Key generation method and apparatus using double encryption
Abstract
The present disclosure provides a key generation method and an apparatus. The key generation method encrypts the first key factor generated by the first device with the initial key and sends the encrypted first key factor to the second device via the first secure channel. The stage, where the initial key is the key preset for the first and second devices, the stage and the second key factor encrypted with the initial key via the first secure channel. In the receiving stage, the second key factor is generated by the second device, encrypted with the initial key to obtain the stage and the second key factor, and over the first secure channel. It comprises a step of decrypting the second key factor received in the process and a step of generating a shared key between the first device and the second device according to the first key factor and the second key factor. .. According to the disclosed embodiments, the gateway device is unable to obtain a shared key negotiated between the first device and the second device, ensuring the security of the data transmitted between them. It guarantees and also reduces the risk of data being illegally captured during transmission.

Term
Projected expiry 16 August 2036.
- Priority
- Filed
- Published
- Today
- Projected expiry
28 claims: 6 independent, 22 dependent
- 1第1のデバイスに適用されるキー生成方法であって、 前記第1のデバイスにより生成された第1のキーファクタを初期キーで暗号化し、暗号化された前記第1のキーファクタを第1のセキュアチャネルを介して第2のデバイスに送信する段階であって、前記初期キーは、前記第1のデバイスおよび前記第2のデバイスにプリセットされたキーである、段階と、 前記初期キーで暗号化された第2のキーファクタを、前記第1のセキュアチャネルを介して受信する段階であって、前記第2のキーファクタは、前記第2のデバイスにより生成される、段階と、 前記第2のキーファクタを取得すべく、前記初期キーで暗号化され、前記第1のセキュアチャネルを介して受信された前記第2のキーファクタを復号する段階と、 前記第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の共有キーを生成する段階と を備える方法。
- 2前記第1のデバイスにより生成された第1のキーファクタを初期キーで暗号化する段階は、 前記第1のデバイスが前記第2のデバイスとのキーネゴシエーション手順を開始する必要がある場合、擬似ランダム関数によって前記第1のキーファクタを生成する段階と、 第1の暗号化を受けた後の前記第1のキーファクタを取得すべく、前記第1のキーファクタを前記初期キーで暗号化する段階と、 第2の暗号化を受けた後の前記第1のキーファクタを取得すべく、前記第1の暗号化を受けた後の前記第1のキーファクタを、前記第1のセキュアチャネルの第1の暗号化キーで暗号化する段階と を含む、 請求項1に記載の方法。
- 3前記初期キーで暗号化され、前記第1のセキュアチャネルを介して受信された前記第2のキーファクタを復号する段階は、 第1の復号を受けた後の前記第2のキーファクタを取得すべく、二重暗号化された第2のキーファクタを第1の暗号化キーで復号する段階と、 前記第2のキーファクタを取得すべく、前記第1の復号を受けた後の前記第2のキーファクタを前記初期キーで復号する段階と を有する、 請求項1に記載の方法。
- 4前記第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の共有キーを生成する段階は、 前記第1のデバイスと前記第2のデバイスとの間で共有される前記初期キーと、前記第1のデバイスのデバイスアイデンティティとを決定する段階と、 前記初期キー、前記デバイスアイデンティティ、前記第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを生成する段階と を有する、 請求項1に記載の方法。
- 5前記初期キー、前記デバイスアイデンティティ、前記第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の共有キーを生成する前記段階は、 結合ストリングを取得すべく、前記初期キー、前記デバイスアイデンティティ、前記第1のキーファクタおよび前記第2のキーファクタを直列に連結する段階と、 前記結合ストリングを等しい長さの2つのサブストリングに分割する段階と、 2つのハッシュ結果を取得すべく、前記2つのサブストリングにそれぞれハッシュ演算を行う段階と、 前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを取得すべく、前記2つのハッシュ結果に対してビットごとにXOR演算を行う段階と を含む、 請求項4に記載の方法。
- 6前記第1のデバイスと前記第2のデバイスとの間の前記共有キーの交換周期を決定する段階と、 前記交換周期に従って、前記第1のキーファクタおよび前記第2のキーファクタを再計算する段階と、 前記再計算された第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを交換する段階と をさらに備える、 請求項1に記載の方法。
- 7前記第1のデバイスから前記第2のデバイスに伝送される必要があるデータを決定する段階と、 伝送対象の前記データを前記共有キーで暗号化し、暗号化された前記データを前記第1のセキュアチャネルを介して前記第2のデバイスに送信する段階と をさらに備える、 請求項1から6のいずれか一項に記載の方法。
- 8伝送対象の前記データを受信したときに第2のデバイスにより生成された応答データを、前記第1のセキュアチャネルを介して受信する段階であって、前記応答データは、前記共有キーで既に暗号化されている、段階と、 前記応答データを取得すべく、前記共有キーで暗号化された前記応答データを、前記共有キーを用いて復号する段階と をさらに備える、 請求項7に記載の方法。
- 9第2のデバイスに適用されるキー生成方法であって、 初期キーで暗号化された第1のキーファクタを、第2のセキュアチャネルを介して第1のデバイスから受信する段階であって、前記初期キーは、前記第1のデバイスと前記第2のデバイスとの間にプリセットされたキーである、段階と、 前記第1のキーファクタを取得すべく、前記初期キーで暗号化された前記第1のキーファクタを復号する段階と、 前記第1のキーファクタおよび前記第2のデバイスにより生成された第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の共有キーを生成する段階と を備える方法。
- 10前記第1のキーファクタおよび前記第2のデバイスにより生成された第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の共有キーを生成する前記段階は、 結合ストリングを取得すべく、前記初期キー、前記第1のデバイスのデバイスアイデンティティ、前記第1のキーファクタおよび前記第2のキーファクタを直列に連結する段階と、 前記結合ストリングを等しい長さの2つのサブストリングに分割する段階と、 2つのハッシュ結果を取得すべく、前記2つのサブストリングにそれぞれハッシュ演算を行う段階と、 前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを取得すべく、前記2つのハッシュ結果に対してビットごとにXOR演算を行う段階と を有する、 請求項9に記載の方法。
- 11前記第2のデバイスにより生成された前記第2のキーファクタを前記初期キーで暗号化する段階と、 前記初期キーで暗号化された前記第2のキーファクタを、前記第2のセキュアチャネルを介して前記第1のデバイスに送信する段階と をさらに備える、 請求項9に記載の方法。
- 12前記第1のデバイスと前記第2のデバイスとの間の前記共有キーの交換周期を決定する段階と、 前記交換周期に従って、前記第1のキーファクタおよび前記第2のキーファクタを再計算する段階と、 前記再計算された第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを交換する段階と をさらに備える、 請求項9に記載の方法。
- 13前記共有キーで暗号化されている伝送対象のデータを、第2のセキュアチャネルを介して第1のデバイスから受信する段階と、 前記伝送対象のデータを前記共有キーで復号する段階と をさらに備える、 請求項9から12のいずれか一項に記載の方法。
- 14前記伝送対象のデータを受信した後に応答データを生成する段階と、 前記応答データを前記共有キーで暗号化する段階と、 前記共有キーで暗号化された前記応答データを、前記第2のセキュアチャネルを介して前記第1のデバイスに送信する段階と をさらに有する、 請求項13に記載の方法。
- 15第1のデバイスに適用されるキー生成装置であって、 前記第1のデバイスにより生成された第1のキーファクタを初期キーで暗号化し、暗号化された前記第1のキーファクタを第1のセキュアチャネルを介して第2のデバイスに送信する第1の暗号化モジュールであって、前記初期キーは、前記第1のデバイスおよび前記第2のデバイスにプリセットされたキーである、第1の暗号化モジュールと、 前記初期キーで暗号化された第2のキーファクタを前記第1のセキュアチャネルを介して受信する第1の受信モジュールであって、前記第2のキーファクタは、前記第2のデバイスにより生成される、第1の受信モジュールと、 前記第2のキーファクタを取得すべく、前記初期キーで暗号化され、前記第1のセキュアチャネルを介して前記第1の受信モジュールにより受信された前記第2のキーファクタを復号する第1の復号モジュールと、 前記第1のキーファクタおよび前記第1の復号モジュールにより復号された前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の共有キーを生成する第1のキー生成モジュールと を備える装置。
- 16前記第1の暗号化モジュールは、 前記第1のデバイスが、前記第2のデバイスとのキーネゴシエーション手順を開始する必要がある場合、擬似ランダム関数によって前記第1のキーファクタを生成する第1のファクタ生成部と、 第1の暗号化を受けた後の前記第1のキーファクタを取得すべく、前記第1のファクタ生成部により生成された前記第1のキーファクタを前記初期キーで暗号化する第1の暗号化部と、 第2の暗号化を受けた後の前記第1のキーファクタを取得すべく、前記第1の暗号化部による前記第1の暗号化を受けた後の前記第1のキーファクタを、前記第1のセキュアチャネルの第1の暗号化キーで暗号化する第2の暗号化部と を有する、 請求項15に記載の装置。
- 17前記第1の復号モジュールは、 第1の復号を受けた後の前記第2のキーファクタを取得すべく、二重暗号化された第2のキーファクタを第1の暗号化キーで復号する第1の復号部と、 前記第2のキーファクタを取得すべく、前記第1の復号部による前記第1の復号を受けた後の前記第2のキーファクタを前記初期キーで復号する第2の暗号化部と を有する、 請求項15に記載の装置。
- 18前記第1のキー生成モジュールは、 前記第1のデバイスと前記第2のデバイスとの間で共有される初期キーと、前記第1のデバイスのデバイスアイデンティティとを決定する第1の決定部と、 前記初期キー、前記第1の決定部により決定された前記デバイスアイデンティティ、前記第1のキーファクタ、および前記第1の復号モジュールにより取得された前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを生成する第1のファクタ生成部と を有する、 請求項15に記載の装置。
- 19前記第1のファクタ生成部はさらに、 結合ストリングを取得すべく、前記初期キー、前記デバイスアイデンティティ、前記第1のキーファクタおよび前記第2のキーファクタを直列に連結し、 前記結合ストリングを等しい長さの2つのサブストリングに分割し、 2つのハッシュ結果を取得すべく、前記2つのサブストリングにそれぞれハッシュ演算を行い、 前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを取得すべく、前記2つのハッシュ結果に対してビットごとにXOR演算を行う、 請求項18に記載の装置。
- 20前記第1のデバイスと前記第2のデバイスとの間の前記共有キーの交換周期を決定する第1の決定モジュールと、 前記第1の決定モジュールにより決定された前記交換周期に従って、前記第1のキーファクタおよび前記第2のキーファクタを再計算する第2の決定モジュールと、 前記第2の決定モジュールにより再計算された前記第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを交換する第1の交換モジュールと をさらに備える、 請求項15に記載の装置。
- 21前記第1のデバイスから前記第2のデバイスに伝送される必要があるデータを決定する第3の決定モジュールと、 前記第3の決定モジュールにより決定された伝送対象の前記データを前記共有キーで暗号化し、暗号化された前記データを前記第1のセキュアチャネルを介して前記第2のデバイスに送信するデータ暗号化モジュールと をさらに備える、 請求項15から20のいずれか一項に記載の装置。
- 22伝送対象の前記データを受信したときに前記第2のデバイスにより生成された応答データを、前記第1のセキュアチャネルを介して受信する第2の受信モジュールであって、前記応答データは、前記共有キーで既に暗号化されている、第2の受信モジュールと、 前記応答データを取得すべく、前記共有キーで暗号化された前記応答データを、前記共有キーを用いて復号する第2の復号モジュールと をさらに有する、 請求項21に記載の装置。
- 23第2のデバイスに適用されるキー生成装置であって、 初期キーで暗号化された第1のキーファクタを、第2のセキュアチャネルを介して第1のデバイスから受信する第3の受信モジュールであって、前記初期キーは、前記第1のデバイスと前記第2のデバイスとの間にプリセットされたキーである、第3の受信モジュールと、 前記第1のキーファクタを取得すべく、前記初期キーで暗号化された前記第1のキーファクタを復号する第3の復号モジュールと、 前記第1のキーファクタおよび前記第2のデバイスにより生成された第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の共有キーを生成する第2のキー生成モジュールと を備える装置。
- 24前記第2のキー生成モジュールはさらに、 結合ストリングを取得すべく、前記初期キー、前記第1のデバイスのデバイスアイデンティティ、前記第1のキーファクタおよび前記第2のキーファクタを直列に連結し、 前記結合ストリングを等しい長さの2つのサブストリングに分割し、 2つのハッシュ結果を取得すべく、前記2つのサブストリングにそれぞれハッシュ演算を行い、 前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを取得すべく、前記2つのハッシュ結果に対してビットごとにXOR演算を行う、 請求項23に記載の装置。
- 25前記第2のデバイスにより生成された前記第2のキーファクタを前記初期キーで暗号化する第2の暗号化モジュールと、 前記初期キーで暗号化された前記第2のキーファクタを、前記第2のセキュアチャネルを介して前記第1のデバイスに送信する第1の送信モジュールと をさらに備える、 請求項24に記載の装置。
- 26前記第1のデバイスと前記第2のデバイスとの間の前記共有キーの交換周期を決定する第3の決定モジュールと、 前記交換周期に従って、前記第1のキーファクタおよび前記第2のキーファクタを再計算する第4の決定モジュールと、 前記再計算された第1のキーファクタおよび前記第2のキーファクタに従って、前記第1のデバイスと前記第2のデバイスとの間の前記共有キーを交換する第2の交換モジュールと をさらに備える、 請求項25に記載の装置。
- 27前記共有キーで暗号化されている伝送対象のデータを、前記第2のセキュアチャネルを介して前記第1のデバイスから受信する第4の受信モジュールと、 伝送対象の前記データを前記共有キーで復号する第4の復号モジュールと をさらに備える、 請求項23から26のいずれか一項に記載の装置。
- 28伝送対象の前記データを受信した後に応答データを生成する応答データ生成モジュールと、 前記応答データを前記共有キーで暗号化する第3の暗号化モジュールと、 前記共有キーで暗号化された前記応答データを、前記第2のセキュアチャネルを介して前記第1のデバイスに送信する第2の送信モジュールと をさらに備える、 請求項27に記載の装置。
Independent claims28
145 paragraphs, as filed
[Cross-reference of related applications] This disclosure is in accordance with Chinese Patent Application No. 201510531892.2, filed August 26, 2015, entitled "Methods and Devices for Key Generation," and August 16, 2016, entitled "Key Generation Methods and Devices." It claims the priority benefit of PCT application No. PCT / CN16 / 95522 filed on the same day, both of which are incorporated herein by reference in their entirety.
The disclosed embodiments relate to the field of network security technology, in particular to key generation methods and devices.
To ensure secure data transmission between the terminal device and the gateway device, and between the gateway device and the public network server, each secure transmission channel is between the terminal device and the gateway device, and between the gateway device and the public. Usually established with a network server. The gateway device transfers data from one secure channel to another to perform the data transfer. However, during data transfer, the gateway device decrypts the data encrypted by the terminal device (with the key shared with the terminal device) before transferring the data to the server, and then with the key shared with the server. The data needs to be encrypted. Therefore, the gateway device has a risk of leaking data information.
In view of this flaw, the present disclosure is a novel technology that makes it impossible for gateway devices to obtain a shared key between two devices, thereby reducing the risk of illegally capturing data during network transmission. Provide a solution.
To achieve the aforementioned goals, the present disclosure provides the following technical solutions.
According to a first aspect of the present disclosure, a key generation method applied to a first device is provided, wherein the method is: The stage where the first key factor generated by the first device is encrypted with the initial key and the encrypted first key factor is transmitted to the second device via the first secure channel. The initial key is a preset key for the first device and the second device, step and The second key factor, encrypted with the initial key, is received over the first secure channel, and the second key factor is generated by the second device. In order to obtain the second key factor, the stage of decrypting the second key factor encrypted with the initial key and received via the first secure channel, The stage of generating a shared key between the first device and the second device according to the first key factor and the second key factor To be equipped.
According to a second aspect of the present disclosure, a key generation method applied to a second device is provided, wherein the method is: The first key factor encrypted with the initial key is received from the first device via the second secure channel, and the initial key is between the first device and the second device. The preset keys to, stage and In order to obtain the first key factor, the stage of decrypting the first key factor encrypted with the initial key, and The stage of generating a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device. To be equipped.
According to a third aspect of the present disclosure, a key generator applied to the first device is provided, the device. It is configured to encrypt the first key factor generated by the first device with the initial key and send the encrypted first key factor to the second device over the first secure channel. The first encryption module, which is the first encryption module and the initial key is the key preset for the first device and the second device, A first receiving module configured to receive a second key factor encrypted with the initial key over the first secure channel, the second key factor being generated by the second device. The first receiving module and A first configured to obtain a second key factor, encrypted with the initial key and decrypted from the second key factor received by the first receiving module over the first secure channel. With decryption module To be equipped. The first key generation module will now generate a shared key between the first device and the second device according to the first key factor and the second key factor decrypted by the first decryption module. It is composed.
According to a fourth aspect of the present disclosure, a key generator applied to a second device is provided, the device. A third receiving module configured to receive the first key factor encrypted with the initial key from the first device over the second secure channel, where the initial key is the first. A third receiver module, which is a preset key between the device and the second device, With a third decryption module configured to decrypt the first key factor encrypted with the initial key to get the first key factor To be equipped. The second key generation module is configured to generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device. Will be done.
As can be seen from the technical solution described above, the first and second key factors are both encrypted with the initial key when transferred by the gateway device. The initial keys are the keys preset for the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor, and the shared key between the first device and the second device is the first key factor and the second key factor. Generated via the key factor of. Therefore, the finally negotiated shared key is only known to the first and second devices. The gateway device also cannot obtain the negotiated shared key, thus ensuring secure data transmission between the first device and the second device, and the data is illegally captured during transmission. Risk is reduced.
<figref num="1">It is a flow chart which shows the key generation method by some embodiment of this disclosure.</figref>
<figref num="2">It is a flow chart which shows the key generation method by some embodiment of this disclosure.</figref>
<figref num="3">It is a flow chart which shows the key generation method by some embodiment of this disclosure.</figref>
<figref num="4">It is a flow chart which shows the key generation method by some embodiment of this disclosure.</figref>
<figref num="5">It is a flow chart which shows the key generation method by some embodiment of this disclosure.</figref>
<figref num="6">It is a flow chart which shows the key generation method by some embodiment of this disclosure.</figref>
<figref num="7">It is a flow chart which shows the key generation method by some embodiment of this disclosure.</figref>
<figref num="8">FIG. 5 is a swimlane diagram showing key negotiation between a terminal device and a server according to some embodiments of the present disclosure.</figref>
<figref num="9">FIG. 5 is a swimlane diagram showing data transmission between a terminal device and a server according to some embodiments of the present disclosure.</figref>
<figref num="10">It is a block diagram which shows the terminal device by some embodiments of this disclosure.</figref>
<figref num="11">It is a block diagram which shows the server by some embodiment of this disclosure.</figref>
<figref num="12">It is a block diagram which shows the key generation apparatus by some embodiments of this disclosure.</figref>
<figref num="13">It is a block diagram which shows the key generation apparatus by some embodiments of this disclosure.</figref>
<figref num="14">It is a block diagram which shows the key generation apparatus by some embodiments of this disclosure.</figref>
<figref num="15">It is a block diagram which shows the key generation apparatus by some embodiments of this disclosure.</figref>
Exemplary embodiments are described in detail herein, examples of which are shown in the drawings. The following description refers to drawings and, unless otherwise indicated, the same numbers in different drawings refer to the same or similar elements. The practices described in the exemplary embodiments below do not represent all practices consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the disclosure described in the appended claims.
The terminology used in this disclosure is for illustration purposes only and is not intended to limit this disclosure. The singular forms "a (1)", "an (1)" and "the" used in this disclosure are plural unless the context expressly means something else. Is also intended to include. It should also be understood that the terms "and / or" as used herein refer to and include any or all possible combinations of one or more of the relevant enumeration items.
Although various types of information may be explained using terms such as, first, second and third of the present disclosure, it is not that such information should be limited by these terms. Should be understood. These terms are only used to distinguish one type of information from another. Without departing from the scope of the present disclosure, for example, the first information may be referred to as the second information, and similarly, the second information may be referred to as the first information. Depending on the context, the word "if" as used herein is "when ..." or "upon ..." or "in response to determining ..." Can be interpreted to mean "(depending on the decision)".
The following embodiments are provided to further illustrate the disclosure.
According to embodiments of the present disclosure, the first and second key factors are both encrypted with the initial key when transferred by the gateway device. The initial keys are the keys preset for the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor. A shared key between the first device and the second device is generated via the first and second key factors. Therefore, the finally negotiated shared key is only known to the first and second devices. The gateway device is still unable to obtain the negotiated shared key, thus ensuring secure data transmission between the first device and the second device, and also illegally capturing data in transit. The risk of being affected is reduced.
FIG. 1 is a flow chart showing a key generation method according to some embodiments of the present disclosure. In the illustrated embodiment, the first device can be a terminal device and the second device can be a server. Alternatively, the first device can be a server and the second device can be a terminal device. The illustrated embodiments are exemplified by being applied to terminal devices by way of example. As shown in FIG. 1, the key generation method includes the following steps.
Step 101: Encrypt the first key factor generated by the first device with the initial key and send the encrypted first key factor to the second device over the first secure channel. The initial keys are the keys preset for the first device and the second device.
Step 102: Receive a second key factor encrypted with the initial key over the first secure channel, and the second key factor is generated by the second device.
Step 103: Decrypt the second key factor encrypted with the initial key and received over the first secure channel to obtain the second key factor.
Step 104: Generate a shared key between the first device and the second device according to the first and second key factors.
With respect to step 101, in one embodiment, the initial key K<sub>basic</sub>Can be issued to the first device by the second device before the first device is used. Initial key K<sub>basic</sub>Can be issued to the device by writing the initial key to the hardware of the first device. In one embodiment, relevant information is transferred between the first device and the second device by the gateway device, and the first secure channel is through negotiation between the first device and the gateway device. Can be established. The relevant information is transmitted over the first secure channel. A second secure channel can be established through negotiation between the server and the gateway device. The relevant information is transmitted over the second secure channel. Those skilled in the art should understand that the process of establishing a first secure channel and a second secure channel can be performed using existing security protocols. For example, a secure socket layer (SSL for short) or transport layer security (TLS for short) key negotiation mechanism can be used for this purpose.
In one embodiment, if the first device needs to initiate a key negotiation procedure with the second device, the first key factor is generated by a pseudo-random function. The first key factor is encrypted with the initial key in order to obtain the first key factor after receiving the first encryption. The first key factor after receiving the first encryption is the first encryption key of the first secure channel in order to obtain the first key factor after receiving the second encryption. Encrypted using. The first key factor is double encrypted so that the first key factor is not known to the gateway device, avoiding the risk of the first key factor being illegally captured by the gateway device.
In step 103, the double-encrypted second key factor is decrypted with the first encryption key in order to obtain the second key factor after receiving the first decryption. The second key factor after receiving the first decryption is decrypted with the initial key in order to obtain the second key factor. Since the second key factor is already double-encrypted on the second device, the second key factor is not known to the gateway device and the second key factor is illegal on the gateway device side. The risk of being captured is avoided.
In step 104, the description of an embodiment described herein with respect to a method of generating a shared key between a first device and a second device according to a first key factor and a second key factor. Can be referenced. Although step 104 is not described in detail herein, the description herein is incorporated by reference in its entirety.
As can be seen from the above description, the first key factor and the second key factor are both encrypted with the initial key when transferred by the gateway device. The initial keys are the keys preset for the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor. The shared key between the first device and the second device is generated via the first key factor and the second key factor. Therefore, the finally negotiated shared key is only known to the first and second devices. The gateway device also cannot obtain the negotiated shared key, thus ensuring secure data transmission between the first device and the second device, and the data is illegally captured during transmission. Risk is reduced.
FIG. 2 is a flow chart showing a key generation method according to some embodiments of the present disclosure. This embodiment generates a shared key between the first device and the second device via the first and second key factors of step 104 in the embodiment shown in FIG. 1 as an example. It is illustrated by using the method of. As shown in FIG. 2, the key generation method includes the following steps.
Step 201: Determine the initial key shared between the first and second devices and the device identity of the first device.
Step 202: Concatenate the initial key, device identity, first key factor and second key factor in series to get the join string.
Step 203: Split the join string into two substrings of equal length.
Step 204: Perform a hash operation on each of the two substrings to get the two hash results.
Step 205: Perform a bit-by-bit exclusive OR (XOR) operation on the two hash results to obtain the shared key between the first device and the second device.
After the first device obtains the second key factor through step 103 in the embodiment shown in FIG. 1, the first device has a first key factor p and a second key factor q. .. The first device may use the first key factor p and the second key factor q as inputs, key K<sub>AC</sub>A shared key generate algorithm (Key Generate) can be used to obtain. The key generation algorithm is as follows. K<sub>AC</sub>= KeyGenerate (K<sub>basic</sub>, SharedKey, p, q)
Where K<sub>basic</sub>Is the initial key and SharedKey is the device identity of the first device. The device identity can be the device serial number or MAC address of the first device, or a combination of both. It would be sufficient if the second device could distinguish the first device from other devices through its device identity.
In addition, in the process of generating a shared key with the KeyGenerate function, the initial key K<sub>basic</sub>, SharedKey, p and q can be concatenated in series to get a join string. Shared key K<sub>AC</sub>Is generated from the join string using the function KeyGenerate.
In one embodiment, the process performed by the function KeyGenerate divides the input join string into two substrings of equal length (1 is the end of the join string if the join string is odd in length). Is added to the bits of), followed by a separate hash operation (eg MD5) on the two substrings, and a bit-by-bit XOR operation on the two acquired calculation results. Can be prepared. The obtained result is the shared key K<sub>AC</sub>Is.
An exemplary description is given by using MD5 as an example. MD5 can convert any length of input into a 128-bit length result, so shared key K<sub>AC</sub>The length of is 128 bits, which reduces the complexity of shared key calculation. Shared key K<sub>AC</sub>Since the calculation of is using MD5, the computational burden can be tolerated by the first device with limited computational power.
In this embodiment, the shared key K<sub>AC</sub>Is generated through the first key factor, the second key factor, the initial key and the device identity of the first device, thereby sharing the key K.<sub>AC</sub>Is securely negotiated and shared between the first device and the second device. Shared key K<sub>AC</sub>Is unknown to the gateway device acting as an intermediate node, so the first device has a shared key K to encrypt the data sent to the second device.<sub>AC</sub>Is guaranteed to be available and the security of data during network transmission is guaranteed.
FIG. 3 is a flow chart showing a key generation method according to some embodiments of the present disclosure. Based on the aforementioned embodiment, as shown in FIG. 3, the key generation method includes the following steps.
Step 301: Determine the shared key exchange cycle between the first device and the second device.
Step 302: Recalculate the first and second key factors according to the exchange cycle.
Step 303: Swap the shared key between the first device and the second device according to the recalculated first and second key factors.
In one embodiment, the first device and the second device are the shared key K.<sub>AC</sub>The exchange cycle of can be specified. Shared key K<sub>AC</sub>However, after being used for the time corresponding to the exchange cycle, the shared key K<sub>AC</sub>The procedure to generate is started again between the first device and the second device, thereby sharing key K<sub>AC</sub>Security and data security during network transmission are further guaranteed, shared key K<sub>AC</sub>Is even less likely to be decrypted.
FIG. 4 is a flow chart showing a key generation method according to some embodiments of the present disclosure. After the shared key is generated in the embodiment shown in FIG. 1, the data to be transmitted by the first device can be encrypted with the shared key and transmitted to the second device. As shown in FIG. 4, the process of encrypting and transmitting the data to be transmitted includes the following steps.
Step 401: Determine the data that needs to be transmitted from the first device to the second device.
Step 402: Encrypt the data to be transmitted with the shared key and send the encrypted data to the second device via the first secure channel.
Step 403: When the data to be transmitted is received, the response data generated by the second device is received via the first secure channel. The response data is already encrypted with the shared key.
Step 404: Decrypt the response data encrypted with the shared key with the shared key to get the response data.
In step 401, the data to be transmitted may be the Internet of Things data acquired by the sensor on the first device.
For a related description of the first secure channel in steps 402 and 403, refer to the related description of the embodiment shown in FIG. 1, which is not described in detail here again, but is incorporated by reference.
In step 404, when the shared key encrypted response data is received over the first secure channel, the shared key encrypted response data is the first encryption of the first secure channel. It can be decrypted first with the key. The response data is then decrypted again with the shared key to get the original response data.
In this embodiment, the data to be transmitted is encrypted with a shared key when transferred by the gateway device, and the shared key is a key jointly negotiated between the first device and the second device. , The gateway device will not know the shared key, thus ensuring that the data to be transmitted will be transmitted more securely between the first device and the second device, and the data will be transmitted during network transmission. The risk of being illegally captured is further reduced.
FIG. 5 is a flow chart showing a key generation method according to some embodiments of the present disclosure. In this embodiment, the first device can be a terminal device and the second device can be a server. This embodiment may be applied to a second device. As shown in FIG. 5, the key generation method includes the following steps.
Step 501: The first key factor encrypted with the initial key is received from the first device over the second secure channel and the initial key is between the first device and the second device. These are preset keys.
Step 502: Decrypt the first key factor encrypted with the initial key to get the first key factor.
Step 503: Generate a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device.
Regarding the related description of the second secure channel in step 501, the related description of the embodiment shown in FIG. 1 may be referred to, which is not described in detail again herein, but is incorporated by reference.
In step 502, after the first key factor encrypted with the initial key is received over the second secure channel, the first key factor encrypted with the initial key is the second secure channel. It can be decrypted first with a second encryption key. The first key factor is then decrypted a second time with the initial key to get the original first key factor.
The description of the embodiment shown in FIG. 2 may be referenced with respect to how to generate a shared key between the first device and the second device according to the first and second key factors in step 503. , That is not described in detail again herein, but is incorporated by reference.
As can be seen from the above description, the first key factor and the second key factor are both encrypted with the initial key when transferred by the gateway device. The initial key is a key preset for the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor, and the shared key between the first device and the second device is the first key factor and the second key factor. Generated via the key factor of. Therefore, the finally negotiated shared key is only known to the first and second devices. The gateway device is still unable to obtain the negotiated shared key, thus ensuring secure data transmission between the first device and the second device, and also illegally capturing data in transit. The risk of being affected is reduced.
FIG. 6 is a flow chart showing a key generation method according to some embodiments of the present disclosure. As shown in FIG. 6, the key generation method includes the following steps.
Step 601: Encrypt the second key factor generated by the second device with the initial key.
Step 602: Send the second key factor encrypted with the initial key to the first device over the second secure channel.
In this embodiment, the second key factor encrypted with the initial key is encrypted with the second encryption key a second time on the second secure channel. Therefore, when the second key factor is transferred by the gateway device during the process of sending the second key factor to the first device, it is not known to the gateway device and the second key factor is on the gateway device side. Avoids the risk of being illegally captured in.
FIG. 7 is a flow chart showing a key generation method according to some embodiments of the present disclosure. As shown in FIG. 7, the key generation method includes the following steps.
Step 701: Receive the data to be transmitted encrypted with the shared key from the first device via the second secure channel.
Step 702: Decrypt the data to be transmitted with the shared key.
Step 703: Generate response data after receiving the data to be transmitted.
Step 704: Encrypt the response data with a shared key.
Step 705: Send the shared key encrypted response data to the first device over the second secure channel.
Regarding the related description of the second secure channel in step 701, the related description of the embodiment shown in FIG. 1 may be referred to, which is not described in detail again herein, but is incorporated by reference.
In step 704, after the data to be transmitted is received from the first device via the second secure channel, the data to be transmitted is decrypted with a shared key to obtain the original data. If the response needs to be made to the first device, the response data encrypted with the shared key can be encrypted first with the second encryption key of the second secure channel, thereby. The gateway device will not be able to obtain the original response data in the process of transferring the response data.
In this embodiment, when the data to be transmitted is transferred by the gateway device, it is encrypted with the shared key, and the shared key is a key jointly negotiated between the first device and the second device. , The gateway device will not know the shared key, thus ensuring that the data to be transmitted will be transmitted more securely between the first device and the second device, and the data will be transmitted during network transmission. The risk of being illegally captured is further reduced.
According to the above embodiment, the shared key can be generated locally on the first device and the second device via a key generation algorithm based on the initial keys preset in the first device and the second device. Finally, the data to be transmitted is encrypted with a shared key, which prevents the gateway device from examining the original data when transferring the data to the network, thereby making it secure. Achieve the purpose of data transmission.
FIG. 8 is a swimlane diagram showing key negotiation between a terminal device and a server according to some embodiments of the present disclosure. An exemplary description is given by using, for example, a first device that is a terminal device and a second device that is a server. Before the terminal device accesses the network, the server has an initial key (K).<sub>basic</sub>) Must be issued to the terminal device in advance, and the initial key (K)<sub>basic</sub>) Can be issued to the terminal device via hardware writing or the like. As shown in FIG. 8, the key negotiation between the terminal device and the server involves the following steps.
Step 801: The terminal device has the first encryption key (K) on the first secure channel.<sub>AB</sub>) Is negotiated with the gateway device to establish a first secure channel between the terminal device and the gateway device. A related description of an existing technique (eg, SSL) described above can be referred to as a method of establishing a first secure channel.
Step 802: The gateway device has a second encryption key (K) for the server and the second secure channel.<sub>BC</sub>) To establish a second secure channel. Similar to step 801 above, the relevant description of the existing technology described above for the process of establishing a second secure channel can be referenced, which can also be used for SSL or TLS key negotiation mechanisms. .. One of ordinary skill in the art should understand that steps 801 and 802 are interchangeable in order. The execution sequence can be set according to the actual execution needs.
Step 803: The terminal device prepares to begin the key negotiation procedure with the server. The terminal device generates a first key factor (p), which is used to generate a shared key between the terminal device and the server. On the other hand, the first key factor is K<sub>basic</sub>Initial key (K) to get (p)<sub>basic</sub>) Encrypted, then K<sub>basic</sub>(p) is K<sub>AB</sub>[K<sub>basic</sub>(p)], the first encryption key K<sub>AB</sub>It is encrypted with.
Step 804: The terminal device has a double-encrypted first key factor K<sub>AB</sub>[K<sub>basic</sub>(p)] is sent to the gateway device via the first secure channel.
Step 805: Double-encrypted first key factor K<sub>AB</sub>[K<sub>basic</sub>(p)] After receiving the gateway device, K<sub>basic</sub>First encryption key K on the first secure channel to obtain (p)<sub>AB</sub>Double-encrypted first key factor K<sub>AB</sub>[K<sub>basic</sub>(p)] is decrypted, and then the double-encrypted K<sub>BC</sub>[K<sub>basic</sub>(p)], the second encryption key K of the second secure channel<sub>BC</sub>In K<sub>basic</sub>Encrypt (p).
Step 806: First key factor K double-encrypted with initial key and second encryption key<sub>BC</sub>[K<sub>basic</sub>(p)] is sent to the server via the second secure channel.
Step 807: After receiving the double-encrypted first key factor, the server K<sub>basic</sub>Second encryption key K on the second secure channel to obtain (p)<sub>BC</sub>Decrypt the first key factor that was double encrypted with, and then get the first key factor p, the initial key K<sub>basic</sub>In K<sub>basic</sub>Decrypt (p).
Step 808: The server generates a second key factor (q) by a pseudo-random function, where the second key factor q is the shared key K.<sub>AC</sub>Will be used with the first key factor p as a parameter to generate.
Step 809: The server is K<sub>basic</sub>Initial key K to get (q)<sub>basic</sub>Encrypt the second key factor q with, then K<sub>BC</sub>[K<sub>basic</sub>(q)], the second encryption key K<sub>BC</sub>In K<sub>basic</sub>Encrypt (q).
Step 810: The server has a double-encrypted second key factor K<sub>BC</sub>[K<sub>basic</sub>(q)] is sent to the gateway device via the second secure channel.
Step 811: Double-encrypted second key factor K<sub>BC</sub>[K<sub>basic</sub>After receiving (q)], the gateway device is K<sub>basic</sub>Second encryption key K on the second secure channel to get (q)<sub>BC</sub>Decrypt the second key factor that was double encrypted with, and then K<sub>AB</sub>[K<sub>basic</sub>(q)], the first encryption key K of the first secure channel<sub>AB</sub>In K<sub>basic</sub>Encrypt (q) and then send the double-encrypted second key factor to the terminal device over the first secure channel.
Step 812: After receiving the double-encrypted second key factor, the terminal device K<sub>basic</sub>First encryption key K on the first secure channel to get (q)<sub>AB</sub>Decrypt the second key factor double-encrypted with, and then get the second key factor q a second time with the initial key K<sub>basic</sub>K after receiving the first decryption in<sub>basic</sub>Decrypt (q).
Step 813: Both the terminal device and the server share the first key factor p and the second key factor q. Both the terminal device and the server have a shared key K between the terminal device and the server.<sub>AC</sub>The first key factor and the second key factor are used as inputs and the key generation algorithm is used to obtain. For a detailed description of the key generation algorithm, a related description of the embodiments shown in FIG. 2 may be referred to, which is not described in detail again herein, but is incorporated by reference.
In this embodiment, the shared key K<sub>AC</sub>Is thus securely negotiated and shared between the terminal device and the public network server. Therefore, the shared key is not known to the gateway device acting as an intermediate node, after which the terminal device uses the shared key to encrypt the Internet of Things data to be sent to the public network server. This can ensure the security of data transmission.
To further ensure the security of the shared key and data transmission, the terminal device should use the shared key K to further reduce the possibility of the shared key being cracked.<sub>AC</sub>The key negotiation procedure with the server for exchanging can be performed periodically.
FIG. 9 is a swimlane diagram showing data transmission between a terminal device and a server according to some embodiments of the present disclosure. If the terminal device needs to send Internet of Things data (data) to the server after the shared key has been generated through the embodiment shown in FIG. 8 , the data transmission method is shown in FIG. Includes the following steps:
Step 901: Ciphertext K<sub>AC</sub>Shared key K to get (data)<sub>AC</sub>Performs the first encryption on the Internet of Things data in, and then ciphertext K<sub>AB</sub>[K<sub>AC</sub>(data)], the first encryption key K of the first secure channel<sub>AB</sub>Perform the second encryption with.
Step 902: The terminal device has ciphertext K<sub>AB</sub>[K<sub>AC</sub>(data)] is sent to the gateway device via the first secure channel.
Step 903: Ciphertext K<sub>AB</sub>[K<sub>AC</sub>After receiving (data)], the gateway device is K<sub>AC</sub>Ciphertext K to get (data)<sub>AB</sub>[K<sub>AC</sub>(data)] is the first encryption key K<sub>AB</sub>Decrypt with, then ciphertext K<sub>BC</sub>[K<sub>AC</sub>(data)] to get the second encryption key K<sub>BC</sub>In K<sub>AC</sub>Encrypt (data).
Step 904: The gateway device has ciphertext K<sub>BC</sub>[K<sub>AC</sub>(data)] is sent to the server via the second secure channel.
Step 905: Double-encrypted ciphertext K<sub>BC</sub>[K<sub>AC</sub>After receiving (data)], the server K<sub>AC</sub>Second encryption key K to get (data)<sub>BC</sub>Ciphertext K<sub>BC</sub>[K<sub>AC</sub>(data)] is decrypted and then the shared key K to retrieve the original Internet of Things data<sub>AC</sub>In K<sub>AC</sub>Decrypt (data).
Step 906: After retrieving the original Internet of Things data, the server generates response data (res) and ciphertext K<sub>AC</sub>Share the response data with key K to get (res)<sub>AC</sub>Encrypt with, then K<sub>BC</sub>[K<sub>AC</sub>(res)] to get the second encryption key K<sub>BC</sub>Perform the second encryption with.
Step 907: The server has double-encrypted ciphertext K<sub>BC</sub>[K<sub>AC</sub>(res)] is sent to the gateway device via the second secure channel.
Step 908: Double-encrypted ciphertext K<sub>BC</sub>[K<sub>AC</sub>After receiving (res)], the gateway device K<sub>AC</sub>Ciphertext K to get (res)<sub>BC</sub>[K<sub>AC</sub>(res)] to the second encryption key K<sub>BC</sub>Decrypt with, then ciphertext K<sub>AB</sub>[K<sub>AC</sub>(res)], the first encryption key K<sub>AB</sub>In K<sub>AC</sub>Encrypt (res).
Step 909: The gateway device has a double-encrypted ciphertext K<sub>AB</sub>[K<sub>AC</sub>(res)] is sent to the terminal device via the first secure channel.
Step 910: Double-encrypted ciphertext K<sub>AB</sub>[K<sub>AC</sub>After receiving (res)], the terminal device is K<sub>AC</sub>First encryption key K to get (res)<sub>AB</sub>Ciphertext K<sub>AB</sub>[K<sub>AC</sub>(res)] is decrypted and then the shared key K to get the original response data (res)<sub>AC</sub>In K<sub>AC</sub>Decrypt (res).
This embodiment allows mutual domain key negotiation and sharing between the terminal device and the server via the gateway device as an intermediate node. The shared key is unknown to the gateway device, thereby ensuring end-to-end secure transmission of Internet of Things data between the terminal device and the server. In addition, secure data transmission between the terminal device and the gateway device and secure data transmission between the gateway device and the public network server are guaranteed. The transfer of data at the gateway device on the transmission path is also protected for security. Even if the gateway device is illegally accessed, the internet of things data transferred through the gateway device is still protected by shared key encryption, which illegally captures the internet of things data. Is avoided.
According to the key generation method described above, the present disclosure further provides a block diagram showing a terminal device according to an exemplary embodiment of the disclosure shown in FIG.
FIG. 10 is a block diagram showing a terminal device 1000 according to some embodiments of the present disclosure. At the hardware level, device 1000 includes processor 1002, internal bus 1004, network interface 1006, memory 1008 and non-volatile storage 1010, which can certainly also include hardware required by other services. Processor 1002 reads the corresponding computer program 1010A from the non-volatile storage 1010 into memory 1008 to form the key generator 1008A at the logical level, and then executes the computer program. The disclosure certainly does not exclude, in addition to, the implementation of the software, for example, other implementations that use logical devices or combinations of software and hardware. That is, the execution body of the following processing flow is not limited to the logical unit, and may be hardware or a logical device.
According to the key generation method described above, the present disclosure further provides a block diagram showing a server according to an exemplary embodiment of the disclosure shown in FIG.
FIG. 11 is a block diagram showing a server according to some embodiments of the present disclosure. At the hardware level, network server 1100 includes processor 1102, internal bus 1104, network interface 1106, memory 1108 and non-volatile storage 1110, which can certainly also include hardware required by other services. Processor 1102 reads the corresponding computer program 1110A from the non-volatile storage 1110 into memory 1108 to form the key generator 1108A at the logical level, and then executes the computer program. In addition to software implementations, the disclosure does not reliably exclude other implementations that use, for example, logical devices or software and hardware combinations. That is, the execution body of the following processing flow is not limited to the logical part, and may be a hardware or a logical device.
FIG. 12 is a block diagram showing a key generator according to some embodiments of the present disclosure. As shown in FIG. 12, the key generator may include a first encryption module 1201, a first receive module 1202, a first decryption module 1203 and a first key generator 1204.
The first encryption module 1201, the first key factor generated by the first device is encrypted with the initial key, and the encrypted first key factor is the second via the first secure channel. Configured to send to the device, the initial keys are the keys preset for the first and second devices.
The first receive module 1202 is configured to receive a second key factor encrypted with the initial key over the first secure channel, and the second key factor is generated by the second device. Will be done.
The first decryption module 1203 is encrypted with the initial key to obtain the second key factor, and decrypts the second key factor received by the first receiving module via the first secure channel. It is configured to do.
The first key generation module 1204 generates a shared key between the first device and the second device according to the first key factor and the second key factor decrypted by the first decryption module 1203. It is configured as follows.
FIG. 13 is a block diagram showing a key generator according to some embodiments of the present disclosure. As shown in FIG. 13, based on the embodiment shown in FIG. 12, the first encryption module 1201 When the first device needs to start the key negotiation procedure with the second device, the first factor generator 12011, which is configured to generate the first key factor by a pseudo-random function, A first configured to encrypt the first key factor generated by the first factor generator with the initial key in order to obtain the first key factor after receiving the first encryption. Encryption Department 12012 and In order to obtain the first key factor after receiving the second encryption, the first key factor after receiving the first encryption by the first encryption unit 12012 is set to the first secure channel. With the second encryption unit 12013 configured to encrypt with the first encryption key May include.
In one embodiment, the first decoding module 1203 A first decryption unit configured to decrypt a double-encrypted second key factor with a first encryption key in order to obtain a second key factor after receiving the first decryption. 12031 and With a second encryption unit 12032 configured to decrypt the second key factor after receiving the first decryption by the first decryption unit 12031 with the initial key in order to acquire the second key factor. including.
In one embodiment, the first key generation module 1204 A first decision unit 12041 configured to determine the initial key shared between the first device and the second device and the device identity of the first device, The first device and the first according to the first encryption key, the device identity determined by the first decision unit 12041, the first key factor, and the second key factor obtained by the first decryption module 1203. With a first factor generator 12042 configured to generate a shared key between two devices May include.
In one embodiment, the first factor generator 12011 concatenates the initial key, device identity, first key factor and second key factor in series to obtain the join string, and join strings of equal length. To get the shared key between the first device and the second device, each of the two substrings is hashed to get the two hash results. It is specifically configured to perform a bit-by-bit XOR operation on one hash result.
In one embodiment, the device is With the first decision module 1205, which is configured to determine the shared key exchange cycle between the first device and the second device, A second decision module 1206, configured to recalculate the first and second key factors according to the exchange cycle determined by the first decision module 1205, A first configured to exchange a shared key between a first device and a second device according to the first and second key factors recalculated by the second decision module 1206. With replacement module 1207 Can be further included.
In one embodiment, the device is A third decision module 1208, configured to determine the data that needs to be transmitted from the first device to the second device, and Data encryption module 1209 configured to encrypt the data to be transmitted determined by the third decision module 1208 with a shared key and send the encrypted data to the second device over the first secure channel. When Can be further included.
In one embodiment, the device is The response data is a second receiving module 1210 configured to receive the response data generated by the second device when the data to be transmitted is received via the first secure channel. The second receiving module 1210, which is already encrypted with the shared key, With a second decryption module 1211 configured to decrypt the response data encrypted with the shared key with the shared key to get the response data Can be further included.
FIG. 14 is a block diagram showing a key generator according to some embodiments of the present disclosure. As shown in FIG. 14, the key generator may include a third receive module 1401, a third decryption module 1402 and a second key generator 1403.
The third receive module 1401 is configured to receive the first key factor encrypted with the initial key from the first device via the second secure channel, and the initial key is the first device and the first. It is a preset key between 2 devices.
The third decryption module 1402 is configured to decrypt the first key factor encrypted with the initial key in order to obtain the first key factor.
The second key generation module 1403 now generates a shared key between the first device and the second device according to the first key factor and the second key factor generated by the second device. It is composed.
FIG. 15 is a block diagram showing a key generator according to some embodiments of the present disclosure. As shown in FIG. 15, based on the embodiment shown in FIG. 14, the second key generation module 1403 obtains the initial key, the device identity of the first device, and the first key in order to obtain the join string. The factor and the second key factor are concatenated in series, the join string is split into two substrings of equal length, and the two substrings are each hashed to obtain the two hash results, and the first It is specifically configured to perform a bit-by-bit XOR operation on the two hash results in order to obtain the shared key between the device and the second device.
In one embodiment, the device further comprises a second encryption module 1404, which is configured to encrypt a second key factor generated by the second device with an initial key. With a first transmit module 1405 configured to transmit a second key factor encrypted with an initial key to a first device over a second secure channel. Can be further included.
In one embodiment, the device is A third decision module 1406, configured to determine the shared key exchange cycle between the first device and the second device, and A fourth decision module 1407, which is configured to recalculate the first and second key factors according to the exchange cycle, and With a second exchange module 1408 configured to exchange a shared key between a first device and a second device according to the recalculated first and second key factors. Can be further included.
In one embodiment, the device is A fourth receive module 1409 configured to receive data to be transmitted encrypted with a shared key from the first device via the second secure channel, and With a fourth decoding module 1410 configured to decode the data to be transmitted with a shared key Can be further included.
In one embodiment, the device is Response data generation module 1411 configured to generate response data after receiving the data to be transmitted, A third encryption module 1412, which is configured to encrypt the response data with a shared key, With a second transmit module 1413 configured to send the shared key encrypted response data to the first device over the second secure channel. Can be further included.
As can be seen from the above embodiments, the first key factor and the second key factor are both encrypted with the initial key when transferred by the gateway device. The initial keys are the keys preset for the first device and the second device. Therefore, the gateway device cannot know the first key factor and the second key factor. The shared key between the first device and the second device is generated via the first key factor and the second key factor. Therefore, the finally negotiated shared key is only known to the first and second devices. The gateway device is still unable to obtain the negotiated shared key, thus ensuring secure data transmission between the first device and the second device, and the data is illegal during transmission. The risk of being captured by the user is reduced.
One of ordinary skill in the art can derive other implementations of the present disclosure after practicing the embodiments disclosed herein in view of the specification. The present disclosure is intended to cover any modification, use or adaptive modification of the present disclosure. These modifications, uses or adaptation changes are in accordance with the general principles of this disclosure and include common sense or conventional technical means in the art not disclosed in this disclosure. The specification and embodiments are considered exemplary only, and the true scope and gist of the present disclosure is set forth in the claims below.
The terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusions, thereby including processes, methods, commodities that include a set of elements. Or it should be further noted that the device includes not only those elements, but also other elements not explicitly listed, or elements that are specific to such processes, methods, commodities or devices. Further Limitations The elements clarified by the description "including one" are not further limited and do not preclude the presence of additional identical elements in the process, method, commodity or device containing the element. Absent.
The above description is merely an exemplary embodiment of the present disclosure and is not intended to limit the present disclosure. Any changes, equivalent replacements, improvements, etc. made within the gist and principles of this disclosure shall fall within the scope of this disclosure.
16 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| JP2005100412A | Cites | Japan | A | Search report | – |
| JP2006512792A | Cites | Japan | Y | Search report | 6-8,12-14,20-22,26-28 |
| JP2007529975A | Cites | Japan | A | Search report | – |
| JP2012506191A | Cites | Japan | A | Search report | – |
| US2013227286A1 | Cites | United States of America | Y | Search report | 1-4,6-9,11-18,20-23,25-28 |
| WO2015057116A1 | Cites | World Intellectual Property Organization (WIPO) | Y | Search report | 4,18 |
| JPH08234658A | Cites | Japan | Y | Search report | 1-4,6-9,11-18,20-23,25-28 |
8 members in 4 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 201510531892 | China | A | |
| 201510531892 | China | A | |
| 2015105318922 | China | – | |
| 2016095522 | China | W | |
| 2016095522 | China | W | |
| 2015105318922 | – | – | – |
| CN201510531892 | – | – | – |
| CN20151531892 | – | – | – |
| CN2016095522 | – | – | – |
| WO2016CN95522 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| WO2017032242A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN106487749A | China | A | |
| US2018241549A1 | United States of America | A1 | |
| JP2018529271AThis record | Japan | A | |
| US10693634B2 | United States of America | B2 | |
| US2020313865A1 | United States of America | A1 | |
| CN106487749B | China | B | |
| US11463243B2 | United States of America | B2 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2018529271
- Publication, DOCDB
- 2018529271
- Publication, EPODOC
- JP2018529271
- Application
- 2018508212
- Application, DOCDB
- 2018508212
- Application, EPODOC
- JP20180508212
Titles2
- Japanese
- 二重暗号化を用いたキー生成方法および装置
- English
- Key generation method and device using double encryption
Classification
- CPC, 9
- H04L63/062
- H04L63/0478
- H04L9/085
- H04L63/06
- H04L2463/062
- H04L9/0822
- H04L9/0861
- H04L12/66
- H04L9/0866
- IPC, 2
- H04L9 08
- H04L9 14
Designated states5
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo
- National, 1
- United States of America