WO2018076289A1 - 密钥协商方法及装置 - Google Patents
密钥协商方法及装置 Download PDFInfo
- Publication number
- WO2018076289A1 WO2018076289A1 PCT/CN2016/103812 CN2016103812W WO2018076289A1 WO 2018076289 A1 WO2018076289 A1 WO 2018076289A1 CN 2016103812 W CN2016103812 W CN 2016103812W WO 2018076289 A1 WO2018076289 A1 WO 2018076289A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- character string
- cloud server
- negotiated
- data packet
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
Definitions
- the present application relates to the field of information security technologies, and in particular, to a key negotiation method and apparatus.
- the terminal device needs to consider the security of data transmission when communicating with the server. In order to ensure the security of the transmitted data, it is not leaked.
- the communication key is first negotiated by an asymmetric algorithm, and then the symmetric key is used to perform encryption and decryption using the negotiated key.
- the purpose of the present application is to solve at least one of the technical problems in the related art to some extent.
- the first object of the present application is to propose a key negotiation method, which increases the complexity of ciphertext by processing a pre-negotiated character string to generate an irregularly circulated key data packet. Improves the security of key negotiation.
- a second object of the present application is to propose another method of key agreement.
- a third object of the present application is to propose a key agreement apparatus.
- a fourth object of the present application is to propose another key agreement apparatus.
- a fifth object of the invention is to propose an apparatus.
- a sixth object of the invention is to propose another device.
- a seventh object of the present invention is to provide a nonvolatile computer storage medium.
- An eighth object of the present invention is to provide another non-volatile computer storage medium.
- a key negotiation method includes: performing a key negotiation in advance with the cloud server in the process of performing key agreement with the cloud server Processing to generate a second character string; applying an encryption key pre-negotiated with the cloud server to encrypt the second character string to generate a key data packet; and transmitting the key data packet to the cloud server, Decrypting the key data packet by the decryption key pre-negotiated by the cloud server application and the terminal device, and determining whether the key negotiation is successful according to whether the first character string is included in the decryption result.
- the key negotiation method in the embodiment of the present application first performs a key negotiation process with the cloud server, and The first string pre-negotiated by the server is processed to generate a second string, and then the second string is encrypted by using an encryption key pre-negotiated with the cloud server to generate a key packet, and finally the key packet is sent to The cloud server decrypts the key data packet by using the decryption key pre-negotiated by the cloud server application and the terminal device, and determines whether the key negotiation is successful according to whether the first string is included in the decryption result. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- the key agreement method according to the above embodiment of the present application may further have the following additional technical features:
- the processing, by using the first number string pre-negotiated with the cloud server, to generate a second character string includes: generating a preset length random number by using a random number generator according to a preset period And splicing the random number with the first character string to generate a second character string.
- the processing, by using the preset algorithm, the first character string that is pre-negotiated with the cloud server to generate the second character string includes: applying a preset algorithm to obtain a reference character corresponding to the first character string. And splicing the reference character with the first character string to generate a second character string.
- another key negotiation method includes: receiving a key data packet sent by the terminal device in a process of performing key agreement with the terminal device, where The key data packet is an encryption key that is pre-negotiated by the terminal device application and the cloud server to encrypt a second character string to generate a key data packet, where the second character string is the terminal.
- the device processes the first character string pre-negotiated with the cloud server, and decrypts the key data packet by using a decryption key pre-negotiated with the terminal device to obtain a decryption result; and detects whether the decryption result is The first string is included to determine whether the key negotiation is successful.
- the key negotiation method in the embodiment of the present application first receives a key data packet sent by the terminal device in a process of performing key agreement with the terminal device, where the key data packet is an encryption that is pre-negotiated by the terminal device application and the cloud server. Encrypting the second character string to generate a key data packet, wherein the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server, and then applying the decryption pre-negotiated with the terminal device The key decrypts the key data packet to obtain a decryption result, and finally detects whether the decryption result includes the first character string to determine whether the key negotiation is successful. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- the key agreement method according to the above embodiment of the present application may further have the following additional technical features:
- the method further includes: if the detection is that the decryption result includes the first character string, encrypting the interaction information by using key information negotiated with the terminal device Or decryption processing.
- a key agreement apparatus includes: a first processing module, configured to pre-pair the cloud server in a process of performing key agreement with the cloud server Negotiated a string is processed to generate a second string; an encryption module is configured to apply an encryption key pre-negotiated with the cloud server to encrypt the second string to generate a key data packet; and a sending module, configured to: Sending the key data packet to the cloud server, for decrypting the key data packet by the cloud server application and a decryption key pre-negotiated with the terminal device, and according to whether the decryption result includes the first A string determines if the key negotiation was successful.
- the first key string pre-negotiated with the cloud server is processed to generate a second character string, and then the application is pre-negotiated with the cloud server.
- the encryption key encrypts the second character string to generate a key data packet, and finally sends the key data packet to the cloud server, so that the cloud server application decrypts the key data packet with the decryption key pre-negotiated with the terminal device. And determining whether the key negotiation is successful according to whether the first string is included in the decrypted result. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- the key agreement apparatus may further have the following additional technical features:
- the first processing module is configured to: generate a preset length random number by using a random number generator according to a preset period; and perform splicing processing on the random number and the first character string Generate a second string.
- the first processing module is further configured to: acquire a reference character corresponding to the first character string by using a preset algorithm; and stitch the reference character with the first character string Processing generates a second string.
- a key agreement apparatus includes: a receiving module, configured to receive a key sent by the terminal device in a process of performing key agreement with a terminal device a data packet, wherein the key data packet is an encryption key pre-negotiated by the terminal device application and the cloud server, and the second character string is encrypted to generate a key data packet, where the second data string is generated.
- the terminal device processes the first character string that is pre-negotiated with the cloud server, and the decryption module is configured to decrypt the key data packet by using a decryption key pre-negotiated with the terminal device to obtain and decrypt the key data packet.
- the detection module is configured to detect whether the first string is included in the decryption result to determine whether the key negotiation is successful.
- the key agreement apparatus of the embodiment of the present invention first receives a key data packet sent by the terminal device in a process of performing key agreement with the terminal device, where the key data packet is an encryption that is pre-negotiated by the terminal device application and the cloud server. Encrypting the second character string to generate a key data packet, wherein the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server, and then applying the decryption pre-negotiated with the terminal device The key decrypts the key data packet to obtain a decryption result, and finally detects whether the decryption result includes the first character string to determine whether the key negotiation is successful. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- the key agreement apparatus may further have the following additional technical features:
- the device further includes: a second processing module, configured to apply a secret negotiated with the terminal device when detecting that the decryption result includes the first character string
- the key information encrypts or decrypts the interactive information.
- An embodiment of the fifth aspect of the present invention provides an apparatus, including: one or more processors; a memory; one or more programs, the one or more programs being stored in the memory when When the multiple processors are executed, the following steps are performed: during the key negotiation with the cloud server, the first character string pre-negotiated with the cloud server is processed to generate a second character string; the application and the cloud server are The pre-negotiated encryption key encrypts the second character string to generate a key data packet; and sends the key data packet to the cloud server for decryption in advance by the cloud server application and the terminal device The key decrypts the key data packet, and determines whether the key negotiation is successful according to whether the first character string is included in the decryption result.
- the device in the embodiment of the present application first processes the first character string pre-negotiated with the cloud server to generate a second character string in the process of performing key agreement with the cloud server, and then applies an encryption key pre-negotiated with the cloud server. Encrypting the second character string to generate a key data packet, and finally transmitting the key data packet to the cloud server, so that the cloud server application decrypts the key data packet with the decryption key pre-negotiated with the terminal device, and according to Whether the first string is included in the decrypted result determines whether the key negotiation is successful. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- a sixth aspect of the present invention provides an apparatus, including: one or more processors; a memory; one or more programs, the one or more programs being stored in the memory when When the multiple processors are executed, the following steps are performed: receiving a key data packet sent by the terminal device in a process of performing key agreement with the terminal device, where the key data packet is the terminal device application and The encryption key pre-negotiated by the cloud server encrypts the second character string to generate a key data packet, where the second character string is processed by the terminal device to the first character string pre-negotiated with the cloud server. Generating; decrypting the key data packet by using a decryption key pre-negotiated with the terminal device to obtain a decryption result; and detecting whether the first character string is included in the decryption result to determine whether the key negotiation is successful.
- the device in the embodiment of the present application first receives a key data packet sent by the terminal device in a process of performing key agreement with the terminal device, where the key data packet is an encryption key pair that is pre-negotiated by the terminal device application and the cloud server.
- the second character string is subjected to an encryption process to generate a key data packet, wherein the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server, and then applying a decryption key pair pre-negotiated with the terminal device.
- the key data packet is decrypted to obtain a decryption result, and finally the first decryption result is included in the decrypted result to determine whether the key negotiation is successful. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- a seventh aspect of the present invention provides a non-volatile computer storage medium storing one or more programs, when the one or more programs are executed by a device, causing the device Performing the following steps: processing a first character string that is pre-negotiated with the cloud server to generate a second character string in a key negotiation process with the cloud server; and applying an encryption key pair pre-negotiated with the cloud server Encrypting the second character string to generate a key data packet; sending the key data packet to the cloud server, where the cloud server application uses a decryption key pre-negotiated with the terminal device to the key The data packet is decrypted, and it is determined whether the key negotiation is successful according to whether the first character string is included in the decrypted result.
- the non-volatile computer storage medium of the embodiment of the present application first processes a first character string pre-negotiated with the cloud server to generate a second character string in a process of performing key agreement with the cloud server, and then applies the cloud server to the cloud server.
- the pre-negotiated encryption key encrypts the second character string to generate a key data packet, and finally sends the key data packet to the cloud server for the cloud server application to pre-negotiate the decryption key pair key data packet with the terminal device.
- Decryption processing is performed, and whether the key negotiation is successful is determined according to whether the first character string is included in the decryption result. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- An eighth aspect of the present invention provides a non-volatile computer storage medium storing one or more programs, when the one or more programs are executed by one device, causing the device Performing the following steps: receiving, in a process of performing key agreement with the terminal device, a key data packet sent by the terminal device, where the key data packet is pre-negotiated by the terminal device application and the cloud server
- the encryption key performs encryption processing on the second character string to generate a key data packet, where the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server;
- the decryption key pre-negotiated by the terminal device decrypts the key data packet to obtain a decryption result; and detects whether the first character string includes the first character string to determine whether the key negotiation is successful.
- the non-volatile computer storage medium of the embodiment of the present application first receives a key data packet sent by the terminal device in a process of performing key agreement with the terminal device, where the key data packet is a terminal device application and a cloud server in advance.
- the negotiated encryption key encrypts the second character string to generate a key data packet, where the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server, and then the application and the terminal device are pre-processed.
- the decrypted key of the negotiation decrypts the key data packet to obtain a decryption result, and finally detects whether the first character string is included in the decrypted result to determine whether the key negotiation is successful. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- FIG. 1 is a schematic diagram of data transmission between a terminal device and a cloud server according to an embodiment of the present application
- FIG. 3 is a flowchart of a key agreement method according to another embodiment of the present application.
- FIG. 4 is a schematic structural diagram of a key agreement apparatus according to an embodiment of the present application.
- FIG. 5 is a schematic structural diagram of a key agreement apparatus according to another embodiment of the present application.
- the communication key is first negotiated by an asymmetric algorithm, and then the symmetric key is used to perform encryption and decryption with the negotiated key to ensure the security of data transmission when the terminal device communicates with the cloud server.
- the asymmetric key negotiation is performed after the terminal device and the cloud server use the asymmetric key for key negotiation, and the terminal device and the cloud server encrypt and decrypt a string of both known characters. It is confirmed by the comparison of the plaintext after decryption whether the negotiated key is correct.
- FIG. 1 is a schematic diagram of data transmission between a terminal device and a cloud server according to an embodiment of the present application.
- the terminal device initiates a key negotiation request, and then the cloud server responds to the key negotiation. After the terminal device confirms the key negotiation, the two perform secure transmission of data.
- An example is as follows:
- the ciphertext and the plaintext operation of "OK" are agreed between the terminal device and the cloud server as confirmation of key negotiation.
- the terminal device interacts with the cloud server for the last time, the terminal device encrypts the "OK" with the negotiated key, and then sends the ciphertext to the cloud server.
- the cloud server uses the negotiated key to the secret server. The text is decrypted, and if the decrypted plaintext is "OK", the key negotiation is confirmed to be completed.
- the key negotiation method in the embodiment of the present application increases the complexity of the ciphertext and improves the key by processing the pre-negotiated character string to generate an irregular data packet.
- Negotiated security details as follows:
- FIG. 2 is a flow chart of a method of key agreement in accordance with an embodiment of the present application.
- the key negotiation method in this embodiment of the present application includes:
- Step 110 Process the first character string pre-negotiated with the cloud server to generate a second character string during the key negotiation process with the cloud server.
- the terminal device initiates a key agreement request, and then the cloud server responds to the key agreement, and finally the terminal device confirms the key agreement.
- the second character string is generated by processing the first character string pre-negotiated by the terminal device and the cloud server.
- the first character string may be one or more of letters, numbers, special symbols, and the like.
- a random number of a preset length is first generated by a random number generator according to a preset period, and then the random number is spliced with the first character string to generate a second character string.
- the preset period can be set as needed, for example, 10 minutes, 20 minutes, and the like.
- the preset length can be set as needed, for example, 5 strings, 10 strings, and the like.
- the random number may be one or more of letters, numbers, special symbols, and the like.
- the splicing process can be understood as “random number + first character string”, and can also be understood as “first character string + random number”, and can also be understood as random characters arbitrarily inserted into each character of the first character string. Wait.
- the first character string is a 4-bit character
- a 12-bit random number generated by the random number generator is spliced to form a second character string.
- a reference algorithm is first used to obtain a reference character corresponding to the first character string, and then the reference character is spliced with the first character string to generate a second character string.
- a reference character corresponding to the first character string is obtained by applying a preset algorithm by setting an algorithm in advance in the terminal device.
- the reference character may be one or more of letters, numbers, and special symbols.
- the splicing process can be understood as “reference character + first character string”, and can also be understood as “first character string + reference character”, and can also be understood as any character of the first character string arbitrarily inserted into the reference character. Wait.
- Step 120 Apply an encryption key pre-negotiated with the cloud server to encrypt the second character string to generate a key data packet.
- Step 130 Send the key data packet to the cloud server, so that the cloud server application decrypts the key data packet by using the decryption key pre-negotiated with the terminal device, and determines the key according to whether the first string is included in the decryption result. Whether the negotiation was successful.
- the result obtained by encrypting the second character string by using an encryption key pre-negotiated with the cloud server may be used as a key data packet by, for example, an MD5 encryption algorithm, a DES encryption algorithm, an RSA encryption algorithm, or the like.
- the key data packet is sent to the cloud server, and the cloud server decrypts the key data packet by using a decryption key pre-negotiated with the terminal device by using a corresponding decryption algorithm.
- the first character string is found in the decryption result, indicating that a connection can be established between the terminal device and the cloud server for data transmission. Further improve the security of key negotiation.
- the first character string is not found in the decryption result, indicating that the connection between the terminal device and the cloud server cannot be established, and data transmission cannot be performed. Further improve the security of key negotiation.
- the first character string pre-negotiated with the cloud server is processed to generate a second character string, and then the application is pre-negotiated with the cloud server.
- the encryption key encrypts the second character string to generate a key data packet, and finally sends the key data packet to the cloud server, so that the cloud server application decrypts the key data packet with the decryption key pre-negotiated with the terminal device. And determining whether the key negotiation is successful according to whether the first string is included in the decrypted result. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- FIG. 3 is a flowchart of a key agreement method according to another embodiment of the present application.
- the key negotiation method in this embodiment of the present application includes:
- Step 210 Receive a key data packet sent by the terminal device in a process of performing key negotiation with the terminal device, where the key data packet is an encryption key pre-negotiated by the terminal device application and the cloud server, and the second character string is performed.
- the encryption process generates a key data packet, wherein the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server.
- the terminal device initiates a key agreement request, and then the cloud server responds to the key agreement, and finally the terminal device confirms the key agreement.
- the key data packet sent by the terminal device is received.
- the key data packet is an encryption key pre-negotiated by the terminal device application and the cloud server to encrypt the second character string to generate a key data packet.
- the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server.
- step 110 how to generate a key data packet according to the second character string generated by processing the first character string pre-negotiated with the cloud server and how to encrypt the second character string according to the encryption key pre-negotiated with the cloud server For the specific process, see step 110. It will not be detailed here.
- Step 220 Decrypt the key data packet by using a decryption key pre-negotiated with the terminal device to obtain a decryption result.
- Step 230 Detect whether the first string is included in the decryption result to determine whether the key negotiation is successful.
- the decryption algorithm corresponding to the encryption algorithm is applied to decrypt the key data packet by using a decryption key pre-negotiated with the terminal device to obtain a decryption result, and further detecting whether the decryption result includes the first String.
- the key data packet is sent to the cloud server, and the cloud server decrypts the key data packet by using a decryption key pre-negotiated with the terminal device by using a corresponding decryption algorithm.
- the key information that is negotiated with the terminal device is applied to encrypt or decrypt the interaction information. That is, after the key negotiation ends, the interaction information may be processed by using the key information negotiated with the terminal device, which may be one or more of encryption and decryption.
- FIG. 4 is a schematic structural diagram of a key agreement apparatus according to an embodiment of the present application.
- the key negotiation includes: a first processing module 41, an encryption module 42, and a sending module 43.
- the first processing module 41 is configured to process the first character string pre-negotiated with the cloud server to generate a second character string in the process of performing key agreement with the cloud server.
- the encryption module 42 is configured to apply an encryption key pre-negotiated with the cloud server to encrypt the second character string to generate a key data packet.
- the sending module 43 is configured to send the key data packet to the cloud server, so that the cloud server application decrypts the key data packet by using the decryption key pre-negotiated with the terminal device, and determines whether the first string is included in the decryption result. Whether the key negotiation was successful.
- the first processing module 41 is configured to: generate a random number of a preset length by using a random number generator according to a preset period; and splicing the random number with the first character string to generate a random number The second string.
- the first processing module 41 is further configured to: apply a preset algorithm to obtain a reference character corresponding to the first character string; and perform splicing processing the reference character with the first character string to generate a second character string.
- the key agreement device provided by the embodiment of the present invention corresponds to the key agreement method provided by the foregoing first embodiment. Therefore, the implementation manner of the foregoing key negotiation method is also applicable to the key agreement device provided in this embodiment. This embodiment will not be described in detail.
- the first key string pre-negotiated with the cloud server is processed to generate a second character string, and then the application is pre-negotiated with the cloud server.
- the encryption key encrypts the second character string to generate a key data packet, and finally sends the key data packet to the cloud server, so that the cloud server application decrypts the key data packet with the decryption key pre-negotiated with the terminal device. And determining whether the key negotiation is successful according to whether the first string is included in the decrypted result. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- FIG. 5 is a schematic structural diagram of a key agreement apparatus according to another embodiment of the present application.
- the key agreement apparatus includes a receiving module 51, a decrypting module 52, and a detecting module 53.
- the receiving module 51 is configured to receive a key data packet sent by the terminal device in a process of performing key negotiation with the terminal device, where the key data packet is an encryption key pair that is pre-negotiated by the terminal device application and the cloud server.
- the second string is subjected to an encryption process to generate a key data packet, wherein the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server.
- the decryption module 52 is configured to decrypt the key data packet by using a decryption key pre-negotiated with the terminal device to obtain a decryption result.
- the detecting module 53 is configured to detect whether the first string is included in the decryption result to determine whether the key negotiation is successful.
- the key agreement apparatus further includes a second processing module 54.
- the second processing module 54 is configured to perform encryption or decryption processing on the interaction information by using key information negotiated with the terminal device when the first decryption result is included in the detection decryption result.
- the key agreement device provided by the embodiment of the present invention corresponds to the key negotiation method provided by the foregoing second embodiment. Therefore, the implementation of the foregoing key negotiation method is also applicable to the key agreement device provided in this embodiment. This will not be described in detail in this embodiment.
- the key agreement apparatus of the embodiment of the present invention first receives a key data packet sent by the terminal device in a process of performing key agreement with the terminal device, where the key data packet is an encryption that is pre-negotiated by the terminal device application and the cloud server. Encrypting the second character string to generate a key data packet, wherein the second character string is generated by the terminal device processing the first character string pre-negotiated with the cloud server, and then applying the decryption pre-negotiated with the terminal device The key decrypts the key data packet to obtain a decryption result, and finally detects whether the decryption result includes the first character string to determine whether the key negotiation is successful. Therefore, by processing the pre-negotiated character string to generate a rule data packet that is irregular, the complexity of the ciphertext is increased, and the security of the key agreement is improved.
- first and second are used for descriptive purposes only and are not to be construed as indicating or implying a relative importance or implicitly indicating the number of technical features indicated.
- features defining “first” or “second” may include at least one of the features, either explicitly or implicitly.
- the meaning of "a plurality” is at least two, such as two, three, etc., unless specifically defined otherwise.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本申请公开了一种密钥协商方法及装置。其中,该方法包括:在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串;应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包;将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
Description
本申请涉及信息安全技术领域,尤其涉及一种密钥协商方法及装置。
通常,终端设备与服务器进行通信时需要考虑到数据传输的安全性问题。为了保证传输数据的安全性,不被泄露。一般通过非对称算法先协商出通信密钥,然后用对称算法用协商出来的密钥进行加密解密。
然而,上述密钥协商的过程中,使用固定的字符串作为密钥协商的确认包,存在一定的规律性,安全性低。
发明内容
本申请的目的旨在至少在一定程度上解决相关技术中的技术问题之一。
为此,本申请的第一个目的在于提出一种密钥协商方法,该方法通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
本申请的第二个目的在于提出另一种密钥协商方法。
本申请的第三个目的在于提出一种密钥协商装置。
本申请的第四个目的在于提出另一种密钥协商装置。
本发明的第五个目的在于提出一种设备。
本发明的第六个目的在于提出另一种设备。
本发明的第七个目的在于提出一种非易失性计算机存储介质。
本发明的第八个目的在于提出另一种非易失性计算机存储介质。
为达上述目的,根据本申请第一方面实施例提出的一种密钥协商方法,包括:在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串;应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的密钥协商方法,首先在与云端服务器进行密钥协商的过程中,对与云
端服务器预先协商的第一字符串进行处理生成第二字符串,接着应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,最后将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
另外,根据本申请上述实施例的密钥协商方法还可以具有如下附加的技术特征:
在本申请的一个实施例中,所述对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串,包括:按照预设周期通过随机数发生器生成预设长度的随机数;将所述随机数与所述第一字符串进行拼接处理生成第二字符串。
在本申请的一个实施例中,所述对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串,包括:应用预设算法获取与所述第一字符串对应的参考字符;将所述参考字符与所述第一字符串进行拼接处理生成第二字符串。
为达上述目的,根据本申请第二方面实施例提出的另一种密钥协商方法,包括:在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的密钥协商方法,首先在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的,接着应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果,最后检测解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
另外,根据本申请上述实施例的密钥协商方法还可以具有如下附加的技术特征:
在本申请的一个实施例中,所述的方法,还包括:如果检测获知所述解密结果中包含所述第一字符串,则应用与所述终端设备协商的密钥信息对交互信息进行加密或解密处理。
为达上述目的,根据本申请第三方面实施例提出的一种密钥协商装置,包括:第一处理模块,用于在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第
一字符串进行处理生成第二字符串;加密模块,用于应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;发送模块,用于将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的密钥协商装置,首先在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串,接着应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,最后将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
另外,根据本申请上述实施例的密钥协商装置还可以具有如下附加的技术特征:
在本申请的一个实施例中,所述第一处理模块用于:按照预设周期通过随机数发生器生成预设长度的随机数;将所述随机数与所述第一字符串进行拼接处理生成第二字符串。
在本申请的一个实施例中,所述第一处理模块还用于:应用预设算法获取与所述第一字符串对应的参考字符;将所述参考字符与所述第一字符串进行拼接处理生成第二字符串。
为达上述目的,根据本申请第四方面实施例提出的一种密钥协商装置,包括:接收模块,用于在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;解密模块,用于应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测模块,用于检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的密钥协商装置,首先在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的,接着应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果,最后检测解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
另外,根据本申请上述实施例的密钥协商装置还可以具有如下附加的技术特征:
在本申请的一个实施例中,所述的装置,还包括:第二处理模块,用于在检测获知所述解密结果中包含所述第一字符串时,应用与所述终端设备协商的密钥信息对交互信息进行加密或解密处理。
本发明第五方面实施例提供了一种设备,包括:一个或者多个处理器;存储器;一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时,执行以下步骤:在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串;应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的设备,首先在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串,接着应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,最后将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
本发明第六方面实施例提供了一种设备,包括:一个或者多个处理器;存储器;一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时,执行以下步骤:在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的设备,首先在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的,接着应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果,最后检测解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
本发明第七方面实施例提供了一种非易失性计算机存储介质,所述计算机存储介质存储有一个或者多个程序,当所述一个或者多个程序被一个设备执行时,使得所述设备执行以下步骤:在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串;应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的非易失性计算机存储介质,首先在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串,接着应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,最后将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
本发明第八方面实施例提供了一种非易失性计算机存储介质,所述计算机存储介质存储有一个或者多个程序,当所述一个或者多个程序被一个设备执行时,使得所述设备执行以下步骤:在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
本申请实施例的非易失性计算机存储介质,首先在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的,接着应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果,最后检测解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
本申请附加的方面和优点将在下面的描述中部分给出,部分将从下面的描述中变得明显,或通过本申请的实践了解到。
本申请的上述和/或附加的方面和优点从结合下面附图对实施例的描述中将变得明显和容易理解,其中:
图1是根据本申请一个实施例的终端设备与云端服务器数据传输的示意图;
图2是根据本申请一个实施例的密钥协商方法的流程图;
图3是根据本申请另一个实施例的密钥协商方法的流程图;
图4是根据本申请一个实施例的密钥协商装置的结构示意图;
图5是根据本申请另一个实施例的密钥协商装置的结构示意图。
下面详细描述本申请的实施例,所述实施例的示例在附图中示出,其中自始至终相同或类似的标号表示相同或类似的元件或具有相同或类似功能的元件。下面通过参考附图描述的实施例是示例性的,旨在用于解释本申请,而不能理解为对本申请的限制。
下面参考附图描述本申请实施例的密钥协商方法及装置。
通常,通过非对称算法先协商出通信密钥,然后用对称算法用协商出来的密钥进行加密解密,以保证终端设备与云端服务器进行通信时传输数据的安全性。
其中,非对称密钥协商是在终端设备与云端服务器使用非对称密钥进行密钥协商之后,终端设备和云端服务器会对一串双方都已知的字符串进行加密、解密。通过解密之后的明文的比对来确认协商的密钥是否正确。
图1是根据本申请一个实施例的终端设备与云端服务器数据传输的示意图。
如图1所示,终端设备发起密钥协商请求,接着云端服务器对密钥协商响应,最后终端设备对密钥协商进行确认后,两者进行数据的安全传输。举例说明如下:
具体地,终端设备与云端服务器之间约定对“OK”的密文和明文操作作为密钥协商的确认。在密钥协商的最后一次终端设备与云端服务器交互的时候,终端设备使用协商出来的密钥对“OK”进行加密,然后将密文发送给云端服务器,云端服务器使用协商出来的密钥对密文进行解密,如果解密出来的明文是“OK”,则确认密钥协商完成。
然而,上述密钥协商的过程中,使用固定的字符串作为密钥协商的确认包,存在一定的规律性,安全性低。
为了解决上述问题,本申请实施例提出的密钥协商方法,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。具体如下:
图2是根据本申请一个实施例的密钥协商方法的流程图。
如图2所示,本申请实施例的密钥协商方法包括:
步骤110,在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串。
具体地,在终端设备发起密钥协商请求,接着云端服务器对密钥协商响应,最后终端设备对密钥协商进行确认。通过对终端设备与云端服务器预先协商的第一字符串进行处理以生成第二字符串。
其中,第一字符串可以是字母、数字和特殊符号等中的一种或者多种。
其中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串的方式有很多种,可以根据需要进行选择。举例说明如下:
第一种示例,首先按照预设周期通过随机数发生器生成预设长度的随机数,接着将随机数与第一字符串进行拼接处理生成第二字符串。
其中,预设周期可以根据需要进行设置,例如10分钟、20分钟等。
其中,预设长度可以根据需要进行设置,例如5个字符串、10个字符串等。
其中,随机数可以是字母、数字和特殊符号等中的一种或者多种。
需要说明的是,拼接处理可以理解为“随机数+第一字符串”、也可以理解为“第一字符串+随机数”、还可以理解为随机数任意插入第一字符串的各个字符之间等。
举例而言,第一字符串为4位字符,在其后面拼接上随机数发生器生成的12位的随机数组成第二字符串。
第二种示例,首先应用预设算法获取与第一字符串对应的参考字符,接着将参考字符与第一字符串进行拼接处理生成第二字符串。
具体地,通过在终端设备中预先设置一种算法,通过应用预设算法获取与第一字符串对应的参考字符。
其中,参考字符可以是字母、数字和特殊符号等中的一种或者多种。
需要说明的是,拼接处理可以理解为“参考字符+第一字符串”、也可以理解为“第一字符串+参考字符”、还可以理解为参考字符任意插入第一字符串的各个字符之间等。
步骤120,应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包。
步骤130,将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。
具体地,可以通过例如MD5加密算法、DES加密算法和RSA加密算法等,应用与云端服务器预先协商的加密密钥对第二字符串进行加密得到的结果作为密钥数据包。
进一步,将密钥数据包发送给云端服务器,云端服务器会利用相应的解密算法,应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理。
进一步地,判断解密结果中是否包含第一字符串以确定终端设备与服务器协商是否成功。
可以理解的是,在解密结果找到第一字符串,表示终端设备与云端服务器之间是可以建立连接以进行数据传输。进一步提高密钥协商的安全性。
可以理解的是,在解密结果没有找到第一字符串,表示终端设备与云端服务器之间是不可以建立连接,不能进行数据传输。进一步提高密钥协商的安全性。
本申请实施例的密钥协商方法,首先在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串,接着应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,最后将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
图3是根据本申请另一个实施例的密钥协商方法的流程图。
如图3所示,本申请实施例的密钥协商方法包括:
步骤210,在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的。
具体地,在终端设备发起密钥协商请求,接着云端服务器对密钥协商响应,最后终端设备对密钥协商进行确认。首先接收终端设备发送的密钥数据包。
其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包。第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的。
需要说明的是,如何根据与云端服务器预先协商的第一字符串进行处理生成的第二字符串以及如何根据与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包的具体过程可以参见步骤110。此处不再详述。
步骤220,应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果。
步骤230,检测解密结果中是否包含第一字符串确定密钥协商是否成功。
具体地,在接收到数据包后应用于加密算法对应的解密算法,利用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果,并进一步检测解密结果中是否包含第一字符串。
进一步,将密钥数据包发送给云端服务器,云端服务器会利用相应的解密算法,应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理。
进一步地,判断解密结果中是否包含第一字符串以确定终端设备与服务器协商是否成功。
需要说明的是,在检测获知解密结果中包含第一字符串时应用与终端设备协商的密钥信息对交互信息进行加密或解密处理。即在密钥协商结束以后,可以利用与终端设备协商的密钥信息对交互信息进行处理,可以是加密、解密等一种或者多种。
本申请实施例的密钥协商方法,首先在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的,接着应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果,最后检测解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
为了实现本申请还提出一种密钥协商装置。
图4是根据本申请一个实施例的密钥协商装置的结构示意图。
如图4所示,该密钥协商包括:第一处理模块41、加密模块42和发送模块43。
其中,第一处理模块41用于在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串。
加密模块42用于应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包。
发送模块43用于将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。
其中,在本申请的一个实施例中,第一处理模块41用于:按照预设周期通过随机数发生器生成预设长度的随机数;将随机数与所述第一字符串进行拼接处理生成第二字符串。
其中,在本申请的一个实施例中,第一处理模块41还用于:应用预设算法获取与第一字符串对应的参考字符;将参考字符与第一字符串进行拼接处理生成第二字符串。
本发明实施例提供的密钥协商装置与上述第一方面实施例提供的密钥协商方法相对应,因此在前述密钥协商方法的实施方式也适用于本实施例提供的密钥协商装置,在本实施例中不再详细描述。
本申请实施例的密钥协商装置,首先在与云端服务器进行密钥协商的过程中,对与云端服务器预先协商的第一字符串进行处理生成第二字符串,接着应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,最后将密钥数据包发送给云端服务器,以供云端服务器应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理,并根据解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
图5是根据本申请另一个实施例的密钥协商装置的结构示意图。
如图5所示,该密钥协商装置包括:接收模块51、解密模块52和检测模块53。
其中,接收模块51用于在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的。
解密模块52用于应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果。
检测模块53用于检测解密结果中是否包含第一字符串确定密钥协商是否成功。
其中,在本申请的一个实施例中,该密钥协商装置还包括第二处理模块54。
其中,第二处理模块54用于在检测获知解密结果中包含第一字符串时,应用与终端设备协商的密钥信息对交互信息进行加密或解密处理。
本发明实施例提供的密钥协商装置与上述第二一方面实施例提供的密钥协商方法相对应,因此在前述密钥协商方法的实施方式也适用于本实施例提供的密钥协商装置,在本实施例中不再详细描述。
本申请实施例的密钥协商装置,首先在与终端设备进行密钥协商的过程中,接收终端设备发送的密钥数据包,其中,密钥数据包是终端设备应用与云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,第二字符串是终端设备对与云端服务器预先协商的第一字符串进行处理生成的,接着应用与终端设备预先协商的解密密钥对密钥数据包进行解密处理获取解密结果,最后检测解密结果中是否包含第一字符串确定密钥协商是否成功。由此,通过对预先协商的字符串进行处理,以生成无规律可循的密钥数据包,增加了密文的复杂性,提高了密钥协商的安全性。
此外,术语“第一”、“第二”仅用于描述目的,而不能理解为指示或暗示相对重要性或者隐含指明所指示的技术特征的数量。由此,限定有“第一”、“第二”的特征可以明示或者隐含地包括至少一个该特征。在本申请的描述中,“多个”的含义是至少两个,例如两个,三个等,除非另有明确具体的限定。
流程图中或在此以其他方式描述的任何过程或方法描述可以被理解为,表示包括一个或更多个用于实现特定逻辑功能或过程的步骤的可执行指令的代码的模块、片段或部分,并且本申请的优选实施方式的范围包括另外的实现,其中可以不按所示出或讨论的顺序,包括根据所涉及的功能按基本同时的方式或按相反的顺序,来执行功能,这应被本申请的实施例所属技术领域的技术人员所理解。
在本说明书的描述中,参考术语“一个实施例”、“一些实施例”、“示例”、“具体示例”、或“一些示例”等的描述意指结合该实施例或示例描述的具体特征、结构、材料或者特点包含于本申请的至少一个实施例或示例中。在本说明书中,对上述术语的示意性表述不必须针对的是相同的实施例或示例。而且,描述的具体特征、结构、材料或者特点可以在任一个或多个实施例或示例中以合适的方式结合。此外,在不相互矛盾的情况下,本领域的技术人员可以将本说明书中描述的不同实施例或示例以及不同实施例或示例的特征进行结合和组合。
尽管上面已经示出和描述了本申请的实施例,可以理解的是,上述实施例是示例性的,不能理解为对本申请的限制,本领域的普通技术人员在本申请的范围内可以对上述实施例进行变化、修改、替换和变型。
Claims (14)
- 一种密钥协商方法,其特征在于,包括以下步骤:在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串;应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
- 如权利要求1所述的方法,其特征在于,所述对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串,包括:按照预设周期通过随机数发生器生成预设长度的随机数;将所述随机数与所述第一字符串进行拼接处理生成第二字符串。
- 如权利要求1所述的方法,其特征在于,所述对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串,包括:应用预设算法获取与所述第一字符串对应的参考字符;将所述参考字符与所述第一字符串进行拼接处理生成第二字符串。
- 一种密钥协商方法,其特征在于,包括以下步骤:在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
- 如权利要求4所述的方法,其特征在于,还包括:如果检测获知所述解密结果中包含所述第一字符串,则应用与所述终端设备协商的密钥信息对交互信息进行加密或解密处理。
- 一种密钥协商装置,其特征在于,包括:第一处理模块,用于在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串;加密模块,用于应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;发送模块,用于将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
- 如权利要求6所述的装置,其特征在于,所述第一处理模块用于:按照预设周期通过随机数发生器生成预设长度的随机数;将所述随机数与所述第一字符串进行拼接处理生成第二字符串。
- 如权利要求6所述的装置,其特征在于,所述第一处理模块还用于:应用预设算法获取与所述第一字符串对应的参考字符;将所述参考字符与所述第一字符串进行拼接处理生成第二字符串。
- 一种密钥协商装置,其特征在于,包括:接收模块,用于在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;解密模块,用于应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测模块,用于检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
- 如权利要求9所述的装置,其特征在于,还包括:第二处理模块,用于在检测获知所述解密结果中包含所述第一字符串时,应用与所述终端设备协商的密钥信息对交互信息进行加密或解密处理。
- 一种设备,其特征在于,包括:一个或者多个处理器;存储器;一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时,执行以下步骤:在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串;应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先 协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
- 一种设备,其特征在于,包括:一个或者多个处理器;存储器;一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时,执行以下步骤:在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
- 一种非易失性计算机存储介质,其特征在于,所述计算机存储介质存储有一个或者多个程序,当所述一个或者多个程序被一个设备执行时,使得所述设备执行以下步骤:在与云端服务器进行密钥协商的过程中,对与所述云端服务器预先协商的第一字符串进行处理生成第二字符串;应用与所述云端服务器预先协商的加密密钥对所述第二字符串进行加密处理生成密钥数据包;将所述密钥数据包发送给所述云端服务器,以供所述云端服务器应用与终端设备预先协商的解密密钥对所述密钥数据包进行解密处理,并根据解密结果中是否包含所述第一字符串确定密钥协商是否成功。
- 一种非易失性计算机存储介质,其特征在于,所述计算机存储介质存储有一个或者多个程序,当所述一个或者多个程序被一个设备执行时,使得所述设备执行以下步骤:在与终端设备进行密钥协商的过程中,接收所述终端设备发送的密钥数据包,其中,所述密钥数据包是所述终端设备应用与所述云端服务器预先协商的加密密钥对第二字符串进行加密处理生成密钥数据包,其中,所述第二字符串是所述终端设备对与云端服务器预先协商的第一字符串进行处理生成的;应用与所述终端设备预先协商的解密密钥对所述密钥数据包进行解密处理获取解密结果;检测所述解密结果中是否包含所述第一字符串确定密钥协商是否成功。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2016/103812 WO2018076289A1 (zh) | 2016-10-28 | 2016-10-28 | 密钥协商方法及装置 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2016/103812 WO2018076289A1 (zh) | 2016-10-28 | 2016-10-28 | 密钥协商方法及装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018076289A1 true WO2018076289A1 (zh) | 2018-05-03 |
Family
ID=62024175
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/103812 Ceased WO2018076289A1 (zh) | 2016-10-28 | 2016-10-28 | 密钥协商方法及装置 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2018076289A1 (zh) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115412247A (zh) * | 2022-11-02 | 2022-11-29 | 中安云科科技发展(山东)有限公司 | 基于时间戳的随机密钥同步方法、平台、设备及存储介质 |
| CN115408675A (zh) * | 2022-11-01 | 2022-11-29 | 湖北芯擎科技有限公司 | eFuse Key的生成方法、装置、设备及存储介质 |
| CN115632763A (zh) * | 2022-09-08 | 2023-01-20 | 北京天融信网络安全技术有限公司 | 模型训练以及密钥协商的方法、装置、电子设备及介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101378320A (zh) * | 2008-09-27 | 2009-03-04 | 北京数字太和科技有限责任公司 | 一种认证方法和认证系统 |
| CN102594823A (zh) * | 2012-02-20 | 2012-07-18 | 南京邮电大学 | 一种远程安全访问智能家居的可信系统 |
| US20160261566A1 (en) * | 2015-03-04 | 2016-09-08 | Ssh Communications Security Oyj | Replacing keys in a computer system |
| US20160294783A1 (en) * | 2015-04-06 | 2016-10-06 | At&T Intellectual Property I, L.P. | Decentralized and distributed secure home subscriber server device |
-
2016
- 2016-10-28 WO PCT/CN2016/103812 patent/WO2018076289A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101378320A (zh) * | 2008-09-27 | 2009-03-04 | 北京数字太和科技有限责任公司 | 一种认证方法和认证系统 |
| CN102594823A (zh) * | 2012-02-20 | 2012-07-18 | 南京邮电大学 | 一种远程安全访问智能家居的可信系统 |
| US20160261566A1 (en) * | 2015-03-04 | 2016-09-08 | Ssh Communications Security Oyj | Replacing keys in a computer system |
| US20160294783A1 (en) * | 2015-04-06 | 2016-10-06 | At&T Intellectual Property I, L.P. | Decentralized and distributed secure home subscriber server device |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115632763A (zh) * | 2022-09-08 | 2023-01-20 | 北京天融信网络安全技术有限公司 | 模型训练以及密钥协商的方法、装置、电子设备及介质 |
| CN115408675A (zh) * | 2022-11-01 | 2022-11-29 | 湖北芯擎科技有限公司 | eFuse Key的生成方法、装置、设备及存储介质 |
| CN115408675B (zh) * | 2022-11-01 | 2023-02-07 | 湖北芯擎科技有限公司 | eFuse Key的生成方法、装置、设备及存储介质 |
| CN115412247A (zh) * | 2022-11-02 | 2022-11-29 | 中安云科科技发展(山东)有限公司 | 基于时间戳的随机密钥同步方法、平台、设备及存储介质 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN106603485B (zh) | 密钥协商方法及装置 | |
| US9673975B1 (en) | Cryptographic key splitting for offline and online data protection | |
| WO2018076365A1 (zh) | 密钥协商方法及装置 | |
| CN106656481B (zh) | 身份认证方法、装置以及系统 | |
| CN105406969B (zh) | 数据加密装置及方法 | |
| CN107294937B (zh) | 基于网络通信的数据传输方法、客户端及服务器 | |
| CN108111497B (zh) | 摄像机与服务器相互认证方法和装置 | |
| CN106470104B (zh) | 用于生成共享密钥的方法、装置、终端设备及系统 | |
| CN111917710B (zh) | Pci-e密码卡及其密钥保护方法、计算机可读存储介质 | |
| US20170085543A1 (en) | Apparatus and method for exchanging encryption key | |
| US10938555B2 (en) | Method and assembly for establishing a secure communication between a first network device (initiator) and a second network device (responder) | |
| CN104836784B (zh) | 一种信息处理方法、客户端和服务器 | |
| CN113079002B (zh) | 数据加密方法、解密方法、密钥管理方法、介质和设备 | |
| JP2020532177A (ja) | データの高度なセキュリティ、高速暗号化および、伝送のためのコンピュータ実装システムおよび方法 | |
| CN106411902A (zh) | 一种数据安全传输方法及系统 | |
| CN112487380A (zh) | 一种数据交互方法、装置、设备及介质 | |
| WO2017084553A1 (zh) | 一种在设备之间进行授权的方法和装置 | |
| CN109005184A (zh) | 文件加密方法及装置、存储介质、终端 | |
| CN117435226A (zh) | 车载电子控制单元的数据刷写方法、设备及存储介质 | |
| JP2016061915A (ja) | 情報処理装置、情報処理システム、情報処理方法及びプログラム | |
| WO2018076289A1 (zh) | 密钥协商方法及装置 | |
| KR101579696B1 (ko) | 암호 기법 프로토콜의 개시 값들을 난독화하는 시스템 및 방법 | |
| CN106453380B (zh) | 密钥协商方法及装置 | |
| CN116455565A (zh) | 敏感数据的安全传输方法、客户端以及服务器 | |
| CN112887983B (zh) | 设备身份认证方法、装置、设备及介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16920043 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 16.09.2019) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16920043 Country of ref document: EP Kind code of ref document: A1 |