WO2017032242A1 - 密钥生成方法及装置 - Google Patents
密钥生成方法及装置 Download PDFInfo
- Publication number
- WO2017032242A1 WO2017032242A1 PCT/CN2016/095522 CN2016095522W WO2017032242A1 WO 2017032242 A1 WO2017032242 A1 WO 2017032242A1 CN 2016095522 W CN2016095522 W CN 2016095522W WO 2017032242 A1 WO2017032242 A1 WO 2017032242A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- factor
- encryption
- encrypted
- shared
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/085—Secret sharing or secret splitting, e.g. threshold schemes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/062—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0478—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload applying multiple layers of encryption, e.g. nested tunnels or encrypting the content with a first key and then with at least a second key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/66—Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0822—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0866—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/062—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying encryption of the keys
Definitions
- the present application relates to the field of network security technologies, and in particular, to a key generation method and apparatus.
- a secure transmission channel is usually established between the terminal device and the gateway device, and between the gateway device and the public network server, and the gateway device will The data is forwarded from one secure channel to another, thereby implementing the function of data forwarding.
- the gateway device needs to decrypt the data encrypted by the terminal device by using the shared key with the terminal device, and then use the server.
- the shared key is encrypted and forwarded to the server, so there is a risk that the gateway device will leak data information.
- the present application provides a new technical solution, which can prevent the gateway device from acquiring the shared key between the two devices, thereby reducing the risk of data being illegally intercepted during network transmission.
- a key generation method is provided, which is applied to a first device, and includes:
- a key generation method is proposed, which is applied to a second device, and includes:
- a key generation apparatus which is applied to a first device, and includes:
- a first encryption module configured to encrypt the first key factor generated by the first device by using an initial key, and send the first key factor to the second device by using a first secure channel, where the initial key is the first a preset key between the device and the second device;
- a first receiving module configured to receive, by using the first secure channel, a second key factor encrypted by the initial key, where the second key factor is generated by the second device;
- a first decryption module configured to decrypt the second key factor that is received by the first receiving module and is encrypted by the initial key, and obtain the second key factor
- a first key generation module configured to generate a shared key of the first device and the second device according to the first key factor and the second key factor obtained by the first decryption module.
- a key generation apparatus which is applied to a second device, and includes:
- a third receiving module configured to receive, by using the second secure channel, a first key factor that is encrypted by the initial key from the first device, where the initial key is the first device and the second device Pre-set key;
- a third decryption module configured to perform the first key factor encrypted by the initial key Decrypting to obtain the first encryption factor
- a second key generating module configured to generate a shared key of the first device and the second device according to the first key factor and a second key factor generated by the second device.
- the first key factor and the second key factor are encrypted by the initial key during the forwarding process of the gateway device, and the initial key is a preset secret between the first device and the second device. a key, so the gateway device does not know the first key factor and the second key factor; and the shared key between the first device and the second device is generated by the first key factor and the second key factor, so that the final The negotiated shared key is only known to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, thereby ensuring more secure transmission of data between the first device and the second device, further reducing data in the data. The risk of being illegally intercepted during transmission.
- FIG. 1 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment of the present invention
- FIG. 2 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 2 of the present invention
- FIG. 3 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 3 of the present invention.
- FIG. 4 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 4 of the present invention.
- FIG. 5 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 5 of the present invention.
- FIG. 6 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 6 of the present invention.
- FIG. 7 is a flow chart showing a key generation method according to an exemplary embodiment 7 of the present invention.
- FIG. 8 illustrates a terminal device and a server to which the present invention is applied according to an exemplary embodiment of the present invention. Schematic diagram of signaling for inter-key negotiation
- FIG. 9 is a schematic diagram of signaling for performing data transmission between a terminal device and a server according to an exemplary embodiment of the present invention.
- FIG. 10 is a schematic structural diagram of a terminal device according to an exemplary embodiment of the present invention.
- FIG. 11 is a block diagram showing the structure of a server according to an exemplary embodiment of the present invention.
- FIG. 12 is a block diagram showing the structure of a key generation apparatus according to an exemplary embodiment of the present invention.
- FIG. 13 is a block diagram showing the structure of a key generation apparatus according to still another exemplary embodiment of the present invention.
- FIG. 14 is a block diagram showing the structure of a key generation apparatus according to still another exemplary embodiment of the present invention.
- FIG. 15 is a block diagram showing the structure of a key generation device according to another exemplary embodiment of the present invention.
- first, second, third, etc. may be used to describe various information in this application, such information should not be limited to these terms. These terms are only used to refer to the same type of information. This area is separate.
- the first information may also be referred to as the second information without departing from the scope of the present application.
- the second information may also be referred to as the first information.
- the word "if” as used herein may be interpreted as "when” or “when” or "in response to a determination.”
- the initial key is preset between the first device and the second device. a key, so the gateway device does not know the first key factor and the second key factor; and the shared key between the first device and the second device is generated by the first key factor and the second key factor, which can be implemented.
- the shared key that is finally negotiated is known only to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, thereby ensuring more secure transmission of data between the first device and the second device, further reducing data. The risk of being illegally intercepted during transmission.
- FIG. 1 is a schematic flowchart of a key generation method according to an exemplary embodiment of the present invention
- a first device may be a terminal device
- a second device may be a server
- a device may be a server
- the second device may be a terminal device.
- the key generation method includes the following steps:
- Step 101 The first key factor generated by the first device is encrypted by using the initial key, and is sent to the second device by using the first secure channel, where the initial key is preset between the first device and the second device. Key
- Step 102 Receive, by using a first secure channel, a second key factor that is encrypted by an initial key, where the second key factor is generated by the second device.
- Step 103 Decrypt a second key factor received through the first secure channel and encrypted by the initial key to obtain a second key factor.
- Step 104 Generate a shared key of the first device and the second device according to the first key factor and the second key factor.
- the initial key K basic device can be put into use before the first, the second to K basic device previously issued to the first device, can be issued to the first device by means of hardware write .
- the first device and the second device forward the related data information by using the gateway device, where the first secure channel may be established by the first device and the gateway device, and the related data information is transmitted through the first secure channel.
- the second secure channel may be established by the server in consultation with the gateway device, and the related data information is transmitted through the second secure channel.
- SSL Secure Socket Layer
- TLS Key agreement mechanism of Transport Layer Security
- the first key factor when the first device needs to initiate a key negotiation process to the second device, the first key factor is generated by using a pseudo-random function, and the first key factor is encrypted by using the initial key to obtain the first time.
- the first key factor after the encryption is encrypted by using the first encryption key of the first secure channel to obtain the first key factor after the second encryption.
- step 103 the double-encrypted second key factor is decrypted by using the first encryption key to obtain the second decrypted second key factor, and the first key is used to decrypt the second key.
- the key factor is decrypted to obtain a second key factor. Since the second key factor has been double encrypted at the second device, the second key factor is not known at the gateway device, avoiding the risk of the second key factor being illegally intercepted on the gateway device side.
- the gateway device does not know the first key factor and the second key factor; and the first key factor and the second key factor generate a shared key between the first device and the second device, so that final negotiation can be implemented.
- the shared key is known only to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, thereby ensuring more secure transmission of data between the first device and the second device, further reducing data transmission. The risk of being illegally intercepted in the process.
- FIG. 2 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment of the present invention.
- the key factor is used as an example to generate a shared key between the first device and the second device.
- the key generation method includes the following steps:
- Step 201 Determine an initial key shared between the first device and the second device and a device identifier of the first device.
- Step 202 Connect the initial key, the device identifier, the first key factor, and the second key factor in sequence to obtain a combined string.
- Step 203 the combined string is divided into two substrings of equal length
- Step 204 Perform hash operations on the two substrings to obtain two hash results.
- Step 205 XOR the two hash results in bits to obtain a shared key between the first device and the second device.
- the first device After the first device obtains the second key factor through step 104 in the embodiment shown in FIG. 1, the first device has the first key factor p and the second key factor q.
- the first device may take the first key factor and the second key factor as inputs, and use the shared key generation algorithm to obtain the key K AC .
- the key generation algorithm is as follows:
- K AC KeyGenerate(K basic , "Shared Key", p, q);
- the K basic is the initial key
- the Shared Key is the device identifier of the first device
- the device identifier may be the device serial number of the first device, or the MAC address, or a combination of the two, etc., as long as The second device can be made to distinguish the first device from the other device by using the device identifier.
- the string corresponding to the first encryption key K basic , "Shared Key", p, q may be sequentially connected to obtain a combined string, and the combined string utilization function is used.
- KeyGenerate generates a shared key K AC .
- the process implemented by the function KeyGenerate may specifically be: dividing the input combined string into two substrings of equal length (if the length of the combined string is an odd number, then the last one of the combined string) Bit complement 1), then hash operation is performed on each of the two substrings (for example, MD5), and the obtained two calculation results are XORed by bits, and the obtained result is the shared key K AC .
- the length of the shared key K AC is 128 bits, which simplifies the complexity of shared key calculation. Since the calculation of the shared key K AC uses MD5, the amount of calculation can be tolerated for the first device with limited computing power.
- the shared key K AC is generated by using the first key factor, the second key factor, the initial key, and the device identifier of the first device, thereby implementing the pass between the first device and the second device.
- the shared key K AC is negotiated and shared securely, and the shared key K AC is unknown to the gateway device as the intermediate node, so it can be ensured that the first device can use the shared key K AC to transmit data to the second device. Encryption ensures the security of the data during network transmission.
- FIG. 3 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 3 of the present invention.
- the key generation method includes the following steps:
- Step 301 Determine a replacement period of the shared key of the first device and the second device.
- Step 302 re-determining the first encryption factor and the second encryption factor according to the replacement period
- Step 303 Replace the shared key of the first device and the second device according to the re-determined first encryption factor and the second encryption factor.
- the first and second devices may agree on a shared key K AC replacement cycle, when using a shared key K AC replacement cycle duration corresponding to relaunch between the first and second devices
- the process of generating the shared key K AC can further ensure the security of the shared key K AC and the data in the network transmission process, and further reduce the possibility that the shared key K AC is cracked.
- FIG. 4 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment of the present invention.
- the first device may be transmitted through the shared key.
- the data is encrypted and transmitted to the second device.
- the process of encrypting and transmitting the data to be transmitted includes the following steps:
- Step 401 Determine data to be transmitted that is sent by the first device to the second device.
- Step 402 Encrypt the data to be transmitted by using the shared key, and pass the first security pass.
- the channel is sent to the second device;
- Step 403 Receive, by using the first security, response data generated by the second device after receiving the data to be transmitted, and the response data has been encrypted by the shared key.
- Step 404 decrypt the response data encrypted by the shared key by using the shared key to obtain response data.
- the data to be transmitted may be the Internet of Things data acquired by the sensor on the first device.
- step 404 when the response data encrypted by the shared key is received through the first secure channel, the response data encrypted by the shared key may be decrypted first through the first encryption key of the first secure channel, and then passed.
- the shared key decrypts the response data a second time to obtain the original response data.
- the gateway device since the data to be transmitted is encrypted by the shared key in the forwarding process of the gateway device, and the shared key is a key negotiated between the first device and the second device, the gateway device cannot be known.
- the shared key can ensure that the data to be transmitted is transmitted more securely between the first device and the second device, further reducing the risk of data being illegally intercepted during transmission.
- FIG. 5 is a schematic flowchart of a key generation method according to an exemplary embodiment 5 of the present invention.
- the first device may be a terminal device
- the second device may be a server.
- the key generation method includes the following steps:
- Step 501 Receive, by using a second secure channel, a first key factor that is encrypted by an initial key from a first device, where the initial key is a preset key between the first device and the second device;
- Step 502 Decrypt a first key factor that has been encrypted by an initial key to obtain a first encryption factor.
- Step 503 Generate a shared key of the first device and the second device according to the first key factor and the second key factor generated by the second device.
- step 501 For a description of the second secure channel in step 501, refer to the phase of the embodiment shown in FIG. 1 above. The description is not detailed here.
- the first key encrypted by the initial key may be first passed through the second encryption key of the second secure channel.
- the factor is decrypted, and then the first key factor is decrypted a second time by the initial key, thereby obtaining the original first key factor.
- the gateway device does not know the first key factor and the second key factor; and the first key factor and the second key factor generate a shared key between the first device and the second device, so that final negotiation can be implemented.
- the shared key is known only to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, thereby ensuring more secure transmission of data between the first device and the second device, further reducing data transmission. The risk of being illegally intercepted in the process.
- FIG. 6 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 6 of the present invention. As shown in FIG. 6, the key generation method includes the following steps:
- Step 601 Encrypt the second key factor generated by the second device by using an initial key.
- Step 602 Send the second key factor encrypted by the initial key to the first device by using the second secure channel.
- the second key factor encrypted by the initial key is used for the second encryption by using the second encryption key of the second secure channel, so that the gateway device can be sent in the process of sending to the first device.
- the second key factor is not known to the gateway device when forwarding, and the risk of the second key factor being illegally intercepted on the gateway device side is avoided.
- FIG. 7 is a schematic flowchart diagram of a key generation method according to an exemplary embodiment 7 of the present invention. As shown in FIG. 7, the key generation method includes the following steps:
- Step 701 Receive, through the second secure channel, the shared key encrypted by the first device. Data to be transmitted;
- Step 702 decrypt the data to be transmitted by using the shared key
- Step 703 After receiving the data to be transmitted, generate response data.
- Step 704 Encrypt the response data by using the shared key.
- Step 705 Send the response data encrypted by the shared key to the first device by using the second secure channel.
- step 701 For a description of the second security channel in step 701, refer to the related description of the embodiment shown in FIG. 1 above, which is not described in detail herein.
- step 704 after receiving the data to be transmitted from the first device through the second secure channel, the data to be transmitted through the shared key is decrypted by the shared key to obtain the original data, and the first device is required to be When the response is received, the response data encrypted by the shared key may be encrypted by the second encryption key of the second secure channel, so that the gateway device cannot obtain the original response data during the process of forwarding the response data.
- the gateway device since the data to be transmitted is encrypted by the shared key in the forwarding process of the gateway device, and the shared key is a key negotiated between the first device and the second device, the gateway device cannot be known.
- the shared key can ensure that the data to be transmitted is transmitted more securely between the first device and the second device, further reducing the risk of data being illegally intercepted during transmission.
- the shared key may be generated by the key generation algorithm based on the initial key preset between the first device and the second device, and finally the data to be transmitted is encrypted by using the shared key. Therefore, the gateway device cannot view the original data when forwarding data in the network, thereby achieving the purpose of securely transmitting data.
- FIG. 8 is a schematic diagram of signaling of a key agreement between a terminal device and a server according to an exemplary embodiment of the present invention.
- the first device is a terminal device
- the second device is a server.
- the server needs to issue an initial key (K basic ) to the terminal device in advance, and can be issued to the terminal device by means of hardware writing, as shown in FIG. 8 , the terminal device and the server Performing key agreement includes the following steps:
- Step 801 The terminal device negotiates a first encryption key (K AB ) of the first secure channel with the gateway device, and establishes a first secure channel between the terminal device and the gateway device.
- K AB first encryption key
- Step 802 The gateway device negotiates a second encryption key (K BC ) of the second secure channel with the server, and establishes a second secure channel. Similar to the foregoing step 801, the process of establishing the second secure channel can be referred to the related description of the related art, and the key negotiation mechanism of SSL and TLS can also be adopted. Those skilled in the art can understand that the order of step 801 and step 802 can be interchanged, and the execution order can be set according to the requirements of actual execution.
- K BC second encryption key
- Step 803 The terminal device prepares to initiate a key negotiation process with the server, and the terminal device generates a first key factor (p), where the first key factor is used to generate a shared key between the terminal device and the server.
- the first key factor is encrypted with the initial key (K basic ) to obtain K basic (p), and then encrypted with the first encryption key K AB to obtain K AB [K basic (p)].
- Step 804 The terminal device sends the double-encrypted first key factor K AB [K basic (p)] to the gateway device through the first secure channel.
- Step 805 After receiving the double-encrypted first key factor K AB [K basic (p)], the gateway device uses the first encryption key K AB of the first secure channel to pair the double-encrypted first key.
- the factor K AB [K basic (p)] is decrypted to obtain K basic (p), and then encrypted by the third encryption key K BC of the second secure channel to obtain double-encrypted K BC [K basic (p) ].
- Step 806 the first key factor K BC [K basic (p)] double encrypted by the initial key and the second encryption key is sent to the server through the second secure channel.
- Step 807 After receiving the double-encrypted first key factor, the server decrypts the double-encrypted first key factor by using the second encryption key K BC of the second secure channel to obtain K basic (p). The K basic (p) is then decrypted using the initial key K basic to obtain the first key factor p.
- Step 808 the server generates a second key factor (q) by using a pseudo-random function, and the second key factor q will be used together with the first key factor p as a parameter to generate a shared key K AC .
- Step 809 the server uses the second initial encrypted encryption key K basic factor q, to give K basic (q), and then using a second encryption key K BC (q) to K basic encryption, to give K BC [K basic (q) ].
- Step 810 The server sends the double-encrypted second key factor K BC [K basic (q)] to the gateway device through the second secure channel.
- Step 811 after receiving the double-encrypted second key factor K BC [K basic (q)], the gateway device performs the double-encrypted second encryption factor by using the second encryption key K BC of the second secure channel. Decrypting, obtaining K basic (q), and then encrypting with the first encryption key K AB of the first secure channel to obtain K AB [K basic (q)], and then passing the double encrypted second encryption factor through the first The secure channel is sent to the terminal device.
- Step 812 After receiving the double-encrypted second encryption factor, the terminal device decrypts the double-encrypted second encryption factor by using the first encryption key K AB of the first secure channel to obtain K basic (q). Then, the first decrypted K basic (q) is secondarily decrypted by the first encryption key K basic to obtain a second key factor q.
- Step 813 The terminal device and the server share the first key factor p and the second key factor q, and the terminal device and the server respectively input the first key factor and the second key factor, and adopt a key generation algorithm. Obtain the shared key K AC between the terminal device and the server.
- the key generation algorithm refer to the related description of the embodiment shown in FIG. 2, which is not described in detail herein.
- the security negotiation and sharing between the terminal device and the public network server is implemented by the shared key K AC , and the shared key pair is unknown to the gateway device of the intermediate node, and then the terminal device can utilize the sharing.
- the key encrypts the Internet of Things data sent to the public network server to ensure the security of data transmission.
- the terminal device can periodically perform a key agreement process with the server to replace the shared key K AC , so that the possibility that the shared key is cracked can be further reduced.
- FIG. 9 is a schematic flowchart diagram of a data transmission method according to an exemplary embodiment of the present invention. After the shared secret key is generated by using the foregoing embodiment shown in FIG. 8, the terminal device needs to send the Internet of Things data to the server. As shown in FIG. 9, the data transmission method includes the following steps:
- Step 901 Encrypt the Internet of Things data once using the shared key K AC to obtain the ciphertext K AC (data), and then use the first encryption key K AB of the first secure channel to perform secondary encryption to obtain the ciphertext K AB [ K AC (data)].
- Step 902 The terminal device sends the ciphertext K AB [K AC (data)] to the gateway device by using the first secure channel.
- Step 903 After receiving the ciphertext K AB [K AC (data)], the gateway device decrypts using the first security key K AB to obtain K AC (data), and then encrypts using the second encryption key K BC to obtain ⁇ K BC [K AC (data)].
- Step 904 The gateway device sends the ciphertext K BC [K AC (data)] to the server through the second secure channel.
- Step 905 after receiving the double-encrypted ciphertext K BC [K AC (data)], the server decrypts using the second encryption key K BC to obtain K AC (data), and then decrypts using the shared key K AC to obtain The original IoT data data.
- Step 906 After obtaining the original IoT data, the server generates response data (res), encrypts the response data by using the shared key K AC , obtains ciphertext K AC (res), and then uses the second encryption key K BC Secondary encryption, get K BC [K AC (res)].
- Step 907 The server sends the double-encrypted ciphertext K BC [K AC (res)] to the gateway device through the second secure channel.
- Step 908 after receiving the double-encrypted ciphertext K BC [K AC (res)], the gateway device decrypts using the second encryption key K BC to obtain K AC (res), and then uses the first encryption key K AB Encryption is performed to obtain ciphertext K AB [K AC (res)].
- Step 909 The gateway device sends the double-encrypted ciphertext K AB [K AC (res)] to the terminal device through the first secure channel.
- Step 910 After receiving the double-encrypted ciphertext K AB [K AC (res], the terminal device decrypts using the first encryption key K AB to obtain K AC (res), and then decrypts using the shared key K AC to obtain Raw response data (res).
- the key device negotiates and shares the cross-domain between the gateway device and the server of the intermediate node, and the shared key is unknown to the gateway device, ensuring that the Internet of Things data is in the End-to-end secure transmission between the terminal device and the server; in addition, in addition to ensuring secure transmission of data between the terminal device and the gateway device and secure transmission of data between the gateway device and the public network server, the data is forwarded within the gateway device on the transmission path
- the process is also protected by security. Even if the gateway device is illegally invaded, the Internet of Things data forwarded via the gateway device is still protected by the shared key encryption, preventing the Internet of Things data from being illegally intercepted.
- the present application also proposes a schematic structural diagram of the terminal device according to an exemplary embodiment of the present application shown in FIG.
- the network server includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may of course include hardware required for other services.
- the processor reads the corresponding computer program from the non-volatile memory into memory and then runs to form a key generation device at a logical level.
- the present application does not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc., that is, the execution body of the following processing flow is not limited to each logical unit, and may be Hardware or logic device.
- the present application also proposes a schematic structural diagram of the server according to an exemplary embodiment of the present application shown in FIG.
- the network server includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may of course include hardware required for other services.
- the processor reads the corresponding computer program from the non-volatile memory into memory and then runs to form a key generation device at a logical level.
- the present application does not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc., that is, the execution body of the following processing flow is not limited to each logical unit, and may be Hardware or logic device.
- FIG. 12 is a schematic structural diagram of a key generation apparatus according to an exemplary embodiment of the present invention. As shown in FIG. 12, the key generation apparatus may include: a first encryption module 1201, a first reception module 1202, and a first A decryption module 1203, a first key generation module 1204. among them:
- the first encryption module 1201 is configured to encrypt the first key factor generated by the first device by using the initial key, and send the first key factor to the second device by using the first secure channel, where the initial key is the first device and the second device. a preset key between;
- the first receiving module 1202 is configured to receive, by using the first secure channel, a second key factor that is encrypted by using an initial key, where the second key factor is generated by the second device;
- the first decryption module 1203 is configured to decrypt the second key factor that is received by the first receiving module 1202 through the first secure channel and is encrypted by the initial key to obtain a second key factor.
- the first key generation module 1204 is configured to generate a shared key of the first device and the second device according to the first key factor and the second key factor decrypted by the first decryption module 1203.
- FIG. 13 is a schematic structural diagram of a key generation apparatus according to still another exemplary embodiment of the present invention.
- the first encryption module 1201 may include:
- a first factor generating unit 12011 configured to generate a first key factor by using a pseudo-random function when the first device needs to initiate a key negotiation process to the second device;
- the first encryption unit 12012 is configured to encrypt the first key factor generated by the first factor generating unit 12011 by using an initial key to obtain a first key factor after the first encryption;
- the second encryption unit 12013 is configured to encrypt the first key factor after the first encryption by the first encryption unit 12012 by using the first encryption key of the first secure channel, to obtain the first key after the second encryption. factor.
- the first decryption module 1203 includes:
- the first decryption unit 12031 is configured to decrypt the double-encrypted second key factor by using the first encryption key to obtain a second key factor after the first decryption;
- the second encryption unit 12032 is configured to decrypt the second key factor after the first decryption by the first decryption unit 12031 by using the initial key to obtain a second key factor.
- the first key generation module 1204 can include:
- a first determining unit 12041 configured to determine a first encryption key shared between the first device and the second device, and a device identifier of the first device;
- the first factor generating unit 12042 is configured to generate, according to the first encryption key, the device identifier determined by the first determining unit 12041, the first key factor, and the second key factor obtained by the first decrypting module 1203, the first device and the first The shared key of the second device.
- the first factor generating unit is specifically configured to:
- the two hash results are XORed by bits to obtain a shared key between the first device and the second device.
- the apparatus may further include:
- the first determining module 1205 is configured to determine a replacement period of the shared key of the first device and the second device;
- the second determining module 1206 is configured to re-determine the first encryption factor and the second encryption factor according to the replacement period determined by the first determining module 1205;
- the first replacement module 1207 is configured to replace the shared key of the first device and the second device according to the first encryption factor and the second encryption factor that are determined by the second determining module 1206.
- the apparatus may further include:
- a third determining module 1208, configured to determine data to be transmitted that is sent by the first device to the second device;
- the data encryption module 1209 is configured to encrypt the data to be transmitted determined by the third determining module 1208 by using the shared key, and send the data to the second device through the first secure channel.
- the apparatus may further include:
- the second receiving module 1210 is configured to receive, by using the first security, the response data generated by the second device after receiving the data to be transmitted, where the response data has been encrypted by the shared key;
- the second decryption module 1211 is configured to decrypt the response data encrypted by the shared key by using the shared key to obtain response data.
- FIG. 14 is a schematic structural diagram of a key generation apparatus according to still another exemplary embodiment of the present invention. As shown in FIG. 14, the key generation apparatus may include: a third receiving module 1401, a third decryption module 1402. The second key generation module 1403. among them:
- the third receiving module 1401 is configured to receive, by using the second secure channel, a first key factor that is encrypted by the initial key from the first device, where the initial key is a preset secret between the first device and the second device. key;
- a third decryption module 1402 configured to decrypt the first key factor encrypted by the initial key to obtain a first encryption factor
- a second key generation module 1403 configured to generate a shared key of the first device and the second device according to the first key factor and the second key factor generated by the second device
- FIG. 15 is a schematic structural diagram of a key generation apparatus according to another exemplary embodiment of the present invention. As shown in FIG. 15, on the basis of the foregoing embodiment shown in FIG. 14, the second key generation module 1403 is specific. Used for:
- the two hash results are XORed by bits to obtain a shared key between the first device and the second device.
- the apparatus may further include:
- a second encryption module 1404 configured to encrypt, by using an initial key, a second key factor generated by the second device
- the first sending module 1405 is configured to send, by using the second secure channel, the second key factor after being encrypted by the initial key to the first device.
- the apparatus may further include:
- a third determining module 1406, configured to determine a replacement period of the shared key of the first device and the second device
- a fourth determining module 1407 configured to re-determine the first encryption factor and the second encryption factor according to the replacement period
- a second replacement module 1408, configured to determine, according to the re-determined first encryption factor and the second encryption factor Replace the shared key of the first device and the second device.
- the apparatus may further include:
- the fourth receiving module 1409 is configured to receive, by using the second secure channel, the data to be transmitted encrypted by the shared key from the first device;
- the fourth decryption module 1410 is configured to decrypt the data to be transmitted by using the shared key.
- the apparatus may further include:
- the response data generating module 1411 is configured to generate response data after receiving the data to be transmitted;
- the third encryption module 1412 is configured to encrypt the response data by using the shared key
- the second sending module 1413 is configured to send the response data encrypted by the shared key to the first device by using the second secure channel.
- the first key factor and the second key factor are encrypted by the initial key during the forwarding process of the gateway device, and the initial key is a preset key between the first device and the second device. Therefore, the gateway device does not know the first key factor and the second key factor; and the first key factor and the second key factor generate a shared key between the first device and the second device, so that final negotiation can be implemented.
- the shared key is known only to the first device and the second device, and the gateway device still cannot obtain the negotiated shared key, thereby ensuring more secure transmission of data between the first device and the second device, further reducing data transmission. The risk of being illegally intercepted in the process.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (28)
- 一种密钥生成方法,应用在第一设备上,其特征在于,所述方法包括:采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通过第一安全通道发送给第二设备,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥;通过所述第一安全通道接收经过所述初始密钥加密的第二密钥因子,其中,所述第二密钥因子由所述第二设备生成;对通过所述第一安全通道接收到的经过所述初始密钥加密的所述第二密钥因子进行解密,得到所述第二密钥因子;根据所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 根据权利要求1所述的方法,其特征在于,所述采用初始密钥对所述第一设备生成的第一密钥因子进行加密,包括:在所述第一设备需要向第二设备发起密钥协商流程时,通过伪随机函数生成第一密钥因子;采用初始密钥对所述第一密钥因子进行加密,得到第一次加密后的所述第一密钥因子;采用第一安全通道的第一加密密钥对所述第一次加密后的所述第一密钥因子进行加密,得到第二次加密后的所述第一密钥因子。
- 根据权利要求1所述的方法,其特征在于,所述对通过所述第一安全通道接收到的经过所述第一加密密钥加密的所述第二密钥因子进行解密,包括:采用所述第一加密密钥对经过双重加密的所述第二密钥因子进行解密,得到第一次解密后的所述第二密钥因子;采用所述初始密钥对所述第一次解密后的所述第二密钥因子进行解密,得到所述第二密钥因子。
- 根据权利要求1所述的方法,其特征在于,所述根据所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密钥,包括:确定所述第一设备与所述第二设备之间共享的初始密钥和所述第一设备的设备标识;根据所述初始密钥、所述设备标识、所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 根据权利要求4所述的方法,其特征在于,所述根据所述设备标识、所述第一加密密钥、所述第一密钥因子、所述第二密钥因子生成所述第一设备与第二设备的共享密钥,包括:将所述第一加密密钥、所述设备标识、所述第一密钥因子、所述第二密钥因子依次连接,得到组合字串;将所述组合字串切分为长度相等的两个子字串;对所述两个子字串分别进行散列运算,得到两个散列结果;将所述两个散列结果以位进行异或运算,得到所述第一设备与第二设备的共享密钥。
- 根据权利要求1所述的方法,其特征在于,所述方法还包括:确定所述第一设备与所述第二设备的共享密钥的更换周期;根据所述更换周期重新确定所述第一加密因子和所述第二加密因子;根据重新确定的所述第一加密因子和所述第二加密因子更换所述第一设备与所述第二设备的共享密钥。
- 根据权利要求1-6任一所述的方法,其特征在于,所述方法还包括:确定所述第一设备需要向所述第二设备发送的待传输的数据;采用所述共享密钥对所述待传输的数据进行加密,并通过所述第一安全通道发送给所述第二设备。
- 根据权利要求7所述的方法,其特征在于,所述方法还包括:通过所述第一安全通过接收所述第二设备在接收到所述待传输的数据生成的响应数据,所述响应数据已经经过所述共享密钥加密;采用所述共享密钥对所述经过所述共享密钥加密的所述响应数据进行解密,得到所述响应数据。
- 一种密钥生成方法,应用在第二设备上,其特征在于,所述方法包括:通过第二安全通道接收来自第一设备的经过初始密钥加密的第一密钥因子,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥;对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所述第一加密因子;根据所述第一密钥因子、所述第二设备生成的第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 根据权利要求9所述的方法,其特征在于,所述根据所述第一密钥因子、所述第二设备生成的第二密钥因子生成所述第一设备与第二设备的共享密钥,包括:将所述第一加密密钥、所述第一设备的设备标识、所述第一密钥因子、所述第二密钥因子依次连接,得到组合字串;将所述组合字串切分为长度相等的两个子字串;对所述两个子字串分别进行散列运算,得到两个散列结果;将所述两个散列结果以位进行异或运算,得到所述第一设备与第二设备的共享密钥。
- 根据权利要求9所述的方法,其特征在于,所述方法还包括:采用所述初始密钥对所述第二设备生成的第二密钥因子进行加密;通过所述第二安全通道将所述经过所述初始密钥加密后的所述第二密钥因子发送给所述第一设备。
- 根据权利要求9所述的方法,其特征在于,所述方法还包括:确定所述第一设备与所述第二设备的共享密钥的更换周期;根据所述更换周期重新确定所述第一加密因子和所述第二加密因子;根据重新确定的所述第一加密因子和所述第二加密因子更换所述第一设备与所述第二设备的共享密钥。
- 根据权利要求9-12任一所述的方法,其特征在于,所述方法还包括:通过第二安全通道接收来自所述第一设备的经过所述共享密钥加密的待传输的数据;采用所述共享密钥对所述待传输的数据进行解密。
- 根据权利要求13所述的方法,其特征在于,所述方法还包括:在接收到所述待传输的数据后,生成响应数据;通过所述共享密钥对所述响应数据进行加密;通过所述第二安全通道向所述第一设备发送经过所述共享密钥加密的响应数据。
- 一种密钥生成装置,应用在第一设备上,其特征在于,所述装置包括:第一加密模块,用于采用初始密钥对所述第一设备生成的第一密钥因子进行加密并通过第一安全通道发送给第二设备,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥;第一接收模块,用于通过所述第一安全通道接收经过所述初始密钥加密的第二密钥因子,其中,所述第二密钥因子由所述第二设备生成;第一解密模块,用于对通过所述第一接收模块通过所述第一安全通道接收到的经过所述初始密钥加密的所述第二密钥因子进行解密,得到所述第二密钥因子;第一密钥生成模块,用于根据所述第一密钥因子、所述第一解密模块解密得到的所述第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 根据权利要求15所述的装置,其特征在于,所述第一加密模块包括:第一因子生成单元,用于在所述第一设备需要向第二设备发起密钥协商流程时,通过伪随机函数生成第一密钥因子;第一加密单元,用于采用初始密钥对所述第一因子生成单元生成的所述第一密钥因子进行加密,得到第一次加密后的所述第一密钥因子;第二加密单元,用于采用第一安全通道的第一加密密钥对所述第一加密 单元第一次加密后的所述第一密钥因子进行加密,得到第二次加密后的所述第一密钥因子。
- 根据权利要求15所述的装置,其特征在于,所述第一解密模块包括:第一解密单元,用于采用所述第一加密密钥对经过双重加密的所述第二密钥因子进行解密,得到第一次解密后的所述第二密钥因子;第二加密单元,用于采用所述初始密钥对所述第一解密单元第一次解密后的所述第二密钥因子进行解密,得到所述第二密钥因子。
- 根据权利要求15所述的装置,其特征在于,所述第一密钥生成模块包括:第一确定单元,用于确定所述第一设备与所述第二设备之间共享的第一加密密钥和所述第一设备的设备标识;第一因子生成单元,用于根据所述第一加密密钥、所述第一确定单元确定的所述设备标识、所述第一密钥因子、所述第一解密模块得到的所述第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 根据权利要求18所述的装置,其特征在于,所述第一因子生成单元具体用于:将所述第一加密密钥、所述设备标识、所述第一密钥因子、所述第二密钥因子依次连接,得到组合字串;将所述组合字串切分为长度相等的两个子字串;对所述两个子字串分别进行散列运算,得到两个散列结果;将所述两个散列结果以位进行异或运算,得到所述第一设备与第二设备的共享密钥。
- 根据权利要求15所述的装置,其特征在于,所述装置还包括:第一确定模块,用于确定所述第一设备与所述第二设备的共享密钥的更换周期;第二确定模块,用于根据所述第一确定模块确定的所述更换周期重新确定所述第一加密因子和所述第二加密因子;第一更换模块,用于根据所述第二确定模块重新确定的所述第一加密因子和所述第二加密因子更换所述第一设备与所述第二设备的共享密钥。
- 根据权利要求15-20任一所述的装置,其特征在于,所述装置还包括:第三确定模块,用于确定所述第一设备需要向所述第二设备发送的待传输的数据;数据加密模块,用于采用所述共享密钥对所述第三确定模块确定的所述待传输的数据进行加密,并通过所述第一安全通道发送给所述第二设备。
- 根据权利要求21所述的装置,其特征在于,所述装置还包括:第二接收模块,用于通过所述第一安全通过接收所述第二设备在接收到所述待传输的数据生成的响应数据,所述响应数据已经经过所述共享密钥加密;第二解密模块,用于采用所述共享密钥对所述经过所述共享密钥加密的所述响应数据进行解密,得到所述响应数据。
- 一种密钥生成装置,应用在第二设备上,其特征在于,所述装置包括:第三接收模块,用于通过第二安全通道接收来自第一设备的经过初始密钥加密的第一密钥因子,其中,所述初始密钥为所述第一设备与所述第二设备之间预设的密钥;第三解密模块,用于对经过所述初始密钥加密的所述第一密钥因子进行解密,得到所述第一加密因子;第二密钥生成模块,用于根据所述第一密钥因子、所述第二设备生成的第二密钥因子生成所述第一设备与第二设备的共享密钥。
- 根据权利要求23所述的装置,其特征在于,所述第二密钥生成模块具体用于:将所述第一加密密钥、所述第一设备的设备标识、所述第一密钥因子、所述第二密钥因子依次连接,得到组合字串;将所述组合字串切分为长度相等的两个子字串;对所述两个子字串分别进行散列运算,得到两个散列结果;将所述两个散列结果以位进行异或运算,得到所述第一设备与第二设备的共享密钥。
- 根据权利要求24所述的装置,其特征在于,所述装置还包括:第二加密模块,用于采用所述初始密钥对所述第二设备生成的第二密钥因子进行加密;第一发送模块,用于通过所述第二安全通道将所述经过所述初始密钥加密后的所述第二密钥因子发送给所述第一设备。
- 根据权利要求25所述的装置,其特征在于,所述装置还包括:第三确定模块,用于确定所述第一设备与所述第二设备的共享密钥的更换周期;第四确定模块,用于根据所述更换周期重新确定所述第一加密因子和所述第二加密因子;第二更换模块,用于根据重新确定的所述第一加密因子和所述第二加密因子更换所述第一设备与所述第二设备的共享密钥。
- 根据权利要求23-26任一所述的装置,其特征在于,所述装置还包括:第四接收模块,用于通过第二安全通道接收来自所述第一设备的经过所述共享密钥加密的待传输的数据;第四解密模块,用于采用所述共享密钥对所述待传输的数据进行解密。
- 根据权利要求27所述的装置,其特征在于,所述装置还包括:响应数据生成模块,用于在接收到所述待传输的数据后,生成响应数据;第三加密模块,用于通过所述共享密钥对所述响应数据进行加密;第二发送模块,用于通过所述第二安全通道向所述第一设备发送经过所述共享密钥加密的响应数据。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2018508212A JP2018529271A (ja) | 2015-08-26 | 2016-08-16 | 二重暗号化を用いたキー生成方法および装置 |
| US15/752,743 US10693634B2 (en) | 2015-08-26 | 2016-08-16 | Key generation method and apparatus using double encryption |
| US16/901,261 US11463243B2 (en) | 2015-08-26 | 2020-06-15 | Key generation method and apparatus using double encryption |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510531892.2 | 2015-08-26 | ||
| CN201510531892.2A CN106487749B (zh) | 2015-08-26 | 2015-08-26 | 密钥生成方法及装置 |
Related Child Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US15/752,743 A-371-Of-International US10693634B2 (en) | 2015-08-26 | 2016-08-16 | Key generation method and apparatus using double encryption |
| US16/901,261 Continuation US11463243B2 (en) | 2015-08-26 | 2020-06-15 | Key generation method and apparatus using double encryption |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017032242A1 true WO2017032242A1 (zh) | 2017-03-02 |
Family
ID=58099579
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/095522 Ceased WO2017032242A1 (zh) | 2015-08-26 | 2016-08-16 | 密钥生成方法及装置 |
Country Status (4)
| Country | Link |
|---|---|
| US (2) | US10693634B2 (zh) |
| JP (1) | JP2018529271A (zh) |
| CN (1) | CN106487749B (zh) |
| WO (1) | WO2017032242A1 (zh) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2018022805A1 (en) * | 2016-07-29 | 2018-02-01 | Alibaba Group Holding Limited | Hypertext transfer protocol secure (https) based packet processing methods and apparatuses |
| CN111193797A (zh) * | 2019-12-30 | 2020-05-22 | 海尔优家智能科技(北京)有限公司 | 具有可信计算架构的物联网操作系统的信息处理方法 |
| CN114244630A (zh) * | 2022-02-15 | 2022-03-25 | 北京指掌易科技有限公司 | 一种通信方法、装置、设备以及存储介质 |
| CN114553552A (zh) * | 2022-02-24 | 2022-05-27 | 北京小米移动软件有限公司 | 数据加密方法和装置、数据解密方法和装置及存储介质 |
Families Citing this family (26)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CA2813758C (en) * | 2010-10-08 | 2023-01-03 | Brian Lee Moffat | Private data sharing system |
| US10691837B1 (en) * | 2017-06-02 | 2020-06-23 | Apple Inc. | Multi-user storage volume encryption via secure enclave |
| CN108243181A (zh) * | 2017-10-09 | 2018-07-03 | 北京车和家信息技术有限公司 | 一种车联网终端、数据加密方法及车联网服务器 |
| US10999265B2 (en) * | 2017-11-15 | 2021-05-04 | Team One International Holding Pte Ltd. | Method and system for deploying wireless IoT sensor nodes |
| CN107808284B (zh) * | 2017-11-17 | 2021-12-28 | 上海瀚银信息技术有限公司 | 一种基于pos机系统的支付方法 |
| CN108667598B (zh) * | 2018-04-28 | 2021-10-15 | 克洛斯比尔有限公司 | 用于实现安全密钥交换的设备和方法及安全密钥交换方法 |
| US11627132B2 (en) * | 2018-06-13 | 2023-04-11 | International Business Machines Corporation | Key-based cross domain registration and authorization |
| CN108924161A (zh) * | 2018-08-13 | 2018-11-30 | 南京敞视信息科技有限公司 | 一种交易数据加密通信方法及系统 |
| CN109151015B (zh) * | 2018-08-13 | 2021-10-08 | 南京敞视信息科技有限公司 | 一种交易信息安全推送方法 |
| CN109379333B (zh) * | 2018-09-10 | 2021-04-13 | 安徽师范大学 | 基于网络层的安全传输方法 |
| CN109302285A (zh) * | 2018-10-25 | 2019-02-01 | 安徽问天量子科技股份有限公司 | 一种IPv6网络节点数据安全传输方法 |
| CN109617696B (zh) * | 2019-01-03 | 2022-08-19 | 北京城市网邻信息技术有限公司 | 一种数据加密、数据解密的方法和装置 |
| KR102885076B1 (ko) * | 2019-01-10 | 2025-11-13 | 삼성전자주식회사 | 전자 장치, 전자 장치 제어방법 및 네트워크 시스템 |
| US20210173950A1 (en) * | 2019-12-06 | 2021-06-10 | TEEware Co., Ltd. | Data sharing between trusted execution environments |
| US11343094B2 (en) | 2020-01-13 | 2022-05-24 | i2Chain, Inc. | Methods and systems for encrypting shared information through its lifecycle |
| CN112260823B (zh) * | 2020-09-16 | 2022-08-09 | 浙江大华技术股份有限公司 | 数据传输方法、智能终端和计算机可读存储介质 |
| CN112564901B (zh) * | 2020-12-08 | 2023-08-25 | 三维通信股份有限公司 | 密钥的生成方法和系统、存储介质及电子装置 |
| CN112769759B (zh) * | 2020-12-22 | 2021-10-26 | 北京深思数盾科技股份有限公司 | 信息处理方法、信息网关、服务器及介质 |
| CN113536355B (zh) * | 2021-07-29 | 2024-06-28 | 中国工商银行股份有限公司 | 会话密钥的生成方法及装置 |
| US12095749B2 (en) | 2021-12-09 | 2024-09-17 | Netflow, UAB | Distributed trust-based communication |
| US12238078B2 (en) | 2021-12-09 | 2025-02-25 | Netflow, UAB | Distributed trust-based communication |
| US12177196B2 (en) | 2021-12-09 | 2024-12-24 | Netflow, UAB | Distributed trust-based communication |
| KR102663891B1 (ko) * | 2022-04-28 | 2024-05-03 | 주식회사 씨브이네트 | 이중보안 특성을 가지는 스마트홈 시스템 및 그의 통신방법 |
| CN115426111B (zh) * | 2022-06-13 | 2024-08-13 | 中国第一汽车股份有限公司 | 一种数据加密方法、装置、电子设备及存储介质 |
| DE102023131881A1 (de) * | 2023-11-15 | 2025-05-15 | Jonathan Rogers | Encryptor, decryptor, kommunikationssystem, verfahren, kommunikationsverfahren |
| US20260105138A1 (en) * | 2024-10-11 | 2026-04-16 | Hewlett-Packard Development Company, L.P. | Shared secret key based on system components |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013089725A1 (en) * | 2011-12-15 | 2013-06-20 | Intel Corporation | Method and device for secure communications over a network using a hardware security engine |
| CN103209075A (zh) * | 2013-03-15 | 2013-07-17 | 南京易司拓电力科技股份有限公司 | 一种密码交换方法 |
| CN104753682A (zh) * | 2015-04-03 | 2015-07-01 | 北京云安世纪科技有限公司 | 一种会话秘钥的生成系统及方法 |
Family Cites Families (23)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5226137A (en) | 1989-05-15 | 1993-07-06 | Dallas Semiconductor Corp. | Electronic key with multiple password protected sub-keys using address and translation to implement a block data move between public and protected sub-keys |
| US5206905A (en) | 1989-05-15 | 1993-04-27 | Dallas Semiconductor Corp. | Password protected device using incorrect passwords as seed values for pseudo-random number generator for outputting random data to thwart unauthorized accesses |
| US5602917A (en) * | 1994-12-30 | 1997-02-11 | Lucent Technologies Inc. | Method for secure session key generation |
| CA2302784A1 (en) | 1997-09-17 | 1999-03-25 | Frank C. Luyster | Improved block cipher method |
| US7013389B1 (en) | 1999-09-29 | 2006-03-14 | Cisco Technology, Inc. | Method and apparatus for creating a secure communication channel among multiple event service nodes |
| US7103185B1 (en) | 1999-12-22 | 2006-09-05 | Cisco Technology, Inc. | Method and apparatus for distributing and updating private keys of multicast group managers using directory replication |
| US6970562B2 (en) | 2000-12-19 | 2005-11-29 | Tricipher, Inc. | System and method for crypto-key generation and use in cryptosystem |
| US7065642B2 (en) | 2000-12-19 | 2006-06-20 | Tricipher, Inc. | System and method for generation and use of asymmetric crypto-keys each having a public portion and multiple private portions |
| US7069435B2 (en) | 2000-12-19 | 2006-06-27 | Tricipher, Inc. | System and method for authentication in a crypto-system utilizing symmetric and asymmetric crypto-keys |
| US7222231B2 (en) | 2001-04-19 | 2007-05-22 | Hewlett-Packard Development Company, L.P. | Data security for distributed file systems |
| US7477748B2 (en) * | 2002-03-18 | 2009-01-13 | Colin Martin Schmidt | Session key distribution methods using a hierarchy of key servers |
| SG105005A1 (en) * | 2002-06-12 | 2004-07-30 | Contraves Ag | Device for firearms and firearm |
| JP2005100412A (ja) * | 2003-09-25 | 2005-04-14 | Ricoh Co Ltd | 暗号機能を内蔵したマルチメディア出力デバイス |
| KR101282972B1 (ko) * | 2004-03-22 | 2013-07-08 | 삼성전자주식회사 | 디바이스와 휴대형 저장장치와의 상호인증 |
| US7680758B2 (en) | 2004-09-30 | 2010-03-16 | Citrix Systems, Inc. | Method and apparatus for isolating execution of software applications |
| US8050405B2 (en) * | 2005-09-30 | 2011-11-01 | Sony Ericsson Mobile Communications Ab | Shared key encryption using long keypads |
| US20130227286A1 (en) * | 2006-04-25 | 2013-08-29 | Andre Jacques Brisson | Dynamic Identity Verification and Authentication, Dynamic Distributed Key Infrastructures, Dynamic Distributed Key Systems and Method for Identity Management, Authentication Servers, Data Security and Preventing Man-in-the-Middle Attacks, Side Channel Attacks, Botnet Attacks, and Credit Card and Financial Transaction Fraud, Mitigating Biometric False Positives and False Negatives, and Controlling Life of Accessible Data in the Cloud |
| US8619982B2 (en) | 2006-10-11 | 2013-12-31 | Bassilic Technologies Llc | Method and system for secure distribution of selected content to be protected on an appliance specific basis |
| US8719954B2 (en) | 2006-10-11 | 2014-05-06 | Bassilic Technologies Llc | Method and system for secure distribution of selected content to be protected on an appliance-specific basis with definable permitted associated usage rights for the selected content |
| US20080092239A1 (en) | 2006-10-11 | 2008-04-17 | David H. Sitrick | Method and system for secure distribution of selected content to be protected |
| KR101594553B1 (ko) * | 2008-10-20 | 2016-02-18 | 코닌클리케 필립스 엔.브이. | 암호화 키를 생성하는 방법, 이를 위한 네트워크 및 컴퓨터 프로그램 |
| US8837738B2 (en) * | 2011-04-08 | 2014-09-16 | Arizona Board Of Regents On Behalf Of Arizona State University | Methods, systems, and apparatuses for optimal group key management for secure multicast communication |
| WO2015057116A1 (en) * | 2013-10-15 | 2015-04-23 | Telefonaktiebolaget L M Ericsson (Publ) | Establishing a secure connection between a master device and a slave device |
-
2015
- 2015-08-26 CN CN201510531892.2A patent/CN106487749B/zh active Active
-
2016
- 2016-08-16 JP JP2018508212A patent/JP2018529271A/ja active Pending
- 2016-08-16 US US15/752,743 patent/US10693634B2/en active Active
- 2016-08-16 WO PCT/CN2016/095522 patent/WO2017032242A1/zh not_active Ceased
-
2020
- 2020-06-15 US US16/901,261 patent/US11463243B2/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013089725A1 (en) * | 2011-12-15 | 2013-06-20 | Intel Corporation | Method and device for secure communications over a network using a hardware security engine |
| CN103209075A (zh) * | 2013-03-15 | 2013-07-17 | 南京易司拓电力科技股份有限公司 | 一种密码交换方法 |
| CN104753682A (zh) * | 2015-04-03 | 2015-07-01 | 北京云安世纪科技有限公司 | 一种会话秘钥的生成系统及方法 |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2018022805A1 (en) * | 2016-07-29 | 2018-02-01 | Alibaba Group Holding Limited | Hypertext transfer protocol secure (https) based packet processing methods and apparatuses |
| CN111193797A (zh) * | 2019-12-30 | 2020-05-22 | 海尔优家智能科技(北京)有限公司 | 具有可信计算架构的物联网操作系统的信息处理方法 |
| CN111193797B (zh) * | 2019-12-30 | 2022-10-11 | 海尔优家智能科技(北京)有限公司 | 具有可信计算架构的物联网操作系统的信息处理方法 |
| CN114244630A (zh) * | 2022-02-15 | 2022-03-25 | 北京指掌易科技有限公司 | 一种通信方法、装置、设备以及存储介质 |
| CN114244630B (zh) * | 2022-02-15 | 2022-06-03 | 北京指掌易科技有限公司 | 一种通信方法、装置、设备以及存储介质 |
| CN114553552A (zh) * | 2022-02-24 | 2022-05-27 | 北京小米移动软件有限公司 | 数据加密方法和装置、数据解密方法和装置及存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20180241549A1 (en) | 2018-08-23 |
| CN106487749A (zh) | 2017-03-08 |
| US11463243B2 (en) | 2022-10-04 |
| CN106487749B (zh) | 2021-02-19 |
| US10693634B2 (en) | 2020-06-23 |
| JP2018529271A (ja) | 2018-10-04 |
| US20200313865A1 (en) | 2020-10-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11463243B2 (en) | Key generation method and apparatus using double encryption | |
| US11115200B2 (en) | System, method, and apparatus for quantum key output, storage, and consistency verification | |
| US20210385201A1 (en) | Systems and methods for secure multi-party communications using aproxy | |
| US10050955B2 (en) | Efficient start-up for secured connections and related services | |
| CN107534665B (zh) | 利用ssl会话票证扩展的可扩缩中间网络设备 | |
| US9338150B2 (en) | Content-centric networking | |
| US20150229621A1 (en) | One-time-pad data encryption in communication channels | |
| WO2018077086A1 (zh) | 数据传输方法、装置及系统 | |
| CN104219041A (zh) | 一种适用于移动互联网的数据传输加密方法 | |
| US11316671B2 (en) | Accelerated encryption and decryption of files with shared secret and method therefor | |
| US10291600B2 (en) | Synchronizing secure session keys | |
| CN107517183A (zh) | 加密内容检测的方法和设备 | |
| CN113609522B (zh) | 数据授权及数据访问方法和装置 | |
| US10015208B2 (en) | Single proxies in secure communication using service function chaining | |
| US10313118B2 (en) | Authenticated access to cacheable sensor information in information centric data network | |
| CN115174188A (zh) | 一种消息传输方法、装置、电子设备和存储介质 | |
| WO2014146609A1 (zh) | 信息处理方法、信任服务器及云服务器 | |
| CN112822016B (zh) | 在区块链上进行数据授权的方法及区块链网络 | |
| Olumide et al. | A hybrid encryption model for secure cloud computing | |
| JPWO2020157928A5 (zh) | ||
| WO2023231817A1 (zh) | 数据处理方法、装置、计算机设备及存储介质 | |
| CN120582782A (zh) | 基于量子密钥的网关拓扑组网方法、装置、设备和介质 | |
| TWI724091B (zh) | 金鑰產生方法及裝置 | |
| HK1234924B (zh) | 密钥生成方法及装置 | |
| HK1234924A (zh) | 密鑰生成方法及裝置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16838501 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 15752743 Country of ref document: US |
|
| ENP | Entry into the national phase |
Ref document number: 2018508212 Country of ref document: JP Kind code of ref document: A |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16838501 Country of ref document: EP Kind code of ref document: A1 |