Method of establishing communication between apparatuses, device, and system
Abstract
The present invention provides a method of establishing communication between apparatuses, device, and system. The method comprises: a second apparatus acquires a first apparatus public key, and encrypts, according to the first apparatus public key, a session key; the second apparatus transmits to the first apparatus the encrypted session key; the first apparatus decrypts, in a trusted environment, using a first apparatus private key, the received session key; and the first apparatus performs, using the decrypted session key, digital communication with the second apparatus. In the invention, the private key of the apparatus is used and the decryption of the session key is performed in a trusted environment, thereby preventing interception of the key and the session key owing to an OS security hole, and increasing security of communication between apparatuses.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
41 claims: 7 independent, 34 dependent
- 1A method for establishing communication between devices, characterized in that the method includes:一种建立设备间通信的方法,其特征在于,该方法包括: The first device receives the encrypted session key sent by the second device;第一设备接收第二设备发送的加密后的会话密钥;In a trusted environment, the private key of the first device is used to decrypt the encrypted session key, and the decrypted session key is used to perform data communication with the second device. 在可信环境中利用第一设备私钥解密所述加密后的会话密钥,并利用解密得到的会话密钥与所述第二设备进行数据通信。
- 10A method for establishing communication between devices, characterized in that the method includes:一种建立设备间通信的方法,其特征在于,该方法包括: The second device obtains the public key of the first device;第二设备获取第一设备公钥;Use the public key of the first device to encrypt the session key and send it to the first device;利用第一设备公钥对会话密钥进行加密后发送给第一设备;Use the session key to perform data communication with the first device. 利用所述会话密钥与所述第一设备进行数据通信。
- 17A method for establishing communication between devices, characterized in that the method includes:一种建立设备间通信的方法,其特征在于,该方法包括: The identification service device receives the identification information of the first device sent by the second device;标识服务设备接收第二设备发送的第一设备的标识信息;Return the first device public key corresponding to the identification information of the first device to the second device, so that the second device uses the first device public key to encrypt the session key and then sends it to the first device. The session key is used for data communication between the first device and the second device. 向所述第二设备返回所述第一设备的标识信息对应的第一设备公钥,以便所述第二设备利用第一设备公钥对会话密钥进行加密后发送给第一设备,所述会话密钥用于第一设备与第二设备之间的数据通信。
- 21A device for establishing communication between devices is set in a first device, and is characterized in that the device includes:一种建立设备间通信的装置,设置于第一设备,其特征在于,该装置包括: The key receiving unit is used to receive the encrypted session key sent by the second device;密钥接收单元,用于接收第二设备发送的加密后的会话密钥;The trusted execution unit is used to decrypt the encrypted session key using the private key of the first device in a trusted environment, and use the decrypted session key to perform the exchange between the first device and the second device Data communication between. 可信执行单元,用于在可信环境中利用第一设备私钥解密所述加密后的会话密钥,并利用解密得到的会话密钥,进行所述第一设备与所述第二设备之间的数据通信。
- 30A device for establishing communication between devices is set in a second device, and is characterized in that the device includes:一种建立设备间通信的装置,设置于第二设备,其特征在于,该装置包括: The public key acquisition unit is used to acquire the public key of the first device;公钥获取单元,用于获取第一设备公钥;The key processing unit is used to encrypt the session key using the public key of the first device and send it to the first device;密钥处理单元,用于利用第一设备公钥对会话密钥进行加密后发送给第一设备;The data communication unit is configured to use the session key to perform data communication between the second device and the first device. 数据通信单元,用于利用所述会话密钥,进行所述第二设备与所述第一设备之间的数据通信。
- 37A device for establishing communication between devices, which is set in an identification service device, and is characterized in that the device includes:一种建立设备间通信的装置,设置于标识服务设备,其特征在于,该装置包括: The receiving unit is used to receive the identification information of the first device sent by the second device;接收单元,用于接收第二设备发送的第一设备的标识信息;The determining unit is used to determine the first device public key corresponding to the identification information of the first device;确定单元,用于确定所述第一设备的标识信息对应的第一设备公钥;The sending unit is configured to return the first device public key to the second device, so that the second device uses the first device public key to encrypt the session key and then sends it to the first device. The session key Used for data communication between the first device and the second device. 发送单元,用于向所述第二设备返回所述第一设备公钥,以便所述第二设备利用第一设备公钥对会话密钥进行加密后发送给第一设备,所述会话密钥用于第一设备与第二设备之间的数据通信。
- 40A system for establishing communication between devices, characterized in that the system includes a first device and a second device;一种建立设备间通信的系统,其特征在于,该系统包括第一设备和第二设备;The first device includes the device according to any one of claims 21 to 28;所述第一设备包括如权利要求21至28任一权项所述的装置;The second device includes the device according to any one of claims 30 to 34. 所述第二设备包括如权利要求30至34任一权项所述的装置。
Independent claims7
242 paragraphs, as filed
Method, device and system for establishing communication between equipment
This application claims the priority of a Chinese patent application filed on February 02, 2016 with the application number 201610072683.0 and the invention title "A method, device and system for establishing communication between devices", the entire content of which is incorporated into this application by reference middle.
Technical field
The present invention relates to the field of computer application technology, in particular to a method, device and system for establishing communication between devices.
Background technique
In order to enhance the security of communication between devices, there are currently some encrypted communications on the market, such as HTTPS (Hyper Text Transfer Protocol over Secure Socket Layer, based on secure hypertext transfer protocol). In HTTPS, the session key is transferred between the server and the client through a pre-agreed encryption algorithm. The key is easily intercepted, so its security level will be greatly reduced as OS vulnerabilities burst, and it cannot meet the security requirements of background applications such as finance.
<u style="single">Summary of the invention</u>
In view of this, the present invention provides a method, device and equipment for establishing communication between devices, so as to improve the security of communication between devices.
The specific technical solutions are as follows:
The present invention provides a method for establishing communication between devices, the method comprising:
The first device receives the encrypted session key sent by the second device;
In a trusted environment, the private key of the first device is used to decrypt the encrypted session key, and the decrypted session key is used to perform data communication with the second device.
According to a preferred embodiment of the present invention, before the first device receives the encrypted session key sent by the second device, the method further includes:
The first device sends the identification information of the first device to the second device, so that the second device determines the first device public key corresponding to the identification information of the first device, and sends it to the first device The session key encrypted with the public key of the first device.
According to a preferred embodiment of the present invention, the identification information of the first device is stored in the trusted environment.
According to a preferred embodiment of the present invention, the identification information of the first device is allocated and maintained by the identification service device in advance;
The first device public key corresponding to the identification information of the first device is allocated and maintained by the identification service device in advance, and is available for the second device to obtain, and the first device private key is written into the first device in advance. In a trusted environment.
According to a preferred embodiment of the present invention, the first device is a client device, and the second device is a server device.
According to a preferred embodiment of the present invention, before the first device receives the encrypted session key sent by the second device, the method further includes:
The first device sends the first device public key to the second device, so that the second device uses the first device public key to encrypt the session key and then returns it to the first device.
According to a preferred embodiment of the present invention, the first device public key and the first device private key are generated by the identity service device and provided to the first device, and the first device private key is written into the first device in advance. In the trusted environment of the device.
According to a preferred embodiment of the present invention, the first device and the second device are both client devices.
According to a preferred embodiment of the present invention, the trusted environment includes:
Trusted chip, or,
The security environment isolated by the virtualization mechanism.
The present invention also provides a method for establishing communication between devices, the method comprising:
The second device obtains the public key of the first device;
Use the public key of the first device to encrypt the session key and send it to the first device;
Use the session key to perform data communication with the first device.
According to a preferred embodiment of the present invention, obtaining the public key of the first device by the second device includes:
The second device receives the identification information of the first device;
Acquire the first device public key corresponding to the identification information of the first device from the identification service device.
According to a preferred embodiment of the present invention, the method further includes:
If the second device receives a response sent by the identification service device that the identification information of the first device is illegal, or there is no response of the first device public key corresponding to the identification information of the first device, then Returning a response that the communication establishment fails to the first device.
According to a preferred embodiment of the present invention, the first device is a client device, and the second device is a server device.
According to a preferred embodiment of the present invention, obtaining the public key of the first device by the second device includes:
The second device receives the first device public key sent by the first device.
According to a preferred embodiment of the present invention, before the session key is encrypted using the public key of the first device and sent to the first device, the method further includes:
The second device allocates a random session key.
According to a preferred embodiment of the present invention, the second device executes the steps of assigning a random session key and encrypting the session key in a trusted environment.
The present invention also provides a method for establishing communication between devices, the method comprising:
The identification service device receives the identification information of the first device sent by the second device;
Return the first device public key corresponding to the identification information of the first device to the second device, so that the second device uses the first device public key to encrypt the session key and then sends it to the first device. The session key is used for data communication between the first device and the second device.
According to a preferred embodiment of the present invention, the method further includes:
The identification service device maintains identification information allocated to the first device in advance, and maintains a first device public key and a first device private key that are generated in advance for the first device.
According to a preferred embodiment of the present invention, the method further includes:
The first device private key is written into the trusted environment of the first device in advance.
According to a preferred embodiment of the present invention, the method further includes:
If the identification service device determines that the identification information of the first device is illegal, it returns a response that the identification information of the first device is illegal to the second device; or,
If the identification service device determines that the first device public key corresponding to the identification information of the first device does not exist, it returns a response that the identification information of the first device does not exist to the second device.
The present invention also provides a device for establishing communication between devices, which is set in the first device, and the device includes:
The key receiving unit is used to receive the encrypted session key sent by the second device;
The trusted execution unit is used to decrypt the encrypted session key using the private key of the first device in a trusted environment, and use the decrypted session key to perform the exchange between the first device and the second device Data communication between.
According to a preferred embodiment of the present invention, the device further includes:
The identification sending unit is configured to send the identification information of the first device to the second device, so that the second device determines the first device public key corresponding to the identification information of the first device, and sends it to the first device. A device sends the session key encrypted with the public key of the first device.
According to a preferred embodiment of the present invention, the trusted execution unit requests and obtains the identification information of the first device;
The trusted execution unit is further configured to obtain the identification information of the first device from the secure storage area in response to the request of the identification sending unit and return it to the identification sending unit.
According to a preferred embodiment of the present invention, the identification information of the first device is allocated and maintained by the identification service device in advance;
The first device public key corresponding to the identification information of the first device is generated and maintained by the identification service device in advance and is obtained by the second device, and the first device private key is written into the first device in advance. Safe storage area.
According to a preferred embodiment of the present invention, the first device is a client device, and the second device is a server device.
According to a preferred embodiment of the present invention, the device further includes:
The public key sending unit is configured to send the public key of the first device to the second device, so that the second device uses the public key of the first device to encrypt the session key and then returns it to the first device.
According to a preferred embodiment of the present invention, the first device public key and the first device private key are generated by the identity service device and provided to the first device, and the first device private key is written into the first device in advance. In the secure storage area of the device.
According to a preferred embodiment of the present invention, the first device and the second device are both client devices.
According to a preferred embodiment of the present invention, the trusted execution unit includes:
Trusted chip, or,
The security module isolated by the virtualization mechanism.
The present invention also provides a device for establishing communication between devices, which is set in a second device, and the device includes:
The public key acquisition unit is used to acquire the public key of the first device;
The key processing unit is used to encrypt the session key using the public key of the first device and send it to the first device;
The data communication unit is configured to use the session key to perform data communication between the second device and the first device.
According to a preferred embodiment of the present invention, the public key acquisition unit is specifically used for:
Receiving identification information of the first device;
Acquire the first device public key corresponding to the identification information of the first device from the identification service device.
According to a preferred embodiment of the present invention, the device further includes:
The response sending unit is configured to, if the public key acquisition unit receives a response that the identification information of the first device sent by the identification service device is illegal, or there is no first device corresponding to the identification information of the first device. In response to the device public key, it returns a communication establishment failure response to the first device.
According to a preferred embodiment of the present invention, the first device is a client device, and the second device is a server device.
According to a preferred embodiment of the present invention, the public key acquisition unit is specifically configured to receive the first device public key sent by the first device.
According to a preferred embodiment of the present invention, the device further includes:
The key generation unit is used to distribute random session keys.
According to a preferred embodiment of the present invention, the key generation unit and the key processing unit are arranged in a trusted environment.
The present invention also provides a device for establishing communication between devices, which is set in the identification service device, and the device includes:
The receiving unit is used to receive the identification information of the first device sent by the second device;
The determining unit is used to determine the first device public key corresponding to the identification information of the first device;
The sending unit is configured to return the first device public key to the second device, so that the second device uses the first device public key to encrypt the session key and then sends it to the first device. The session key Used for data communication between the first device and the second device.
According to a preferred embodiment of the present invention, the device further includes:
The information maintenance unit is configured to maintain the identification information allocated to the first device in advance, and maintain the first device public key and the first device private key generated in advance for the first device.
According to a preferred embodiment of the present invention, the sending unit is further configured to, if the determining unit determines that the identification information of the first device is illegal, return the identification information of the first device to the second device. A legitimate response; or,
If the determining unit determines that the first device public key corresponding to the identification information of the first device does not exist, it returns a response that the identification information of the first device does not exist to the second device.
The present invention also provides a system for establishing communication between devices. The system includes a first device and a second device.
According to a preferred embodiment of the present invention, the system further includes an identification service device.
It can be seen from the above technical solutions that in the present invention, the private key of the device and the decryption of the session key are performed in a trusted environment, thereby avoiding the interception of the key and the session key due to OS vulnerabilities, and improving This improves the security of communication between devices.
Description of the drawings
Figure 1 is a diagram of the system architecture on which the present invention is based;
Figure 2 is a flowchart of a main method provided by an embodiment of the present invention;
Figure 3 is a flowchart of a method for establishing communication between a client device and a server device according to an embodiment of the present invention;
Figure 4 is a flowchart of a method for establishing communication between client devices provided by an embodiment of the present invention;
Figure 5 is a flowchart of a specific implementation method corresponding to Figure 3 provided by an embodiment of the present invention;
Figure 6 is a flowchart of a specific implementation method corresponding to Figure 4 provided by an embodiment of the present invention;
Figure 7 is a structural diagram of a first device provided by an embodiment of the present invention;
Figure 8 is a structure diagram of a second device provided by an embodiment of the present invention;
Figure 9 is a structural diagram of a third device provided by an embodiment of the present invention;
Figure 10 is a schematic diagram of an application scenario provided by an embodiment of the present invention;
FIG. 11 is a schematic diagram of another application scenario provided by an embodiment of the present invention.
Detailed ways
In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.
The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms of "a", "said" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
It should be understood that the term "and/or" used in this article is only an association relationship that describes associated objects, indicating that there can be three relationships, for example, A and/or B can mean: A alone exists, and A and A exist at the same time. B, there are three cases of B alone. In addition, the character "/" in this article generally means that the associated objects before and after are in an "or" relationship.
Depending on the context, the word "if" as used herein can be interpreted as "when" or "when" or "in response to determination" or "in response to Detection". Similarly, depending on the context, the phrase "if determined" or "if detected (statement or event)" can be interpreted as "when determined" or "in response to determination" or "when detected (statement or event) )" or "in response to detection (statement or event)".
The system architecture on which the present invention is based is shown in Figure 1 and includes a first device and a second device. Among them, the first device may be a client device, and the second device may be a server device, that is, secure communication between the client device and the server device is established. Or, the first device and the second device are both client devices, that is, secure communication between the client devices is established.
Client devices may include, but are not limited to: smart mobile terminals, smart home appliances, network devices, wearable devices, smart medical devices, PCs (personal computers), etc. Among them, smart mobile devices can include, for example, mobile phones, tablet computers, notebook computers, PDAs (personal digital assistants), and so on. Smart home appliances may include smart TVs, smart air conditioners, smart water heaters, smart refrigerators, smart air purifiers, and so on. Network equipment may include, for example, switches, wireless APs, servers, and so on. Wearable devices may include, for example, smart watches, smart glasses, smart bracelets, and so on. Smart medical equipment may include, for example, smart thermometers, smart blood pressure meters, smart blood glucose meters, and so on. The server equipment can be a server, a switch, a router, etc.
These client devices and server devices can all include some basic components in the architecture, such as a bus, a processing system, a storage system, one or more input/output systems, and communication interfaces. The bus can include one or more wires to realize the communication between the components of the server or terminal equipment. The processing system includes various types of processors or microprocessors for executing instructions, processing processes, or threads. The storage system may include dynamic memory such as random access memory (RAM) for storing dynamic information, static memory such as read-only memory (ROM) for storing static information, and large-capacity memory including magnetic or optical recording media and corresponding drives. The input system allows users to input information to the server device or client device, such as buttons, keyboard, mouse, touch screen, stylus, voice recognition system, or biometric system. The output system includes displays, printers, speakers, etc. used to output information. The communication interface is used to enable the server device or the client device to communicate with other systems or systems. The communication interfaces can be connected to the network through a wired connection, a wireless connection, or an optical connection.
FIG. 2 is a flow chart of the main method provided by an embodiment of the present invention. As shown in FIG. 2, the method may mainly include the following steps:
In 201, the second device obtains the first device public key, and uses the first device public key to encrypt the session key.
The second device can obtain the public key of the first device from the server. For example, the second device can use the identification information of the first device to obtain the public key of the first device from the identification service device. This situation can be applied to the second device being a server device. Time. The second device may also obtain the first device public key from the first device, and this situation may be applicable when the first device is a client device. The details will be described in detail in subsequent embodiments.
The session key can be generated or distributed by the second device, but in order to ensure security, the session key needs to have a certain degree of randomness, and the session key is used for subsequent data communication between the first device and the second device.
In 202, the second device sends the encrypted session key to the first device.
In 203, the first device uses the first device private key to decrypt the received session key in a trusted environment.
The private key of the first device is pre-stored in the trusted environment of the first device, and the decryption of the session key is performed in the trusted environment, thereby ensuring the security of the session key. In the embodiment of the present invention, the trusted environment can be a security zone isolated on hardware using mechanisms such as ARM TrustZone or Secure Element or TI M-Shield, or it can be a virtualized mechanism to isolate an independent security environment. . The trusted environment ensures that the stored private key of the first device cannot be tampered with or erased, and the privacy of the decryption of the session key.
In 204, the first device uses the decrypted session key to perform data communication with the second device.
During subsequent data communication between the first device and the second device, the session key is used for data encryption and decryption. For example, when the first device sends data to the second device, the session key is used to encrypt the data and then sent to the second device, and the second device uses the session key to decrypt the data sent by the first device. When the second device sends data to the first device, it also uses the session key to encrypt the data before sending it to the first device, and the first device uses the session key to decrypt the data sent by the second device.
In the following, the method provided by the present invention will be described in detail by taking the client device and the server device to establish secure communication, and the client device and the client device to establish secure communication as examples.
FIG. 3 is a flowchart of a method for establishing communication between a client device and a server device according to an embodiment of the present invention. As shown in FIG. 3, the method may specifically include the following steps:
In 301, the client device obtains its own ID information.
In the embodiment of the present invention, the ID information of the client device is used to uniquely identify the client device, and may be, but not limited to: IMEI, MAC address, etc. As a preferred embodiment, the identity of the client device can be allocated by the identity service device and provided to the client device. The ID of the end device is written to the client device.
In consideration of the security of the ID information of the client device, the ID information of the client device can be stored in a secure environment, such as a secure storage area, so as to ensure that the ID information is not tampered with.
This step can be triggered and executed when the client device needs to establish a communication connection with the server device, and can be triggered and executed by the client device. The execution can also be triggered by the server device, for example, when the client device receives a connection request from the server device, this step is executed.
In 302, the client device sends its ID information to the server device.
In 303, the server device sends the ID information of the client device to the identification service device to request the public key of the client device from the identification service device.
In this embodiment, the server device uses the ID information of the client device to obtain the client device public key from the identification service device.
In 304, the identification service device determines the client device public key corresponding to the ID information of the client device.
In the embodiment of the present invention, the identification service device may be responsible for uniformly maintaining the corresponding relationship between the ID information of the client device and the public key of the client device, and the corresponding relationship may be stored in the identification service device in advance.
As a preferred embodiment, the ID information of the legal client device can be allocated and maintained by the identity service device, and provided to the identity writing device at the factory stage of the legal client device, and the identity writing device is written into the legal client device. In the trusted environment of the device.
In this step, the identification service device can first determine the validity of the received ID information of the client device, that is, determine whether the received ID information of the client device is locally maintained ID information, and if so, determine the If the ID information of the client device is legal, you can continue to determine the client device public key corresponding to the ID information; otherwise, if the ID information of the client device is determined to be illegal, you can return the ID information of the client device to the server device as illegal. The server device determines that the communication establishment has failed, and can return a communication establishment failure response to the client device.
The client device public key and the client device private key are paired keys, which can be generated by the identification service device, and the client private key is provided to the client device for maintenance, that is, written into the trusted environment of the client device (can be It is executed in the delivery stage of the client device, or it can be executed in other stages that can ensure information security), the identification service device locally maintains the correspondence between the ID information of the client device and the client public key.
If the identification service device can determine the client device public key corresponding to the ID information of the client device, then execute 305; if the client device public key corresponding to the ID information of the client device is not maintained locally, you can send to the server device Return a response that the public key of the client device does not exist, and the server device determines that the communication establishment failed, and can return a response of the communication establishment failure to the client device.
In 305, the identification service device returns the public key of the client device to the server device.
In 306, the server device generates a session key, and encrypts the session key with the public key of the client device.
The session key can be a random key generated according to a certain algorithm, a symmetric key, or an asymmetric key. In view of the fact that the generation and utilization of the session key is already a relatively mature technology, it will not be described in detail here. The focus of this step is to use the public key of the client device to encrypt the session key to ensure that the session key can be safely and privately transmitted to the client.. End device. End equipment.
In addition to real-time generation of session keys, a session key pool can also be generated and maintained in advance. In this step, the server device randomly allocates a session key from the session key pool. Usually the session key has a certain validity period. When the validity period is exceeded, the session key becomes invalid, and the invalid session key can be redistributed to a new communication connection. The session key distribution method in the subsequent embodiments may also adopt one of the above two types, which will not be described in detail in the following.
In 307, the server device sends the encrypted session key to the client device.
Since the server device is usually a single service type server and does not have other applications, the server device itself has a certain level of security, and it can also be regarded as the server device itself is a trusted environment.
In 308, the client device obtains the client device private key in a trusted environment, and uses the client device private key to decrypt the session key.
Since the session key is encrypted using the public key of the client device, only the client private key can decrypt it. In the embodiment of the present invention, the client device private key can only be obtained from a trusted environment, thus ensuring The session key can only be decrypted by the client device, and since the decryption of the session key is also performed in a trusted environment, it is ensured that the session key is not acquired and tampered with by other devices.
In 309, the client device uses the decrypted session key to communicate with the server device.
Subsequent data communication between the client device and the server device uses the session key for encryption and decryption. If the session key is a symmetric key, then the client device and the server device use the same key to encrypt and decrypt data. If the session key is an asymmetric key, the client device and the server device use one of the key pairs to encrypt and decrypt data.
When the client device uses the session key to communicate with the server device, it encrypts and decrypts the data in a trusted environment.
FIG. 4 is a flowchart of a method for establishing communication between client devices provided by an embodiment of the present invention. In this embodiment, device A and device B are taken as examples for description. As shown in FIG. 4, the method may specifically include the following step:
In 401, device A sends device A's public key information to device B.
This step can be triggered when device A needs to establish a communication connection with device B, that is, device A can trigger execution. It can also be triggered by device B. For example, when device A receives a connection request from device B, this step is executed.
Similar to the embodiment shown in Figure 3, in this embodiment, the public key and private key of device A can be pre-generated by the identification service device and provided to device A, wherein the private key of device A is written into the trusted device A in advance. Environment.
In 402, the device B generates a session key in a trusted environment, and uses the public key information of the device A to encrypt the session key.
Similarly, the session key can be a random key generated according to a certain algorithm, a symmetric key, or an asymmetric key.
In 403, device B sends the encrypted session key to device A.
In 404, device A uses the private key of device A to decrypt the session key in a trusted environment.
Since the session key is encrypted with the public key of device A, only the private key of device A can decrypt it. In the embodiment of the present invention, the private key of device A can only be obtained from a trusted environment, thus ensuring The session key can only be decrypted by device A, and since the decryption of the session key is also performed in a trusted environment, it is ensured that the session key is not acquired or tampered with by other devices.
In 405, device A uses the decrypted session key to communicate with device B.
Subsequent data communication between device A and device B uses the session key for encryption and decryption. If the session key is a symmetric key, then device A and device B use the same key to encrypt and decrypt data. If the session key is an asymmetric key, then device A and device B use one of the key pairs to encrypt and decrypt data.
When device A uses the session key to communicate with device B, it encrypts and decrypts the data in a trusted environment.
The following describes the specific implementation of the client device in FIG. 3 and FIG. 4 through two embodiments.
FIG. 5 is a flowchart of a specific implementation method corresponding to FIG. 3 provided by an embodiment of the present invention. The client device is subdivided into a client, a security service module, and a trusted environment module. As shown in Figure 5, the method can specifically include the following steps:
In 501a, the client requests the security service module for ID information of the client device.
In 501b, after the security service module parses the request, it requests the client device ID information from the trusted environment module.
In 501c, the trusted environment module obtains and returns the stored ID information of the client device to the security service module.
The ID information of the client device is pre-stored in the secure environment, and the trusted environment module is responsible for maintenance and processing.
In 501d, the security service module returns the ID information of the client device to the client.
The above steps 501a to 501d correspond to step 301 in FIG. 3.
In 502, the client sends the ID information of the client device to the server device.
Steps 503 to 507 are the same as steps 303 to 307 in FIG. 3.
In 508a, the client receives the encrypted session key sent by the server device and provides it to the security service module.
In 508b, the security service module requests the trusted environment module to decrypt the session key.
In 508c, the trusted environment module obtains the client device private key, and uses the client device private key to decrypt the session key.
The above steps 508a to 508c correspond to step 308 in FIG. 3.
In 509a, the trusted environment module uses the session key to encrypt data.
In 509b, the trusted environment module sends the encrypted data to the security service module.
In 509c, the security service module provides the encrypted data to the client.
In 509d, the client sends the encrypted data to the server device.
In 509e, the server device uses the session key to decrypt the data.
After the data encrypted by the server device using the session key is sent to the client, the client sends it to the trusted environment module via the security service module, and the trusted environment module uses the session key to decrypt it. This process is not shown in FIG. 5. The process of 509a to 509e corresponds to step 309 in FIG. 3.
FIG. 6 is a flowchart of a specific implementation method corresponding to FIG. 4 provided by an embodiment of the present invention. The client device is refined into a Bluetooth application and a trusted environment module. As shown in Figure 6, the method may specifically include the following steps:
In 601, the Bluetooth application of device A sends the public key information of device A to the Bluetooth application of device B.
In 602a, the Bluetooth application of device B sends the public key of device A to the trusted environment module of device B.
In 602b, the trusted environment module of device B generates and stores the session key.
In 602c, the trusted environment module of device B uses the public key of device A to encrypt the session key.
The process from 602a to 602c corresponds to step 402 in FIG. 4.
In 603a, the trusted environment module of device B sends the encrypted session key to the Bluetooth application of device B.
In 603b, the Bluetooth application of device B sends the encrypted session key to the Bluetooth application of device A.
In 603c, the Bluetooth application of device A sends the encrypted session key to the trusted environment module of device A.
The process from 603a to 603c corresponds to step 403 in FIG. 4.
In 604, the trusted environment module of device A uses the private key of device A to decrypt the session key.
In 605a, the trusted environment module of device A uses the session key to encrypt data.
In 605b, the trusted environment module of device A sends the encrypted data to the Bluetooth application of device A.
In 605c, the Bluetooth application of device A sends the encrypted data to the Bluetooth application of device B via Bluetooth.
In 605d, the Bluetooth application of device B sends the encrypted data to the trusted environment module of device B.
In 605e, the trusted environment module of device B uses the session key to decrypt the encrypted data.
Subsequently, the trusted environment module of device B uses the session key to encrypt the data sent to device A, and sends the encrypted data to the Bluetooth application of device A through the Bluetooth application, and the Bluetooth application of device A provides the confidential data To the trusted environment module of device A, the trusted environment module of device A uses the session key to decrypt the data. This process is not shown in FIG. 6. The process of 605a to 605e corresponds to step 405 in FIG. 4.
The above is a description of the method provided by the present invention, and the device provided by the present invention will be described in detail below in conjunction with embodiments.
FIG. 7 is a structural diagram of the first device provided by an embodiment of the present invention. The device may be set in the first device in the above embodiment. As shown in FIG. 7, the device may include: a key receiving unit 01 and The letter execution unit 02 may also include: an identification sending unit 03. The main functions of each component are as follows:
The key receiving unit 01 is responsible for receiving the encrypted session key sent by the second device. Specifically, it can include but not limited to the following two ways:
The first method: the identification sending unit 03 sends the identification information of the first device to the second device, so that the second device determines the public key of the first device corresponding to the identification information of the first device, and sends the usage information to the first device. The session key encrypted by the public key of the first device.
Among them, the identification sending unit 03 can request and obtain the identification information of the first device from the trusted execution unit 02; the trusted execution unit 02 should identify the request of the sending unit 03, obtain the identification information of the first device from the secure storage area and return it to Identify the sending unit 03.
The identification information of the first device may be allocated and maintained by the identification service device in advance. For example, in the delivery stage of the client device, it is provided to the identification writing device, and the identification writing device writes the ID of the client device into the client device. In consideration of the security of the ID information of the client device, the ID information of the client device can be stored in a secure environment, such as a secure storage area, so as to ensure that the ID information is not tampered with.
The first device public key corresponding to the identification information of the first device can also be generated and maintained by the identification service device in advance, and can be obtained by the second device, and the first device private key is written into the secure storage area of the first device in advance.
This implementation manner can be applied to a scenario where the first device is a client device and the second device is a server device.
The second method: The public key sending unit sends the public key of the first device to the second device, so that the second device uses the public key of the first device to encrypt the session key and then returns it to the first device. This method is not shown in the figure. .
Similarly, the above-mentioned first device public key and first device private key may be generated by the identification service device and provided to the first device, and the first device private key is pre-written in the secure storage area of the first device.
This implementation manner can be applied to a scenario where the first device and the second device are both client devices.
The trusted execution unit 02 is responsible for decrypting the encrypted session key using the private key of the first device in a trusted environment, and using the decrypted session key to perform data communication between the first device and the second device.
The trusted execution unit 02 may be a secure area isolated on hardware using mechanisms such as ARM TrustZone, Secure Element, or TI M-Shield, for example, in the form of a trusted chip. It can also be a security module isolated by a virtualization mechanism.
FIG. 8 is a structure diagram of a second device provided by an embodiment of the present invention. The device may be set in the above-mentioned second device. As shown in FIG. 8, the device may include: a public key acquisition unit 11, a key processing unit 12 The data communication unit 13 may also include a response sending unit 14 and a key generation unit 15. The main functions of each component are as follows:
The public key obtaining unit 11 is responsible for obtaining the public key of the first device. Specifically, the following two methods can be used but not limited to:
The first method: the public key obtaining unit 11 receives the identification information of the first device, and obtains the first device public key corresponding to the identification information of the first device from the identification service device.
If the public key acquisition unit 11 receives a response that the identification information of the first device sent by the identification service device is illegal, or there is no response to the public key of the first device corresponding to the identification information of the first device, the response sending unit 14 may send a message to The first device returns a response that the communication establishment failed.
This situation can be applied to a scenario where the first device is a client device and the second device is a server device.
In the second way, the public key acquisition unit 11 receives the first device public key sent by the first device.
This situation can be applied to a scenario where the first device and the second device are both client devices.
The key processing unit 12 is responsible for encrypting the session key using the public key of the first device and sending it to the first device.
The data communication unit 13 is responsible for using the session key to perform data communication between the second device and the first device.
The above-mentioned session key may be generated by the key generation unit 15. The session key may be a random key generated according to a certain algorithm, and may be a symmetric key or an asymmetric key.
In order to ensure the security of the session key, as a preferred embodiment, the key generation unit 15 and the key processing unit 12 may be set in a trusted environment.
FIG. 9 is a structural diagram of a third device provided by an embodiment of the present invention. The device may be set in the identification service equipment in the above method embodiment. As shown in FIG. 9, the device may include: a receiving unit 21, a determining unit 22 And the sending unit 23 also includes an information maintenance unit 24. The main functions of each component are as follows:
The receiving unit 21 is responsible for receiving the identification information of the first device sent by the second device.
The determining unit 22 is responsible for determining the first device public key corresponding to the identification information of the first device.
The sending unit 23 is responsible for returning the first device public key to the second device, so that the second device uses the first device public key to encrypt the session key and then sends it to the first device. The session key is used for the first device and the second device. Data communication between.
The information maintenance unit 24 is responsible for maintaining the identification information allocated to the first device in advance, and maintaining the first device public key and the first device private key generated in advance for the first device. Wherein, the identification information of the first device can be allocated by the identification service device, and provided to the identification writing device at the factory stage of the first device, and written into the first device. The first device public key and the first device private key can also be generated by the identity service device, and provided to the identity writing device at the factory stage of the first device to write into the secure storage area of the first device.
In addition, if the determining unit 22 determines that the identification information of the first device is illegal, the sending unit 23 returns a response that the identification information of the first device is illegal to the second device. If the determining unit 22 determines that the first device public key corresponding to the identification information of the first device does not exist, the sending unit 23 may return to the second device a response that the identification information of the first device does not exist.
Here are a few specific application scenarios:
The first application scenario: As shown in Figure 10, the identification service device generates the ID information of the smart car in advance for the smart car, and generates the public key-private key pair for the smart car, and sends the ID information and private key of the smart car to The identification writing device, so that the identification writing device writes the ID information and private key of the smart car into the trusted chip of the smart car during the factory stage of the smart car.
When a smart car wants to establish a connection with the server through the Internet of Things, so as to enjoy the services of the business server, such as obtaining navigation information, road condition information, control information, etc. from the business server, the ID information of the smart car is sent to the business Server, the business server sends the ID information to the identification service device, and the identification service device sends the public key corresponding to the ID information of the smart car to the business server. The service server uses the public key of the smart car to encrypt the generated random session key, and sends the encrypted session key to the smart car. After the smart car receives the session key, it provides it to the trusted chip. After the trusted chip obtains the smart car's private key, the private key is used to decrypt the received encrypted session key, and then the decrypted session key is used later. The session key performs data communication with the service server. Thereby ensuring the safety of data communication between the smart car and the service server.
The second application scenario: As shown in Figure 11, the identification service device generates the ID information of the smart watch in advance for the smart watch, and generates a public key-private key pair for the smart watch, and sends the ID information and private key of the smart watch to The identification writing device, so that the identification writing device writes the ID information and private key of the smart watch into the trusted chip of the smart watch during the factory stage of the smart watch.
When the smart watch wants to establish a connection with the mobile phone for data interaction, the public key of the smart watch is sent to the mobile phone, and the trusted chip in the mobile phone uses the public key of the smart watch to encrypt the generated session key and then sends it to the smart watch. watch.
After the smart watch receives the encrypted session key, the trusted chip obtains the private key of the smart watch, and uses the private key to decrypt the encrypted session key. Then use the decrypted session key to communicate with the mobile phone, so as to ensure the security of data communication between the smart watch and the mobile phone.
In addition to the above application scenarios, the present invention can also be applied to other application scenarios, such as secure communication between smart TVs and video servers, secure communication between smart phones and smart home appliances, etc., and will not be here one by one. Exhaustive.
As can be seen from the above description, the method, device and system provided by the present invention can have the following advantages:
1) In the present invention, the private key of the device and the decryption of the session key are performed in a trusted environment, thereby avoiding the interception of the key and the session key due to OS vulnerabilities, and improving the security of communication between devices sex.
2) It can be applied to multiple application scenarios between client devices and between client and server devices, and flexibly meet multiple application requirements.
3) When performing secure communication between the client device and the server device, the legality of the device identification and the legality of the corresponding relationship between the device identification and the device public key are controlled by the identification service device, which further increases The security of the communication between the client device and the server device.
In the several embodiments provided by the present invention, it should be understood that the disclosed system, device, and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation.
The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the solutions of the embodiments.
In addition, the functional units in the various embodiments of the present invention may be integrated into one processing unit, or each unit may exist alone physically, or two or more units may be integrated into one unit. The above-mentioned integrated unit can be realized in the form of hardware, or in the form of hardware plus software functional unit.
The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer readable storage medium. The above-mentioned software functional unit is stored in a storage medium and includes several instructions to make a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor (processor) execute the method described in each embodiment of the present invention Part of the steps. The aforementioned storage media include: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and other media that can store program code .
The above are only preferred embodiments of the present invention, and are not used to limit the present invention. Any modification, equivalent replacement, improvement, etc., made within the spirit and principle of the present invention should be included in the present invention Within the scope of protection.
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN109286636A | Cited by | China | – | Search report | – |
| CN109286635A | Cited by | China | – | Search report | – |
| CN109167801A | Cited by | China | – | Search report | – |
| CN109361680A | Cited by | China | – | Search report | – |
| CN109274690A | Cited by | China | – | Search report | – |
| CN101212293A | Cites | China | Y | International search | 2-5, 11-13, 17-20, 22-25, 31-33, 37-39, 41 |
| CN101479984A | Cites | China | A | International search | 1-41 |
| CN102143487A | Cites | China | A | International search | 1-41 |
| CN102427449A | Cites | China | XY | International search | 1, 6-10, 14-16, 21, 26-30, 34-36, 40 |
| US2008226065A1 | Cites | United States of America | A | International search | 1-41 |
| US2009024845A1 | Cites | United States of America | A | International search | 1-41 |
7 members in 3 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 201610072683 | China | A | |
| 201610072683 | China | A | |
| 2016100726830 | China | – | |
| 2016100726830 | – | – | – |
| CN20161072683 | – | – | – |
| CN2016172683 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| CN107026727A | China | A | |
| WO2017133485A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| US2019052635A1 | United States of America | A1 | |
| CN107026727B | China | B | |
| CN110176987A | China | A | |
| US11140160B2 | United States of America | B2 | |
| CN110176987B | China | B |
4 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Ep: pct application non-entry in european phase122 | 122 | WO | |
| Ep: pct application non-entry in european phase122 | 122 | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO |
Numbers
- Publication
- 2017/133485
- Publication, DOCDB
- 2017133485
- Publication, EPODOC
- WO2017133485
- Application
- 71832
- Application, DOCDB
- 2017071832
- Application, EPODOC
- WO2017CN71832
Titles5
- English
- METHOD OF ESTABLISHING COMMUNICATION BETWEEN APPARATUSES, DEVICE, AND SYSTEM
- French
- PROCÉDÉ D'ÉTABLISSEMENT DE COMMUNICATION ENTRE APPAREILS, DISPOSITIF ET SYSTÈME
- Chinese
- 一种建立设备间通信的方法、装置和系统
- Unlabeled
- 一种建立设备间通信的方法、装置和系统
- Unlabeled
- Method, device and system for establishing communication between equipment
Classification
- CPC, 15
- G06F21/53
- H04L63/0876
- H04L9/0825
- G06F2221/2107
- H04L9/0897
- G06F21/72
- H04L63/061
- H04W12/50
- H04L63/045
- H04W12/33
- H04L63/0442
- H04L9/006
- H04L9/0866
- H04L63/0428
- H04L2463/062
- IPC, 1
- H04L9 08
Designated states164
- Regional, 86
- European Patent Office (EPO)
- Albania
- PATENT
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Lithuania
- Luxembourg
and 62 moreShow fewer
- Latvia
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
- African Intellectual Property Organization (OAPI)
- Burkina Faso
- UTILITY-MODEL
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Comoros
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- African Regional Intellectual Property Organization (ARIPO)
- Botswana
- Ghana
- Gambia
- Kenya
- Liberia
- Lesotho
- Malawi
- Mozambique
- Namibia
- Rwanda
- Sudan
- Sierra Leone
- Sao Tome and Principe
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Eurasian Patent Organization (EAPO)
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Russian Federation
- Tajikistan
- Turkmenistan
- National, 78
- United Arab Emirates
- Antigua and Barbuda
- Angola
- Australia
- Bosnia and Herzegovina
- CONSENSUAL-PATENT
- Barbados
- Bahrain
- Brunei Darussalam
- Brazil
- UTILITY-MODEL-CERTIFICATE
- Belize
- Canada
- Chile
- China
- Colombia
- Costa Rica
- Cuba
- Djibouti
- Dominica
- Dominican Republic
- Algeria
- Ecuador
- Egypt
and 54 moreShow fewer
- Grenada
- Georgia
- UTILITY-CERTIFICATE
- Guatemala
- Honduras
- Indonesia
- Israel
- India
- Iran (Islamic Republic of)
- Japan
- Cambodia
- Saint Kitts and Nevis
- Democratic People’s Republic of Korea
- INVENTOR-CERTIFICATE
- Republic of Korea
- Kuwait
- Lao People’s Democratic Republic
- Saint Lucia
- Sri Lanka
- Libya
- Morocco
- Republic of Moldova
- Montenegro
- Madagascar
- Mongolia
- Mexico
- Malaysia
- UTILITY-INNOVATION
- Nigeria
- Nicaragua
- New Zealand
- Oman
- Panama
- Peru
- Papua New Guinea
- Philippines
- Qatar
- PETTY-PATENT
- Saudi Arabia
- Seychelles
- Singapore
- El Salvador
- Syrian Arab Republic
- Thailand
- PROVISIONAL-PATENT
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines
- Viet Nam
- PATENT-FOR-UTILITY-SOLUTION
- South Africa