The invention discloses a forward security zero round-trip time
authentication method and
system based on a
hash function, and the method comprises the steps: generating a first random number, a first private key and a corresponding public key through a
client, encrypting application data through combining with a temporary
session key, and constructing a protocol request message for transmission; the
server generates a second random number, a second private key and a public key after
verification, returns a protocol response message, and negotiates a shared key based on temporary private keys of the two parties; the two parties derive a new pre-shared key, a temporary
session key and a
session key using the shared key and a
hash function. And the temporary private key is discarded after being used, so that the historical session still has forward security even if the key is leaked for a long time, and 0-RTT
data transmission is supported at the same time. According to the invention, the shared key based on temporary private key negotiation is introduced, and the
hash function is combined to derive and dynamically update the pre-shared key and the temporary session key, so that
authentication key exchange with forward security and 0-RTT low-
delay characteristics is realized.