The invention discloses a method for applying an anti-
quantum certificate to a TLS1.2
handshake process, which realizes the application of an MLDSA anti-
quantum signature
algorithm and an MLKEM anti-
quantum key encapsulation mechanism in the
handshake process by expanding a
cipher suite and a signature
algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a
cipher suite supporting MLKEM and an MLDSA signature
algorithm enumeration value; the
client declares algorithm support in ClientHello, and the
server responds and returns a
certificate chain containing the double-
antibody quantum
certificate; after the
client verifies the certificate, the pre-
master key is encapsulated by using MLKEM, and the
server de-encapsulates the derived
session key; and the two parties send Finished messages to each other to complete
handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance
quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile,
adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing
system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum
upgrade of the TLS1.2 protocol.