Nova Patents
CN106487749A

Key generation method and device

Abstract

The invention provides a key generation method and device. The key generation method comprises the steps of encrypting a first key factor generated by a first device through adoption of a basic key and sending the encrypted key factor to a second device through a first secure channel, wherein the basic key is a preset key between the first device and the second device; receiving a second key factor through the first secure channel, wherein the second key factor is encrypted by the basic key, and the second key factor is generated by the second device; decrypting the second key factor which is received through the first secure channel and is encrypted by the basic key, thereby obtaining the second key factor; and generating a shared key between the first device and the second device according to the first key factor and the second key factor. According to the technical scheme of the method and the device, a gateway device cannot obtain the shared key negotiated by the first device and the second device, data can be transmitted between the first device and the second device more securely, and the risk that the data is illegally intercepted in the transmission process is further reduced.

Term

8.9 yearsto projected expiry

Projected expiry 26 August 2035, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

24 claims: 7 independent, 17 dependent

  1. 1
    A key generation method applied to a first device, wherein the method comprises:encrypting a first key factor generated by the first device using an initial key and sending it to The second device, wherein the initial key is a key preset between the first device and the second device;receiving the second key encrypted by the initial key through the first secure channel Key factor, wherein the second key factor is generated by the second device;decrypt the second key factor that is received through the first secure channel and encrypted with the initial key to obtain The second key factor;generating a shared key for the first device and the second device according to the first key factor and the second key factor. 1. 一种密钥生成方法,应用在第一设备上,其特征在于,所述方法包括: 采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通过第一安全通道发 送给第二设备,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 通过所述第一安全通道接收经过所述初始密钥加密的第二密钥因子,其中,所述第二 密钥因子由所述第二设备生成; 对通过所述第一安全通道接收到的经过所述初始密钥加密的所述第二密钥因子进行 解密,得到所述第二密钥因子; 根据所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密 钥。
  2. 7
    9. A key generation method applied to a second device, wherein the method includes:receiving a first key factor encrypted by an initial key from a first device through a second secure channel, wherein the An initial key is a key preset between the first device and the second device;decrypting the first key factor encrypted by the initial key to obtain the first encryption factor;The shared key of the first device and the second device is generated according to the first key factor and the second key factor generated by the second device. 9. 一种密钥生成方法,应用在第二设备上,其特征在于,所述方法包括: 通过第二安全通道接收来自第一设备的经过初始密钥加密的第一密钥因子,其中,所 述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所述第一加密因子; 根据所述第一密钥因子、所述第二设备生成的第二密钥因子生成所述第一设备与第二 设备的共享密钥。
  3. 11
    13. The method according to any one of claims 9-12, wherein the method further comprises:receiving the data to be transmitted encrypted by the shared key from the first device from the first device through a second secure channel;adopting The shared key decrypts the data to be transmitted. 13. 根据权利要求9-12任一所述的方法,其特征在于,所述方法还包括: 通过第二安全通道接收来自所述第一设备的经过所述共享密钥加密的待传输的数 据; 采用所述共享密钥对所述待传输的数据进行解密。
  4. 13
    15. A key generation device applied to a first device, wherein the device includes:a first encryption module, configured to use an initial key to encrypt a first key factor generated by the first device and It is sent to the second device through the first secure channel, wherein the initial key is a key preset between the first device and the second device;the first receiving module is configured to pass the first device The secure channel receives the second key factor encrypted by the initial key, where the second key factor is generated by the second device;the first decryption module is configured to pass through the first receiving module The second key factor encrypted by the initial key received by the first secure channel is decrypted to obtain the second key factor;a first key generation module is used to generate the second key factor according to the first key factor. The key factor and the second key factor obtained by decryption by the first decryption module generate a shared key between the first device and the second device. 15. 一种密钥生成装置,应用在第一设备上,其特征在于,所述装置包括: 第一加密模块,用于采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通 过第一安全通道发送给第二设备,其中,所述初始密钥为所述第一设备与所述第二设备之 间预设的密钥; 第一接收模块,用于通过所述第一安全通道接收经过所述初始密钥加密的第二密钥因 子,其中,所述第二密钥因子由所述第二设备生成; 第一解密模块,用于对通过所述第一接收模块通过所述第一安全通道接收到的经过所 述初始密钥加密的所述第二密钥因子进行解密,得到所述第二密钥因子; 第一密钥生成模块,用于根据所述第一密钥因子、所述第一解密模块解密得到的所述 第二密钥因子生成所述第一设备与第二设备的共享密钥。
  5. 18
    21. 根据权利要求15-20任一所述的装置,其特征在于,所述装置还包括: 第三确定模块,用于确定所述第一设备需要向所述第二设备发送的待传输的数据; 数据加密模块,用于采用所述共享密钥对所述第三确定模块确定的所述待传输的数据 进行加密,并通过所述第一安全通道发送给所述第二设备。 twenty one. The apparatus according to any one of claims 15-20, wherein the apparatus further comprises:a third determining module, configured to determine the data to be transmitted that the first device needs to send to the second device;The data encryption module is configured to use the shared key to encrypt the data to be transmitted determined by the third determining module, and send it to the second device through the first secure channel.
  6. 20
    23. 一种密钥生成装置,应用在第二设备上,其特征在于,所述装置包括: 第三接收模块,用于通过第二安全通道接收来自第一设备的经过初始密钥加密的第一 密钥因子,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 第三解密模块,用于对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所 述第一加密因子; 第二密钥生成模块,用于根据所述第一密钥因子、所述第二设备生成的第二密钥因子 生成所述第一设备与第二设备的共享密钥。 twenty three. A key generation device applied to a second device, characterized in that the device includes:a third receiving module, configured to receive a first key encrypted by an initial key from a first device through a second secure channel Key factor, wherein the initial key is a key preset between the first device and the second device;and the third decryption module is configured to encrypt the first The key factor is decrypted to obtain the first encryption factor;a second key generation module is configured to generate the first device according to the first key factor and the second key factor generated by the second device Shared key with the second device.
  7. 24
    27. The device according to any one of claims 23-26, wherein the device further comprises:a fourth receiving module, configured to receive from the first device through the shared key plus the shared key through a second secure channel 27. 根据权利要求23-26任一所述的装置,其特征在于,所述装置还包括: 第四接收模块,用于通过第二安全通道接收来自所述第一设备的经过所述共享密钥加 Encrypted data to be transmitted;a fourth decryption module, configured to use the shared key to decrypt the data to be transmitted. 密的待传输的数据; 第四解密模块,用于采用所述共享密钥对所述待传输的数据进行解密。 2& The device according to claim 27, wherein the device further comprises: a response data generating module, which is used to generate response data after receiving the data to be transmitted;and a third encryption module, which is used to pass The shared key encrypts the response data;and a second sending module is configured to send the response data encrypted by the shared key to the first device through the second secure channel. 2&根据权利要求27所述的装置,其特征在于,所述装置还包括: 响应数据生成模块,用于在接收到所述待传输的数据后,生成响应数据; 第三加密模块,用于通过所述共享密钥对所述响应数据进行加密; 第二发送模块,用于通过所述第二安全通道向所述第一设备发送经过所述共享密钥加 密的响应数据。
Independent claims7