Generating system and method of session keys
Abstract
The invention discloses a generating system and method of session keys. The method includes: S1, a first terminal judges whether mutual communication between the first terminal and a second terminal is available; S2, during bidirectional communication between the first terminal and the second terminal, the first terminal and the second terminal mutually communicates for authentication; S3, after the first terminal and the second terminal pass authentication, the first terminal generates a first session key according to first authentication information sent by the second terminal, and meanwhile, the second terminal generates the first session key; S4, the second terminal generates a second session key according to second authentication information sent by the first terminal. The session keys for communication of the first and second terminals are the first session key or the second session key or a combination of the first and second session keys. The session keys ensure security of communication between the terminals.
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
10 claims: 2 independent, 8 dependent
- 1The production method of session secret-key, comprising a characterised, comprising:St 51, wherein the first judgement and a second terminal with communication;Nd 52, wherein the first and second terminal two-way communication, wherein the first and second terminal with communication end of the identity authentication;53 Rd, wherein the first terminal and identity authentication of the second terminal are, wherein the first base of the second terminal by the first authentication information generation first session secret-key, at the second terminal to generate the first session;secret-key 54 Ohm;the second terminal to act according to the first terminal by the second authentication information to generate the second session;secret-key , Wherein the first and second terminal communication session secret-key to the first session secret-key or the second session secret-key or the two and. 1.一种会话秘钥的生成方法,其特征在于,包括: 51、第一终端判断是否能够与第二终端相互通信; 52、在第一终端和第二终端双向通信时,所述第一终端和所述第二终端相互通信进行身份认证; 53、在所述第一终端和所述第二终端的身份认证通过后,所述第一终端根据所述第二终端发送的第一认证信息生成第一会话秘钥,同时所述第二终端生成第一会话秘钥; 54、所述第二终端根据所述第一终端发送的第二认证信息生成第二会话秘钥; 其中,所述第一终端和所述第二终端的通信的会话秘钥为所述第一会话秘钥或所述第二会话秘钥或二者之和。
- 6The power system of session secret-key, comprising a characterised, comprising:First terminal and second terminal;the The first terminal, which is a cover and second terminal with communication, and second terminal with communication end of the identity authentication;The first terminal, further - by, wherein the back identity authentication of the second terminal are, according to the second terminal by the first authentication information generation first session;secret-key The second terminal, for generating first session;secret-key The second terminal, a to the first terminal by the second authentication information to generate the second session;secret-key , Wherein the first and second terminal communication session secret-key to the first session secret-key or the second session secret-key or the two and. 6.一种会话秘钥的生成系统,其特征在于,包括:第一终端和第二终端; 所述第一终端,用于在能够与第二终端相互通信时,和所述第二终端相互通信进行身份认证; 所述第一终端,还用于在和所述第二终端的身份认证通过后,根据所述第二终端发送的第一认证信息生成第一会话秘钥; 所述第二终端,用于生成第一会话秘钥; 所述第二终端,用于根据所述第一终端发送的第二认证信息生成第二会话秘钥; 其中,所述第一终端和所述第二终端的通信的会话秘钥为所述第一会话秘钥或所述第二会话秘钥或二者之和。
Independent claims2
131 paragraphs, as filed
The generating system and method of secret-key session
technical field
[0001] The invention relates to safety communication technical field, specifically to a generating system and method of secret-key session.
Background method
[0002] OTP (The Time Intervals; disposable dynamic password) is a pseudo-random hole is parallel to the dynamic password authentication method. OTP usually is divided into the time synchronization, a paging synchronous and challenge/replies three authentication manner. The basic circuit of OTP for special preservation's seed (current), adding time (Time) or event (Counter) or the challenges (Challenge parameter), and a hash algorithm to generate the disposable dynamic password.
[0003]The is arranged in the terminal performing a communication, OTP with is provided with identity authentication method, comprising an consulted a provided with two terminals are on the safety communication the secret-key, therefore, the multiple situations it ensure the safety communication.
invention content
[0004] The defect in aggregate of prior art, the invention claims a generating system and method of session secret-key, a claims a safety control for communication between terminal.
[0005] Of handle, the invention claims a production method of session secret-key, comprising:
[0006] S1 and first terminal judgement for and a second terminal with communication;
[0007] S2, wherein the first and second terminal two-way communication, wherein the first and second terminal with communication end of the identity authentication;
[0008] S3, wherein the first terminal and identity authentication of the second terminal are, wherein the first base of the second terminal by the first authentication information generation first session secret-key, at the second terminal to generate the first session; secret-key
[0009] Wire, comprising two sides authenticate, and first regenerates the first session secret-key, operation unit time, the inside of the identity authentication is not connected, comprising wasted the magnetism secondary computing.
[0010] S4, the second terminal to act according to the first terminal by the second authentication information to generate the second session; secret-key
[0011] , Wherein the first and second terminal communication session secret-key to the first session secret-key or the second session secret-key or the two and.
[0012] Further used; and S3, wherein the first base of the second terminal by the first authentication information generation first session secret-key, comprising:
[0013] The first terminal base of the first authentication information, series value and/or a current, a one-way hash algorithm for session first; secret-key
[0014] Corresponding, wherein the second terminal to act according to the second authentication information, series value and/or a current generated, the second session secret-key through a hash algorithm.
[0015] Further used, wherein the first authentication information and second authentication information comprising a a time, event and challenge information.
[0016] Further used; the number SI, wherein the first terminal judgement is not connected with the second terminal with communication, wherein the method comprises:
[0017] S5, wherein the first when it with the second terminal with communication, a to the second authentication, information
[0018] S6, the first terminal base of the second authentication information generation first authentication password and first session; secret-key
[0019] S7, wherein the first terminal is used transmission's data through the first session secret-key to encrypt, and data sending is connected in series, the second authentication information, the first authentication password and device for encrypting the second terminal; the
[0020] S8, the second terminal is fixed to the OTP data to the first authentication password, and according to the second authentication information generation first session secret-key, and connected with the first session secret-key a to the data encrypting, a gain to the first terminal transmission's data.
[0021] Further used; the second authentication information a time or event information.
[0022] The second surface, the invention further claims a generating system of session secret-key, comprising: First terminal and second terminal; the
[0023] The first terminal, which is a cover and second terminal with communication, and second terminal with communication end of the identity authentication;
[0024] The first terminal, further - by, wherein the back identity authentication of the second terminal are, according to the second terminal by the first authentication information generation first session; secret-key
[0025] The second terminal, for generating first session; secret-key
[0026] The second terminal, a to the first terminal by the second authentication information to generate the second session; secret-key
[0027] , Wherein the first and second terminal communication session secret-key to the first session secret-key or the second session secret-key or the two and.
[0028] Further used, wherein the first terminal, is further used to act according to the first authentication information, series value and/or a current, a one-way hash algorithm for session first; secret-key
[0029] Corresponding, wherein the second terminal, is further used to act according to the second authentication information, series value and/or a current generated, the second session secret-key through a hash algorithm.
[0030] Further used, wherein the first authentication information and second authentication information comprising a a time, event and challenge information.
[0031] Further used, wherein the first terminal, wherein it is connected with the second terminal with communication, designed to the second authentication, information
[0032] The first terminal, a to the second authentication information generation first authentication password and first session; secret-key
[0033] The first terminal, further - is used transmission's data through the first session secret-key to encrypt, and data sending is connected in series, the second authentication information, the first authentication password and device for encrypting the second terminal; the
[0034] The second terminal, a adopting the OTP data the first authentication password, and according to the second authentication information generation first session secret-key, and connected with the first session secret-key a to the data encrypting, a gain to the first terminal transmission's data.
[0035] Further used; the second authentication information a time or event information.
[0036] A know of the technical solution, a session secret-key the generating system and method for the invention claims, wherein the method in aggregate of the terminal communication's different condition, how respectively provided with a a session secret-key, claims a safety control for communication between terminal.
brief description fo the drawings
[0037] Digital 1 is the invention embodiment provision a session secret-key the current schematic drawing of generating method,
[0038] Digital 2 is a session secret-key the current schematic drawing device for producing method the invention In one embodiment, a
[0039] Digital 3 is a session secret-key the current schematic drawing device for producing method the invention In one embodiment, a
[0040] Digital 4 is a session secret-key the current schematic drawing device for producing method the invention In one embodiment, a
[0041] Digital 5 is the invention embodiment provision a session secret-key the current schematic drawing of generating method,
[0042] The pattern 6 is the invention embodiment provision a session secret-key the current schematic drawing of generating method,
[0043] Digital 7 is the invention embodiment provision a session secret-key the current schematic drawing of production method.
Performing is specifically
[0044] Below the light of the auxiliary shape, to the specific embodiment of this invention describes further. The following embodiment is only which are more clearly is in the invention the technical solution, and it limiting the invention is formed by the has a protection.
[0045] For clearer emitter the invention, the firstly (The Time Key, 0TK) production method and simple declaration to the disposable secret-key session.
[0046] A with two ends of communication with the completed OTP identity authentication, X is OTP verifying the successful counter and time factor, or the challenge information.
[0047] Method for: 1Two sides sharing a serial number SN and seed Current, at two sides common further comprises a current Seed2, calculating Hash (Seed2, X), a given secret-key session.
[0048] Method for: 2Two sides sharing a serial number SN and seed Current, Y consult the same is two sides beforehand the constant, or a waterproof SN or some wherein a conversion, or the Y is Current automatic or some wherein a conversion, or the Y is X automatic or some wherein a conversion. Calculating Hash (Current, X, RAIL), a given secret-key session.
[0049] Method for: 3Two sides sharing a serial number SN and seed Current, and a OTP different Hash algorithm, calculating Hash (Current, X), a given secret-key session.
[0050] The calculating session secret-key, and using the symmetrical encryption algorithm, using Current X, and Y the two or variables is a secret-key, encryption current Current X, and variables of Y finally, and secret-key session.
(0051) Session secret-key capable of being receiving into a communication the data encrypting secret-key and encryption IV, or according to all mapping method for producing the following communication data encrypting secret-key and encryption IV.
[0052] Digital 1 is a session secret-key the current schematic drawing device for producing method the embodiment of the invention claims, and shown the digital 1, wherein the first terminal and second terminal two-way communication, and sharing serial number and current, the method comprises the following steps:
[0053] S1 and first terminal judgement for and a second terminal with communication;
[0054] S2, wherein the first and second terminal two-way communication, wherein the first and second terminal with communication end of the identity authentication;
[0055] S3, wherein the first terminal and identity authentication of the second terminal are, wherein the first base of the second terminal by the first authentication information generation first session secret-key, at the second terminal to generate the first session; secret-key
[0056] S4, the second terminal to act according to the first terminal by the second authentication information to generate the second session; secret-key
[0057] , Wherein the first and second terminal communication session secret-key to the first session secret-key or the second session secret-key or the two and.
[0058] Particularly, wherein the first base of the first authentication information, series value and/or a current, a one-way hash algorithm for session first; secret-key
[0059] Corresponding, wherein the second terminal to act according to the second authentication information, series value and/or a current generated, the second session secret-key through a hash algorithm.
[0060] The invention, and shown the digital 2, a communication of A and B of the two-way communication, A and B for sharing a serial number SN and seed Current, and distribution Seed2.
[0061] The first, A production challenge c1; The light SN and second electrically connected with the B;
[0062] The second, B using OTP generating P1 based on c1, using OTK based on fourth generation session secret-key K1, a production challenges C2;
[0063] The third invention, the current loop comprises P1 and C2 to powering; A
[0064] The fourth, A using OTP verifying P1, using OTK based on fourth generation session secret-key K1, using OTP generating P2, A using OTK to generate session secret-key K2 based on C2 based on C2;
[0065] The fifth, A light P2 is a, B
[0066] The sixth, B using OTP verifying P2, using OTK generating session secret-key K2 based on C2;
[0067] The seventh, B loop to perform A, completes the identity authentication, finally the session secret-key is K1 or K2 or K1+K2.
[0068] The other achievable groove; and shown the digital 3, a communication of A and B of the two-way communication with a, B is provided with a authentication server S two-way communication. A and S sharing a serial number SNa and seed Seeda, further used for current; Seeda2B and S sharing a serial number SNb and seed Seedb, further used for current Seedb20
[0069] The the first, A generate challenge c1, using OTK generating session secret-key K1 based on c1;
[0070] The second, A light SNa and second electrically connected with the B;
[0071] The third of a, B generate challenges C2; using OTK generating session secret-key K2 based on C2;
[0072]The invention claims a, B for SNa, c1, SNb and C2 to the S,
[0073] The fifth, S using OTP generating Pl based on c1, using OTP generating P2 based on C2; using OTK based on fourth generation session secret-key K1, using OTK generating session secret-key K2 based on C2. Production secret-key session Kx, using K1 encryption Kx and data result of Ky, K2 using encryption Kx and data result of Kz;
[0074] The sixth, the S connected to the current to P1, P2, and Ky; Kz
[0075] The seventh, the B verifying P2, deciphers Kz obtaining Kx and inspection data;
[0076] Eighth of a, B to P2 and Ky loop; A
[0077] The ninth, A verifying P1, deciphers Ky obtaining Kx and inspection data; completes the mutual authentication, and session secret-key is Kx.
[0078] And the first or a step; and addressing generating and supplements any of R, and conversation terminal is secret-key Hash (Kx, R), or is Kx to the R symmetrical encryption result, or R is a Kx symmetrical encryption result.
[0079] The method, wherein the first authentication information and second authentication information comprising a a time, event and challenge information.
[0080] Digital 4 of the invention claims a session secret-key the current schematic drawing for producing method, and shown the digital 4, the number SI, wherein the first terminal judgement is not connected with the second terminal with communication, wherein the method comprises:
[0081] S5, the first terminal production of the second authentication, information
[0082] S6, the first terminal base of the second authentication information generation first authentication password and first session; secret-key
[0083] S7, wherein the first terminal is used transmission's data through the first session secret-key to encrypt, and data sending is connected in series, the second authentication information, the first authentication password and device for encrypting the second terminal; the
[0084] S8, the second terminal is fixed to the OTP data to the first authentication password, and according to the second authentication information generation first session secret-key, and connected with the first session secret-key a to the data encrypting, a gain to the first terminal transmission's data.
[0085] Particularly, the second authentication information a time or event information.
[0086] The invention, and shown the digital 5, for communication of A to the B without of the one-way communication, two sides sharing a serial number SN and seed Current, further used for current Seed2.
[0087] The the first, A using OTP based on inverse T-SHAPED (time or event) for P, using OTK generating session secret-key K based on T, using session secret-key K enciphered data obtaining D;
[0088] The second, A light SN, P and AN electrically connected with the B;
[0089] The third of a, B using OTP p-type apparatus, using OTK generating session secret-key K based on T-SHAPED. Using the ends deciphers AN obtaining data D; the completes authentication and encrypted data transmission.
[0090] The other achievable manner; and pattern 6 cooling, a communication without energy-accumulating of A to the B the one-way communication with a, B and authentication server S of the two-way communication. A and S sharing a serial number SNa and seed Seeda, further used for current Seeda2. B and S sharing a serial number SNb and seed Seedb, further used for current Seedb20
[0091] The the first, A using OTP (t1 time or event) for generating Pl based on the counter, using OTK based on t1 generating session secret-key K1, generating session secret-key Kx, using session secret-key K1 encryption Kx obtaining Ky, using Kx enciphered data obtaining D; AN
[0092]The second, A light SNa and Ρ 1, Ky and AN electrically connected with the B;
[0093] The invention claims a, B using OTP (time or event) for generating P2 based on counter T2, using OTK generating session secret-key K2 based on, And
[0094] The fourth, 8 from 3 shames? 1st, Tube, 5 shame sums? 2 To 3;
[0095] The fifth, the S verifying Pl and P2, using OTK based on t1 generating session secret-key K1, using OTK based on production And session secret-key K2, using K1 deciphers Ky obtaining Kx, using 2 Κ encryption Kx obtaining; Kz
[0096] The sixth, the S loop comprises Kz and inspection data to a, B
[0097] The seventh, the current deciphers Kz obtaining Κχ, Kx using SAME deciphers data obtaining D; Completes the authentication and encrypted data transmission.
[0098] The first number of the addressing generating and supplements any of R, the data enciphered D session secret-key is Hash (Kx, R), or is Kx to the R symmetrical encryption result, or R is a Kx symmetrical encryption result.
[0099] The other achievable groove; and shown the digital 7, a communication without energy-accumulating of A to the B the one-way communication, A and authentication server S of the two-way communication. A and S sharing a serial number SNa and seed Seeda, further used for current Seeda2. B and S sharing a serial number SNb and seed Seedb, further used for current Seedb20
[0100] The the first, A using OTP (t1 time or event) for generating Pl based on the counter, using OTK based on t1 generating session secret-key K1, generating session secret-key Kx, using session secret-key K1 encryption Kx obtaining Ky, using Kx enciphered data obtaining D; AN
[0101]The second, A light SNa and Ρ 1, Ky to the S,
[0102] The third invention, the S verifying Pl, using OTK based on t1 generating session secret-key K1, using OTP (time or event) for generating P2 based on counter T2, using OTK based on production And session secret-key K2, using K1 deciphers Ky obtaining Kx, using 2 Κ encryption Kx obtaining; Kz
[0103] The fourth invention, the S is Ρ to 2, Kz and data to perform; A
[0104] The fifth, A light Ρ 2, Kz and AN electrically connected with the B;
[0105] And a, B verifying Ρ 2, OTK using based on Τ 2 for session secret-key Κ 2, deciphers Kz obtaining Κχ, Kx using SAME deciphers obtaining data D; the completes authentication and encrypted data transmission.
[0106] The first number of the addressing generating and supplements any of R, the data enciphered D session secret-key is Hash (Kx, R), or is Kx to the R symmetrical encryption result, or R is a Kx symmetrical encryption result.
[0107] Kx is capable of the S generate, and using the K1, encryption connected to A, and A deciphers Kx.
[0108] The one-way communication's condition, OTP it using challenge/acknowledge mode,The two-way communication's condition, OTP of the period of rotating and time or challenges/acknowledge mode,The safety communication method without to limit the specific timing time, or challenge/acknowledge mode.
[0109] The embodiment of the invention further claims a generating system of session secret-key, comprising: First terminal and second terminal; the
[0110] The first terminal, which is a cover and second terminal with communication, and second terminal with communication end of the identity authentication;
[0111] The first terminal, further - by, wherein the back identity authentication of the second terminal are, according to the second terminal by the first authentication information generation first session; secret-key
[0112] The second terminal, for generating first session; secret-key
[0113] The second terminal, a to the first terminal by the second authentication information to generate the second session; secret-key
[0114] , Wherein the first and second terminal communication session secret-key to the first session secret-key or the second session secret-key or the two and.
[0115] Particularly, wherein the first terminal, is further used to act according to the first authentication information, series value and/or a current, a one-way hash algorithm for session first; secret-key
[0116] Corresponding, wherein the second terminal, is further used to act according to the second authentication information, series value and/or a current generated, the second session secret-key through a hash algorithm.
[0117] The first authentication information and second authentication information comprising a a time, event and challenge information.
[0118] Particularly, wherein the first terminal, wherein it is connected with the second terminal with communication, designed to the second authentication, information
[0119] The first terminal, a to the second authentication information generation first authentication password and first session; secret-key
[0120] The first terminal, further - is used transmission's data through the first session secret-key to encrypt, and data sending is connected in series, the second authentication information, the first authentication password and device for encrypting the second terminal; the
[0121] The second terminal, a adopting the OTP data the first authentication password, and according to the second authentication information generation first session secret-key, and connected with the first session secret-key a to the data encrypting, a gain to the first terminal transmission's data.
[0122] The second authentication information a time or event information.
[0123] On the edges of the invention, the invention claims a magnetism fastening bolts and. The; and understand of the embodiment of this invention can not practice in the fastening bolts and situations. All examples, comprising an shown the male knowledge the detail method, structurally with a technique, so is no blur the battery to the instruction of.
[0124] The technical provide the field of understand, although some embodiments, wherein comprises multiple characteristics of the other embodiments, and it is not the characteristic, wherein the implemented of the combination to averaging according differently is the invention the distance, and is different embodiment. For example, wherein the following claim 1-3, demand protection for example's Ren Yizhi the can receive the using a combination of step.
[0125] Finally are arranged explain: The embodiments is made to show the invention the technical solution, it is made wherein limiting; Although the reference preceding embodiments is carried out detailed distributed to the invention, the common a provide the field claim understand: A position of use to the technical solution of the preceding embodiment two recording, or or with a function based on to equate the alternative to part; And the revisions or the alternatives, connected with of the precise of corresponding technical solution is separated from the invention the embodiment a wireless the distance, wherein the first covering on the invention claims and middle of the instruction of broadband.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2018153252A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN107548542A | Cited by | China | Search report |
| WO2017032242A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10693634B2 | Cited by | United States of America | Applicant |
| CN109075965A | Cited by | China | Search report |
| CN101252577A | Cites | China | Search report |
| CN101267301A | Cites | China | Search report |
| CN102421095A | Cites | China | Search report |
| US2005086504A1 | Cites | United States of America | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201510158953 | China | A | |
| CN20151158953 | – | – | – |
Numbers
- Publication
- 104753682
- Publication, DOCDB
- 104753682
- Publication, EPODOC
- CN104753682
- Application
- 101589535
- Application, DOCDB
- 201510158953
- Application, EPODOC
- CN20151158953
Titles3
- Chinese
- 一种会话秘钥的生成系统及方法
- English
- The generating system and method of secret-key session
- English
- Generating system and method of session keys
Classification
- IPC, 2
- H04L9 32
- H04L29 06