The invention relates to the technical field of
information security, and discloses an anti-
quantum multi-key binding digital
certificate implementation mode, which comprises a main body public key
information field (SubjectPublic Key Info) used for storing a first anti-
quantum algorithm public key, the type of the first anti-
quantum algorithm public key is determined through an associated
algorithm identifier, and the type of the first anti-
quantum algorithm public key is stored in the main body public key
information field. Comprising an anti-
quantum signature public key or an anti-quantum
encryption public key, and further comprises a
certificate extension for storing a second anti-
quantum algorithm public key. According to the anti-quantum multi-key binding digital
certificate implementation mode, an anti-
quantum signature public key (SubjectPublic Key Info) and an
encryption public key (extension item) are separately stored in a single X.509 certificate, signature and
encryption dual-function integration is achieved, the dual-certificate requirement is avoided, the extension item adopts an ASN.1 standard and a critical = FALSE mechanism, traditional RSA / ECC public key mixed storage is compatible, transitional smooth migration is supported, and the anti-quantum multi-key binding digital certificate implementation mode is suitable for application and popularization. Through key isolation, anti-quantum hash / KEM
verification and unified management, 50% of certificate operation and maintenance cost is reduced, quantum security protection is enhanced, and the method is suitable for high-sensitivity scenes such as
the Internet of Things and 5G.