5. In some embodiments, step 013 (obtaining the first quantum key from the first network node of the access terminal based on the login ticket) includes:

[0164] 0131: Using a service node to fill the terminal's cryptographic module with multiple keys;

[0165] 0132: Send a quantum key request to the service node based on the login ticket;

[0166] 0133: The quantum key encryption result obtained by the receiving service node encrypting the first quantum key according to the protection key;

[0167] 0134: The first quantum key is obtained by decrypting the quantum key encryption result.

[0168] In some implementations, the charging module is used to charge multiple keys into the terminal's cryptographic module using the service node. The sending module is used to send a quantum key request to the service node based on the login ticket. The receiving module is used to receive the quantum key encryption result obtained by the service node encrypting the first quantum key using the protection key. The decryption module is used to decrypt the quantum key encryption result to obtain the first quantum key.

[0169] In some implementations, the processor is further configured to use the service node to fuel the terminal's cryptographic module with multiple keys, and to send a quantum key request to the service node based on the login ticket, the quantum key request being protected by a protection key. The processor is also configured to receive a quantum key encryption result obtained by the service node encrypting a first quantum key using the protection key, and to decrypt the quantum key encryption result to obtain the first quantum key.

[0170] Specifically, the terminal uses a service node to feed multiple keys into its cryptographic module. Next, based on the authorization code received from the server, the terminal sends a quantum key request to the service node. This quantum key request is protected by a protection key, which is randomly selected from the multiple keys fed into the cryptographic module. Then, the terminal receives the quantum key encryption result obtained by the service node encrypting the first quantum key using the protection key. The first quantum key is generated and distributed to the service node by the first network node connected to the service node. Finally, the terminal decrypts the quantum key encryption result to obtain the first quantum key. In this way, the terminal obtains the first quantum key, which has good resistance to quantum computing attacks and can protect the communication between the terminal and the server.

[0171] Continuing with the example above, please refer to Figure 3 again. The client uses the key service node to pre-share a key to its personal cryptographic module. The total pre-shared key is 1M bits (128 bits). The personal cryptographic module includes, but is not limited to, a Smart Cryptographic Key (HSM) and a Virtual Security Module (VSM). Next, the client sends a quantum key request to the key service node based on its login ticket and randomly selects one of the Smart Cryptographic Keys as its protection key. The client performs a hash operation (Hash-based Message Authentication Code, HMAC) on the key ID and request content using the SM3 algorithm and the protection key. Subsequently, the key service node also performs a hash operation on the key ID and request content using the SM3 algorithm and the protection key to verify the integrity and authenticity of the data. HMAC is a method that uses a hash function and a key to provide data integrity and source authentication.

[0172] After the quantum key application is successfully confirmed, the user terminal receives the quantum key encryption result obtained by the key service node encrypting the first quantum key QK_UUID-1 according to the protection key. The first quantum key QK_UUID-1 is generated and distributed to the key service node by the first quantum network node connected to the key service node. The user terminal then decrypts the quantum key encryption result according to the protection key to obtain the first quantum key QK_UUID-1.

[0173] In this way, the user obtains the first quantum key QK_UUID-1. The first quantum key QK_UUID-1 has good resistance to quantum computing attacks and can protect the communication between the user and the authentication server.

[0174] Please refer to Figure 6. In some embodiments, step 015 (processing the authentication information according to the first quantum key and the post-quantum cryptography algorithm to obtain ticket request information, and sending the ticket request information to the server) includes:

[0175] 0151: Encrypt the authentication information by encrypting it using the first quantum key;

[0176] 0152: Perform post-quantum signature processing on the temporary public key in the temporary key pair randomly generated by the terminal to obtain a temporary public key signature message;

[0177] 0153: Send the encrypted authentication information, temporary public key signature message, temporary public key, login ticket, and resource information corresponding to the resource accessed by the first resource request to the server as ticket request information.

[0178] In some implementations, the encryption module is used to encrypt the authentication information according to the first quantum key to obtain encrypted authentication information. The signature module is used to perform post-quantum signature processing on the temporary public key in the temporary key pair randomly generated by the terminal to obtain a temporary public key signature message. The processing module is used to send the encrypted authentication information, the temporary public key signature message, the temporary public key, the login ticket, and the resource information corresponding to the resource of the first resource access request as ticket request information to the server.

[0179] In some implementations, the processor is further configured to encrypt the authentication information according to the first quantum key to obtain encrypted authentication information, and to perform post-quantum signature processing on the temporary public key in the temporary key pair randomly generated by the terminal to obtain a temporary public key signature message. The processor then sends the encrypted authentication information, the temporary public key signature message, the temporary public key, the login ticket, and the resource information corresponding to the resource in the first resource access request as ticket request information to the server.

[0180] Specifically, the terminal encrypts the authentication information using the first quantum key to obtain encrypted authentication information. Next, the terminal performs post-quantum signature processing on the temporary public key in a randomly generated temporary key pair to obtain a temporary public key signature message. Finally, the terminal sends the encrypted authentication information, the temporary public key signature message, the temporary public key, the login ticket, and the resource information corresponding to the first resource access request as ticket request information to the server. In this way, the terminal obtains encrypted authentication information by encrypting the authentication information using the first quantum key, giving the authentication information strong resistance to quantum computing attacks. Furthermore, signing the temporary public key using the post-quantum public key ensures the integrity and authenticity of the temporary public key during transmission.

[0181] Continuing with the example above, a temporary key pair includes a temporary public key and a temporary private key.

[0182] Referring again to Figure 3, after the user obtains the first quantum key QK_UUID-1 based on the login ticket, the user encrypts the authentication information m1 using the first quantum key QK_UUID-1 to obtain encrypted authentication information M1. Next, the user performs post-quantum signature processing on the temporary public key in the randomly generated temporary key pair to obtain a temporary public key signature message M2. In some implementations, an ECC algorithm is used to randomly generate a temporary key pair, with the temporary public key being an ECC temporary public key and the temporary private key being an ECC temporary private key. Finally, the user sends the encrypted authentication information M1, the temporary public key signature message M2, the temporary public key, the login ticket, and the resource information Z1 corresponding to the resource access request to the server as ticket request information.

[0183] Thus, the user end encrypts the authentication information m1 using the first quantum key QK_UUID-1 to obtain the encrypted authentication information M1, giving the authentication information m1 strong resistance to quantum computing attacks. Furthermore, the temporary public key is signed using the subsequent quantum public key, ensuring the integrity and authenticity of the temporary public key during transmission.

[0184] Please refer to Figure 7. In some embodiments, step 017 (sending a second resource access request generated based on the service ticket to the server) includes the following method:

[0185] 0171: Concatenate the resource information and the randomly generated verification number from the terminal to obtain the verification concatenation body;

[0186] 0172: Sign the verification concatenation using the temporary private key in the temporary key pair to obtain the verification signature message;

[0187] 0173: Send the verification message, service ticket, and resource information as a second resource access request to the server. The verification message includes a verification signature message and a verification random number.

[0188] In some implementations, the concatenation module concatenates resource information and a randomly generated verification random number from the terminal to obtain a verification concatenation. The signature module signs the verification concatenation using a temporary private key from a temporary key pair to obtain a verification signature message. The processing module sends the verification message, service ticket, and resource information as a second resource access request to the server.

[0189] In some implementations, the processor is further configured to concatenate resource information and a randomly generated verification random number from the terminal to obtain a verification concatenation; sign the verification concatenation using a temporary private key from a temporary key pair to obtain a verification signature message; and send the verification message, service ticket, and resource information as a second resource access request to the server.

[0190] Specifically, the terminal concatenates the resource information and a randomly generated verification random number to obtain a verification concatenation. Next, the terminal performs post-quantum signature processing on the verification concatenation using the temporary private key from the temporary key pair to obtain a verification signature message. Finally, the terminal sends the verification message, service ticket, and resource information as a second resource access request to the server. The verification message includes the verification signature message and the verification random number. In this way, the terminal uses a post-quantum signature algorithm to sign the verification concatenation obtained by concatenating the resource information and the randomly generated verification random number to obtain the verification signature message. This ensures that the second resource access request has strong quantum resistance during communication between the terminal and the server, preventing unauthorized access to communication data.

[0191] Continuing with the example above, please refer to Figure 3 again. The client concatenates the resource information Z1 and the client-generated random verification number R1 to obtain the verification concatenation T1. Next, the client performs post-quantum signature processing on the verification concatenation T1 based on the temporary private key in the temporary key pair to obtain the verification signature message M3. Finally, the client sends the verification message, service ticket ST, and resource information Z1 as a second resource access request to the resource server. The verification message includes the verification signature message M3 and the verification random number R1.

[0192] Thus, the user end uses the post-quantum signature algorithm to concatenate the resource information Z1 and the user end's randomly generated verification random number R1 to obtain a verification concatenation body, and then signs the verification signature message M3 obtained from the signature processing. This gives the second resource access request good quantum resistance during the communication process between the user end and the resource server, preventing unauthorized access to the communication data.

[0193] Please refer to Figure 8. In some embodiments, the method further includes:

[0194] 019: Receive the authorization ticket sent by the server.

[0195] In some implementations, the receiving module is used to receive the ticket authorization ticket sent by the server.

[0196] In some implementations, the processor is also used to receive ticket authorization tickets sent by the server.

[0197] Specifically, the terminal receives a ticket authorization ticket sent by the server, which is generated by the server based on the ticket request information. In this way, the terminal obtains the ticket authorization ticket, which allows the terminal to simplify the process of obtaining the service ticket (ST).

[0198] Continuing with the example above, please refer to Figure 3 again. The user receives the Ticket Granting Ticket (TGT) sent by the authentication server. The Ticket Granting Ticket (TGT) is generated by the authentication server based on the ticket request information.

[0199] In this way, the client obtains the Ticket Authorization Ticket (TGT), which allows the client to simplify the process of obtaining the Service Ticket (ST).

[0200] Please refer to Figure 9. In some embodiments, the method further includes:

[0201] 020: When accessing resources on the server for the first time, send a ticket authorization ticket to the server;

[0202] 021: Receive the follow-up service ticket generated based on the ticket authorization ticket sent by the server;

[0203] 022: Send a third resource access request generated based on the subsequent service ticket to the server. The server confirms the access permissions of the subsequent resources corresponding to the third resource access request, so that the terminal can access the subsequent resources in the server.

[0204] In some implementations, the sending module is used to send a ticket authorization ticket to the server when accessing resources on the server for the first time. The receiving module is also used to receive a subsequent service ticket generated by the server based on the ticket authorization ticket. The sending module is further used to send a third resource access request generated by the subsequent service ticket to the server, and the server confirms the access rights to the subsequent resources corresponding to the third resource access request, so that the terminal can access the subsequent resources on the server.

[0205] In some implementations, the processor is further configured to send a ticket authorization ticket to the server when accessing resources on the server for the first time, and to receive a subsequent service ticket generated from the ticket authorization ticket by the server. It also sends a third resource access request generated from the subsequent service ticket to the server, and the server confirms access permissions for the subsequent resources corresponding to the third resource access request, thereby enabling the terminal to access the subsequent resources on the server.

[0206] Specifically, the subsequent resource corresponding to the third resource access request can be the same as or different from the resource corresponding to the second resource access request. The subsequent service ticket can also be the same as or different from the service ticket.

[0207] When accessing resources on the server for the first time, the terminal sends a ticket authorization ticket to the server. Next, the terminal receives a subsequent service ticket generated from the ticket authorization ticket by the server. Finally, the terminal sends a third resource access request generated from the subsequent service ticket to the server. The server confirms the access permissions for the subsequent resource corresponding to the third resource access request, enabling the terminal to access the subsequent resource on the server. In this way, when accessing resources on the server for the first time, the terminal uses the obtained ticket authorization ticket to obtain a subsequent service ticket from the server, thereby accessing the required resource, simplifying the process of obtaining service tickets. Furthermore, because the ticket service ticket is quantum resistant, the communication process of obtaining service tickets based on the ticket authorization ticket has good resistance to quantum computing attacks.

[0208] Continuing with the example above, please refer to Figure 3 again. In cases where the user is accessing resources on the server for the first time—that is, when the user accesses other resources on the resource server or accesses the second resource corresponding to the second resource access request again after the service ticket ST's cookie expires—the user sends a Ticket Authorization Ticket (TGT) to the authentication server. Next, the user receives a subsequent service ticket ST-2 generated from the Ticket Authorization Ticket TGT by the authentication server. Finally, the user sends a third resource access request generated from the subsequent service ticket ST-2 to the resource server, which submits the third resource access request to the authentication server. The authentication server, based on the third resource access request, confirms the access permissions for the subsequent resource corresponding to the third resource access request, enabling the user to access the subsequent resource on the resource server.

[0209] Thus, in cases where the user client is accessing resources on the server for the first time, they can use the obtained Ticket Authorization Ticket (TGT) to retrieve the subsequent service ticket (ST-2) from the server, thereby accessing the required resources. This simplifies the process for the user client to obtain the subsequent service ticket (ST-2). Furthermore, because the Ticket Service Ticket (TGT) is quantum resistant, the communication process of obtaining the subsequent service ticket (ST-2) based on the Ticket Authorization Ticket (TGT) has good resistance to quantum computing attacks.

[0210] Please refer to Figure 10. This application provides a method for enhancing the quantum security of a central authentication service protocol in a communication network. The communication network includes a terminal and a server. The method is used on the server and includes:

[0211] 031: Receive the first resource access request sent by the terminal. The first resource access request is generated by the terminal when it accesses a resource in the server for the first time.

[0212] 032: Obtain the second quantum key and quantum key identifier from the second network node connected to the access server;

[0213] 033: Send a login ticket and login form to the terminal. The login ticket is a quantum key identifier, and the login form is generated by the server based on the first resource access request.

[0214] 034: The ticket request information sent by the receiving terminal, obtained by processing the authentication information according to the first quantum key and the post-quantum cryptography algorithm;

[0215] 035: Generate a service ticket based on the ticket request information and send the service ticket to the terminal;

[0216] 036: The receiving terminal generates a second resource access request based on the service ticket, confirms the access permissions of the resource corresponding to the second resource access request, so that the terminal can access the server's resources.

[0217] This application also provides a server, including a memory and a processor. The method of this application can be implemented by the server of this application. Specifically, the memory stores a computer program, and the processor is used to receive a first resource access request sent by a terminal, and to obtain a second quantum key and a quantum key identifier from a second network node accessing the server, and to send a login ticket and a login form to the terminal. The processor is also used to receive ticket request information sent by the terminal, obtained by processing authentication information according to the first quantum key and a post-quantum cryptography algorithm, and to generate a service ticket according to the ticket request information and send the service ticket to the terminal. It also receives a second resource access request generated by the terminal according to the service ticket, confirms the access rights of the resource corresponding to the second resource access request, so that the terminal can access the server resources.

[0218] This application also provides a server security enhancement device. The method of this application can be implemented by the server security enhancement device of this application. Specifically, the server security enhancement device includes a receiving module, an acquiring module, a sending module, and a generating module. The receiving module is used to receive a first resource access request sent by a terminal. The acquiring module is used to acquire a second quantum key and a quantum key identifier from a second network node accessing the server. The sending module is used to send a login ticket and a login form to the terminal. The receiving module is also used to receive ticket request information sent by the terminal, obtained by processing authentication information according to the first quantum key and a post-quantum cryptography algorithm. The generating module is also used to generate a service ticket according to the ticket request information and send the service ticket to the terminal. The receiving module is also used to receive a second resource access request generated by the terminal according to the service ticket, and confirm the access permissions of the resource corresponding to the second resource access request, so that the terminal can access the server resources.

[0219] This application provides a communication system based on a central authentication service protocol. The communication system includes a server, a terminal, and a quantum key distribution network as described in the above embodiments. The quantum key distribution network is configured to distribute quantum keys to the terminal or the server.

[0220] Specifically, the quantum security enhancement method of this embodiment is basically the same as the quantum security enhancement method of the aforementioned embodiment that uses the terminal as the execution target. For details, please refer to the explanation of the corresponding section. The difference is that this embodiment uses the server as the execution target, which will not be repeated here.

[0221] In summary, in the quantum-resistant security enhancement method, communication system, terminal, and server of the central authentication service protocol in the communication network according to the embodiments of this application, for the communication process of the terminal's initial request to access resources in the server, the terminal uses the login ticket received from the server to request a quantum key from the first network node accessing the terminal. The quantum key and a post-quantum cryptography algorithm are then used to encrypt the authentication information generated from the login form received from the server, generating a ticket request information resistant to quantum computing attacks. The post-quantum cryptography algorithm includes a series of encryption algorithms designed to resist quantum computing attacks, and the quantum key has good resistance to quantum computing attacks. Next, the server generates a service ticket based on the ticket request information sent by the terminal and sends the service ticket to the terminal. Then, the terminal generates a resource access request based on the service ticket to access resources in the server. Finally, the server verifies the correctness of the service ticket to determine whether the terminal can access the resource corresponding to the resource access request. Thus, the quantum key distribution technology and the post-quantum cryptography algorithm enhance the resistance to quantum computing attacks in the communication process of the terminal requesting access to server resources.

[0222] Please refer to Figure 11. In some embodiments, the method further includes:

[0223] 037: The post-quantum public key of the receiving terminal.

[0224] In some implementations, the receiving module is also used to receive the terminal's post-quantum public key sent by the terminal.

[0225] In some implementations, the processor is also used to receive the terminal's post-quantum public key sent by the terminal.

[0226] Specifically, the server receives the terminal's own post-quantum public key from the terminal. In this way, the server obtains the terminal's post-quantum public key and can decrypt the communication data sent by the terminal based on it. The post-quantum public key has strong resistance to quantum computing attacks, enabling data protected by the post-quantum public key to be highly resistant to such attacks.

[0227] Continuing with the example above, the post-quantum public key is the PQC public key. Please refer to Figure 3 again; the authentication server receives the user's own PQC public key sent by the user.

[0228] In this way, the authentication server obtains the user's PQC public key and can decrypt the communication data sent by the user based on the user's PQC public key. The PQC public key has strong resistance to quantum computing attacks, enabling data protected by the PQC public key to be highly resistant to such attacks.

[0229] Referring to Figure 12, in some embodiments, step 032 (obtaining the second quantum key and quantum key identifier from the second network node of the access server) includes:

[0230] 0321: Upon receiving the first resource access request, send a quantum key application to the second network node of the access server;

[0231] 0322: Receive the second quantum key and quantum key identifier sent by the second network node.

[0232] In some implementations, the sending module is further configured to send a quantum key request to a second network node accessing the server upon receiving a first resource access request. The receiving module is further configured to receive a second quantum key and a quantum key identifier sent by the second network node.

[0233] In some implementations, the processor is further configured to, upon receiving a first resource access request, send a quantum key request to a second network node accessing the server, and receive a second quantum key and a quantum key identifier sent by the second network node.

[0234] Specifically, upon receiving a first resource access request, the server sends a quantum key request to the second network node accessing the server. Next, the server receives a second quantum key and a quantum key identifier from the second network node. The second quantum key is obtained by the second network node according to the quantum key request, and the quantum key identifier is obtained by the second network node by identifying the second quantum key using its own identification code. In this way, the server obtains the second quantum key and the quantum key identifier. The second quantum key has strong resistance to quantum computing attacks and can be used to provide strong confidentiality for communication between the terminal and the server. The quantum key identifier facilitates the management and use of the quantum key. Using the quantum key identifier as a login ticket provides strong confidentiality.

[0235] Continuing with the example above, please refer to Figure 3. Before communicating with the user, the authentication server connects to the closest physically located and authorized second quantum network node via a trusted channel. A trusted channel refers to a mechanism or protocol that provides a secure communication path between two communicating entities. One way to establish this channel is for the authentication server and the second quantum network node to be located in the same rack and directly connected by shielded network cables. This channel ensures the confidentiality, integrity, and availability of data during transmission, preventing unauthorized access, tampering, or eavesdropping.

[0236] Upon receiving the first resource access request, the authentication server sends a quantum key request to the second quantum network node. Next, the authentication server receives the second quantum key QK_UUID-2 (128 bits or more) and the quantum key identifier UUID_QK sent by the second quantum network node according to the quantum key request. The quantum key identifier UUID_QK is obtained by the second quantum network node identifying the second quantum key QK_UUID-2 using its unique universal identifier. The authentication server uses the quantum key identifier as a login ticket.

[0237] In this way, the authentication server obtains the second quantum key QK_UUID-2 and the quantum key identifier UUID_QK. The second quantum key QK_UUID-2 has strong resistance to quantum computing attacks and can be used to make the communication between the client and the authentication server highly confidential. The quantum key identifier UUID_QK helps in the management and use of quantum keys. Using the quantum key identifier UUID_QK as a login ticket provides strong confidentiality.

[0238] Referring to Figure 13, in some implementations, the ticket request information includes encrypted authentication information, a temporary public key signature message, a login ticket, and a temporary public key. The method further includes:

[0239] 038: Confirm the usage status of the second quantum key corresponding to the login ticket;

[0240] 039: In the absence of the second quantum key, the encrypted authentication information is decrypted using the second quantum key to obtain the authentication information;

[0241] 040: Verify the signature of the temporary public key based on the post-quantum public key to determine the correctness of the temporary public key;

[0242] 041: Once the authentication information is obtained, the second quantum key is deleted to ensure that the second quantum key cannot be reused;

[0243] 042: Divide the temporary public key into a first temporary public key and a second temporary public key.

[0244] In some implementations, the verification module is used to verify the usage of the second quantum key corresponding to the login ticket. The decryption module is used to decrypt the encrypted authentication information using the second quantum key if it is not in use, thus obtaining the authentication information. The signature verification module is used to verify the signature of the temporary public key using the subsequent quantum public key to determine the correctness of the temporary public key. The deletion module is used to delete the second quantum key if authentication information is obtained, ensuring that the second quantum key cannot be reused. The segmentation module is used to divide the temporary public key into a first temporary public key and a second temporary public key.

[0245] In some implementations, the processor is further configured to verify the usage of the second quantum key corresponding to the login ticket; and, if the second quantum key is not in use, to decrypt the encrypted authentication information using the second quantum key to obtain authentication information; and to verify the signature of the temporary public key using the subsequent quantum public key to determine the correctness of the temporary public key. The processor is also configured to delete the second quantum key upon obtaining authentication information to ensure that the second quantum key is not reusable; and to divide the temporary public key into a first temporary public key and a second temporary public key.

[0246] Specifically, the authentication information includes the username and password entered by the user.

[0247] The server first verifies the usage of the second quantum key corresponding to the login ticket. If the second quantum key is not in use, the server decrypts the encrypted authentication information using it to obtain the authentication information. Next, the server verifies the signature of the temporary public key using the subsequent quantum public key to confirm the correctness of the temporary public key. Upon obtaining the authentication information, the server deletes the second quantum key to ensure it cannot be reused. Furthermore, the server divides the temporary public key into a first temporary public key and a second temporary public key. This ensures the security of the authentication process and prevents unauthorized access by confirming that the quantum key corresponding to the login ticket has not been used for previous logins. Deleting the second quantum key after obtaining authentication information ensures that a used quantum key cannot be reused. Additionally, the server divides the temporary public key into a first temporary public key and a second temporary public key for subsequent processes to reduce potential security risks.

[0248] Continuing with the example above, please refer to Figure 3. After receiving the ticket request information from the user, the authentication server first confirms the usage of the second quantum key QK_UUID-2 corresponding to the login ticket, confirming that the second quantum key QK_UUID-2 corresponding to the quantum key identifier UUID_QK in the login ticket has not been used for login before. If the second quantum key QK_UUID-2 is not used, the authentication server decrypts the encrypted authentication information M1 using the second quantum key QK_UUID-2 to obtain authentication information m1. Next, the authentication server verifies the signature of the temporary public key message M2 using the subsequent quantum public key to determine the correctness of the temporary public key. Having obtained authentication information M1, the authentication server deletes the second quantum key QK_UUID-2 to ensure that it cannot be reused. Furthermore, the authentication server divides the temporary public key into two parts: a first temporary public key P1 and a second temporary public key P2.

[0249] Thus, by confirming that the quantum key corresponding to the login ticket has not been used for previous logins, and by processing the temporary public key signing message and encrypted authentication message, the security of the authentication process and the prevention of unauthorized access are ensured. Furthermore, having already obtained authentication information m1, the second quantum key QK_UUID-2 is deleted to ensure that a used quantum key cannot be reused. In addition, the authentication server also divides the temporary public key into a first temporary public key P1 and a second temporary public key P2 for use in subsequent processes to reduce potential security risks.

[0250] Please refer to Figure 14. In some embodiments, the ticket request information includes resource information. Step 035 (generating a service ticket based on the ticket request information and sending the service ticket to the terminal) includes the following methods:

[0251] 0351: Generate temporary ticket authorization tickets based on resource information;

[0252] 0352: Generate the first temporary service ticket based on the temporary ticket authorization ticket;

[0253] 0353: Concatenate the temporary public key and the ticket authorization ticket attribute value in the first temporary service ticket to obtain a temporary concatenation body;

[0254] 0354: Perform post-quantum signature processing on the temporary concatenation based on the server's second post-quantum private key to obtain the service ticket signature message;

[0255] 0355: Store the service ticket signature message and the first temporary public key in the first temporary service ticket to obtain the second temporary service ticket;

[0256] 0356: Sign the second temporary service ticket using the server's second classic public key to obtain a service ticket, and send the service ticket to the terminal;

[0257] 0357: Cache the second temporary public key and delete the first temporary public key.

[0258] In some implementations, the derivation module is further configured to generate a temporary ticket authorization ticket based on resource information. The derivation module is also configured to generate a first temporary service ticket based on the temporary ticket authorization ticket. The concatenation module is configured to concatenate the temporary public key and the ticket authorization ticket attribute value from the first temporary service ticket to obtain a temporary concatenation. The signing module is configured to perform post-quantum signing processing on the temporary concatenation based on the server's second post-quantum private key to obtain a service ticket signature message. The storage module is configured to store the service ticket signature message and the first temporary public key in the first temporary service ticket to obtain a second temporary service ticket. The storage module is configured to sign the second temporary service ticket based on the server's second classical public key to obtain a service ticket, and send the service ticket to the terminal. The processing module is further configured to cache the second temporary public key and delete the first temporary public key.

[0259] In some implementations, the processor is further configured to generate a temporary ticket authorization ticket based on resource information, and to generate a first temporary service ticket based on the temporary ticket authorization ticket. It also concatenates the temporary public key and the ticket authorization ticket attribute value from the first temporary service ticket to obtain a temporary concatenation. The processor is further configured to perform post-quantum signature processing on the temporary concatenation based on the server's second post-quantum private key to obtain a service ticket signature message. It then stores the service ticket signature message and the first temporary public key in the first temporary service ticket to obtain a second temporary service ticket. Finally, it signs the second temporary service ticket based on the server's second classical public key to obtain a service ticket, sends the service ticket to the terminal, caches the second temporary public key, and deletes the first temporary public key.

[0260] Specifically, the server generates a temporary authorization ticket based on resource information. Next, the server generates a first temporary service ticket based on the temporary authorization ticket. Then, the server concatenates the temporary public key and the authorization ticket attribute values ​​from the first temporary service ticket to obtain a temporary concatenation. The authorization ticket attribute values ​​are used to store relevant information related to the temporary authorization ticket. The server then performs post-quantum signature processing on the temporary concatenation using its second post-quantum private key to obtain a service ticket signature message. The service ticket signature message and the first temporary public key are stored in the first temporary service ticket to obtain a second temporary service ticket. Finally, the server signs the second temporary service ticket using its second classical public key to obtain the service ticket and sends it to the terminal. Furthermore, the server caches the second temporary public key and deletes the first temporary public key. In this way, the server generates a first temporary service ticket and uses post-quantum signature algorithms and classical signature algorithms to sign and protect the first temporary service ticket, giving the signed service ticket good confidentiality and quantum resistance. Furthermore, the server caches a portion of the temporary public key locally and deletes the other portion to reduce potential security risks and maintain the integrity of the public key.

[0261] Continuing with the example above, please refer to Figure 3. The authentication server generates a temporary ticket granting ticket (TGT-1) based on resource information Z1. Next, the authentication server generates a first temporary service ticket ST1 based on the temporary ticket granting ticket (TGT-1). Then, the authentication server concatenates the temporary public key and the ticket granting ticket attribute value (ticketGrantingTicket) from the first temporary service ticket ST1 to obtain a temporary concatenation T2. ​​The ticket granting ticket attribute value (ticketGrantingTicket) is used to store information related to the temporary ticket granting ticket (TGT-1). The authentication server then performs post-quantum signature processing on the temporary concatenation T2 based on its second post-quantum private key to obtain a service ticket signature message M4. The service ticket signature message M4 and the first temporary public key P1 are stored in the first temporary service ticket to obtain a second temporary service ticket ST2. Finally, the authentication server signs the second temporary service ticket ST2 using its second classic public key to obtain a service ticket (ST), and sends the service ticket (ST) to the terminal. In addition, the authentication server caches the second temporary public key P2 and deletes the first temporary public key P1.

[0262] In this way, the authentication server generates a first temporary service ticket ST1 and uses a post-quantum signature algorithm and a classical signature algorithm to sign and protect the first temporary service ticket ST1, giving the service ticket (ST) with good confidentiality and quantum resistance. Furthermore, the authentication server caches a portion of the temporary public key locally and deletes the other portion to reduce potential security risks and maintain the integrity of the public key.

[0263] Please refer to Figure 15. In some embodiments, step 036 (receiving the second resource access request generated by the terminal based on the service ticket, confirming the access permissions of the resource corresponding to the second resource access request, so that the terminal can access the server for resources) includes:

[0264] 0361: The receiving terminal generates a second resource access request based on the service ticket;

[0265] 0362: Verify the signature message using the server's second classic private key to confirm the validity of the service ticket;

[0266] 0363: Combine the second temporary public key and the received first temporary public key to obtain a temporary public key;

[0267] 0364: Verify the service ticket signature message based on the server's second post-quantum public key to confirm the validity of the ticket authorization ticket corresponding to the ticket authorization ticket attribute value;

[0268] 0365: Verify the correctness of the authentication information based on the temporary public key; if the authentication information is correct, allow the terminal to access the server's resources.

[0269] In some implementations, the receiving module receives a second resource access request generated by the terminal based on a service ticket. The signature verification module verifies the signature message using the server's second classical private key to confirm the validity of the service ticket. The processing module combines the second temporary public key and the received first temporary public key to obtain a temporary public key. The signature verification module also verifies the service ticket signature message using the server's second post-quantum public key to confirm the validity of the ticket authorization ticket corresponding to the ticket authorization attribute value. The determining module verifies the correctness of the authentication information using the temporary public key; if the authentication information is correct, the terminal is allowed to access the server's resources.

[0270] In some implementations, the processor is further configured to receive a second resource access request generated by the terminal based on a service ticket; and to perform signature verification processing on the verification signature message based on the server's second classical private key to confirm the validity of the service ticket; and to synthesize the second temporary public key and the received first temporary public key to obtain a temporary public key. The processor is also configured to perform signature verification processing on the service ticket signature message based on the server's second post-quantum public key to confirm the validity of the ticket authorization ticket corresponding to the ticket authorization ticket attribute value; and to verify the correctness of the authentication information based on the temporary public key; so that if the authentication information is correct, the terminal is allowed to access resources on the server.

[0271] Specifically, the server receives a second resource access request generated by the terminal based on a service ticket. This request includes a verification message, a service ticket, and resource information. The verification message includes a verification signature message and a verification random number. Next, the server verifies the verification signature message using its second classical private key to confirm the validity of the service ticket. Then, the server synthesizes the second temporary public key and the received first temporary public key to obtain a temporary public key. The server then verifies the service ticket signature message using its second post-quantum public key to confirm the validity of the authorization ticket corresponding to the ticket's attribute value. Finally, the server verifies the correctness of the authentication information using the temporary public key; if the authentication information is correct, the terminal is allowed to access the server's resources. In this way, by verifying the validity of the service ticket in the second resource access request and verifying the service ticket signature message using the synthesized temporary public key to confirm the validity of the authorization ticket, the server can ensure the authenticity of the terminal's identity, providing strong security and quantum security for resource access requests, thus helping to protect data and communication security.

[0272] Continuing with the example above, please refer to Figure 3. The resource server receives a second resource access request generated by the user based on the Service Ticket (ST). The second resource access request includes a verification message, the Service Ticket (ST), and resource information Z1. The verification message includes a verification signature message M3 and a verification random number R1. After receiving this data, the resource server submits it to the authentication server. Next, the authentication server verifies the verification signature message M3 using its second classical private key to confirm the validity of the Service Ticket (ST). Then, the authentication server combines the second temporary public key P2 and the received first temporary public key P1 to obtain a temporary public key. The authentication server then verifies the service ticket signature message M4 using its second post-quantum public key to confirm the validity of the Ticket Granting Ticket (TGT) corresponding to the TicketGrantingTicket attribute value. Finally, the authentication server verifies the correctness of the authentication information m1 using the temporary public key; if the authentication information m1 is correct, the user is allowed to access the resource server's resources. In this way, by verifying the validity of the Service Ticket (ST) in the second resource access request, and confirming the validity of the ticket authorization by processing the signature message M4 of the Service Ticket using the synthesized temporary public key, the authentication server can ensure the authenticity of the user's identity, providing strong security and quantum security for resource access requests, and helping to protect the security of data and communications.

[0273] Thus, by verifying the validity of the Service Ticket (ST) in the second resource access request, and confirming the validity of the Ticket Authorization Ticket (TGT) by processing the signature message M4 of the Service Ticket using the synthesized temporary public key, the authentication server can ensure the authenticity of the user's identity, providing strong and quantum security for resource access requests, and helping to protect the security of data and communications.

[0274] Please refer to Figure 16. In some embodiments, the method further includes:

[0275] 0381: Sign the temporary ticket authorization ticket using the server's second classic public key to obtain the classic signed ticket authorization ticket;

[0276] 0382: Perform post-quantum signature processing on the temporary ticket authorization ticket based on the server's second post-quantum public key to obtain the post-quantum signed ticket authorization ticket;

[0277] 0383: Store the classic signature ticket authorization ticket and the post-quantum signature ticket authorization ticket in the temporary ticket authorization ticket to obtain the ticket authorization ticket;

[0278] 0384: Send the ticket authorization ticket to the terminal.

[0279] In some implementations, the signature module is further configured to sign the temporary ticket authorization ticket using the server's second classical public key to obtain a classically signed ticket authorization ticket. The signature module is also configured to perform post-quantum signing on the temporary ticket authorization ticket using the server's second post-quantum public key to obtain a post-quantum signed ticket authorization ticket. The storage module stores the classically signed ticket authorization ticket and the post-quantum signed ticket authorization ticket in the temporary ticket authorization ticket, obtaining a ticket authorization ticket. The sending module sends the ticket authorization ticket to the terminal.

[0280] In some implementations, the processor is further configured to sign the temporary ticket authorization ticket using the server's second classical public key to obtain a classically signed ticket authorization ticket, and to perform post-quantum signing on the temporary ticket authorization ticket using the server's second post-quantum public key to obtain a post-quantum signed ticket authorization ticket. The processor is also configured to store the classically signed ticket authorization ticket and the post-quantum signed ticket authorization ticket in the temporary ticket authorization ticket to obtain a ticket authorization ticket, and to send the ticket authorization ticket to the terminal.

[0281] Specifically, the authentication server signs the temporary ticket authorization ticket using its second classical public key to obtain a classically signed ticket authorization ticket. Next, the authentication server performs a post-quantum signature process on the temporary ticket authorization ticket using its own second post-quantum public key to obtain a post-quantum signed ticket authorization ticket. Then, the authentication server stores both the classically signed and post-quantum signed ticket authorization tickets in the temporary ticket authorization ticket, resulting in the final ticket authorization ticket. Finally, the authentication server sends the final ticket authorization ticket to the terminal. In this way, by signing the temporary ticket authorization ticket using both classical and post-quantum signature algorithms, and then storing these two tickets in the temporary ticket authorization ticket, the final ticket authorization ticket possesses strong quantum resistance and confidentiality.

[0282] Continuing with the example above, please refer to Figure 3. The authentication server signs the temporary granting ticket (Ticket Granting Ticket-1, TGT-1) using its second classical public key to obtain the classically signed granting ticket Q1. Next, the authentication server performs a post-quantum signature on the temporary granting ticket (Ticket Granting Ticket-1, TGT-1) using its second post-quantum public key to obtain the post-quantum signed granting ticket Q2. Then, the authentication server stores the classically signed granting ticket Q1 and the post-quantum signed granting ticket Q2 in the temporary granting ticket (Ticket Granting Ticket-1, TGT-1), obtaining the granting ticket TGT. Finally, the authentication server sends the granting ticket TGT to the client.

[0283] Thus, the temporary ticket granting ticket (Ticket Granting Ticket-1, TGT-1) is signed using both classical and post-quantum signature algorithms, resulting in classically signed ticket granting ticket Q1 and post-quantum signed ticket granting ticket Q2. These two tickets are then stored within the temporary ticket granting ticket (Ticket Granting Ticket-1, TGT-1) to obtain the ticket granting ticket TGT, which possesses good quantum resistance and confidentiality.

[0284] Please refer to Figure 17. In some embodiments, the method further includes:

[0285] 043: When accessing resources on the server for the first time, receive a ticket authorization ticket sent by the terminal;

[0286] 044: Generate a follow-up service ticket based on the ticket authorization ticket, and send the follow-up service ticket to the terminal;

[0287] 045: Receive the third resource access request generated by the receiving terminal based on the subsequent service ticket, confirm the access permissions of the subsequent resources corresponding to the third resource access request, so that the terminal can access the subsequent resources of the server.

[0288] In some implementations, the receiving module is further configured to receive a ticket authorization ticket sent by the terminal when accessing resources on the server for the first time. The sending module is further configured to generate a follow-up service ticket based on the ticket authorization ticket and send the follow-up service ticket to the terminal. The receiving module is further configured to receive a third resource access request generated by the terminal based on the follow-up service ticket, confirm the access permissions of the follow-up resource corresponding to the third resource access request, so as to enable the terminal to access the follow-up resources of the server.

[0289] In some implementations, the processor is further configured to: receive a ticket authorization ticket sent by the terminal when accessing resources on the server for the first time; generate a subsequent service ticket based on the ticket authorization ticket and send the subsequent service ticket to the terminal; and receive a third resource access request generated by the terminal based on the subsequent service ticket, confirm the access rights to the subsequent resources corresponding to the third resource access request, so that the terminal can access the subsequent resources of the server.

[0290] Specifically, in cases where the terminal is accessing resources on the server for the first time, the server receives a ticket authorization ticket from the terminal. Next, the server generates a subsequent service ticket based on the ticket authorization ticket and sends it to the terminal. Finally, the server receives a third resource access request generated by the terminal based on the subsequent service ticket, confirms the access permissions for the corresponding subsequent resources, and enables the terminal to access those resources. In this way, in cases where the terminal is accessing resources on the server for the first time, the server generates a subsequent service ticket based on the received ticket authorization ticket, enabling the terminal to access the server's resources. This greatly simplifies the process of the terminal obtaining service tickets while also providing good quantum resistance and confidentiality.

[0291] Continuing with the example above, please refer to Figure 3. When a user's client accesses resources on the resource server before, the authentication server receives the Ticket Authorization Ticket (TGT) sent by the client. Next, the authentication server generates a follow-up service ticket (ST-2) based on the TGT and sends it to the client. Finally, the resource server receives a third resource access request generated by the client based on the follow-up service ticket (ST-2), confirms the access permissions for the corresponding follow-up resource, and enables the client to access the resource server's subsequent resources.

[0292] Thus, when a user accesses resources on the resource server for the first time, the authentication server generates a subsequent service ticket ST-2 based on the received ticket authorization ticket TGT, enabling the user to access resources on the resource server. This greatly simplifies the process for the user to obtain a service ticket, while also providing good quantum resistance and confidentiality.

[0293] Please refer to Figure 18. In some embodiments, step 044 (generating a follow-up service ticket based on the ticket authorization ticket and sending the follow-up service ticket to the terminal) includes:

[0294] 0441: Verify the signature of the authorized ticket based on the second classical public key and the second post-quantum public key to confirm the correctness of the authorized ticket;

[0295] 0442: After confirming that the ticket authorization ticket is correct, send the follow-up service ticket to the terminal.

[0296] In some implementations, the signature verification module is further configured to verify the ticket authorization ticket based on the second classical public key and the second post-quantum public key to confirm its correctness. The receiving module is further configured to send a subsequent service ticket to the terminal if the ticket authorization ticket is confirmed to be correct.

[0297] In some implementations, the processor is further configured to verify the validity of the ticket authorization ticket based on the second classical public key and the second post-quantum public key, and, if the ticket authorization ticket is confirmed to be valid, send a subsequent service ticket to the terminal.

[0298] Specifically, the server verifies the signature of the authorization ticket using the second classical public key and the second post-quantum public key to confirm its correctness. Upon confirming the ticket's correctness, the server sends subsequent service tickets to the terminal. In this way, by verifying the signature of the authorization ticket, confirming its correctness, generating and distributing subsequent service tickets, and verifying the terminal's identity, the security of resources on the server is ensured.

[0299] Continuing with the example above, please refer to Figure 3 again. The authentication server verifies the signature of the Ticket Authorization Ticket (TGT) based on the second classical public key and the second post-quantum public key to confirm the correctness of the TGT. If the TGT is confirmed to be correct, the authentication server sends the subsequent service ticket ST-2 to the user.

[0300] In this way, by verifying the signature of the ticket authorization ticket (TGT), the correctness of the ticket authorization ticket (TGT) is confirmed, thereby generating and distributing the subsequent service ticket (ST-2), confirming the identity of the user, and ensuring the security of resources in the authentication server.

[0301] The various component embodiments of this application can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the computing processing device according to the embodiments of this application. This application can also be implemented as a device or apparatus program (e.g., a computer program and computer program product) for performing part or all of the methods described herein. Such an implementation of this application can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.

[0302] For example, Figure 19 illustrates a computing processing device that can implement the methods according to this application. This computing processing device conventionally includes a processor 1010 and a computer program product or computer-readable medium in the form of a memory 1020. The memory 1020 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. The memory 1020 has storage space 1030 for program code 1031 for performing any of the method steps described above. For example, the storage space 1030 for program code may include various program codes 1031 for implementing the various steps in the methods described above. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, compact discs (CDs), memory cards, or floppy disks. Such computer program products are typically portable or fixed storage units as described with reference to Figure 20. This storage unit may have storage segments, storage spaces, etc., arranged similarly to the memory 1020 in the computing processing device of Figure 19. The program code may be compressed, for example, in a suitable form. Typically, the storage unit includes computer-readable code 1031', which is code that can be read by a processor such as 1010, which, when run by a computing processing device, causes the computing processing device to perform the various steps in the method described above.

[0303] It is understood that a computer program includes computer program code. Computer program code can be in the form of source code, object code, executable files, or some intermediate form. Computer-readable storage media can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, external hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media, etc.

[0304] In this specification, the terms "specifically," "furthermore," "particularly," "understandably," etc., refer to specific features, structures, materials, or characteristics described in connection with embodiments or examples that are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0305] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this application pertain.

[0306] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

A method for enhancing the quantum-resistant security of a central authentication service protocol in a communication network, wherein, The communication network includes a terminal and a server, and the method is used on the terminal, the method comprising: In the case of the first access to a resource on the server, a first resource access request is sent to the server; Receive the login ticket and login form obtained by the server based on the first resource access request; The first quantum key is obtained from the first network node accessing the terminal based on the login ticket; Obtain the terminal's authentication information based on the login form; The authentication information is processed according to the first quantum key and the post-quantum cryptography algorithm to obtain ticket request information, and the ticket request information is sent to the server; Receive the service ticket generated by the server based on the ticket request information; The terminal sends a second resource access request generated based on the service ticket to the server. The server confirms the access permissions of the resource corresponding to the second resource access request based on the second resource access request, so that the terminal can access the server's resources. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 1, wherein, The method further includes: Send the terminal's post-quantum public key to the server. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 1, wherein, The step of obtaining the first quantum key from the first network node accessing the terminal based on the login ticket includes: The service node is used to fill the cryptographic module of the terminal with multiple keys; A quantum key request is sent to the service node based on the login ticket. The quantum key request is protected by a protection key, which is one of multiple keys randomly used from those injected into the cryptographic module. The service node receives the quantum key encryption result obtained by encrypting the first quantum key according to the protection key, and the first quantum key is distributed to the service node by the first network node connected to the service node. The first quantum key is obtained by decrypting the quantum key encryption result. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 1, wherein, The step of processing the authentication information according to the first quantum key and the post-quantum cryptography algorithm to obtain ticket request information, and sending the ticket request information to the server, includes: The authentication information is encrypted using the first quantum key to obtain encrypted authentication information. A temporary public key signature message is obtained by performing post-quantum signature processing on the temporary public key in the temporary key pair randomly generated by the terminal. The encrypted authentication information, the temporary public key signature message, the temporary public key, the login ticket, and the resource information corresponding to the resource access request of the first resource are sent to the server as ticket request information. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 4, wherein, Sending the second resource access request generated based on the service ticket to the server includes: The resource information and the verification random number randomly generated by the terminal are concatenated to obtain the verification concatenation body. The verification concatenation is signed using the temporary private key in the temporary key pair to obtain a verification signature message. The verification message, the service ticket, and the resource information are sent to the server as a second resource access request. The verification message includes the verification signature message and the verification random number. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 1, wherein, The method further includes: The server receives a ticket authorization ticket sent by the server, which is generated by the server based on the ticket request information. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 6, wherein, The method further includes: When accessing resources on the server for the first time, a ticket authorization ticket is sent to the server. Receive the follow-up service ticket generated based on the ticket authorization ticket sent by the server; The terminal sends a third resource access request generated based on the subsequent service ticket to the server. The server confirms the access permissions of the subsequent resources corresponding to the third resource access request based on the third resource access request, so that the terminal can access the subsequent resources in the server. A method for enhancing the quantum-resistant security of a central authentication service protocol in a communication network, wherein, The communication network includes a terminal and a server, and the method is used on the server, the method comprising: Receive a first resource access request sent by the terminal, wherein the first resource access request is generated by the terminal when it first accesses a resource in the server; The second quantum key and quantum key identifier are obtained from the second network node connected to the server; Send a login ticket and a login form to the terminal, wherein the login ticket is the quantum key identifier and the login form is generated by the server based on the first resource access request; The terminal receives a ticket request message sent by the terminal, which is obtained by processing authentication information according to a first quantum key and a post-quantum cryptography algorithm. The first quantum key is obtained by the terminal based on the login ticket, and the authentication information is obtained by the terminal based on the login form. A service ticket is generated based on the ticket request information, and the service ticket is sent to the terminal. The system receives a second resource access request generated by the terminal based on the service ticket, confirms the access permissions of the resource corresponding to the second resource access request, and enables the terminal to access the server for resources. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 8, wherein, The method further includes: Receive the terminal's post-quantum public key sent by the terminal. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 8, wherein, The process of obtaining the second quantum key and quantum key identifier from the second network node connected to the server includes: Upon receiving the first resource access request, a quantum key application is sent to the second network node connected to the server; The system receives the second quantum key and the quantum key identifier sent by the second network node. The second quantum key is obtained by the second network node based on the quantum key application, and the quantum key identifier is obtained by the second network node by identifying the second quantum key based on the identification code of the second network node. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 9, wherein, The ticket request information includes encrypted authentication information, a temporary public key signature message, a login ticket, and a temporary public key. The method further includes: Confirm the usage status of the second quantum key corresponding to the login ticket; If the second quantum key is not used, the encrypted authentication information is decrypted using the second quantum key to obtain the authentication information; The temporary public key signature message is verified using the post-quantum public key to determine the correctness of the temporary public key; Upon obtaining the authentication information, the second quantum key is deleted to ensure that the second quantum key is not reusable; The temporary public key is divided into a first temporary public key and a second temporary public key. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 11, wherein, The ticket request information includes resource information. The step of generating a service ticket based on the ticket request information and sending the service ticket to the terminal includes: Generate a temporary ticket authorization ticket based on the resource information; A first temporary service ticket is generated based on the temporary ticket authorization ticket; The temporary public key and the ticket authorization ticket attribute value in the first temporary service ticket are concatenated to obtain a temporary concatenation body. The ticket authorization ticket attribute value is used to store relevant information related to the temporary ticket authorization ticket. The temporary concatenation is processed with a post-quantum signature based on the server’s second post-quantum private key to obtain a service ticket signature message. The service ticket signature message and the first temporary public key are stored in the first temporary service ticket to obtain the second temporary service ticket; The second temporary service ticket is signed using the server's second classic public key to obtain a service ticket, and the service ticket is sent to the terminal. Cache the second temporary public key and delete the first temporary public key. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 12, wherein, Receiving the second resource access request generated by the terminal based on the service ticket, and confirming the access permissions of the resource corresponding to the second resource access request, so that the terminal can access the server resources, includes: The terminal receives a second resource access request generated based on the service ticket. The second resource access request includes a verification message, the service ticket, and the resource information. The verification message includes a verification signature message and a verification random number. The verification signature message is processed using the server's second classic private key to confirm the validity of the service ticket; The second temporary public key and the received first temporary public key are combined to obtain the temporary public key; The service ticket signature message is verified using the server’s second post-quantum public key to confirm that the ticket authorization ticket corresponding to the ticket authorization ticket attribute value is valid. The authentication information is verified using the temporary public key; if the authentication information is correct, the terminal is allowed to access resources of the server. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 12, wherein, The method further includes: The temporary ticket authorization ticket is signed using the server's second classic public key to obtain a classic signed ticket authorization ticket. The temporary ticket authorization ticket is processed by post-quantum signature processing based on the server's second post-quantum public key to obtain a post-quantum signature ticket authorization ticket. The classic signature ticket authorization ticket and the post-quantum signature ticket authorization ticket are stored in the temporary ticket authorization ticket to obtain the ticket authorization ticket; The authorized ticket is sent to the terminal. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 14, wherein, The method further includes: In cases where access to resources on the server is not the first time, the terminal sends a ticket authorization ticket. A follow-up service ticket is generated based on the authorized ticket, and the follow-up service ticket is sent to the terminal. The server receives a third resource access request generated based on the subsequent service ticket from the terminal, confirms the access permissions of the subsequent resources corresponding to the third resource access request, and enables the terminal to access the subsequent resources of the server. The quantum-resistant security enhancement method for the central authentication service protocol of a communication network according to claim 15, wherein, The step of generating a follow-up service ticket based on the authorized ticket and sending the follow-up service ticket to the terminal includes: The ticket authorization ticket is verified using the second classical public key and the second post-quantum public key to confirm its correctness. If the authorization ticket is confirmed to be correct, a follow-up service ticket is sent to the terminal. A computing processing device, wherein, include: Memory containing computer-readable code; One or more processors, when the computer-readable code is executed by the one or more processors, the computing processing device performs a quantum-resistant security enhancement method for a central authentication service protocol of a communication network as described in any one of claims 1-7 or 8-16. A computer program comprising computer-readable code, which, when executed on a computing processing device, causes the computing processing device to perform a quantum-resistant security enhancement method for a central authentication service protocol of a communication network according to any one of claims 1-7 or 8-16. A computer-readable medium storing the computer program as described in claim 18.

Citation Information

Patent Citations

  • Identity authentication authorization method suitable for quantum key distribution network

    CN115276980A

  • Anti-quantum security enhancement method for national secret SSL VPN protocol

    CN118540163A

  • Anti-quantum security enhancement method for internet key exchange protocol

    CN118540164A

  • Anti-quantum security enhancement method for central authentication service protocol

    CN118694618A

  • Systems and methods for providing user authentication for quantum-entangled communications in a cloud environment

    US20230353348A1