CN106487749B

Key generation method and apparatus using double encryption

Abstract

The present application provides a key generation method and device. The key generation method includes: using an initial key to encrypt a first key factor generated by a first device and sending it to a second device through a first secure channel, wherein: The initial key is a key preset between the first device and the second device; the second key factor encrypted by the initial key is received through the first secure channel, where the second key factor is generated by the second device; Decrypt the second key factor encrypted by the initial key received through the first secure channel to obtain the second key factor; generate the first device and the second device according to the first key factor and the second key factor Shared secret key. The technical solution of the present invention can prevent the gateway device from obtaining the shared key negotiated between the first device and the second device, ensure more secure data transmission between the first device and the second device, and further reduce the amount of data being transmitted during the transmission process. The risk of illegal interception.

CN106487749B, drawing sheet 1
Sheet 1 of 1

Term

8.9 yearsleft in the term

Expires 26 August 2035.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

24 claims: 4 independent, 20 dependent

  1. 1
    1 A method for data transmission across network domains, applied to a first device in a first network domain, comprising:before data transmission, using a gateway device to negotiate a shared key with a second device in the second network domain;After the shared key is negotiated, the shared key is used to encrypt the data, and the encrypted data is re-encrypted with the first encryption key, and then sent to the gateway device so that the The gateway device uses the first encryption key to decrypt the re-encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key to perform the second encryption on the data encrypted with the shared key. After being encrypted, it is forwarded to the second device, where the first encryption key is the transmission key corresponding to the first secure channel between the first device and the gateway device;the second encryption key is the The transmission key corresponding to the second secure channel between the second device and the gateway device;wherein, using the gateway device to negotiate a shared key with the second device in the second network domain includes: using an initial key to pair the first device The generated first key factor is encrypted and sent to the gateway device through the first secure channel, and sent by the gateway device to the second device through the second secure channel, wherein the initial key is the first device A key preset with the second device;receiving the second key encrypted by the initial key and sent by the gateway device through the first secure channel Factor, wherein the second key factor is generated by the second device and sent to the gateway device through a second secure channel;encrypting the initial key received through the first secure channel Decrypt the second key factor to obtain the second key factor;generate a shared key for the first device and the second device according to the first key factor and the second key factor . 1 .一种跨网域的数据传输方法,应用于第一网域的第一设备,其特征在于,包括: 在数据传输之前,利用网关设备与第二网域内的第二设备协商共享密钥; 在协商好所述共享密钥后,利用所述共享密钥对数据进行加密,并将加密后的数据通 过第一加密密钥进行二次加密后,发送给所述网关设备,以使所述网关设备利用所述第一 加密密钥将二次加密的数据解密,还原出利用所述共享密钥加密后的数据,再利用第二加 密密钥对利用所述共享密钥加密的数据二次加密后,转发给第二设备,其中,所述第一加密 密钥为所述第一设备与网关设备之间的第一安全通道对应的传输密钥;所述第二加密密钥 为所述第二设备与网关设备之间的第二安全通道对应的传输密钥;其中,利用网关设备与 第二网域内的第二设备协商共享密钥,包括: 采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通过第一安全通道发 送给网关设备,并由所述网关设备通过第二安全通道发送给第二设备,其中,所述初始密钥 为所述第一设备与所述第二设备之间预设的密钥; 通过所述第一安全通道接收所述网关设备发送的经过所述初始密钥加密的第二密钥 因子,其中,所述第二密钥因子由所述第二设备生成,并通过第二安全通道发送给所述网关 设备; 对通过所述第一安全通道接收到的经过所述初始密钥加密的所述第二密钥因子进行 解密,得到所述第二密钥因子; 根据所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密 钥。
  2. 8
    8 A method for data transmission across network domains, applied to a second device in a second network domain, comprising:before data transmission, using a gateway device to negotiate a shared key with a first device in the first network domain;After the shared key is negotiated, the data forwarded by the gateway device is received, the received data is decrypted using the second encryption key, and then the decrypted data is doubled using the shared key. The second decryption;wherein, the data forwarded by the gateway device is obtained in the following manner: the first device encrypts the data using the shared key, and performs the second encryption of the encrypted data with the first encryption key , Sent to the gateway device, and the gateway device uses the first encryption key to decrypt the secondly encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key After the data encrypted with the shared key is encrypted twice, it is forwarded to the second device;wherein, the first encryption key is the transmission key corresponding to the first secure channel between the first device and the gateway device The second encryption key is the transmission key corresponding to the second secure channel between the second device and the gateway device;wherein the gateway device is used to negotiate a shared key with the first device in the first network domain, Including: receiving the first key factor encrypted by the initial key from the first device from the gateway device through the second secure channel , Wherein the initial key is a key preset between the first device and the second device, and the second secure channel is established between the second device and the gateway device A secure transmission channel, where the first key factor is sent by the first device to the gateway device through the first secure channel;the first key factor encrypted by the initial key is decrypted to obtain the The first encryption factor;generating a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device. 8 .一种跨网域的数据传输方法,应用于第二网域的第二设备,其特征在于,包括: 在数据传输之前,利用网关设备与第一网域内的第一设备协商共享密钥; 在协商好所述共享密钥后,接收所述网关设备转发的数据,利用第二加密密钥对所接 收的数据进行解密后,再利用所述共享密钥对所述解密后的数据进行二次解密;其中,所述 网关设备转发的数据通过以下方式得到: 所述第一设备利用所述共享密钥对数据进行加密,并将加密后的数据通过第一加密密 钥进行二次加密后,发送给所述网关设备,并由所述网关设备利用所述第一加密密钥将二 次加密的数据解密,还原出利用所述共享密钥加密后的数据,再利用第二加密密钥对利用 所述共享密钥加密的数据二次加密后,转发给第二设备;其中,所述第一加密密钥为所述第 一设备与网关设备之间的第一安全通道对应的传输密钥;所述第二加密密钥为所述第二设 备与网关设备之间的第二安全通道对应的传输密钥;其中,利用网关设备与第一网域内的 第一设备协商共享密钥,包括: 通过第二安全通道从网关设备接收来自第一设备的经过初始密钥加密的第一密钥因 子,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥,所述第二安全通 道为所述第二设备与所述网关设备之间建立的安全传输通道,所述第一密钥因子由所述第 一设备通过第一安全通道发送给所述网关设备; 对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所述第一加密因子; 根据所述第一密钥因子、所述第二设备生成的第二密钥因子生成所述第一设备与第二 设备的共享密钥。
  3. 13
    13 A cross-network data transmission device, applied to a first device in a first network domain, characterized in that it comprises:a key agreement module, configured to use a gateway device to communicate with a second network domain in the second network domain before data transmission Two devices negotiate a shared key;a data transmission module is used to encrypt data using the shared key after the shared key is negotiated, and perform secondary encryption on the encrypted data using the first encryption key After that, it is sent to the gateway device so that the gateway device uses the first encryption key to decrypt the twice-encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key. The key pair encrypts the data encrypted with the shared key for a second time, and then forwards it to the second device, where the first encryption key is the transmission corresponding to the first secure channel between the first device and the gateway device The key;the second encryption key is the transmission key corresponding to the second secure channel between the second device and the gateway device;wherein, the key agreement module includes: a first encryption module for using The initial key encrypts the first key factor generated by the first device and sends it to the gateway device through the first secure channel, and the gateway device sends it to the second device through the second secure channel. The initial key is a key preset between the first device and the second device;the first receiving module is configured to receive through the first secure channel the initial key sent by the gateway device The second key factor for key encryption, where the second key factor is generated by the second device and sent to the gateway device through a second secure channel;the first decryption module is configured to The first receiving module decrypts the second key factor encrypted by the initial key received by the first secure channel to obtain the second key factor;the first key generation module is configured to The shared key of the first device and the second device is generated according to the first key factor and the second key factor decrypted by the first decryption module. 13 .一种跨网域的数据传输装置,应用于第一网域的第一设备,其特征在于,包括: 密钥协商模块,用于在数据传输之前,利用网关设备与第二网域内的第二设备协商共 享密钥; 数据传输模块,用于在协商好所述共享密钥后,利用所述共享密钥对数据进行加密,并 将加密后的数据通过第一加密密钥进行二次加密后,发送给所述网关设备,以使所述网关 设备利用所述第一加密密钥将二次加密的数据解密,还原出利用所述共享密钥加密后的数 据,再利用第二加密密钥对利用所述共享密钥加密的数据二次加密后,转发给第二设备,其 中,所述第一加密密钥为所述第一设备与网关设备之间的第一安全通道对应的传输密钥; 所述第二加密密钥为所述第二设备与网关设备之间的第二安全通道对应的传输密钥;其 中,所述密钥协商模块包括: 第一加密模块,用于采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通 过第一安全通道发送给网关设备,并由所述网关设备通过第二安全通道发送给第二设备, 其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 第一接收模块,用于通过所述第一安全通道接收所述网关设备发送的经过所述初始密 钥加密的第二密钥因子,其中,所述第二密钥因子由所述第二设备生成,并通过第二安全通 道发送给所述网关设备; 第一解密模块,用于对通过所述第一接收模块通过所述第一安全通道接收到的经过所 述初始密钥加密的所述第二密钥因子进行解密,得到所述第二密钥因子; 第一密钥生成模块,用于根据所述第一密钥因子、所述第一解密模块解密得到的所述 第二密钥因子生成所述第一设备与第二设备的共享密钥。
  4. 20
    20 A cross-network data transmission device applied to a second device in a second network domain, characterized in that it comprises:a key agreement module, configured to use a gateway device to communicate with a second device in the first network domain before data transmission A device negotiates a shared key;a data transmission module is used to receive the data forwarded by the gateway device after the shared key is negotiated, use the second encryption key to decrypt the received data, and then use all The shared key decrypts the decrypted data twice;wherein, the data forwarded by the gateway device is obtained in the following manner: 20 .一种跨网域的数据传输装置,应用于第二网域的第二设备,其特征在于,包括: 密钥协商模块,用于在数据传输之前,利用网关设备与第一网域内的第一设备协商共 享密钥; 数据传输模块,用于在协商好所述共享密钥后,接收所述网关设备转发的数据,利用第 二加密密钥对所接收的数据进行解密后,再利用所述共享密钥对所述解密后的数据进行二 次解密;其中,所述网关设备转发的数据通过以下方式得到: The first device encrypts the data using the shared key, and after the encrypted data is re-encrypted with the first encryption key, it is sent to the gateway device, and the gateway device uses the The first encryption key decrypts the re-encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key to re-encrypt the data encrypted with the shared key, and then forward it to The second device;wherein, the first encryption key is the transmission key corresponding to the first secure channel between the first device and the gateway device;the second encryption key is the second device and the gateway The transmission key corresponding to the second secure channel between the devices;wherein, the third receiving module is configured to receive the first key factor encrypted by the initial key from the first device from the gateway device through the second secure channel, wherein , The initial key is a key preset between the first device and the second device, and the first key factor is sent by the first device to the gateway device through a first secure channel The third decryption module is used to decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;the second key generation module is used to decrypt the first key factor according to the first key;The key factor and the second key factor generated by the second device generate a shared key between the first device and the second device. 所述第一设备利用所述共享密钥对数据进行加密,并将加密后的数据通过第一加密密 钥进行二次加密后,发送给所述网关设备,并由所述网关设备利用所述第一加密密钥将二 次加密的数据解密,还原出利用所述共享密钥加密后的数据,再利用第二加密密钥对利用 所述共享密钥加密的数据二次加密后,转发给第二设备;其中,所述第一加密密钥为所述第 一设备与网关设备之间的第一安全通道对应的传输密钥;所述第二加密密钥为所述第二设 备与网关设备之间的第二安全通道对应的传输密钥;其中,第三接收模块,用于通过第二安 全通道从网关设备接收来自第一设备的经过初始密钥加密的第一密钥因子,其中,所述初 始密钥为所述第一设备与所述第二设备之间预设的密钥,所述第一密钥因子由所述第一设 备通过第一安全通道发送给所述网关设备; 第三解密模块,用于对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所 述第一加密因子; 第二密钥生成模块,用于根据所述第一密钥因子、所述第二设备生成的第二密钥因子 生成所述第一设备与第二设备的共享密钥。