Key generation method and apparatus using double encryption
Abstract
The present application provides a key generation method and device. The key generation method includes: using an initial key to encrypt a first key factor generated by a first device and sending it to a second device through a first secure channel, wherein: The initial key is a key preset between the first device and the second device; the second key factor encrypted by the initial key is received through the first secure channel, where the second key factor is generated by the second device; Decrypt the second key factor encrypted by the initial key received through the first secure channel to obtain the second key factor; generate the first device and the second device according to the first key factor and the second key factor Shared secret key. The technical solution of the present invention can prevent the gateway device from obtaining the shared key negotiated between the first device and the second device, ensure more secure data transmission between the first device and the second device, and further reduce the amount of data being transmitted during the transmission process. The risk of illegal interception.

Term
8.9 yearsleft in the term
Expires 26 August 2035.
- Priority and filed
- Granted
- Today
- Expires
24 claims: 4 independent, 20 dependent
- 11 A method for data transmission across network domains, applied to a first device in a first network domain, comprising:before data transmission, using a gateway device to negotiate a shared key with a second device in the second network domain;After the shared key is negotiated, the shared key is used to encrypt the data, and the encrypted data is re-encrypted with the first encryption key, and then sent to the gateway device so that the The gateway device uses the first encryption key to decrypt the re-encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key to perform the second encryption on the data encrypted with the shared key. After being encrypted, it is forwarded to the second device, where the first encryption key is the transmission key corresponding to the first secure channel between the first device and the gateway device;the second encryption key is the The transmission key corresponding to the second secure channel between the second device and the gateway device;wherein, using the gateway device to negotiate a shared key with the second device in the second network domain includes: using an initial key to pair the first device The generated first key factor is encrypted and sent to the gateway device through the first secure channel, and sent by the gateway device to the second device through the second secure channel, wherein the initial key is the first device A key preset with the second device;receiving the second key encrypted by the initial key and sent by the gateway device through the first secure channel Factor, wherein the second key factor is generated by the second device and sent to the gateway device through a second secure channel;encrypting the initial key received through the first secure channel Decrypt the second key factor to obtain the second key factor;generate a shared key for the first device and the second device according to the first key factor and the second key factor . 1 .一种跨网域的数据传输方法,应用于第一网域的第一设备,其特征在于,包括: 在数据传输之前,利用网关设备与第二网域内的第二设备协商共享密钥; 在协商好所述共享密钥后,利用所述共享密钥对数据进行加密,并将加密后的数据通 过第一加密密钥进行二次加密后,发送给所述网关设备,以使所述网关设备利用所述第一 加密密钥将二次加密的数据解密,还原出利用所述共享密钥加密后的数据,再利用第二加 密密钥对利用所述共享密钥加密的数据二次加密后,转发给第二设备,其中,所述第一加密 密钥为所述第一设备与网关设备之间的第一安全通道对应的传输密钥;所述第二加密密钥 为所述第二设备与网关设备之间的第二安全通道对应的传输密钥;其中,利用网关设备与 第二网域内的第二设备协商共享密钥,包括: 采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通过第一安全通道发 送给网关设备,并由所述网关设备通过第二安全通道发送给第二设备,其中,所述初始密钥 为所述第一设备与所述第二设备之间预设的密钥; 通过所述第一安全通道接收所述网关设备发送的经过所述初始密钥加密的第二密钥 因子,其中,所述第二密钥因子由所述第二设备生成,并通过第二安全通道发送给所述网关 设备; 对通过所述第一安全通道接收到的经过所述初始密钥加密的所述第二密钥因子进行 解密,得到所述第二密钥因子; 根据所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密 钥。
- 88 A method for data transmission across network domains, applied to a second device in a second network domain, comprising:before data transmission, using a gateway device to negotiate a shared key with a first device in the first network domain;After the shared key is negotiated, the data forwarded by the gateway device is received, the received data is decrypted using the second encryption key, and then the decrypted data is doubled using the shared key. The second decryption;wherein, the data forwarded by the gateway device is obtained in the following manner: the first device encrypts the data using the shared key, and performs the second encryption of the encrypted data with the first encryption key , Sent to the gateway device, and the gateway device uses the first encryption key to decrypt the secondly encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key After the data encrypted with the shared key is encrypted twice, it is forwarded to the second device;wherein, the first encryption key is the transmission key corresponding to the first secure channel between the first device and the gateway device The second encryption key is the transmission key corresponding to the second secure channel between the second device and the gateway device;wherein the gateway device is used to negotiate a shared key with the first device in the first network domain, Including: receiving the first key factor encrypted by the initial key from the first device from the gateway device through the second secure channel , Wherein the initial key is a key preset between the first device and the second device, and the second secure channel is established between the second device and the gateway device A secure transmission channel, where the first key factor is sent by the first device to the gateway device through the first secure channel;the first key factor encrypted by the initial key is decrypted to obtain the The first encryption factor;generating a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device. 8 .一种跨网域的数据传输方法,应用于第二网域的第二设备,其特征在于,包括: 在数据传输之前,利用网关设备与第一网域内的第一设备协商共享密钥; 在协商好所述共享密钥后,接收所述网关设备转发的数据,利用第二加密密钥对所接 收的数据进行解密后,再利用所述共享密钥对所述解密后的数据进行二次解密;其中,所述 网关设备转发的数据通过以下方式得到: 所述第一设备利用所述共享密钥对数据进行加密,并将加密后的数据通过第一加密密 钥进行二次加密后,发送给所述网关设备,并由所述网关设备利用所述第一加密密钥将二 次加密的数据解密,还原出利用所述共享密钥加密后的数据,再利用第二加密密钥对利用 所述共享密钥加密的数据二次加密后,转发给第二设备;其中,所述第一加密密钥为所述第 一设备与网关设备之间的第一安全通道对应的传输密钥;所述第二加密密钥为所述第二设 备与网关设备之间的第二安全通道对应的传输密钥;其中,利用网关设备与第一网域内的 第一设备协商共享密钥,包括: 通过第二安全通道从网关设备接收来自第一设备的经过初始密钥加密的第一密钥因 子,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥,所述第二安全通 道为所述第二设备与所述网关设备之间建立的安全传输通道,所述第一密钥因子由所述第 一设备通过第一安全通道发送给所述网关设备; 对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所述第一加密因子; 根据所述第一密钥因子、所述第二设备生成的第二密钥因子生成所述第一设备与第二 设备的共享密钥。
- 1313 A cross-network data transmission device, applied to a first device in a first network domain, characterized in that it comprises:a key agreement module, configured to use a gateway device to communicate with a second network domain in the second network domain before data transmission Two devices negotiate a shared key;a data transmission module is used to encrypt data using the shared key after the shared key is negotiated, and perform secondary encryption on the encrypted data using the first encryption key After that, it is sent to the gateway device so that the gateway device uses the first encryption key to decrypt the twice-encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key. The key pair encrypts the data encrypted with the shared key for a second time, and then forwards it to the second device, where the first encryption key is the transmission corresponding to the first secure channel between the first device and the gateway device The key;the second encryption key is the transmission key corresponding to the second secure channel between the second device and the gateway device;wherein, the key agreement module includes: a first encryption module for using The initial key encrypts the first key factor generated by the first device and sends it to the gateway device through the first secure channel, and the gateway device sends it to the second device through the second secure channel. The initial key is a key preset between the first device and the second device;the first receiving module is configured to receive through the first secure channel the initial key sent by the gateway device The second key factor for key encryption, where the second key factor is generated by the second device and sent to the gateway device through a second secure channel;the first decryption module is configured to The first receiving module decrypts the second key factor encrypted by the initial key received by the first secure channel to obtain the second key factor;the first key generation module is configured to The shared key of the first device and the second device is generated according to the first key factor and the second key factor decrypted by the first decryption module. 13 .一种跨网域的数据传输装置,应用于第一网域的第一设备,其特征在于,包括: 密钥协商模块,用于在数据传输之前,利用网关设备与第二网域内的第二设备协商共 享密钥; 数据传输模块,用于在协商好所述共享密钥后,利用所述共享密钥对数据进行加密,并 将加密后的数据通过第一加密密钥进行二次加密后,发送给所述网关设备,以使所述网关 设备利用所述第一加密密钥将二次加密的数据解密,还原出利用所述共享密钥加密后的数 据,再利用第二加密密钥对利用所述共享密钥加密的数据二次加密后,转发给第二设备,其 中,所述第一加密密钥为所述第一设备与网关设备之间的第一安全通道对应的传输密钥; 所述第二加密密钥为所述第二设备与网关设备之间的第二安全通道对应的传输密钥;其 中,所述密钥协商模块包括: 第一加密模块,用于采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通 过第一安全通道发送给网关设备,并由所述网关设备通过第二安全通道发送给第二设备, 其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥; 第一接收模块,用于通过所述第一安全通道接收所述网关设备发送的经过所述初始密 钥加密的第二密钥因子,其中,所述第二密钥因子由所述第二设备生成,并通过第二安全通 道发送给所述网关设备; 第一解密模块,用于对通过所述第一接收模块通过所述第一安全通道接收到的经过所 述初始密钥加密的所述第二密钥因子进行解密,得到所述第二密钥因子; 第一密钥生成模块,用于根据所述第一密钥因子、所述第一解密模块解密得到的所述 第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 2020 A cross-network data transmission device applied to a second device in a second network domain, characterized in that it comprises:a key agreement module, configured to use a gateway device to communicate with a second device in the first network domain before data transmission A device negotiates a shared key;a data transmission module is used to receive the data forwarded by the gateway device after the shared key is negotiated, use the second encryption key to decrypt the received data, and then use all The shared key decrypts the decrypted data twice;wherein, the data forwarded by the gateway device is obtained in the following manner: 20 .一种跨网域的数据传输装置,应用于第二网域的第二设备,其特征在于,包括: 密钥协商模块,用于在数据传输之前,利用网关设备与第一网域内的第一设备协商共 享密钥; 数据传输模块,用于在协商好所述共享密钥后,接收所述网关设备转发的数据,利用第 二加密密钥对所接收的数据进行解密后,再利用所述共享密钥对所述解密后的数据进行二 次解密;其中,所述网关设备转发的数据通过以下方式得到: The first device encrypts the data using the shared key, and after the encrypted data is re-encrypted with the first encryption key, it is sent to the gateway device, and the gateway device uses the The first encryption key decrypts the re-encrypted data, restores the data encrypted with the shared key, and then uses the second encryption key to re-encrypt the data encrypted with the shared key, and then forward it to The second device;wherein, the first encryption key is the transmission key corresponding to the first secure channel between the first device and the gateway device;the second encryption key is the second device and the gateway The transmission key corresponding to the second secure channel between the devices;wherein, the third receiving module is configured to receive the first key factor encrypted by the initial key from the first device from the gateway device through the second secure channel, wherein , The initial key is a key preset between the first device and the second device, and the first key factor is sent by the first device to the gateway device through a first secure channel The third decryption module is used to decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;the second key generation module is used to decrypt the first key factor according to the first key;The key factor and the second key factor generated by the second device generate a shared key between the first device and the second device. 所述第一设备利用所述共享密钥对数据进行加密,并将加密后的数据通过第一加密密 钥进行二次加密后,发送给所述网关设备,并由所述网关设备利用所述第一加密密钥将二 次加密的数据解密,还原出利用所述共享密钥加密后的数据,再利用第二加密密钥对利用 所述共享密钥加密的数据二次加密后,转发给第二设备;其中,所述第一加密密钥为所述第 一设备与网关设备之间的第一安全通道对应的传输密钥;所述第二加密密钥为所述第二设 备与网关设备之间的第二安全通道对应的传输密钥;其中,第三接收模块,用于通过第二安 全通道从网关设备接收来自第一设备的经过初始密钥加密的第一密钥因子,其中,所述初 始密钥为所述第一设备与所述第二设备之间预设的密钥,所述第一密钥因子由所述第一设 备通过第一安全通道发送给所述网关设备; 第三解密模块,用于对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所 述第一加密因子; 第二密钥生成模块,用于根据所述第一密钥因子、所述第二设备生成的第二密钥因子 生成所述第一设备与第二设备的共享密钥。
Independent claims4
194 paragraphs, as filed
Key generation method and device technical field
[0001] This application relates to the field of network security technology, and in particular to a method and device for generating a key.
Background technique
[0002] In order to ensure the secure transmission of data between the terminal device and the gateway device, and between the gateway device and the public network server, a secure transmission channel is usually established between the terminal device and the gateway device, and between the gateway device and the public network server. The gateway device forwards data from one secure channel to another secure channel, thereby realizing the function of data forwarding. In the process of forwarding data, the gateway device needs to use the shared key with the terminal device to decrypt the data encrypted by the terminal device, and then It is encrypted with the shared key with the server and then forwarded to the server, so the gateway device may have the risk of data leakage.
Summary of the invention
[0003] In view of this, this application provides a new technical solution that can prevent the gateway device from obtaining the shared key between the two devices, thereby reducing the risk of illegal interception of data during network transmission.
[0004] In order to achieve the above purpose, the present application provides technical solutions as follows:
[0005] According to the first aspect of the present application, a key generation method is proposed, which is applied on a first device, and includes:
[0006] The first key factor generated by the first device is encrypted with an initial key and sent to the second device through the first secure channel, where the initial key is the first device and the A key preset between the second device; [0007] receiving a second key factor encrypted by the initial key through the first secure channel, wherein the second key factor is determined by the second key factor Equipment generation;
[0008] decrypt the second key factor encrypted by the initial key received through the first secure channel to obtain the second key factor;
[0009] Generate a shared key for the first device and the second device according to the first key factor and the second key factor.
[0010] According to the second aspect of the present application, a key generation method is proposed, which is applied to a second device, and includes:
[0011] The first key factor encrypted by the initial key is received from the first device through the second secure channel, wherein the initial key is a preset between the first device and the second device Key
[0012] decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;
[0013] Generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device.
[0014] According to the third aspect of the present application, a key generation device is proposed, which is applied to a first device and includes:
[0015] The first encryption module is configured to use the initial key to encrypt the first key factor generated by the first device and send it to the second device through the first secure channel, wherein the initial key is A key preset between the first device and the second device;
[0016] The first receiving module is configured to receive the second secret encrypted by the initial key through the first secure channel
A key factor, wherein the second key factor is generated by the second device;
[0017] The first decryption module is configured to decrypt the second key factor encrypted by the initial key and received by the first receiving module through the first secure channel to obtain the first Two key factor;
[0018] The first key generation module is configured to generate a shared secret between the first device and the second device according to the first key factor and the second key factor decrypted by the first decryption module. key.
[0019] According to the fourth aspect of the present application, a key generation device is proposed, which is applied to a second device, and includes:
[0020] The third receiving module is configured to receive the first key factor encrypted by the initial key from the first device through the second secure channel, wherein the initial key is the first device and the first key factor. 2. The preset key between the devices;
[0021] The third decryption module is configured to decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;
[0022] The second key generation module is configured to generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device.
[0023] It can be seen from the above technical solution that the first key factor and the second key factor are both encrypted by the initial key during the forwarding process of the gateway device, and the initial key is the pre-key between the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor; the shared key between the first device and the second device is generated through the first key factor and the second key factor, The shared key that can be finally negotiated is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key. Therefore, it can ensure more secure transmission of data between the first device and the second device, and further Reduce the risk of illegal interception of data during transmission.
Description of the drawings
[0024] FIG. 1 shows a schematic flowchart of a key generation method according to an exemplary embodiment 1 of the present invention;
[0025] FIG. 2 shows a schematic flowchart of a key generation method according to an exemplary embodiment 2 of the present invention;
[0026] FIG. 3 shows a schematic flowchart of a key generation method according to an exemplary embodiment 3 of the present invention; [0027] FIG. 4 shows a key generation method according to an exemplary embodiment 4 of the present invention [0028] FIG. 5 shows a schematic flowchart of a key generation method according to an exemplary embodiment 5 of the present invention; [0029] FIG. 6 shows a schematic diagram of a key generation method according to an exemplary embodiment 6 of the present invention Schematic diagram of the flow of the key generation method; [0030] FIG. 7 shows a schematic diagram of the flow of the key generation method according to an exemplary embodiment 7 of the present invention;
[0031] FIG. 8 shows a schematic diagram of signaling for key negotiation between a terminal device and a server applicable according to an exemplary embodiment of the present invention;
[0032] FIG. 9 shows a schematic diagram of signaling for data transmission between a terminal device and a server applicable to an exemplary embodiment of the present invention;
[0033] FIG. 10 shows a schematic structural diagram of a terminal device according to an exemplary embodiment of the present invention;
[0034] FIG. 11 shows a schematic structural diagram of a server according to an exemplary embodiment of the present invention;
[0035] FIG. 12 shows a schematic structural diagram of a key generation device according to an exemplary embodiment of the present invention;
[0036] FIG. 13 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; [0037] FIG. 14 shows a key generation device according to still another exemplary embodiment of the present invention [0038] FIG. 15 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention.
Detailed ways
[0039] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings indicate the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the application as detailed in the appended claims.
[0040] The terms used in this application are only for the purpose of describing specific embodiments, and are not intended to limit the application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and/or" as used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0041] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, the information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this application, the first information may also be referred to as second information, and similarly, the second information may also be referred to as first information. Depending on the context, the word "if" as used herein can be interpreted as "when" or when" or "in response to determination".
[0042] To further illustrate this application, the following examples are provided:
[0043] According to an embodiment of the present application, since both the first key factor and the second key factor are encrypted by the initial key during the forwarding process of the gateway device, the initial key is between the first device and the second device. A preset key, so the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device , It can be realized that the final negotiated shared key is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, so data can be transmitted more securely between the first device and the second device. Further reduce the risk of illegal interception of data during transmission.
[0044] FIG. 1 shows a schematic flowchart of a method for generating a key according to an exemplary embodiment of the present invention; in an embodiment, the first device may be a terminal device, and the second device may be a server, which can be replaced Ground, the first device may be a server, and the second device may be a terminal device. In this embodiment, application on a terminal device is taken as an example for illustration. As shown in FIG. 1, the key generation method includes the following steps:
[0045] Step 101: Use the initial key to encrypt the first key factor generated by the first device and send it to the second device through the first secure channel, where the initial key is between the first device and the second device. Preset key;
[0046] Step 102: Receive a second key factor encrypted with an initial key through the first secure channel, where the second key factor is generated by the second device;
[0047] Step 103: Decrypt the second key factor encrypted by the initial key received through the first secure channel to obtain the second key factor;
[0048] Step 104: Generate a shared key between the first device and the second device according to the first key factor and the second key factor.
[0049] In step 101, in an embodiment, the initial key Kbasic may be issued to the first device by the second device before the first device is put into use, and may be issued to the first device through hardware writing. equipment. In an embodiment, related data information is forwarded between the first device and the second device through the gateway device, where the first secure channel can be established through negotiation between the first device and the gateway device, and the related data information is transmitted through the first secure channel The second secure channel can be established through negotiation between the server and the gateway device, and relevant data information can be transmitted through the second secure channel. Those skilled in the art can understand that the establishment process of the first secure channel and the second secure channel can refer to the related description in the prior art.
For example, a key agreement mechanism of Secure Socket Layer (SSL) and Transport Layer Security (TLS) may be adopted.
[0050] In an embodiment, when the first device needs to initiate a key agreement process to the second device, the first key factor is generated by a pseudo-random function, and the first key factor is encrypted using the initial key to obtain The first key factor after the first encryption, the first encryption key of the first secure channel is used to encrypt the first key factor after the first encryption, and the first key factor after the second encryption is obtained . By double-encrypting the first key factor, the first key factor can be made unknown at the gateway device, and the risk of the first key factor being illegally intercepted on the gateway device side can be avoided.
[0051] In step 103, the first encryption key is used to decrypt the double-encrypted second key factor to obtain the second key factor after the first decryption, and the initial key is used to decrypt the second key factor for the first time. The second key factor of is decrypted to obtain the second key factor. Since the second key factor has been double-encrypted at the second device, the second key factor is not known at the gateway device, which avoids the risk of illegal interception of the second key factor on the gateway device side.
[0052] For a detailed description of how to generate the shared key of the first device and the second device according to the first key factor and the second key factor in step 104, refer to the following description, which will not be described in detail here.
[0053] It can be seen from the above description that the first key factor and the second key factor are both encrypted by the initial key during the forwarding process of the gateway device, and the initial key is preset between the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device. The shared key to achieve the final negotiation is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key. Therefore, it can ensure more secure data transmission between the first device and the second device, and further reduce The risk of illegal interception of data during transmission.
[0054] FIG. 2 shows a schematic flow chart of a key generation method according to an exemplary embodiment 2 of the present invention. In this embodiment, how to pass the first key factor in step 105 in the embodiment shown in FIG. Using the second key factor to generate a shared key between the first device and the second device is taken as an example to illustrate. As shown in FIG. 2, the key generation method includes the following steps:
[0055] Step 201, determine the initial key shared between the first device and the second device and the device identifier of the first device;
[0056] Step 202: Connect the initial key, the device ID, the first key factor, and the second key factor in sequence to obtain a combined string;
[0057] Step 203, split the combined character string into two sub-strings of equal length;
[0058] Step 204, perform a hash operation on the two sub-strings to obtain two hash results;
[0059] Step 205: Perform an exclusive OR operation on the two hash results to obtain the shared key of the first device and the second device.
[0060] After the first device obtains the second key factor through step 104 in the embodiment shown in FIG. 1, the first device has the first key factor P and the second key factor q. The first device can take the first key factor and the second key factor as input, and obtain the key Kac by using the shared key generation algorithm. Among them, the key generation algorithm is as follows:
[0061] KAc = KeyGenerate (Kbasic, "Shared Key", p, q);
[0062] Among them, Kbasic is the initial key, and Shared Key is the device identification of the first device. The device identification can be the device serial number of the first device, or the MAC address, or a combination of the above two, etc., As long as the second device can distinguish the first device from other devices through the device identifier.
[0063] In addition, in the process of generating the shared key through the function KeyGenerate, the character string corresponding to the first encryption key Kbasic, "Shared Key, p, q can be connected in sequence to obtain a combined character string, and the combined character string can be used function
KeyGenerate generates the shared key Kac.
[0064] In an embodiment, the process implemented by the function KeyGenerate may specifically be: cutting the input combined string into two sub-strings of equal length (if the combined string has an odd length, then the combined string Add 1 to the last digit of, and then perform a hash operation (for example, MD5) on the two substrings respectively, and perform an exclusive OR operation on the two calculation results obtained, and the result obtained is the shared key Kac.
[0065] Taking MD5 as an example to illustrate, since MD5 can convert an input of any length into a 128-bit length result, the length of the shared key Kac is 128 bits, which simplifies the complexity of the shared key calculation. Since the calculation of the shared key Kac uses MD5, the amount of calculation is affordable for the first device with limited computing capability.
[0066] In this embodiment, the shared key Kac is generated by the first key factor, the second key factor, the initial key, and the device identification of the first device, thus realizing the communication between the first device and the second device The shared key Kac is negotiated and shared securely, and the shared key Kac is not known to the gateway device as the intermediate node, so it can be ensured that the first device can use the shared key Kac to perform data sent to the second device. Encryption to ensure the security of data during network transmission.
[0067] FIG. 3 shows a schematic flowchart of a key generation method according to an exemplary embodiment 3 of the present invention. On the basis of the foregoing embodiment, as shown in FIG. 3, the key generation method includes the following steps:
[0068] Step 301, determine the replacement period of the shared key of the first device and the second device;
[0069] Step 302, re-determine the first encryption factor and the second encryption factor according to the replacement period;
[0070] Step 303: Replace the shared key of the first device and the second device according to the re-determined first encryption factor and second encryption factor.
[0071] In an embodiment, the first device and the second device may agree on a replacement period for the shared key Kac. After the shared key Kac has been used for the duration corresponding to the replacement period, the first device and the second device will reconnect with each other. Initiate the process of generating the shared key Kac, so as to further ensure the security of the shared key Kac and the data during network transmission, and further reduce the possibility of the shared key Kac being cracked.
[0072] FIG. 4 shows a schematic flowchart of a key generation method according to an exemplary embodiment 4 of the present invention. After the shared key is generated in the embodiment shown in FIG. 1, the first device can be authenticated through the shared key The data to be transmitted is encrypted and transmitted to the second device. As shown in FIG. 4, the process of encrypting and transmitting the data to be transmitted includes the following steps: [0073] Step 401, determining that the first device needs to send to the second device The data to be transmitted;
[0074] Step 402, use a shared key to encrypt the data to be transmitted, and send it to the second device through the first secure channel;
[0075] Step 403, the response data generated by receiving the data to be transmitted by the second device through the first security, the response data has been encrypted by the shared key;
[0076] Step 404: Use the shared key to decrypt the response data encrypted by the shared key to obtain the response data.
[0077] In step 401, the data to be transmitted may be IoT data obtained by a sensor on the first device.
[0078] For the related description of the first safe channel in step 402 and step 403, reference may be made to the related description of the embodiment shown in FIG. 1, which will not be described in detail here.
[0079] In step 404, when the response data encrypted by the shared key is received through the first secure channel, the response data encrypted by the shared key may be decrypted by the first encryption key of the first secure channel. , And then use the shared key to decrypt the response data a second time to get the original response data.
[0080] In this embodiment, since the data to be transmitted is encrypted by the shared key during the forwarding process of the gateway device, and the shared key is a key jointly negotiated between the first device and the second device, the gateway device The shared key cannot be known, so it can ensure that the data to be transmitted is more securely transmitted between the first device and the second device, and further reduce the risk of illegal interception of the data during the transmission process.
[0081] FIG. 5 shows a schematic flowchart of a key generation method according to an exemplary embodiment 5 of the present invention. In this embodiment, the first device may be a terminal device, and the second device may be a server. It can be applied to the second device. As shown in Figure 5, the key generation method includes the following steps:
[0082] Step 501: Receive a first key factor encrypted with an initial key from a first device through a second secure channel, where the initial key is a preset key between the first device and the second device;
[0083] Step 502, decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;
[0084] Step 503: Generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device.
[0085] For the related description of the second secure channel in step 501, please refer to the related description of the embodiment shown in FIG. 1, which will not be described in detail here.
[0086] In step 502, after receiving the first key factor encrypted by the initial key through the second secure channel, the second encryption key of the second secure channel may be used to pair the first key factor encrypted by the initial key. A key factor is decrypted, and then the first key factor is decrypted a second time using the initial key to obtain the original first key factor.
[0087] For a detailed description of how to generate a shared key between the first device and the second device according to the first key factor and the second key factor in step 503, please refer to the description of the embodiment shown in FIG. Detailed.
[0088] As can be seen from the above description, since the first key factor and the second key factor are both encrypted by the initial key during the forwarding process of the gateway device, and the initial key is preset between the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device. The shared key to achieve the final negotiation is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key. Therefore, it can ensure more secure data transmission between the first device and the second device, and further reduce The risk of illegal interception of data during transmission.
[0089] FIG. 6 shows a schematic flowchart of a key generation method according to an exemplary embodiment 6 of the present invention. As shown in FIG. 6, the key generation method includes the following steps:
[0090] Step 601: Use the initial key to encrypt the second key factor generated by the second device;
[0091] Step 602: Send the second key factor encrypted by the initial key to the first device through the second secure channel.
[0092] In this embodiment, the second encryption key of the second secure channel is used to perform the second encryption on the second key factor after the initial key encryption, so that the When forwarding via the gateway device, the second key factor is not known to the gateway device, so as to avoid the risk of illegal interception of the second key factor on the gateway device side.
[0093] FIG. 7 shows a schematic flowchart of a key generation method according to an exemplary embodiment 7 of the present invention. As shown in FIG. 7, the key generation method includes the following steps:
[0094] Step 701: Receive data to be transmitted encrypted with a shared key from the first device through the second secure channel;
[0095] Step 702, using a shared key to decrypt the data to be transmitted;
[0096] Step 703, after receiving the data to be transmitted, generate response data;
[0097] Step 704: Encrypt the response data by using a shared key;
[0098] Step 705: Send the response data encrypted by the shared key to the first device through the second secure channel.
[0099] For the related description of the second secure channel in step 701, reference may be made to the related description of the embodiment shown in FIG. 1, which will not be described in detail here.
[0100] In step 704, after receiving the data to be transmitted from the first device through the second secure channel, the data to be transmitted is decrypted by the shared key using the shared key to obtain the original data. When a device responds, it can first encrypt the response data encrypted by the shared key through the second encryption key of the second secure channel, so that the gateway device cannot obtain the original response during the process of forwarding the response data. data.
[0101] In this embodiment, since the data to be transmitted is encrypted by the shared key during the forwarding process of the gateway device, and the shared key is a key jointly negotiated between the first device and the second device, the gateway device The shared key cannot be known, so it can ensure that the data to be transmitted is more securely transmitted between the first device and the second device, and further reduce the risk of illegal interception of the data during the transmission process.
[0102] Through the above embodiments, based on the initial key preset between the first device and the second device, a shared key can be generated locally through a key generation algorithm in their respective counterparts, and finally the shared key is used to transmit the data to be transmitted. Encryption is performed, so that the gateway device cannot view the original data when forwarding the data in the network, thereby achieving the purpose of safe data transmission.
[0103] FIG. 8 shows a schematic diagram of signaling for key negotiation between a terminal device and a server applicable to an exemplary embodiment of the present invention, taking the first device as the terminal device and the second device as the server as an example. Illustratively, before the terminal device is connected to the network, the server needs to issue an initial key (Kbasic) for the terminal device in advance, which can be issued to the terminal device by means of hardware writing, etc., as shown in Figure 8, the terminal device and Key negotiation between servers includes the following steps:
[0104] Step 801, the terminal device and the gateway device negotiate a first encryption key (Kab) of the first secure channel, and establish a first secure channel between the terminal device and the gateway device. For the method for establishing the first secure channel, reference may be made to related descriptions in the prior art.
[0105] Step 802: The gateway device negotiates the second encryption key (Kbc) of the second secure channel with the server, and establishes the second secure channel. Similar to the above step 801, the process of establishing the second secure channel can be referred to the related description in the prior art, and the key agreement mechanism of SSL and TLS can also be adopted. Those skilled in the art can understand that the order of step 801 and step 802 can be interchanged, and the execution order can be set according to actual execution requirements.
[0106] Step 803: The terminal device prepares to initiate a key agreement process with the server, and the terminal device generates a first key factor (p), and the first key factor is used to generate a shared key between the terminal device and the server. At the same time, use the initial key (Kbasic) to encrypt the first key factor to obtain Kbasic (p), and then use the first encryption key KAB to encrypt to obtain Kab [Kbasic (p)].
[0107] Step 804: The terminal device sends the double-encrypted first key factor KAB[Kbasic(p)] to the gateway device through the first secure channel.
[0108] Step 805: After receiving the double-encrypted first key factor KAB[Kbasic(p)], the gateway device uses the first encryption key Kab of the first secure channel to pair the double-encrypted first key The factor KAB[Kbasic(p)] is decrypted to obtain Kbasic (p), and then the third encryption key Kbc of the second secure channel is used for encryption to obtain the double-encrypted Kbc [Kbasic(p)].
[0109] Step 806, the first key factor KBc [Kbasic
(p)] Send to the server through the second secure channel.
[0110] Step 807: After receiving the double-encrypted first key factor, the server uses the second encryption key KBC of the second secure channel to decrypt the double-encrypted first key factor to obtain Kbasic(p) , Then use the initial key Kbasic to decrypt Kbasic (p) to obtain the first key factor P.
[0111] Step 808, the server generates a second key factor (q) through a pseudo-random function, and the second key factor q will be used as a parameter with the first key factor P to generate a shared key Kac.
[0112] Step 809, the server uses the initial key Kbasic to encrypt the second encryption factor q to obtain Kbasic(q), and then uses the second encryption key Kbc to encrypt Kbasic (q) to obtain KBc[Kbasic (q)].
[0113] Step 810: The server sends the double-encrypted second key factor Kbc [Kbasic (q)] to the gateway device through the second secure channel.
[0114] Step 811: After receiving the double-encrypted second key factor Kbc [Kbasic (q)], the gateway device uses the second encryption key Kbc of the second secure channel to perform the double-encrypted second encryption factor Decrypt to obtain Kbasic (q), then use the first encryption key Kab of the first secure channel to encrypt to obtain KAB[Kbasic (q)], and then send the double-encrypted second encryption factor through the first secure channel to Terminal Equipment.
[0115] Step 812: After receiving the double-encrypted second encryption factor, the terminal device uses the first encryption key Kab of the first secure channel to decrypt the double-encrypted second encryption factor to obtain Kbasic (q) , And then use the first encryption key Kbasic to decrypt the Kbasic (q) after the first decryption for the second time to obtain the second key factor q.
[0116] Step 813, the terminal device and the server both share the first key factor p and the second key factor q, and both the terminal device and the server take the first key factor and the second key factor as input, and use the key Generate an algorithm to obtain the shared key Kac between the terminal device and the server. For a detailed description of the key generation algorithm, reference may be made to the related description of the embodiment shown in FIG. 2, which will not be described in detail here.
[0117] In this embodiment, the secure negotiation and sharing of the shared key Kac between the terminal device and the public network server is thus realized, and the shared key pair is unknown to the gateway device as an intermediate node, and then the terminal device can use The shared key encrypts the Internet of Things data sent to the public network server, thereby ensuring the security of data transmission.
[0118] In order to further ensure the security of the shared key and data transmission, the terminal device and the server can periodically perform a key agreement process to replace the shared key Kac, thereby further reducing the possibility of the shared key being cracked. .
[0119] FIG. 9 shows a schematic flowchart of a data transmission method according to an exemplary embodiment of the present invention. After the shared secret key is generated by the embodiment shown in FIG. Data (data), as shown in Figure 9, the data transmission method includes the following steps:
[0120] Step 901: Use the shared key Kac to encrypt the IoT data once to obtain the cipher text Kac (data), and then use the first encryption key Kab of the first secure channel to encrypt twice to obtain the cipher text Kab[Kac (data)].
[0121] Step 902: The terminal device sends the cipher text Kab[Kac (data)] to the gateway device through the first secure channel.
[0122] Step 903: After receiving the cipher text Kab [Kac (data)], the gateway device uses the first security key Kab to decrypt to obtain Kac (data), and then uses the second encryption key Kbc for encryption to obtain the cipher text Kbc[Kac (data)].
[0123] Step 904: The gateway device sends the cipher text Kbc[Kac (data)] to the server through the second secure channel.
[0124] Step 905: After the server receives the double-encrypted ciphertext Kbc [Kac (data)], it decrypts it with the second encryption key Kbc to obtain Kac (data), and then decrypts it with the shared key Kac to obtain the original Internet of Things data.
[0125] Step 906, the server generates response data (res) after obtaining the original Internet of Things data, using the shared key
Kac encrypts the response data to obtain the cipher text KAc(res), and then uses the second encryption key Kbc to perform secondary encryption to obtain Kbc[Kac (res)].
[0126] Step 907: The server sends the double-encrypted cipher text Kbc [Kac (res)] to the gateway device through the second secure channel.
[0127] Step 908, after the gateway device receives the double-encrypted cipher text Kbc [Kac (res)], it uses the second encryption key Kbc to decrypt to obtain Kac (res), and then uses the first encryption key Kab to encrypt , Get the ciphertext Kab[Kac (res)].
[0128] Step 909: The gateway device sends the double-encrypted cipher text Kab [Kac (res)] to the terminal device through the first secure channel.
[0129] Step 910: After receiving the double-encrypted cipher text Kab [Kac (res]), the terminal device uses the first encryption key Kab to decrypt it to obtain Kac (res), and then uses the shared key Kac to decrypt it to obtain the original Response data (res).
[0130] In this embodiment, cross-domain key negotiation and sharing between the terminal device and the server through the gateway device of the intermediate node is realized. End-to-end secure transmission between servers; in addition, in addition to ensuring the secure transmission of data between terminal equipment and gateway equipment and the secure transmission of data between gateway equipment and public network servers, the forwarding process of data in the gateway equipment on the transmission path is also affected. Security protection, even if the gateway device is illegally invaded, the IoT data forwarded via the gateway device is still protected because it is encrypted by the shared key, so as to prevent the IoT data from being illegally intercepted.
[0131] Corresponding to the above-mentioned key generation method, this application also proposes a schematic structural diagram of a terminal device according to an exemplary embodiment of the application shown in FIG. 10. Please refer to FIG. 10, at the hardware level, the network server includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, it may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory to the memory and then runs it, forming a key generation device on a logical level. Of course, in addition to software implementation, this application does not exclude other implementations, such as logic devices or a combination of software and hardware, etc. That is to say, the execution body of the following processing flow is not limited to each logic unit, and may also be Hardware or logic device.
[0132] Corresponding to the above-mentioned key generation method, the present application also proposes a schematic structural diagram of a server according to an exemplary embodiment of the present application as shown in FIG. 11. Please refer to FIG. 11, at the hardware level, the network server includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, it may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory to the memory and then runs, forming a key generation device on the logical level. Of course, in addition to the software implementation, this application does not exclude other implementations, such as logic devices or a combination of software and hardware, etc. That is to say, the execution body of the following processing flow is not limited to each logic unit, and can also be Hardware or logic device.
[0133] FIG. 12 shows a schematic structural diagram of a key generation device according to an exemplary embodiment of the present invention; as shown in FIG. 12, the key generation device may include: a first encryption module 1201, a first receiving module 1202, a first decryption module 1203, and a first key generation module 1204. in:
[0134] The first encryption module 1201 is configured to use the initial key to encrypt the first key factor generated by the first device and send it to the second device through the first secure channel, where the initial key is the first device and A key preset between the second device;
[0135] The first receiving module 1202 is configured to receive the second key factor encrypted by the initial key through the first secure channel, where the second key factor is generated by the second device;
[0136] The first decryption module 1203 is used for verifying the data received through the first receiving module 1202 through the first secure channel.
Decrypt with the second key factor encrypted by the initial key to obtain the second key factor;
[0137] The first key generation module 1204 is configured to generate a shared key between the first device and the second device according to the first key factor and the second key factor decrypted by the first decryption module 1203.
[0138] FIG. 13 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; as shown in FIG. 13, on the basis of the embodiment shown in FIG. 12, the first encryption module 1201 Can include:
[0139] The first factor generating unit 12011 is configured to generate a first key factor through a pseudo-random function when the first device needs to initiate a key agreement process to the second device;
[0140] The first encryption unit 12012 is configured to use the initial key to encrypt the first key factor generated by the first factor generation unit 12011 to obtain the first key factor after the first encryption;
[0141] The second encryption unit 12013 is configured to use the first encryption key of the first secure channel to pair the first encryption unit
12012 The first key factor after the first encryption is encrypted, and the first key factor after the second encryption is obtained.
[0142] In an embodiment, the first decryption module 1203 includes:
[0143] The first decryption unit 12031 is configured to use the first encryption key to decrypt the double-encrypted second key factor to obtain the second key factor after the first decryption;
[0144] The second encryption unit 12032 is configured to use the initial key to decrypt the second key factor after the first decryption unit 12031 decrypts for the first time to obtain the second key factor.
[0145] In an embodiment, the first key generation module 1204 may include:
[0146] The first determining unit 12041 is configured to determine the first encryption key shared between the first device and the second device and the device identifier of the first device;
[0147] The first factor generating unit 12042 is configured to generate the first key factor according to the first encryption key, the device identification determined by the first determining unit 12041, the first key factor, and the second key factor obtained by the first decryption module 1203. The shared secret key between the device and the second device.
[0148] In an embodiment, the first factor generating unit is specifically configured to:
[0149] Connect the first encryption key, the device ID, the first key factor, and the second key factor in sequence to obtain a combined string;
[0150] Divide the combined string into two sub-strings of equal length;
[0151] Perform hash operations on the two substrings to obtain two hash results;
[0152] Perform an exclusive OR operation on the two hash results to obtain the shared key of the first device and the second device.
[0153] In an embodiment, the device may further include:
[0154] The first determining module 1205 is configured to determine the replacement period of the shared key of the first device and the second device;
[0155] The second determination module 1206 is configured to re-determine the first encryption factor and the second encryption factor according to the replacement period determined by the first determination module 1205;
[0156] The first replacement module 1207 is configured to replace the shared key of the first device and the second device according to the first encryption factor and the second encryption factor re-determined by the second determination module 1206.
[0157] In an embodiment, the device may further include:
[0158] The third determining module 1208 is configured to determine the data to be transmitted that the first device needs to send to the second device;
[0159] The data encryption module 1209 is configured to use a shared key to encrypt the data to be transmitted determined by the third determination module 1208, and send it to the second device through the first secure channel.
[0160] In an embodiment, the device may further include:
[0161] The second receiving module 1210 is configured to receive the response data generated by the second device after receiving the data to be transmitted through the first security pass, and the response data has been encrypted by the shared key;
[0162] The second decryption module 1211 is configured to use the shared key to decrypt the response data encrypted by the shared key to obtain the response data.
[0163] FIG. 14 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; as shown in FIG. 14, the key generation device may include: a third receiving module 1401, a third decryption Module 1402, second key generation module 1403. in:
[0164] The third receiving module 1401 is configured to receive the first key factor encrypted by the initial key from the first device through the second secure channel, where the initial key is the pre-key between the first device and the second device. Set key;
[0165] The third decryption module 1402 is configured to decrypt the first key factor encrypted by the initial key to obtain the first encryption factor;
[0166] The second key generation module 1403 is configured to generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device
[0167] FIG. 15 shows a schematic structural diagram of a key generation device according to another exemplary embodiment of the present invention; as shown in FIG. 15, on the basis of the above-mentioned embodiment shown in FIG. 14, the second key generation Module 1403 is specifically used for:
[0168] The first encryption key, the device identification of the first device, the first key factor, and the second key factor are sequentially connected to obtain a combined string;
[0169] Divide the combined character string into two sub-strings of equal length;
[0170] Perform hash operations on the two substrings to obtain two hash results;
[0171] Perform an exclusive OR operation on the two hash results to obtain the shared key of the first device and the second device.
[0172] In an embodiment, the device may further include:
[0173] The second encryption module 1404 is configured to use the initial key to encrypt the second key factor generated by the second device;
[0174] The first sending module 1405 is configured to send the second key factor encrypted by the initial key to the first device through the second secure channel.
[0175] In an embodiment, the device may further include:
[0176] The third determining module 1406 is used to determine the replacement period of the shared key of the first device and the second device;
[0177] The fourth determining module 1407 is configured to re-determine the first encryption factor and the second encryption factor according to the replacement period;
[0178] The second replacement module 1408 is configured to replace the shared key of the first device and the second device according to the re-determined first encryption factor and second encryption factor.
[0179] In an embodiment, the device may further include:
[0180] The fourth receiving module 1409 is configured to receive the data to be transmitted encrypted by the shared key from the first device through the second secure channel;
[0181] The fourth decryption module 1410 is configured to use a shared key to decrypt the data to be transmitted.
[0182] In an embodiment, the device may further include:
[0183] The response data generating module 1411 is configured to generate response data after receiving the data to be transmitted;
[0184] The third encryption module 1412 is configured to encrypt the response data by using a shared key;
[0185] The second sending module 1413 is configured to send the response data encrypted by the shared key to the first device through the second secure channel.
[0186] It can be seen from the above embodiment that the first key factor and the second key factor are both encrypted by the initial key during the forwarding process of the gateway device, and the initial key is preset between the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor; the first key factor and the second key factor are used to generate the shared key between the first device and the second device. The shared key to achieve the final negotiation is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key. Therefore, it can ensure more secure data transmission between the first device and the second device, and further reduce The risk of illegal interception of data during transmission.
[0187] After considering and practicing the invention disclosed herein, those skilled in the art will easily think of other embodiments of the present application. This application is intended to cover any variations, uses, or adaptive changes of this application. These variations, uses, or adaptive changes follow the general principles of this application and include common knowledge or customary technical means in the technical field that are not disclosed in this application. . And the embodiments are only regarded as exemplary, and the true scope and spirit of the application are pointed out by the following claims.
[0188] It should also be noted that the terms "including", "including" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, It also includes other elements not explicitly listed, or elements inherent to the process, method, commodity, or equipment. If there are no more restrictions, the element defined by the sentence "including a..." does not exclude the existence of other identical elements in the process, method, commodity, or equipment that includes the element.
[0189] The above descriptions are only preferred embodiments of the application, and are not intended to limit the application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the application shall include Within the scope of protection of this application.
CN 106487749 Β
1 sheet
Sheet 1
7 members in 4 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 201510531892 | China | A | |
| CN201510531892 | – | – | – |
| CN20151531892 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| WO2017032242A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN106487749A | China | A | |
| US2018241549A1 | United States of America | A1 | |
| JP2018529271A | Japan | A | |
| US10693634B2 | United States of America | B2 | |
| US2020313865A1 | United States of America | A1 | |
| CN106487749BThis record | China | B |
4 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Patent grantGrantedGR01 | GR01 | CN | |
| Requests to designate patent in hong kongDE | DE | HK | |
| Entry into force of request for substantive examinationSE01 | SE01 | CN | |
| PublicationC06 | C06 | CN |
Numbers
- Publication
- 106487749
- Publication, DOCDB
- 106487749
- Publication, EPODOC
- CN106487749B
- Application
- 105318922
- Application, DOCDB
- 201510531892
- Application, EPODOC
- CN201510531892
Titles2
- Chinese
- 密钥生成方法及装置
- English
- Key generation method and device
Classification
- CPC, 9
- H04L63/062
- H04L63/0478
- H04L9/085
- H04L63/06
- H04L2463/062
- H04L9/0822
- H04L9/0861
- H04L12/66
- H04L9/0866
- IPC, 1
- H04L29 06