Disclosure of Invention
The invention provides a key generation method, a method and a device for analyzing encrypted data and a key management center, which aim to solve the problem of low network access security of household electrical appliance configuration in the prior art.
One aspect of the present invention provides a method for generating a key, including:
receiving a key acquisition request sent by a terminal, wherein the key acquisition request carries an equipment identifier and a terminal identifier;
generating a secret key according to the secret key acquisition request, and sending the secret key to the terminal, wherein the secret key is used for enabling the terminal to be in safe communication with household appliances so as to connect the household appliances with a network;
wherein the key uniquely corresponds to the get key request.
Preferably, the method further comprises: setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquiring request;
the step of generating a key according to the key acquisition request specifically includes:
and generating the secret key according to the equipment identifier, the terminal identifier, the shared secret key and the timestamp.
Preferably, the generating a key according to the key obtaining request, and the sending the key to the terminal specifically includes:
and generating a key according to the key acquisition request, obtaining a corresponding public key according to the generated key, and sending the public key serving as a final key to the terminal.
Preferably, the method further comprises: setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquiring request;
the generating a key according to the key obtaining request and sending the key to the terminal specifically include:
and randomly generating a secret key, encrypting the secret key, the equipment identifier, the terminal identifier and the timestamp by the shared secret key to obtain an encrypted message, and sending the encrypted message and the secret key to the terminal.
Preferably, the method further comprises: setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquiring request;
the generating a key according to the key obtaining request and sending the key to the terminal specifically include:
randomly generating a pair of public key and private key, encrypting the private key, the equipment identifier, the terminal identifier and the timestamp by the shared key to obtain an encrypted message, taking the public key as a final key, and sending the encrypted message and the public key to the terminal.
Preferably, after the key obtaining request sent by the receiving terminal and before the key is generated according to the key obtaining request, the method further includes:
and judging whether the terminal is legal or not, and generating a key according to the key acquisition request when the terminal is judged to be legal.
In another aspect, the present invention provides a method for parsing encrypted data, the method comprising:
receiving encrypted data sent by a terminal, wherein the encrypted data is data obtained by encrypting preset networking data by the terminal according to a key generated by a key management center, the key is generated by the key management center according to a key acquisition request sent by the terminal, the key uniquely corresponds to the key acquisition request, and the key acquisition request carries an equipment identifier and a terminal identifier;
and analyzing the encrypted data to obtain the networking data, and accessing the network according to the networking data.
Preferably, the method further comprises: receiving a timestamp and a terminal identifier sent by the terminal;
the analyzing the encrypted data to obtain the networking data specifically includes:
obtaining the secret key according to the timestamp, the terminal identification, the equipment identification and the shared secret key, and analyzing the encrypted data according to the secret key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances; the timestamp is a time value set by the key management center after receiving a key acquisition request of the terminal.
Preferably, the analyzing the encrypted data to obtain the networking data specifically includes:
and obtaining a corresponding public key according to the secret key, and analyzing the encrypted data by taking the public key as a final secret key to obtain the networking data.
Preferably, the method further comprises: receiving an encrypted message sent by a terminal;
the analyzing the encrypted data to obtain the networking data specifically includes:
analyzing the encrypted message according to a shared key to obtain a timestamp and the key, and analyzing the encrypted data according to the key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
Preferably, the method further comprises: receiving an encrypted message sent by the terminal;
the analyzing the encrypted data to obtain the networking data specifically includes:
analyzing the encrypted message according to a shared key to obtain a timestamp and a private key, obtaining a corresponding public key according to the private key, and analyzing the encrypted data according to the public key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
Preferably, after the analyzing the encrypted data to obtain the networking data, before accessing the network according to the networking data, the method further includes:
and verifying the timestamp, and accessing the network according to the networking data when the timestamp is verified to be legal.
In still another aspect, the present invention provides a key generation apparatus, including:
the device comprises a receiving unit, a sending unit and a receiving unit, wherein the receiving unit is used for receiving a key obtaining request sent by a terminal, and the key obtaining request carries an equipment identifier and a terminal identifier;
and the generating unit is used for generating a key according to the key acquiring request and sending the key to the terminal, wherein the key is used for enabling the terminal to be in safe communication with the household appliance so as to connect the household appliance with a network, and the key uniquely corresponds to the key acquiring request.
Preferably, the apparatus further comprises: a setting unit;
the setting unit is used for setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquisition request;
the generating unit is further configured to generate the key according to the device identifier, the terminal identifier, the shared key, and the timestamp, and send the key to the terminal.
Preferably, the generating unit is further configured to generate a key according to the key obtaining request, obtain a corresponding public key according to the generated key, and send the public key to the terminal as a final key.
Preferably, the apparatus further comprises a setting unit;
the setting unit is used for setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquisition request;
the generating unit is further configured to randomly generate a secret key, encrypt the secret key, the device identifier, the terminal identifier, and the timestamp with the shared secret key to obtain an encrypted message, and send the encrypted message and the secret key to the terminal.
Preferably, the apparatus further comprises: a setting unit;
the setting unit is used for setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquisition request;
the generation unit is further configured to randomly generate a pair of a public key and a private key, encrypt the private key, the device identifier, the terminal identifier, and the timestamp with the shared key to obtain an encrypted message, use the public key as a final key, and send the encrypted message and the public key to the terminal.
In yet another aspect, the present invention further provides an apparatus for parsing encrypted data, including:
the terminal comprises a receiving module, a sending module and a receiving module, wherein the receiving module is used for receiving encrypted data sent by the terminal, the encrypted data is obtained by encrypting preset networking data by the terminal according to a key generated by a key management center, the key is generated by the key management center according to a key acquiring request sent by the terminal, the key uniquely corresponds to the key acquiring request, and the key acquiring request carries an equipment identifier and a terminal identifier;
and the analysis module is used for analyzing the encrypted data to obtain the networking data and accessing the network according to the networking data.
Preferably, the receiving module is further configured to receive a timestamp and a terminal identifier sent by the terminal;
the analysis is also used for obtaining the key according to the timestamp, the terminal identifier, the equipment identifier and the shared key, and analyzing the encrypted data according to the key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
Preferably, the receiving module is further configured to receive a timestamp and a terminal identifier sent by the terminal;
the analysis module is further configured to obtain a corresponding public key according to the secret key, and analyze the encrypted data using the public key as a final secret key to obtain the networking data.
Preferably, the receiving module is further configured to receive an encrypted message sent by the terminal;
the analysis module is further configured to analyze the encrypted message according to a shared key to obtain a timestamp and the key, and analyze the encrypted data according to the key to obtain the networking data;
the shared key is preset by the key management center according to household appliances, and the timestamp is the time set by the key management center after receiving a key acquisition request of the terminal.
Preferably, the receiving module is further configured to receive an encrypted message sent by the terminal;
the analysis module is further used for analyzing the encrypted message according to a shared secret key to obtain a timestamp and a private key, obtaining a corresponding public key according to the private key, and analyzing the encrypted data according to the public key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
Preferably, the apparatus further comprises a verification module;
and the verification module is used for verifying the timestamp and accessing the network according to the networking data when the timestamp is verified to be legal.
In still another aspect, the present invention provides a key management center including any one of the key generation apparatuses described above.
The invention has the following beneficial effects:
the key management center generates corresponding keys according to the key acquiring requests sent by the terminal, so that different key acquiring requests correspond to different keys, thereby greatly reducing the risk of key leakage and further effectively solving the problem of low security of the re-networking of the household appliances after the household appliances are configured to be networked and disconnected in the prior art.
Detailed Description
In order to solve the problem of low security of network access of the household electrical equipment and network reconnection of the household electrical equipment after network disconnection in the prior art, the invention provides a key generation method, a key analysis method, a device and a key management center. The present invention will be described in further detail below with reference to the drawings and examples. It should be understood that the specific embodiments described herein are merely illustrative of the invention and do not limit the invention.
Method embodiment one
An embodiment of the present invention provides a key generation method, where an execution subject of the method is a key management center, and referring to fig. 1, the method includes:
s101, receiving a key acquisition request sent by a terminal, wherein the key acquisition request carries an equipment identifier and a terminal identifier;
and S102, generating a secret key according to the secret key acquisition request, and sending the secret key to the terminal, wherein the secret key is used for enabling the terminal to be in safe communication with the household appliance equipment so as to connect the household appliance equipment with a network, and the secret key is uniquely corresponding to the secret key acquisition request.
According to the method and the device, the corresponding key is generated according to the key acquiring request sent by the terminal, so that different key acquiring requests correspond to different keys, the risk of key leakage is greatly reduced, and the problem of low security of network access of the household electrical appliance equipment and network reconnection of the household electrical appliance equipment after network disconnection in the prior art is effectively solved.
That is, in the method according to the embodiment of the present invention, when the home appliance needs to be configured to access the network, or when the home appliance has already accessed the local area network but the local area network loses the connection with the internet, at this time, the terminal in the local area network wants to send some confidential information to the home appliance through the secure path, and the terminal may also apply for the key from the 3G network to the key management center, and establish a secure communication path according to the method of the present invention, so as to implement the connection between the home appliance and the network.
In specific implementation, the key obtaining request according to the embodiment of the present invention carries the device identifier dID and the terminal identifier tID, and certainly, a person skilled in the art may also carry other information in the key obtaining request, so as to be used by the key management center to generate a corresponding key, such as setting a number of the key obtaining request, and the like.
The device Identification dID is used for identifying the household electrical appliance to distinguish different household electrical appliances, the device Identification dID is acquired from the household electrical appliance by a terminal, and the specific acquisition method can be realized by scanning a two-dimensional code, Near Field Communication (NFC) contact, Personal Identification Number (PIN) manual input, sensor sensing and other modes.
The method of the embodiment of the invention further comprises the following steps:
setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquiring request;
step S102 in the embodiment of the present invention specifically includes:
and generating the secret key according to the equipment identifier, the terminal identifier, the shared secret key and the timestamp, and sending the secret key to the terminal so that the terminal can carry out safe communication with household appliances by using the secret key.
The method comprises the steps of setting different shared keys according to different household appliances in advance, generating the keys by the shared keys, the appliance identification, the terminal identification and the timestamp, sending the keys to the terminal, encrypting data to be sent to the household appliances by the terminal by using the keys to obtain encrypted data, and sending the encrypted data to the household appliances so as to realize the network access of the household appliances.
It should be noted that, in the key management center according to the embodiment of the present invention, a shared key corresponding to a home appliance needs to be set according to the home appliance, each shared key is stored, and the shared key is sent to the corresponding home appliance, so that the home appliance decrypts encrypted data. In addition, for greater security, the shared key is known only to the key management center and the corresponding home devices.
The method according to the invention will be illustrated below by means of a specific example:
fig. 2 is a schematic flow chart of another method for generating a secret key according to an embodiment of the present invention, and as shown in fig. 2, the method for configuring a home device to access a network includes:
1. a user logs in a key management center to authenticate the identity of a terminal and establishes a secure channel;
specifically, the terminal can establish a secure authenticated communication channel with the key management center by adopting a certificate mutual authentication mode. Of course, those skilled in the art may also use techniques such as Secure Sockets Layer (SSL) or Transport Layer Security (TLS), Internet protocol Security (IPsec) to establish a secure communication channel;
2. the terminal obtains a home appliance identifier dID;
the specific acquisition mode can be realized by scanning a two-dimensional code, NFC contact, manual PIN code input, sensor sensing and the like;
3. a terminal sends a key acquisition request to a key management center, wherein the request carries a self identifier (namely, a terminal identifier tID which can be a mobile phone number, MAC and the like) and a household appliance identifier dID;
4. the key management center judges whether the tID is a legal terminal;
5. the key management center finds a shared key master _ key of the device according to the dID;
6. the key management center generates a time stamp T;
7. the key management center calculates a key KeyD according to the master _ key, the dID, the tID and the T;
8. the key management center returns KeyD and T to the terminal;
9. the terminal encrypts the data m to be transmitted by using KeyD to obtain a ciphertext EKeyD(m);
10. Terminal sending EKeyD(m),tID,T;
11. Reception of Home appliance EKeyD(m),tID,T;
12. The home device verifies that the timestamp is valid;
13. the household appliance calculates a key KeyD according to the master _ key, the dID, the tID and the T;
14. KeyD decryption message E for household applianceKeyD(m) to obtain m.
It should be noted that, in the embodiment of the present invention, by adding the timestamp and verifying whether the timestamp is valid by the home appliance device, replay attack of others can be effectively prevented, so as to further enhance the security of network access of the home appliance device configured in the present invention and network reconnection of the home appliance device after network disconnection.
In the method according to the embodiment of the present invention, step S102 further includes: and generating a key according to the key acquisition request, obtaining a corresponding public key according to the generated key, and sending the public key serving as a final key to the terminal so that the terminal can carry out safe communication with the household appliance by using the public key to realize the network access of the household appliance, or the household appliance disconnected from the network is accessed to the network again.
Namely, in the embodiment of the invention, the key management center sets the public and private keys so as to further improve the network access security of the configured household electrical appliance.
Fig. 3 is a schematic flow chart of a further method for key generation according to an embodiment of the present invention, which will be described in detail below with reference to fig. 3, it should be noted that relevant portions of the method of fig. 3 can be understood with reference to the method described in fig. 2, and for the sake of brevity, the description is not repeated here:
1. a user logs in a key management center to authenticate the identity of a terminal and establishes a secure channel;
2. the method comprises the steps that a terminal obtains a home appliance identification dID, and the specific obtaining mode can be achieved by scanning a two-dimensional code, NFC contact, manual input of a PIN code, sensor sensing and the like;
3. the terminal sends a key obtaining request to the key management center, wherein the request message carries a self identifier tID (which can be a mobile phone number, MAC and the like) and a household appliance identifier dID;
4. the key management center judges whether the tID is a legal terminal;
5. the key management center finds a shared key master _ key of the device according to the dID;
6. the key management center generates a time stamp T;
7. the Key management center calculates a private Key Key _ pri according to the master _ Key, the dID, the tID and the T;
8. the Key management center calculates a public Key Key _ pub corresponding to Key _ pri;
9. the Key management center returns Key _ pub and T to the terminal;
10. the terminal encrypts data m to be sent by using Key _ pub to obtain a ciphertext EKey _ pub (m);
11. the terminal sends EKey _ pub (m), tID and T;
12. the household appliance equipment receives EKey _ pub (m), tID and T;
13. the home device verifies that the timestamp is valid;
14. the household appliance calculates a Key Key _ pri according to the master _ Key, the dID, the tID and the T;
15. the Key _ pri is used by the household appliance to decrypt the EKey _ pub (m) to obtain m.
The embodiment of the invention also provides another method for generating the secret key, which specifically comprises the following steps:
the method comprises the steps of setting a shared secret key corresponding to the household appliance in advance according to the household appliance, setting a timestamp after receiving a secret key obtaining request, randomly generating a secret key, encrypting the secret key, an appliance identifier, a terminal identifier and the timestamp through the shared secret key to obtain an encrypted message, and sending the encrypted message and the secret key to the terminal, so that the terminal utilizes the encrypted message and the secret key to carry out safe communication with the household appliance, and the purpose that the household appliance which is disconnected from a network is configured to be accessed to the network or the household appliance which is disconnected from the network is accessed to the network again is achieved.
That is, after receiving the key acquiring request, the key management center of the invention randomly generates a key, encrypts the key with other identifiers and timestamps to obtain an encrypted message, then sends the key and the encrypted message to the terminal, the terminal encrypts the information by using the key, and then sends the encrypted information and the encrypted message to the household appliance, thereby realizing the safe network access of the household appliance.
Fig. 4 is a schematic flow chart of a further method for key generation according to an embodiment of the present invention, which will be described in detail below with reference to fig. 4, and it should be noted that relevant portions of the method can be understood with reference to the method described in fig. 2, and for the sake of brevity, the description is not repeated here:
1. a user logs in a key management center to authenticate the identity of a terminal and establishes a secure channel;
2. the method comprises the steps that a terminal obtains a home appliance identification dID, and the specific obtaining mode can be achieved by scanning a two-dimensional code, NFC contact, manual input of a PIN code, sensor sensing and the like;
3. the terminal sends a key obtaining request to the key management center, wherein the request message carries a self identifier tID (which can be a mobile phone number, MAC and the like) and a household appliance identifier dID;
4. the key management center judges whether the tID is a legal terminal;
5. the key management center finds a shared key master _ key of the device according to the dID;
6. the key management center generates a key KeyD and a time stamp T;
7. the key management center encrypts KeyD, dID, tID and T by using master _ key to obtain Emaster _ key (KeyD, tID, dID and T);
8. the key management center returns KeyD, tID, dID, T and Emaster _ key (KeyD, tID, dID, T) to the terminal;
9. the terminal encrypts data m to be transmitted by using KeyD to obtain a ciphertext EKeyD (m);
10. the terminal sends EKeyD (m), Emaster _ key (KeyD, tID, dID, T);
11. the household appliance receives EKeyD (m), Emaster _ key (KeyD, tID, dID, T);
12. the home appliance equipment decrypts owner _ key (KeyD, tID, dID, T) by using master _ key to obtain KeyD, tID, dID, T;
13. the home device verifies that the timestamp is valid;
14. the home device decrypts the message ekeyd (m) with KeyD to obtain m.
The embodiment of the invention also provides a method for generating the key, which comprises the following steps:
the method comprises the steps of setting a shared secret key corresponding to the household appliance in advance according to the household appliance, setting a timestamp after receiving a secret key obtaining request, randomly generating a pair of public key and private key, encrypting the private key, an appliance identification, a terminal identification and the timestamp through the shared secret key to obtain an encrypted message, using the public key as a final secret key, and sending the encrypted message and the public key to the terminal, so that the terminal utilizes the encrypted message and the public key to carry out safe communication with the household appliance to realize the network access of the household appliance, or to re-access the household appliance disconnected with the network.
Fig. 5 is a flowchart of yet another method for generating a key according to an embodiment of the present invention, which is described below with reference to fig. 5:
1. a user logs in a key management center to authenticate the identity of a terminal and establishes a secure channel;
2. the method comprises the steps that a terminal obtains a home appliance identification dID, and the specific obtaining mode can be achieved by scanning a two-dimensional code, NFC contact, manual input of a PIN code, sensor sensing and the like;
3. the terminal sends a key obtaining request to the key management center, wherein the request message carries a self identifier tID (which can be a mobile phone number, MAC and the like) and a household appliance identifier dID;
4. the key management center judges whether the tID is a legal terminal;
5. the key management center finds a shared key master _ key of the device according to the dID;
6. the Key management center generates a public Key pair Key _ pub, a private Key pair Key _ pri and a time stamp T;
7. the Key management center encrypts Key _ pri, dID, tID and T by using master _ Key to obtain Emaster _ Key (Key _ pri, tID, dID and T);
8. the Key management center returns Key _ pub, tID, dID, T and Emaster _ Key (Key _ pri, tID, dID, T) to the terminal;
9. the terminal encrypts data m to be sent by using Key _ pub to obtain a ciphertext Ekey _ pub (m);
10. the terminal sends Ekey _ pub (m), Emaster _ Key (Key _ pri, tID, dID, T);
11. the household appliance equipment receives Ekey _ pub (m) and Emaster _ Key (Key _ pri, tID, dID and T);
12. the home appliance equipment decrypts owner _ Key (Key _ pri, tID, dID, T) by using master _ Key to obtain Key _ pri, tID, dID, T;
13. the home device verifies that the timestamp is valid;
14. the home appliance device decrypts the message Ekey _ pub (m) with Key _ pri to obtain m.
In summary, the present invention provides a method for a terminal to securely send configuration information to an intelligent home appliance, in which the terminal obtains an identifier of a home appliance, and sends the identifier and the identifier to a key management center to request a key, so as to obtain an encryption key generated by the key management center according to a shared key preset with the home appliance, and the terminal uses the encryption key to encrypt a message and securely transmit the message to the home appliance, thereby greatly reducing the risk of key leakage.
Method embodiment two
Corresponding to the method for key generation introduced in fig. 1, the present embodiment provides a method for parsing encrypted data, where an execution subject of the method is a home device, and referring to fig. 6, an execution subject of the method is a home device, and the method includes:
s601, receiving encrypted data sent by a terminal, wherein the encrypted data is obtained by encrypting preset networking data by the terminal according to a key generated by a key management center, the key is generated by the key management center according to a key acquisition request sent by the terminal, the key uniquely corresponds to the key acquisition request, and the key acquisition request carries an equipment identifier and a terminal identifier;
s602, analyzing the encrypted data to obtain the networking data, and accessing the network according to the networking data.
The keys of the invention are generated by the key management center according to the specific key acquisition request, namely, all the keys are different, thereby greatly reducing the risk of key leakage and further improving the network access safety of the household electrical appliance.
The key described in the embodiment of the present invention may be a key transmitted from the key management center through the terminal, or may be a key generated by the home appliance itself according to a method for generating a key by the key management center.
The encrypted data is obtained by encrypting data or messages by the terminal according to the key produced by the key management center, and after the household appliance receives the encrypted data, the household appliance analyzes the encrypted data to analyze the data or messages and configures an access network according to the data or messages.
The networking data described in the embodiment of the present invention is data for networking the home appliance and the key management center by the terminal, and of course, a person skilled in the art may encrypt other data according to the method described in the present invention as needed, so as to better ensure the security of the data.
The encrypted data is obtained by encrypting data to be transmitted by using a key generated by any one of the methods in the embodiment.
Corresponding to the method flow of key generation in fig. 2, the home appliance device according to the embodiment of the present invention further receives a timestamp and a terminal identifier sent by the terminal;
the analyzing the encrypted data to obtain the networking data in the embodiment of the present invention specifically includes:
obtaining the secret key according to the timestamp, the terminal identification, the equipment identification and the shared secret key, and analyzing the encrypted data according to the secret key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances; the timestamp is a time value set by the key management center after receiving a key acquisition request of the terminal.
That is, the home appliance device in the embodiment of the present invention obtains the key according to the corresponding shared key set by the key management center, the timestamp and the terminal identifier sent by the terminal, and the device identifier of the home appliance device itself, and analyzes the encrypted data according to the key to obtain specific networking data.
Corresponding to the method flow of key generation in fig. 3, the analyzing the encrypted data to obtain the networking data in the method according to the embodiment of the present invention specifically includes:
and obtaining a corresponding public key according to the secret key, and analyzing the encrypted data by taking the public key as a final secret key to obtain the networking data.
Namely, the invention further improves the security of configuring the network access of the household electrical appliance equipment by setting the public key corresponding to the secret key.
Corresponding to the method flow of key generation in fig. 4, the analyzing the encrypted data to obtain the networking data according to the method in the embodiment of the present invention specifically includes:
analyzing the encrypted message according to a shared key to obtain a timestamp and the key, and analyzing the encrypted data according to the key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
That is, the embodiment of the present invention obtains the key by parsing the encrypted message through the shared key.
Corresponding to the method flow of key generation in fig. 5, the analyzing the encrypted data to obtain the networking data in the embodiment of the present invention specifically includes:
analyzing the encrypted message according to a shared key to obtain a timestamp and a private key, obtaining a corresponding public key according to the private key, and analyzing the encrypted data according to the public key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
That is to say, the embodiment of the present invention sets the public and private key to better improve the security of configuring the home appliance to access the network.
After the analyzing the encrypted data to obtain the networking data and before accessing the network according to the networking data, the embodiment of the present invention further includes:
and verifying the timestamp, and accessing the network according to the networking data when the timestamp is verified to be legal.
Namely, the invention can effectively prevent other people from illegally attacking the household appliance by verifying the timestamp in the secret key through the household appliance, thereby further improving the safety of the household appliance accessing the network.
That is to say, the method of the present invention applies the secret key generated by the secret key management center in the first embodiment of the method to perform secure communication with the terminal, thereby greatly improving the security of the home appliance network access.
The key described in the present invention is obtained according to the method in the first method embodiment, and the related content can be understood with reference to the related part of the first method embodiment, which is not described herein again.
Apparatus embodiment one
An embodiment of the present invention provides a key generation apparatus, and referring to fig. 7, the apparatus includes a receiving unit and a generating unit coupled to each other, specifically:
the device comprises a receiving unit, a sending unit and a receiving unit, wherein the receiving unit is used for receiving a key obtaining request sent by a terminal, and the key obtaining request carries an equipment identifier and a terminal identifier;
the generation unit is used for generating a secret key according to the secret key acquisition request and sending the secret key to the terminal, wherein the secret key is used for enabling the terminal to be in safe communication with household appliances so as to connect the household appliances with a network;
wherein the key uniquely corresponds to the get key request.
According to the method and the device, the corresponding key is generated according to the key acquiring request sent by the terminal, so that different key acquiring requests correspond to different keys, the risk of key leakage is greatly reduced, and the problem of low security of network access of the household electrical appliance equipment and network reconnection of the household electrical appliance equipment after network disconnection in the prior art is effectively solved.
In specific implementation, the key obtaining request according to the embodiment of the present invention carries the device identifier dID and the terminal identifier tID, and certainly, a person skilled in the art may also carry other information in the key obtaining request, so as to be used by the key management center to generate a corresponding key, such as setting a number of the key obtaining request, and the like.
The device Identification dID is used for identifying the household electrical appliance to distinguish different household electrical appliances, the device Identification dID is acquired from the household electrical appliance by a terminal, and the specific acquisition method can be realized by scanning a two-dimensional code, Near Field Communication (NFC) contact, Personal Identification Number (PIN) manual input, sensor sensing and other modes.
The embodiment of the present invention further provides a preferred implementation manner, and the apparatus further includes: a setting unit;
the setting unit is used for setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquisition request;
the generating unit is specifically configured to generate the key according to the device identifier, the terminal identifier, the shared key, and the timestamp, and send the key to the terminal, so that the terminal performs secure communication with the home appliance by using the key, and connects the home appliance with a network.
The invention sets different shared keys according to different household appliances in advance, generates the shared keys with the appliance identification, the terminal identification and the timestamp, sends the keys to the terminal, and the terminal encrypts data to be sent to the household appliances by using the keys and sends the encrypted data to the household appliances so as to realize the network access of the household appliances.
It should be noted that, in the embodiment of the present invention, by adding the timestamp and verifying whether the timestamp is valid by the home appliance device, replay attack of others can be effectively prevented, so as to further enhance the security of network access of the home appliance device configured in the present invention and network reconnection of the home appliance device after network disconnection.
The generation unit in the embodiment of the present invention is further configured to generate a key according to the key acquisition request, obtain a corresponding public key according to the generated key, and send the public key to the terminal as a final key, so that the terminal performs secure communication with the home appliance device by using the public key.
Namely, in the embodiment of the invention, the key management center sets the public and private keys so as to further improve the security of the network access of the household electrical appliance after the network access of the household electrical appliance is configured and the network access of the household electrical appliance is reconnected after the network is disconnected.
The embodiment of the present invention further provides another preferred embodiment, and the apparatus of the present invention further includes: a setting unit;
the setting unit is used for setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquisition request;
the generation unit is further configured to randomly generate a secret key after receiving the secret key obtaining request, encrypt the secret key, the device identifier, the terminal identifier, and the timestamp with the shared secret key to obtain an encrypted message, and send the encrypted message and the secret key to the terminal, so that the terminal performs secure communication with the home appliance device by using the encrypted message and the secret key.
That is, after receiving the key acquiring request, the key management center of the present invention randomly generates a key, encrypts the key with other identifiers and timestamps to obtain an encrypted message, and then sends the key and the encrypted message to the terminal, which encrypts the information by using the key and then sends the encrypted information and the encrypted message to the home appliance, thereby achieving better security of the home appliance in the network.
The embodiment of the present invention further provides a preferred embodiment, and the apparatus of the present invention further includes: a setting unit;
the setting unit is used for setting a shared key corresponding to the household appliance according to the household appliance in advance, and setting a timestamp after receiving the key acquisition request;
the generation unit is further used for randomly generating a pair of public key and private key after receiving the key acquisition request, encrypting the private key, the equipment identifier, the terminal identifier and the timestamp through the shared key to obtain an encrypted message, using the public key as a final key, and sending the encrypted message and the public key to the terminal, so that the terminal utilizes the encrypted message and the public key to perform secure communication with the household appliance, and connects the household appliance with a network.
That is, after receiving the key acquisition request, the key management center of the present invention randomly generates a pair of public key and private key, encrypts the private key, the identifier and the timestamp with the shared key to obtain an encrypted message, and sends the encrypted message and the public key to the terminal, thereby realizing secure network access of the configured home appliance.
Relevant parts of the device embodiment of the invention can be understood by referring to the method embodiment part, and are not described herein again.
Device embodiment II
An embodiment of the present invention provides a device for parsing encrypted data, referring to fig. 8, where the device is disposed on a home appliance, and the device includes a receiving module and a parsing module that are coupled to each other, specifically:
the terminal comprises a receiving module, a sending module and a receiving module, wherein the receiving module is used for receiving encrypted data sent by the terminal, the encrypted data is obtained by encrypting preset networking data by the terminal according to a key generated by a key management center, the key is generated by the key management center according to a key acquiring request sent by the terminal, the key uniquely corresponds to the key acquiring request, and the key acquiring request carries an equipment identifier and a terminal identifier;
and the analysis module is used for analyzing the encrypted data to obtain the networking data and accessing the network according to the networking data.
The keys of the invention are generated by the key management center according to the specific key acquisition request, namely, all the keys are different, so that the risk of key leakage is reduced, and the network access safety of the household electrical appliance is improved.
The key described in the embodiment of the present invention may be a key transmitted from the key management center through the terminal, or may be a key generated by the home appliance itself according to a method for generating a key by the key management center.
The encrypted data is obtained by encrypting data to be transmitted by using a key generated by any one of the methods in the embodiment.
Preferably, the receiving module in the embodiment of the present invention is further configured to receive a timestamp and a terminal identifier sent by the terminal;
the analysis is also used for obtaining the key according to the timestamp, the terminal identifier, the equipment identifier and the shared key, and analyzing the encrypted data according to the key to obtain the networking data;
the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
That is, the home appliance device in the embodiment of the present invention obtains the key according to the corresponding shared key set by the key management center, the timestamp and the terminal identifier sent by the terminal, and the device identifier of the home appliance device itself, and analyzes the encrypted data according to the key to obtain specific networking data.
Preferably, the receiving module of the apparatus of the present invention is further configured to receive a timestamp and a terminal identifier sent by the terminal; the analysis module is further configured to obtain a corresponding public key according to the secret key, and analyze the encrypted data using the public key as a final secret key to obtain the networking data.
Namely, the invention further improves the security of configuring the network access of the household electrical appliance equipment by setting the public key corresponding to the secret key.
Preferably, the receiving module of the apparatus according to the embodiment of the present invention is further configured to receive an encrypted message sent by the terminal; the analysis module is further configured to analyze the encrypted message according to a shared key to obtain a timestamp and the key, and analyze the encrypted data according to the key to obtain the networking data; the shared key is preset by the key management center according to household appliances, and the timestamp is the time set by the key management center after receiving a key acquisition request of the terminal.
Preferably, the receiving module of the apparatus according to the embodiment of the present invention is further configured to receive an encrypted message sent by the terminal; the analysis module is further used for analyzing the encrypted message according to a shared secret key to obtain a timestamp and a private key, obtaining a corresponding public key according to the private key, and analyzing the encrypted data according to the public key to obtain the networking data; the shared secret key is preset by the secret key management center according to household appliances, and the timestamp is the time set by the secret key management center after receiving a secret key acquisition request of the terminal.
Preferably, the device of the present invention further comprises a verification module;
and the verification module is used for verifying the timestamp in the secret key and enabling the household appliance to access the network according to the networking data when the timestamp is verified to be legal.
Namely, the invention can effectively prevent other people from illegally attacking the household appliance by verifying the timestamp in the secret key through the household appliance, thereby further improving the safety of the household appliance accessing the network.
That is to say, the method of the present invention applies the secret key generated by the secret key management center in the first embodiment of the method to perform secure communication with the terminal, thereby greatly improving the security of the home appliance network access.
Relevant parts of the device embodiment of the invention can be understood by referring to the method embodiment part, and are not described herein again.
Key management center embodiments
The embodiment of the invention provides a key management center, which comprises any one of the devices in the device embodiments, so that the security of the re-network of the household electrical appliance after the household electrical appliance is configured to access the network and the network is disconnected is improved.
The related content in the embodiments of the present invention can be understood by referring to the apparatus embodiments and the method embodiments, and will not be described herein again.
The invention can at least achieve the following beneficial effects:
1. different terminals or different devices of the invention share different passwords at different times, thereby greatly reducing the risk of secret key leakage;
2. before generating the key, the key management center judges the legality of the terminal, thereby further improving the security of the network access of the household electrical appliance configured and the network re-access of the household electrical appliance after the network is disconnected;
3. the method of the invention adds the timestamp, thereby effectively preventing replay attack of others and improving the safety of the household appliance which is configured to access the network and the household appliance which is disconnected from the network to access the network again to a certain extent.
Although the preferred embodiments of the present invention have been disclosed for illustrative purposes, those skilled in the art will appreciate that various modifications, additions and substitutions are possible, and the scope of the invention should not be limited to the embodiments described above.