Key generation method and device
Abstract
The invention provides a key generation method and device. The key generation method comprises the steps of encrypting a first key factor generated by a first device through adoption of a basic key and sending the encrypted key factor to a second device through a first secure channel, wherein the basic key is a preset key between the first device and the second device; receiving a second key factor through the first secure channel, wherein the second key factor is encrypted by the basic key, and the second key factor is generated by the second device; decrypting the second key factor which is received through the first secure channel and is encrypted by the basic key, thereby obtaining the second key factor; and generating a shared key between the first device and the second device according to the first key factor and the second key factor. According to the technical scheme of the method and the device, a gateway device cannot obtain the shared key negotiated by the first device and the second device, data can be transmitted between the first device and the second device more securely, and the risk that the data is illegally intercepted in the transmission process is further reduced.
Term
8.9 yearsto projected expiry
Projected expiry 26 August 2035, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
24 claims: 7 independent, 17 dependent
- 1A key generation method applied to a first device, wherein the method comprises:encrypting a first key factor generated by the first device using an initial key and sending it to The second device, wherein the initial key is a key preset between the first device and the second device;receiving the second key encrypted by the initial key through the first secure channel Key factor, wherein the second key factor is generated by the second device;decrypt the second key factor that is received through the first secure channel and encrypted with the initial key to obtain The second key factor;generating a shared key for the first device and the second device according to the first key factor and the second key factor. 1. 一种密钥生成方法,应用在第一设备上,其特征在于,所述方法包括: 采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通过第一安全通道发 送给第二设备,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 通过所述第一安全通道接收经过所述初始密钥加密的第二密钥因子,其中,所述第二 密钥因子由所述第二设备生成; 对通过所述第一安全通道接收到的经过所述初始密钥加密的所述第二密钥因子进行 解密,得到所述第二密钥因子; 根据所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密 钥。
- 79. A key generation method applied to a second device, wherein the method includes:receiving a first key factor encrypted by an initial key from a first device through a second secure channel, wherein the An initial key is a key preset between the first device and the second device;decrypting the first key factor encrypted by the initial key to obtain the first encryption factor;The shared key of the first device and the second device is generated according to the first key factor and the second key factor generated by the second device. 9. 一种密钥生成方法,应用在第二设备上,其特征在于,所述方法包括: 通过第二安全通道接收来自第一设备的经过初始密钥加密的第一密钥因子,其中,所 述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所述第一加密因子; 根据所述第一密钥因子、所述第二设备生成的第二密钥因子生成所述第一设备与第二 设备的共享密钥。
- 1113. The method according to any one of claims 9-12, wherein the method further comprises:receiving the data to be transmitted encrypted by the shared key from the first device from the first device through a second secure channel;adopting The shared key decrypts the data to be transmitted. 13. 根据权利要求9-12任一所述的方法,其特征在于,所述方法还包括: 通过第二安全通道接收来自所述第一设备的经过所述共享密钥加密的待传输的数 据; 采用所述共享密钥对所述待传输的数据进行解密。
- 1315. A key generation device applied to a first device, wherein the device includes:a first encryption module, configured to use an initial key to encrypt a first key factor generated by the first device and It is sent to the second device through the first secure channel, wherein the initial key is a key preset between the first device and the second device;the first receiving module is configured to pass the first device The secure channel receives the second key factor encrypted by the initial key, where the second key factor is generated by the second device;the first decryption module is configured to pass through the first receiving module The second key factor encrypted by the initial key received by the first secure channel is decrypted to obtain the second key factor;a first key generation module is used to generate the second key factor according to the first key factor. The key factor and the second key factor obtained by decryption by the first decryption module generate a shared key between the first device and the second device. 15. 一种密钥生成装置,应用在第一设备上,其特征在于,所述装置包括: 第一加密模块,用于采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通 过第一安全通道发送给第二设备,其中,所述初始密钥为所述第一设备与所述第二设备之 间预设的密钥; 第一接收模块,用于通过所述第一安全通道接收经过所述初始密钥加密的第二密钥因 子,其中,所述第二密钥因子由所述第二设备生成; 第一解密模块,用于对通过所述第一接收模块通过所述第一安全通道接收到的经过所 述初始密钥加密的所述第二密钥因子进行解密,得到所述第二密钥因子; 第一密钥生成模块,用于根据所述第一密钥因子、所述第一解密模块解密得到的所述 第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 1821. 根据权利要求15-20任一所述的装置,其特征在于,所述装置还包括: 第三确定模块,用于确定所述第一设备需要向所述第二设备发送的待传输的数据; 数据加密模块,用于采用所述共享密钥对所述第三确定模块确定的所述待传输的数据 进行加密,并通过所述第一安全通道发送给所述第二设备。 twenty one. The apparatus according to any one of claims 15-20, wherein the apparatus further comprises:a third determining module, configured to determine the data to be transmitted that the first device needs to send to the second device;The data encryption module is configured to use the shared key to encrypt the data to be transmitted determined by the third determining module, and send it to the second device through the first secure channel.
- 2023. 一种密钥生成装置,应用在第二设备上,其特征在于,所述装置包括: 第三接收模块,用于通过第二安全通道接收来自第一设备的经过初始密钥加密的第一 密钥因子,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 第三解密模块,用于对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所 述第一加密因子; 第二密钥生成模块,用于根据所述第一密钥因子、所述第二设备生成的第二密钥因子 生成所述第一设备与第二设备的共享密钥。 twenty three. A key generation device applied to a second device, characterized in that the device includes:a third receiving module, configured to receive a first key encrypted by an initial key from a first device through a second secure channel Key factor, wherein the initial key is a key preset between the first device and the second device;and the third decryption module is configured to encrypt the first The key factor is decrypted to obtain the first encryption factor;a second key generation module is configured to generate the first device according to the first key factor and the second key factor generated by the second device Shared key with the second device.
- 2427. The device according to any one of claims 23-26, wherein the device further comprises:a fourth receiving module, configured to receive from the first device through the shared key plus the shared key through a second secure channel 27. 根据权利要求23-26任一所述的装置,其特征在于,所述装置还包括: 第四接收模块,用于通过第二安全通道接收来自所述第一设备的经过所述共享密钥加 Encrypted data to be transmitted;a fourth decryption module, configured to use the shared key to decrypt the data to be transmitted. 密的待传输的数据; 第四解密模块,用于采用所述共享密钥对所述待传输的数据进行解密。 2& The device according to claim 27, wherein the device further comprises: a response data generating module, which is used to generate response data after receiving the data to be transmitted;and a third encryption module, which is used to pass The shared key encrypts the response data;and a second sending module is configured to send the response data encrypted by the shared key to the first device through the second secure channel. 2&根据权利要求27所述的装置,其特征在于,所述装置还包括: 响应数据生成模块,用于在接收到所述待传输的数据后,生成响应数据; 第三加密模块,用于通过所述共享密钥对所述响应数据进行加密; 第二发送模块,用于通过所述第二安全通道向所述第一设备发送经过所述共享密钥加 密的响应数据。
Independent claims7
190 paragraphs, as filed
Key generation method and device technical field
[0001] This application relates to the field of network security technology, and in particular to a method and device for generating a key.
Background technique
[0002] In order to ensure the secure transmission of data between the terminal device and the gateway device, and between the gateway device and the public network server, a secure transmission channel is usually established between the terminal device and the gateway device, and between the gateway device and the public network server. The gateway device forwards data from one secure channel to another, thereby realizing the function of data forwarding. In the process of forwarding data, the gateway device needs to use the shared key with the terminal device to decrypt the data encrypted by the terminal device, and then It is encrypted with the shared key with the server and then forwarded to the server, so the gateway device may have the risk of data leakage.
Summary of the invention
[0003] In view of this, this application provides a new technical solution that can prevent the gateway device from obtaining the shared key between the two devices, thereby reducing the risk of illegal interception of data during network transmission.
[0004] In order to achieve the above purpose, the present application provides technical solutions as follows:
[0005] According to the first aspect of the present application, a key generation method is proposed, which is applied on a first device, and includes:
[0006] The first key factor generated by the first device is encrypted with an initial key and sent to the second device through the first secure channel, wherein the initial key is the first device and the A key preset between the second device;
[0007] receiving a second key factor encrypted by the initial key through the first secure channel, wherein the second key factor is generated by the second device;
[0008] decrypt the second key factor encrypted by the initial key received through the first secure channel to obtain the second key factor;
[0009] Generate a shared key for the first device and the second device according to the first key factor and the second key factor.
[0010] According to the second aspect of the present application, a key generation method is proposed, which is applied to a second device, and includes:
[0011] Receive the first key factor encrypted by the initial key from the first device through the second secure channel, wherein the initial key is a preset between the first device and the second device Key
[0012] decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;
[0013] Generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device.
[0014] According to the third aspect of the present application, a key generation device is proposed, which is applied to a first device, and includes:
[0015] The first encryption module is configured to use an initial key to encrypt the first key factor generated by the first device and send it to the second device through the first secure channel, wherein the initial key is A key preset between the first device and the second device;
[0016] The first receiving module is configured to receive a second key factor encrypted by the initial key through the first secure channel, wherein the second key factor is generated by the second device;
[0017] The first decryption module is configured to decrypt the second key factor encrypted by the initial key and received by the first receiving module through the first secure channel to obtain the first Two key factor;
[0018] The first key generation module is configured to generate a shared secret between the first device and the second device according to the first key factor and the second key factor decrypted by the first decryption module. key.
[0019] According to the fourth aspect of the present application, a key generation device is proposed, which is applied to a second device, and includes:
[0020] The third receiving module is configured to receive the first key factor encrypted by the initial key from the first device through the second secure channel, wherein the initial key is the first device and the first key factor. A key preset between the two devices; [0021] a third decryption module for decrypting the first key factor encrypted by the initial key to obtain the first encryption factor;
[0022] The second key generation module is configured to generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device.
[0023] It can be seen from the above technical solutions that the first key factor and the second key factor are both encrypted by the initial key during the forwarding process of the gateway device, and the initial key is the pre-key between the first device and the second device. Set the key, so the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device, The shared key that can be finally negotiated is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key. Therefore, it can ensure more secure data transmission between the first device and the second device, and further Reduce the risk of illegal interception of data during transmission.
Description of the drawings
[0024] FIG. 1 shows a schematic flowchart of a key generation method according to an exemplary embodiment 1 of the present invention;
[0025] FIG. 2 shows a schematic flowchart of a key generation method according to an exemplary embodiment 2 of the present invention; [0026] FIG. 3 shows a key generation method according to an exemplary embodiment 3 of the present invention [0027] FIG. 4 shows a schematic flowchart of a key generation method according to an exemplary embodiment 4 of the present invention; [0028] FIG. 5 shows a schematic diagram of a key generation method according to an exemplary embodiment 5 of the present invention [0029] FIG. 6 shows a schematic flow diagram of a key generation method according to an exemplary embodiment 6 of the present invention; [0030] FIG. 7 shows an exemplary flow diagram according to the present invention Schematic diagram of the flow of the key generation method of the seventh embodiment; [0031] FIG. 8 shows a schematic diagram of signaling for key negotiation between a terminal device and a server according to an exemplary embodiment of the present invention;
[0032] FIG. 9 shows a schematic diagram of signaling for data transmission between a terminal device and a server applicable to an exemplary embodiment of the present invention;
[0033] FIG. 10 shows a schematic structural diagram of a terminal device according to an exemplary embodiment of the present invention;
[0034] FIG. 11 shows a schematic structural diagram of a server according to an exemplary embodiment of the present invention;
[0035] FIG. 12 shows a schematic structural diagram of a key generation device according to an exemplary embodiment of the present invention;
[0036] FIG. 13 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; [0037] FIG. 14 shows a key generation device according to still another exemplary embodiment of the present invention [0038] FIG. 15 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention.
Detailed ways
[0039] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings indicate the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the application as detailed in the appended claims.
[0040] The terms used in this application are only for the purpose of describing specific embodiments, and are not intended to limit the application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and/or" as used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0041] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, the information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this application, the first information may also be referred to as second information, and similarly, the second information may also be referred to as first information. Depending on the context, the word "if" as used herein can be interpreted as "when" or "when" or "in response to determination".
[0042] To further illustrate this application, the following embodiments are provided:
[0043] According to an embodiment of the present application, since both the first key factor and the second key factor are encrypted by the initial key during the forwarding process of the gateway device, the initial key is between the first device and the second device. A preset key, so the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device , It can be realized that the final negotiated shared key is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, so it can ensure more secure data transmission between the first device and the second device. Further reduce the risk of illegal interception of data during transmission.
[0044] FIG. 1 shows a schematic flowchart of a key generation method according to an exemplary embodiment of the present invention; in an embodiment, the first device may be a terminal device, and the second device may be a server, which may be replaced Ground, the first device may be a server, and the second device may be a terminal device. In this embodiment, application on a terminal device is taken as an example for illustration. As shown in FIG. 1, the key generation method includes the following steps:
[0045] Step 101: Use the initial key to encrypt the first key factor generated by the first device and send it to the second device through the first secure channel, where the initial key is between the first device and the second device. Preset key;
[0046] Step 102: Receive a second key factor encrypted with an initial key through the first secure channel, where the second key factor is generated by the second device;
[0047] Step 103: Decrypt the second key factor encrypted by the initial key received through the first secure channel to obtain the second key factor;
[0048] Step 104: Generate a shared key for the first device and the second device according to the first key factor and the second key factor.
[0049] In step 101, in an embodiment, the initial key Kbaac may be issued to the first device by the second device before the first device is put into use, and may be issued to the first device by means of hardware writing. One device. In an embodiment, the first device and the second device forward related data information through the gateway device, wherein the first secure channel can be established through negotiation between the first device and the gateway device, and the related data information is transmitted through the first secure channel The second secure channel can be established through negotiation between the server and the gateway device, and relevant data information can be transmitted through the second secure channel. Those skilled in the art can understand that the establishment process of the first safe passage and the second safe passage can refer to the related art in the prior art.
Description, for example, a key agreement mechanism of Secure Socket Layer (SSL) and Transport Layer Security (TLS) can be used.
[0050] In an embodiment, when the first device needs to initiate a key agreement process to the second device, the first key factor is generated through a pseudo-random function, and the first key factor is encrypted using the initial key to obtain The first key factor after the first encryption, the first encryption key of the first secure channel is used to encrypt the first key factor after the first encryption, and the first key factor after the second encryption is obtained . By double-encrypting the first key factor, the first key factor can be made unknown at the gateway device, and the risk of the first key factor being illegally intercepted on the gateway device side can be avoided.
[0051] In step 103, the first encryption key is used to decrypt the double-encrypted second key factor to obtain the second key factor after the first decryption, and the initial key is used to decrypt the second key factor for the first time. The second key factor is decrypted to obtain the second key factor. Since the second key factor has been double-encrypted at the second device, the second key factor is not known at the gateway device, which avoids the risk of illegal interception of the second key factor on the gateway device side.
[0052] For a detailed description of how to generate the shared key of the first device and the second device according to the first key factor and the second key factor in step 104, refer to the following description, which will not be described in detail here.
[0053] As can be seen from the above description, since both the first key factor and the second key factor are encrypted by the initial key during the forwarding process of the gateway device, the initial key is preset between the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device. The shared key that realizes the final negotiation is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, so it can ensure more secure data transmission between the first device and the second device, and further reduce The risk of illegal interception of data during transmission.
[0054] FIG. 2 shows a schematic flow chart of a key generation method according to an exemplary embodiment 2 of the present invention. This embodiment uses how the first key factor is passed in step 105 in the embodiment shown in FIG. Using the second key factor to generate a shared key between the first device and the second device is taken as an example for illustration. As shown in FIG. 2, the key generation method includes the following steps:
[0055] Step 201: Determine the initial key shared between the first device and the second device and the device identifier of the first device;
[0056] Step 202: Connect the initial key, the device ID, the first key factor, and the second key factor in sequence to obtain a combined string;
[0057] Step 203, split the combined character string into two sub-strings of equal length;
[0058] Step 204: Perform hash operations on the two substrings to obtain two hash results;
[0059] Step 205: Perform an exclusive OR operation on the two hash results to obtain the shared key of the first device and the second device.
[0060] After the first device obtains the second key factor through step 104 in the embodiment shown in FIG. 1, the first device has the first key factor P and the second key factor q. The first device can take the first key factor and the second key factor as input, and use the shared key generation algorithm to obtain the key K&, where the key generation algorithm is as follows:
[0061] Heart=KeyGenerate (K basic, Shared Key, p, q);
[0062] Wherein, is the initial key, and Shared Key is the device identification of the first device. The device identification can be the device serial number of the first device, or the MAC address, or a combination of the above two, etc., as long as It is sufficient that the second device can distinguish the first device from other devices through the device identifier.
[0063] In addition, in the process of generating the shared key through the function KeyGenerate, the first encryption key can be
ΚΜ. Corresponding strings, "Shared Key", p, q are connected in sequence to obtain a combined string, and use the function KeyGenerate to generate a shared key K from the combined string<sub>ACO</sub>
[0064] In an embodiment, the process implemented by the function KeyGenerate may specifically be: cutting the input combined string into two sub-strings of equal length (if the combined string has an odd length, then the combined string The last digit of is complemented by 1), and then the two substrings are hashed separately (for example, MD5), and the two calculation results obtained are XORed by bits, and the result is the shared key K<sub>ACO</sub>
[0065] Taking MD5 as an example to illustrate, since MD5 can convert an input of any length into a result of 128-bit length, the shared key K<sub>A</sub>The length of c is 128 bits, which simplifies the complexity of the shared key calculation. Since the calculation of the shared key Ik adopts MD5, the amount of calculation is affordable for the first device with limited computing capability.
[0066] In this embodiment, the shared key K© is generated by the first key factor, the second key factor, the initial key, and the device identification of the first device. Therefore, it is implemented between the first device and the second device. It is through secure negotiation and sharing the shared key K<sub>A</sub>"And the shared key Km is not known to the gateway device as an intermediate node, so it can be ensured that the first device can use the shared key Km to encrypt the data sent to the second device to ensure the security of the data during network transmission. sex.
[0067] FIG. 3 shows a schematic flowchart of a key generation method according to an exemplary embodiment 3 of the present invention. On the basis of the foregoing embodiment, as shown in FIG. 3, the key generation method includes the following steps:
[0068] Step 301: Determine the replacement period of the shared key of the first device and the second device;
[0069] Step 302, re-determine the first encryption factor and the second encryption factor according to the replacement period;
[0070] Step 303: Replace the shared key of the first device and the second device according to the re-determined first encryption factor and second encryption factor.
[0071] In an embodiment, the first device and the second device may agree to share the key K<sub>A</sub>The replacement cycle of c, when the shared key Km uses the time corresponding to the replacement cycle, the first device and the second device re-initiate the process of generating the shared key Km, which can further ensure that the shared key Ik and the data are in The security in the network transmission process further reduces the shared key K<sub>A</sub>c may be cracked.
[0072] FIG. 4 shows a schematic flowchart of a key generation method according to an exemplary embodiment 4 of the present invention. After the shared key is generated in the embodiment shown in FIG. 1, the first device can be authenticated through the shared key The data to be transmitted is encrypted and transmitted to the second device. As shown in FIG. 4, the process of encrypting and transmitting the data to be transmitted includes the following steps: [0073] Step 401: Determine what the first device needs to send to the second device Data to be transmitted;
[0074] Step 402: Use a shared key to encrypt the data to be transmitted, and send it to the second device through the first secure channel;
[0075] Step 403: The response data generated by the second device after receiving the data to be transmitted is received by the first security, and the response data has been encrypted by the shared key;
[0076] Step 404: Use the shared key to decrypt the response data encrypted by the shared key to obtain the response data.
[0077] In step 401, the data to be transmitted may be Internet of Things data obtained by a sensor on the first device.
[0078] For the related description of the first safe channel in step 402 and step 403, reference may be made to the related description of the embodiment shown in FIG. 1, which will not be described in detail here.
[0079] In step 404, when the response data encrypted by the shared key is received through the first secure channel, the response data encrypted by the shared key may be decrypted by the first encryption key of the first secure channel. , Then pass
The response data is decrypted a second time through the shared key, and the original response data is obtained.
[0080] In this embodiment, since the data to be transmitted is encrypted by the shared key during the forwarding process of the gateway device, and the shared key is a key jointly negotiated between the first device and the second device, the gateway device The shared key cannot be known, so it can ensure that the data to be transmitted is more securely transmitted between the first device and the second device, and further reduce the risk of illegal interception of the data during the transmission process.
[0081] FIG. 5 shows a schematic flowchart of a key generation method according to an exemplary embodiment 5 of the present invention. In this embodiment, the first device may be a terminal device, and the second device may be a server. It can be applied to the second device. As shown in Figure 5, the key generation method includes the following steps:
[0082] Step 501: Receive a first key factor encrypted with an initial key from a first device through a second secure channel, where the initial key is a preset key between the first device and the second device;
[0083] Step 502, decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;
[0084] Step 503: Generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device.
[0085] For the related description of the second secure channel in step 501, please refer to the related description of the embodiment shown in FIG. 1, which will not be described in detail here.
[0086] In step 502, after receiving the first key factor encrypted by the initial key through the second secure channel, the second encryption key of the second secure channel may first be used to pair the first key factor encrypted by the initial key. A key factor is decrypted, and then the first key factor is decrypted a second time through the initial key, thereby obtaining the original first key factor.
[0087] For a detailed description of how to generate a shared key between the first device and the second device according to the first key factor and the second key factor in step 503, please refer to the description of the embodiment shown in FIG. Detailed.
[0088] As can be seen from the above description, since both the first key factor and the second key factor are encrypted by the initial key during the forwarding process of the gateway device, the initial key is preset between the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device. The shared key that realizes the final negotiation is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, so it can ensure more secure data transmission between the first device and the second device, and further reduce The risk of illegal interception of data during transmission.
[0089] FIG. 6 shows a schematic flowchart of a key generation method according to an exemplary embodiment 6 of the present invention. As shown in FIG. 6, the key generation method includes the following steps:
[0090] Step 601: Use the initial key to encrypt the second key factor generated by the second device;
[0091] Step 602: Send the second key factor encrypted by the initial key to the first device through the second secure channel.
[0092] In this embodiment, the second encryption key of the second secure channel is used to perform the second encryption on the second key factor after the initial key encryption, so that the When forwarding via the gateway device, the second key factor is not known to the gateway device, so as to avoid the risk of illegal interception of the second key factor on the gateway device side.
[0093] FIG. 7 shows a schematic flowchart of a key generation method according to an exemplary embodiment 7 of the present invention. As shown in FIG. 7, the key generation method includes the following steps:
[0094] Step 701: Receive data to be transmitted encrypted with a shared key from the first device through the second secure channel;
[0095] Step 702: Use a shared key to decrypt the data to be transmitted;
[0096] Step 703: After receiving the data to be transmitted, generate response data;
[0097] Step 704: Encrypt the response data by using a shared key;
[0098] Step 705: Send the response data encrypted by the shared key to the first device through the second secure channel.
[0099] For the related description of the second secure channel in step 701, reference may be made to the related description of the embodiment shown in FIG. 1, which will not be described in detail here.
[0100] In step 704, after receiving the data to be transmitted from the first device through the second secure channel, the data to be transmitted is decrypted by the shared key using the shared key to obtain the original data. When a device responds, it can first encrypt the response data encrypted by the shared key through the second encryption key of the second secure channel, so that the gateway device cannot obtain the original response during the process of forwarding the response data. data.
[0101] In this embodiment, since the data to be transmitted is encrypted by a shared key during the forwarding process of the gateway device, and the shared key is a key jointly negotiated between the first device and the second device, the gateway device The shared key cannot be known, so it can ensure that the data to be transmitted is more securely transmitted between the first device and the second device, and further reduces the risk of illegal interception of the data during the transmission process.
[0102] Through the above-mentioned embodiments, based on the initial key preset between the first device and the second device, a shared key can be generated locally through a key generation algorithm in their respective counterparts, and finally the shared key is used for the data to be transmitted. Encryption, so that the gateway device can not view the original data when forwarding the data in the network, so as to achieve the purpose of safe data transmission.
[0103] FIG. 8 shows a schematic diagram of signaling for key negotiation between a terminal device and a server applicable to an exemplary embodiment of the present invention, taking the first device as the terminal device and the second device as the server as an example. Illustrative description, where, before the terminal device is connected to the network, the server needs to pre-issue an initial key (K<sub>baslc</sub>), can be issued to the terminal device through hardware writing, etc., as shown in Figure 8, the key negotiation between the terminal device and the server includes the following steps:
[0104] Step 801, the terminal device and the gateway device negotiate a first encryption key (K©) of the first secure channel, and establish a first secure channel between the terminal device and the gateway device. The method for establishing the first secure channel may be See the related description of the prior art.
[0105] Step 802: The gateway device negotiates with the server a second encryption key (K<sub>BC</sub>), and establish a second safe channel. Similar to the above step 801, the process of establishing the second secure channel can refer to the related description in the prior art, and the key agreement mechanism of SSL.TLS can also be adopted. Those skilled in the art can understand that the order of step 801 and step 802 can be interchanged, and the execution order can be set according to actual execution requirements.
[0106] Step 803: The terminal device prepares to initiate a key agreement process with the server, and the terminal device generates a first key factor (P), and the first key factor is used to generate a shared key between the terminal device and the server. At the same time, use the initial key (Kbaac) to encrypt the first key factor to obtain K<sub>baslc</sub>(p), then use the first encryption key K<sub>A</sub>B encrypts, get K<sub>AB</sub>: K<sub>ba</sub> sic (ρ)].
[0107] Step 804: The terminal device sends the double-encrypted first key factor K to the gateway device through the first secure channel.<sub>AB</sub> [K<sub>basic</sub> (ρ)]
[0108] Step 805, when the gateway device receives the double-encrypted first key factor K<sub>AB</sub>[K<sub>baslc</sub>(p)] After using the first encryption key K of the first secure channel<sub>A</sub>b for the double-encrypted first key factor K<sub>AB</sub>[K<sub>baslc</sub>(p)] Decrypt and get K<sub>baslc</sub>(p), and then use the third encryption key of the second secure channel for encryption to obtain the double-encrypted K<sub>BC</sub>: K<sub>ba</sub> sic (ρ)].
[0109] Step 806, the first key factor K double-encrypted with the initial key and the second encryption key<sub>BC</sub>[K<sub>baslc</sub>(p)] Send to the server through the second secure channel.
[0110] Step 807: After receiving the double-encrypted first key factor, the server uses the second encryption key of the second secure channel to decrypt the double-encrypted first key factor to obtain K<sub>baslc</sub>(p), then use the initial key pair K <sub>baslc</sub> (ρ) Perform decryption to obtain the first key factor Po
[0111] Step 808, the server generates a second key factor (q) through a pseudo-random function, and the second key factor q will be used as a parameter together with the first key factor P to generate a shared key K<sub>ACO</sub>
[0112] Step 809, the server uses the initial key K<sub>basl</sub>The second encryption factor q of the Jq key is obtained, and the heart "(q) is obtained, and then the second encryption key is used for K <sub>baslc</sub> (q) Encryption, get K<sub>BC</sub> [K<sub>baslc</sub> (q)].
[0113] Step 810: The server sends the double-encrypted second key factor K to the gateway device through the second secure channel.<sub>BC</sub> [Kbasic (q)] °
[0114] Step 811, the gateway device receives the double-encrypted second key factor K<sub>BC</sub>[K<sub>baslc</sub>After (q)], use the second encryption key Kbc of the second secure channel to decrypt the double-encrypted second encryption factor to obtain K <sub>baslc</sub> (q), then use the first encryption key of the first secure channel Κ<sub>Α</sub>β is encrypted to get K<sub>AB</sub>[K<sub>baslc</sub>(q)], and then send the double-encrypted second encryption factor to the terminal device through the first secure channel.
[0115] Step 812: After receiving the double-encrypted second encryption factor, the terminal device uses the first encryption key of the first secure channel to decrypt the double-encrypted second encryption factor to obtain K<sub>baslc</sub>(q), then use the first encryption key K<sub>baslc</sub>K after Xt's first decryption<sub>baslc</sub>(q) Perform secondary decryption to obtain the second key factor q.
[0116] Step 813, the terminal device and the server both share the first key factor p and the second key factor q, and both the terminal device and the server take the first key factor and the second key factor as input, and use the key Generate the algorithm to obtain the shared key Km between the terminal device and the server. For a detailed description of the key generation algorithm, reference may be made to the related description of the embodiment shown in FIG. 2, which will not be detailed here.
[011] In this embodiment, the secure negotiation and sharing of the shared key Km between the terminal device and the public network server is realized, and the shared key pair is unknown to the gateway device as an intermediate node, and then the terminal device can use The shared key encrypts the Internet of Things data sent to the public network server, thereby ensuring the security of data transmission.
[0118] In order to further ensure the security of the shared key and data transmission, the terminal device and the server may periodically perform a key agreement process to replace the shared key K<sub>A</sub>"Therefore, the possibility of the shared key being cracked can be further reduced.
[0119] FIG. 9 shows a schematic flowchart of a data transmission method according to an exemplary embodiment of the present invention. After the shared secret key is generated by the embodiment shown in FIG. Data (data), as shown in Figure 9, the data transmission method includes the following steps:
[0120] Step 901: Use the shared key Km to encrypt the Internet of Things data once to obtain the cipher text Km (data), and then use the first encryption key K of the first secure channel.<sub>Α</sub>β twice encryption, get ciphertext K<sub>A</sub>BK<sub>A</sub>c(data)].
[0121] Step 902, the terminal device sends the cipher text K to the gateway device through the first secure channel.<sub>AB</sub> [K<sub>AC</sub> (data)].
[0122] Step 903, the gateway device receives the ciphertext K<sub>A</sub>BK<sub>A</sub>After c(data)], use the first security key to decrypt and get K<sub>AC</sub> (data), then use the second encryption key to encrypt, get the ciphertext K <sub>BC</sub> [K<sub>AC</sub> (data)].
[0123] Step 904, the gateway device sends the cipher text K to the server through the second secure channel.<sub>BC</sub>[K<sub>AC</sub>(data)]<sub>o</sub>
[0124] Step 905, the server receives the double-encrypted cipher text Kbc [K<sub>A</sub>After c (data)], use the second encryption key Ik to decrypt to obtain K^(data), and then use the shared key Km to decrypt to obtain the original Internet of Things data data.
[0125] Step 906: After obtaining the original Internet of Things data, the server generates response data (res), and encrypts the response data using the shared key to obtain the cipher text K <sub>A</sub>c (res), and then use the second encryption key to perform secondary encryption to get Kbc [Krc (res)] °
[0126] Step 907, the server sends the double-encrypted ciphertext to the gateway device through the second secure channel
Kbc [Krc (res)] °
[0127] Step 908, the gateway device receives the double-encrypted ciphertext K<sub>BC</sub>[K<sub>AC</sub>(res)], use the second encryption key
Kbc decryption, get K AC (res), then use the first encryption key to encrypt, get the cipher text K <sub>AB</sub> [K<sub>AC</sub> (res)].
[0128] Step 909: The gateway device sends the double-encrypted ciphertext K to the terminal device through the first secure channel.<sub>AB</sub>[K<sub>AC</sub>(res)].
[0129] Step 910, the terminal device receives the double-encrypted ciphertext K<sub>AB</sub>[K<sub>AC</sub>After (res), use the first encryption key K<sub>A</sub>b decrypt, get K<sub>AC</sub>(res), then use the shared key Km to decrypt to get the original response data (res).
[0130] In this embodiment, cross-domain key negotiation and sharing between the terminal device through the gateway device of the intermediate node and the server is realized. The shared key is agnostic to the gateway device, ensuring that the Internet of Things data is between the terminal device and the server. End-to-end secure transmission between servers; in addition, in addition to ensuring the secure transmission of data between terminal equipment and gateway equipment and the secure transmission of data between gateway equipment and public network servers, the forwarding process of data within the gateway equipment on the transmission path is also affected. Security protection, even if the gateway device is illegally invaded, the IoT data forwarded via the gateway device is still protected because it is encrypted by the shared key, so as to prevent the IoT data from being illegally intercepted.
[0131] Corresponding to the above-mentioned key generation method, the present application also proposes a schematic structural diagram of the terminal device according to an exemplary embodiment of the present application shown in FIG. 10. Please refer to Figure 10. At the hardware level, the network server includes a processor, internal bus, network interface, memory, and non-volatile memory. Of course, it may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory to the memory and then runs, forming a key generation device on a logical level. Of course, in addition to the software implementation, this application does not exclude other implementations, such as logic devices or a combination of software and hardware, etc. That is to say, the execution body of the following processing flow is not limited to each logic unit, and can also be Hardware or logic device.
[0132] Corresponding to the above-mentioned key generation method, the present application also proposes a schematic structural diagram of a server according to an exemplary embodiment of the present application shown in FIG. 11. Please refer to Figure 11. At the hardware level, the network server includes a processor, internal bus, network interface, memory, and non-volatile memory. Of course, it may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory to the memory and then runs it, forming a key generation device on a logical level. Of course, in addition to the software implementation, this application does not exclude other implementations, such as logic devices or a combination of software and hardware, etc. That is to say, the execution body of the following processing flow is not limited to each logic unit, and can also be Hardware or logic device.
[0133] FIG. 12 shows a schematic structural diagram of a key generation device according to an exemplary embodiment of the present invention; as shown in FIG. 12, the key generation device may include: a first encryption module 1201, a first receiving module 1202, a first decryption module 1203, and a first key generation module 1204. in:
[0134] The first encryption module 1201 is configured to use the initial key to encrypt the first key factor generated by the first device and send it to the second device through the first secure channel, where the initial key is the connection between the first device and the second device. A key preset between the second device;
[0135] The first receiving module 1202 is configured to receive the second key factor encrypted by the initial key through the first secure channel, where the second key factor is generated by the second device;
[0136] The first decryption module 1203 is configured to decrypt the second key factor encrypted by the initial key and received through the first receiving module 1202 through the first secure channel to obtain the second key factor;
[0137] The first key generation module 1204 is configured to generate a shared key between the first device and the second device according to the first key factor and the second key factor decrypted by the first decryption module 1203.
[0138] FIG. 13 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; as shown in FIG. 13, on the basis of the embodiment shown in FIG. 12, the first encryption module 1201 Can include:
[0139] The first factor generating unit 12011 is configured to generate a first key factor through a pseudo-random function when the first device needs to initiate a key agreement process to the second device;
[0140] The first encryption unit 12012 is configured to use the initial key to encrypt the first key factor generated by the first factor generation unit 12011 to obtain the first key factor after the first encryption;
[0141] The second encryption unit 12013 is configured to use the first encryption key of the first secure channel to encrypt the first key factor after the first encryption of the first encryption unit 12012 to obtain the second encryption after the second encryption. A key factor.
[0142] In an embodiment, the first decryption module 1203 includes:
[0143] The first decryption unit 12031 is configured to use the first encryption key to decrypt the double-encrypted second key factor to obtain the second key factor after the first decryption;
[0144] The second encryption unit 12032 is configured to use the initial key to decrypt the second key factor after the first decryption unit 12031 decrypts for the first time to obtain the second key factor.
[0145] In an embodiment, the first key generation module 1204 may include:
[0146] The first determining unit 12041 is configured to determine the first encryption key shared between the first device and the second device and the device identifier of the first device;
[0147] The first factor generating unit 12042 is configured to generate the first key factor according to the first encryption key, the device identification determined by the first determining unit 12041, the first key factor, and the second key factor obtained by the first decryption module 1203. The shared secret key between the device and the second device.
[0148] In an embodiment, the first factor generating unit is specifically configured to:
[0149] Connect the first encryption key, the device ID, the first key factor, and the second key factor in sequence to obtain a combined string;
[0150] Divide the combined character string into two sub-strings of equal length;
[0151] Perform a hash operation on the two substrings to obtain two hash results;
[0152] Perform an exclusive OR operation on the two hash results to obtain the shared key of the first device and the second device.
[0153] In an embodiment, the device may further include:
[0154] The first determining module 1205 is configured to determine the replacement period of the shared key of the first device and the second device;
[0155] The second determination module 1206 is configured to re-determine the first encryption factor and the second encryption factor according to the replacement period determined by the first determination module 1205;
[0156] The first replacement module 1207 is configured to replace the shared key of the first device and the second device according to the first encryption factor and the second encryption factor re-determined by the second determination module 1206.
[0157] In an embodiment, the device may further include:
[0158] The third determining module 1208 is configured to determine the data to be transmitted that the first device needs to send to the second device;
[0159] The data encryption module 1209 is configured to use a shared key to encrypt the data to be transmitted determined by the third determining module 1208, and send it to the second device through the first secure channel.
[0160] In an embodiment, the device may further include:
[0161] The second receiving module 1210 is configured to receive the response data generated by the second device after receiving the data to be transmitted through the first security pass, and the response data has been encrypted by the shared key;
[0162] The second decryption module 1211 is configured to use the shared key to decrypt the response data encrypted by the shared key to obtain the response data.
[0163] FIG. 14 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; as shown in FIG. 14, the key generation device may include: a third receiving module 1401, a third decryption Module 1402, second key generation module 1403. in:
[0164] The third receiving module 1401 is configured to receive the first key factor encrypted by the initial key from the first device through the second secure channel, where the initial key is the pre-key between the first device and the second device. Set key;
[0165] The third decryption module 1402 is configured to decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;
[0166] The second key generation module 1403 is configured to generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device
[0167] FIG. 15 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; as shown in FIG. 15, on the basis of the above-mentioned embodiment shown in FIG. 14, the second key generation Module 1403 is specifically used for:
[0168] The first encryption key, the device identification of the first device, the first key factor, and the second key factor are sequentially connected to obtain a combined string;
[0169] Divide the combined character string into two sub-strings of equal length;
[0170] Perform hash operations on the two substrings to obtain two hash results;
[0171] Perform an exclusive OR operation on the two hash results to obtain the shared key of the first device and the second device.
[0172] In an embodiment, the device may further include:
[0173] The second encryption module 1404 is configured to use the initial key to encrypt the second key factor generated by the second device;
[0174] The first sending module 1405 is configured to send the second key factor encrypted by the initial key to the first device through the second secure channel.
[0175] In an embodiment, the device may further include:
[0176] The third determining module 1406 is used to determine the replacement period of the shared key of the first device and the second device;
[0177] The fourth determining module 1407 is configured to re-determine the first encryption factor and the second encryption factor according to the replacement period;
[0178] The second replacement module 1408 is configured to replace the shared key of the first device and the second device according to the re-determined first encryption factor and second encryption factor.
[0179] In an embodiment, the device may further include:
[0180] The fourth receiving module 1409 is configured to receive the data to be transmitted encrypted by the shared key from the first device through the second secure channel;
[0181] The fourth decryption module 1410 is configured to use a shared key to decrypt the data to be transmitted.
[0182] In an embodiment, the device may further include:
[0183] The response data generating module 1411 is configured to generate response data after receiving the data to be transmitted;
[0184] The third encryption module 1412 is configured to encrypt the response data by using a shared key;
[0185] The second sending module 1413 is configured to send the shared key encrypted data to the first device through the second secure channel.
Response data.
[0186] It can be seen from the above embodiment that the first key factor and the second key factor are both encrypted by the initial key during the forwarding process of the gateway device, and the initial key is preset between the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device. The shared key to achieve the final negotiation is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key. Therefore, it can ensure more secure data transmission between the first device and the second device, and further reduce The risk of illegal interception of data during transmission.
[0187] After considering and practicing the invention disclosed herein, those skilled in the art will easily think of other embodiments of the present application. This application is intended to cover any variations, uses, or adaptive changes of this application. These variations, uses, or adaptive changes follow the general principles of this application and include common knowledge or customary technical means in the technical field that are not disclosed in this application. . And the embodiments are only regarded as exemplary, and the true scope and spirit of the application are pointed out by the following claims.
[0188] It should also be noted that the terms "include", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, It also includes other elements that are not explicitly listed, or elements inherent to the process, method, commodity, or equipment. If there are no more restrictions, the element defined by the sentence "including a..." does not exclude the existence of other identical elements in the process, method, commodity, or equipment that includes the element.
[0189] The above descriptions are only preferred embodiments of the application, and are not intended to limit the application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the application shall include Within the scope of protection of this application.
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN112769759A | Cited by | China | – | Search report | – |
| CN108667598A | Cited by | China | – | Search report | – |
| CN109151015A | Cited by | China | – | Search report | – |
| CN108243181A | Cited by | China | – | Search report | – |
| CN107808284A | Cited by | China | – | Search report | – |
| CN108924161A | Cited by | China | – | Search report | – |
| CN109302285A | Cited by | China | – | Search report | – |
| CN112564901A | Cited by | China | – | Search report | – |
| CN103209075A | Cites | China | X | Search report | 1-28 |
8 members in 4 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 201510531892 | China | A | |
| CN201510531892 | – | – | – |
| CN20151531892 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| WO2017032242A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN106487749AThis record | China | A | |
| US2018241549A1 | United States of America | A1 | |
| JP2018529271A | Japan | A | |
| US10693634B2 | United States of America | B2 | |
| US2020313865A1 | United States of America | A1 | |
| CN106487749B | China | B | |
| US11463243B2 | United States of America | B2 |
4 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Patent grantGrantedGR01 | GR01 | CN | |
| Requests to designate patent in hong kongDE | DE | HK | |
| Entry into force of request for substantive examinationSE01 | SE01 | CN | |
| PublicationC06 | C06 | CN |
Numbers
- Publication
- 106487749
- Publication, DOCDB
- 106487749
- Publication, EPODOC
- CN106487749
- Application
- 105318922
- Application, DOCDB
- 201510531892
- Application, EPODOC
- CN201510531892
Titles2
- Chinese
- 密钥生成方法及装置
- English
- Key generation method and device
Classification
- CPC, 9
- H04L63/062
- H04L63/0478
- H04L9/085
- H04L9/0822
- H04L9/0861
- H04L63/06
- H04L2463/062
- H04L9/0866
- H04L12/66
- IPC, 1
- H04L29 06