A shared key update method and system

Through the dual-end interaction between the IoT device and the key management server, the hash value is used to encrypt and decrypt request and reply information, the problem of pre-shared keys of IoT devices cannot be updated and key theft is solved, and the continuous update and security of shared keys is achieved.

CN114117501BActive Publication Date: 2025-05-02BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111555417.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-17
Publication Date
2025-05-02
Estimated Expiration
2041-12-17

AI Technical Summary

Technical Problem

IoT devices cannot update pre-shared keys during their life cycle, and a large number of devices use the same key, resulting in the problem of key theft.

Method used

Through the dual-end interaction between the IoT device and the key management server, the request and reply information is encrypted and decrypted using hash values ​​to ensure stable issuance and update of new shared keys.

Benefits of technology

It realizes continuous update of shared keys for IoT devices, avoiding the situation where keys cannot be updated, and preventing key theft caused by a large number of devices using the same key.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117501B_ABST
    Figure CN114117501B_ABST
Patent Text Reader

Abstract

The present application provides a shared key update method and system, the method is applied in a shared key update system, the shared key update system includes an Internet of Things device and a key management server, the method includes: the Internet of Things device sends an encryption request to the key management server; the key management server receives the encryption request and generates a new shared key when the verification is successful; the key management server sends an encrypted reply to the Internet of Things device; the Internet of Things device receives the encrypted reply and decrypts it to obtain a new shared key; the Internet of Things device uses the new shared key to update the shared key when the verification is successful. It can be seen that the implementation of this implementation method can effectively ensure that the Internet of Things device can continuously update the corresponding pre-shared key, thereby greatly avoiding the situation where the update cannot be performed and the problem that a large number of Internet of Things devices use the same pre-shared key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data encryption, and in particular, to a shared key updating method and system. Background Art

[0002] With the continuous development of IoT technology, more and more IoT devices are put into practical application. However, in practice, the pre-shared key may not be updated during the life cycle of IoT devices in IoT application scenarios. At the same time, if all IoT devices use the same pre-shared key, the key may be stolen, which makes it impossible to continuously and effectively update the pre-shared key. Summary of the invention

[0003] The purpose of the embodiments of the present application is to provide a shared key update method and system, which can effectively ensure that IoT devices can continuously update their corresponding pre-shared keys, thereby avoiding the situation where updates cannot be made to a great extent and solving the problem that a large number of IoT devices use the same pre-shared key.

[0004] A first aspect of an embodiment of the present application provides a shared key update method, the method being applied to a shared key update system, the shared key update system comprising an Internet of Things device and a key management server, the method comprising:

[0005] The IoT device generates a first Hash value, and uses the first Hash value to encrypt a shared key update request to obtain an encrypted request; the shared key update request includes the first identity information of the IoT device;

[0006] The Internet of Things device sends the encryption request to the key management server;

[0007] The key management server generates a second Hash value, and uses the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request;

[0008] The key management server determines whether the first identity information is the same as the second identity information of the device to be updated in the database; and generates a new shared key when the first identity information is the same as the second identity information;

[0009] The key management server generates a reply message according to the new shared key, the second identity information and the random value, and encrypts the reply message using the second Hash value to obtain an encrypted reply;

[0010] The key management server sends the encrypted reply to the IoT device;

[0011] The IoT device decrypts the encrypted reply using the first hash value to obtain the new shared key, the second identity information and the random value;

[0012] The Internet of Things device determines whether the second identity information is the same as the first identity information; and when the second identity information is the same as the first identity information, uses the new shared key to update the shared key.

[0013] In the above implementation process, the method can be applied to the shared key update system to enable multiple IoT devices to communicate with the key management server, and enable the physical network device to perform corresponding multi-step operations with the key management server, such as requesting updates, verifying identities, issuing new shared keys, and verifying key issuance results. It can be seen that by implementing this implementation method, the stable issuance of new shared keys can be achieved through the two-end interaction between the IoT device and the key management server, thereby avoiding the situation where the shared key of the IoT device cannot be updated by verifying and confirming the update; at the same time, the IoT device corresponds to the new shared key one by one, which can avoid a large number of IoT devices using the same pre-shared key, thereby solving the problem of large-scale theft of pre-shared keys.

[0014] Furthermore, after the step of determining by the IoT device whether the second identity information is the same as the first identity information; and updating the shared key using the new shared key when the second identity information is the same as the first identity information, the method further includes:

[0015] The IoT device encrypts the random value and the first identity information using the new shared key to obtain verification information;

[0016] The Internet of Things device sends the verification information to the key management server;

[0017] The key management server uses the new shared key to decrypt the verification information to obtain the random value and the first identity information;

[0018] The key management server determines whether the first identity information is the same as the second identity information, and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, updates the shared key version number corresponding to the second identity information in the database.

[0019] In the above implementation process, the method can verify the result of the IoT device updating the shared key, so that the key management server can record whether the physical network device successfully updates the shared key, thereby ensuring the effective update of the IoT device.

[0020] Furthermore, the IoT device generates a first hash value, and uses the first hash value to encrypt the shared key update request, and the step of obtaining the encrypted request includes:

[0021] The IoT device determines whether it has a historical shared key; when it has the historical shared key, it obtains the encryption time, the first identity information of the IoT device and the historical shared key, and calculates a first Hash value according to the encryption time, the first identity information and the historical shared key; when it does not have the historical shared key, it obtains the encryption time and the first identity information, and calculates a first Hash value according to the encryption time and the first identity information;

[0022] The Internet of Things device encrypts the shared key update request using the first hash value to obtain an encrypted request.

[0023] Further, the key management server generates a second Hash value, and uses the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request, including:

[0024] The key management server determines whether the device to be updated has a historical shared key in the database; if the device has the historical shared key, obtains the decryption time, the second identity information of the device to be updated and the historical shared key, and calculates a second hash value according to the decryption time, the second identity information and the historical shared key; if the device does not have the historical shared key, obtains the decryption time and the second identity information, and calculates a second hash value according to the decryption time and the second identity information;

[0025] The key management server uses the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request.

[0026] Further, the key management server determines whether the first identity information is the same as the second identity information of the device to be updated in the database; and when the first identity information is the same as the second identity information, the step of generating a new shared key includes:

[0027] The key management server determines whether the first identity information is the same as the second identity information of the device to be updated in the database;

[0028] When the first identity information and the second identity information are the same, the key management server performs multiple hash calculations on the preset total key to obtain a calculation result; and calculates a key hash value based on the calculation result and the second identity information, and determines the key hash value as a new shared key.

[0029] A second aspect of an embodiment of the present application provides a shared key update method, the method being applied to a shared key update system, the shared key update system comprising an Internet of Things device and a key management server, the method comprising:

[0030] The key management server searches for the historical shared key of the device to be updated in the database and generates a new shared key;

[0031] The key management server encrypts the key update information using the historical shared key to obtain an update notification; the key update request includes the second identity information of the device to be updated, the random value and the new shared key;

[0032] The key management server sends the update notification to the Internet of Things device;

[0033] The IoT device decrypts the update notification using the historical shared key to obtain the second identity information, the random value and the new shared key;

[0034] The Internet of Things device determines whether the second identity information is the same as the first identity information of the Internet of Things device; and when the second identity information is the same as the first identity information, uses the new shared key to update the shared key.

[0035] In the above implementation process, the method can send a key update request through the key management server, so as to achieve the effect that the key management server commands the IoT device to update the shared key. It can be seen that the implementation of this implementation method can enable the key management server to command the IoT device to update the shared key, thereby ensuring the diversity of methods for the IoT device to update the shared key.

[0036] Furthermore, after the step of determining, by the IoT device, whether the second identity information is the same as the first identity information of the IoT device; and updating the shared key using the new shared key when the second identity information is the same as the first identity information, the method further includes:

[0037] The IoT device encrypts the random value and the first identity information using the new shared key to obtain verification information;

[0038] The Internet of Things device sends the verification information to the key management server;

[0039] The key management server uses the new shared key to decrypt the verification information to obtain the random value and the first identity information;

[0040] The key management server determines whether the first identity information is the same as the second identity information, and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, updates the shared key version number corresponding to the second identity information in the database.

[0041] In the above implementation process, the method can verify the result of the IoT device updating the shared key, so that the key management server can record whether the physical network device successfully updates the shared key, thereby ensuring the effective update of the IoT device.

[0042] A third aspect of an embodiment of the present application provides a shared key update system, the shared key update system comprising an Internet of Things device and a key management server, wherein:

[0043] The IoT device is configured to generate a first hash value, and use the first hash value to encrypt a shared key update request to obtain an encrypted request; the shared key update request includes first identity information of the IoT device;

[0044] The Internet of Things device is further used to send the encryption request to the key management server;

[0045] The key management server is configured to generate a second Hash value, and use the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request;

[0046] The key management server is further configured to determine whether the first identity information is the same as the second identity information of the device to be updated in the database; and to generate a new shared key when the first identity information is the same as the second identity information;

[0047] The key management server is further configured to generate a reply message according to the new shared key, the second identity information and the random value, and encrypt the reply message using the second Hash value to obtain an encrypted reply;

[0048] The key management server is further used to send the encrypted reply to the Internet of Things device;

[0049] The IoT device is further configured to decrypt the encrypted reply using the first hash value to obtain the new shared key, the second identity information and the random value;

[0050] The Internet of Things device is further used to determine whether the second identity information is the same as the first identity information; and when the second identity information is the same as the first identity information, use the new shared key to update the shared key.

[0051] In the above implementation process, the shared key update system can achieve the effects of identification, verification, update, and re-verification through two-way interaction, thereby ensuring that the IoT device can effectively request the shared key to be updated and complete the update of the shared key.

[0052] Furthermore, the IoT device is further configured to encrypt the random value and the first identity information using the new shared key to obtain verification information;

[0053] The Internet of Things device is further used to send the verification information to the key management server;

[0054] The key management server is further configured to use the new shared key to decrypt the verification information to obtain the random value and the first identity information;

[0055] The key management server is also used to determine whether the first identity information is the same as the second identity information, and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, update the shared key version number corresponding to the second identity information in the database.

[0056] A fourth aspect of an embodiment of the present application provides a shared key update system, the shared key update system comprising an Internet of Things device and a key management server, wherein:

[0057] The key management server is used to search the database for the historical shared key of the device to be updated and generate a new shared key;

[0058] The key management server is further used to encrypt the key update information using the historical shared key to obtain an update notification; the key update request includes the second identity information of the device to be updated, the random value and the new shared key;

[0059] The key management server is further used to send the update notification to the Internet of Things device;

[0060] The IoT device is configured to decrypt the update notification using the historical shared key to obtain the second identity information, the random value, and the new shared key;

[0061] The Internet of Things device is also used to determine whether the second identity information is the same as the first identity information of the Internet of Things device; and when the second identity information is the same as the first identity information, use the new shared key to update the shared key.

[0062] In the above implementation process, the shared key update system can achieve the effects of identification, verification, update, and re-verification through two-way interaction, so that the key management server can control the Internet of Things device to update the shared key, thereby effectively updating the shared key when the Internet of Things device does not actively initiate an update request.

[0063] A fifth aspect of an embodiment of the present application provides an electronic device, including a memory and a processor, wherein the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to perform any shared key update method described in any one of the first aspect of the embodiments of the present application.

[0064] A sixth aspect of an embodiment of the present application provides a computer-readable storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, the shared key updating method described in any one of the first aspect of the embodiment of the present application is executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0066] Figure 1 A schematic diagram of a shared key update method provided in an embodiment of the present application;

[0067] Figure 2 A schematic diagram of a shared key update method provided in an embodiment of the present application;

[0068] Figure 3 A schematic diagram of the system structure of a shared key update system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0069] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0070] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0071] Example 1

[0072] Please see Figure 1 , Figure 1 A flow chart of a shared key update method is provided for an embodiment of the present application, wherein the shared key update method is applied to a shared key update system, and the shared key update system includes an Internet of Things device and a key management server.

[0073] The IoT device is a device that has the shared key update program PSKeyUpdateClient and the update key generation program SetupKeyGenClient installed;

[0074] The key management server PSKeyUpdateServer is a server that runs the shared key generation program PSKeyGen, the update key generation program SetupKeyGenServer and the shared key update service PSKeyUpdateService.

[0075] The shared key updating method includes:

[0076] S11. The Internet of Things device generates a first hash value, and uses the first hash value to encrypt a shared key update request to obtain an encrypted request; the shared key update request includes the first identity information of the Internet of Things device.

[0077] In this embodiment, this step includes the process in which the IoT device calls SetupKeyGenClient through PSKeyUpdateClient to generate KsetupClient, where KsetupClient is the first hash value.

[0078] In this embodiment, this step also includes the IoT device sending a shared key update request message RequestKey to the key management server through PSKeyUpdateClient, the message contains the IDs information of the IoT device, is encrypted using KsetupClient, and the encryption algorithm used is a symmetric encryption algorithm. Among them, the shared key update request message RequestKey is the encryption request in the above step, and the IDs information of the IoT device is the above-mentioned first identity information.

[0079] As an optional implementation manner, the IoT device generates a first hash value, and uses the first hash value to encrypt the shared key update request, and the step of obtaining the encrypted request includes:

[0080] The IoT device determines whether it has a historical shared key; when it has the historical shared key, it obtains the encryption time, the first identity information of the IoT device and the historical shared key, and calculates a first Hash value according to the encryption time, the first identity information and the historical shared key; when it does not have the historical shared key, it obtains the encryption time and the first identity information, and calculates a first Hash value according to the encryption time and the first identity information;

[0081] The Internet of Things device encrypts the shared key update request using the first hash value to obtain an encrypted request.

[0082] In this embodiment, the encryption time is the current system time of the IoT device. The time unit can be configured as hours or minutes. For example, if the current time of the device is 10:13:20 am and the configured time unit is every 1 minute, the obtained time time is 10:13 am. If the configured time unit is every 1 hour, the obtained time time is 10:00 am.

[0083] In this embodiment, the IDs (first identity information) of the IoT device are obtained. The obtained IDs should be able to uniquely identify a device, and the IDs can be device serial numbers, MAC addresses, or other types of device identification information. Furthermore, the device serial number can also be a CPU serial number, a single board serial number, or a hard disk serial number, or a combination of the above information. In addition, the IDs of the IoT device have been pre-configured in the DeviceTable stored in the key management server.

[0084] In this embodiment, the method determines whether the IoT device is online through the historical shared key (PSK). If the IoT device is not configured with PSK (PSK = NULL), it means that the IoT device is not online. At this time, according to the IDs and time of the IoT device, KsetupClient = Hash (IDs | time) is calculated, and the hash algorithm used is HMAC_SHA256.

[0085] In this embodiment, if the IoT device is configured with PSK (PSK!=NULL), KsetupClient=Hash(IDs|time|PSK) is calculated based on the IDs, time and PSK of the IoT device, and the Hash algorithm uses HMAC_SHA256.

[0086] In this embodiment, since time is always changing, the PSK of the device is also constantly changing. Therefore, the KsetupClient calculated by the algorithm is also constantly changing. Since the KsetupClient calculation is calculated by an irreversible hash algorithm, the PSK of the device cannot be inferred through KsetupClient, thus avoiding the exposure of the PSK. KsetupClient is only dynamically generated when the IoT device initiates the process of updating the shared key, and is discarded after use, thus avoiding the possibility of KsetupClient being cracked.

[0087] In this embodiment, for an IoT device that is not configured with a PSK, SetupKeyGenClient runs in a secure environment.

[0088] S12. The IoT device sends an encryption request to the key management server.

[0089] S21. The key management server generates a second Hash value, and uses the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request.

[0090] In this embodiment, when the key management server receives RequestKey (encryption request), it calls SetupKeyGenServer to calculate KsetupServer (second hash value); uses KsetupServer (second hash value) to decrypt RequestKey to obtain the IDs (first identity information) of the Internet of Things device.

[0091] As an optional implementation manner, the key management server generates a second hash value, and uses the second hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request, including:

[0092] The key management server determines whether the device to be updated has a historical shared key in the database; if the device has the historical shared key, obtains the decryption time, the second identity information of the device to be updated and the historical shared key, and calculates a second hash value according to the decryption time, the second identity information and the historical shared key; if the device does not have the historical shared key, obtains the decryption time and the second identity information, and calculates a second hash value according to the decryption time and the second identity information;

[0093] The key management server uses the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request.

[0094] In this embodiment, the key management server can obtain the decryption time time. The time unit can be configured as hours or minutes. For example, if the current time of the device is 10:13:20 am and the configured time unit is every 1 minute, the obtained time time is 10:13 am; if the configured time unit is every 1 hour, the obtained time time is 10:00 am.

[0095] In this embodiment, the key management server can search for the device to be updated with IP address DevIP in the DeviceTable (database, or data table). If Login=0, it means that the device is not online (PSK=NULL), and the IDs of the device to be updated are obtained from the DeviceTable; if the device is already online, the IDs and Version information are obtained from the DeviceTable.

[0096] In this embodiment, the key management server can use the previous PSK (historical shared key) to generate KsetupServer (second hash value). Specifically, the method can call PSKeyGen to calculate the current PSK (historical shared key); and then calculate the second hash value by KsetupServer = hash (ids | time | PSK). The hash algorithm uses HMAC_SHA256.

[0097] In this embodiment, when there is no historical shared key, the method can calculate KsetupServer=Hash(IDs|time) according to the IDs and time of the device to be updated, and the adopted Hash algorithm is HMAC_SHA256.

[0098] In this embodiment, since the IDs, time, PSK and hash algorithm used by the SetupKeyGenClient algorithm and the SetupKeyGenServer algorithm are the same, for the same device, the KsetupServer calculated by the key management server and the KsetupClient calculated by the IoT device are the same.

[0099] In this embodiment, the database may be an IoT device table DeviceTable, in which information of IoT devices managed by the key management server is stored. The contents of the table items may include:

[0100] (1) IDs, unique identification information IDs of IoT devices, such as MAC, SerialNumber;

[0101] (2) Login, indicating whether the IoT device is configured with a shared key;

[0102] (3) Version: indicates the current pre-shared key version of this IoT device.

[0103] (4) IP, which indicates the IP address of the IoT device.

[0104] The initial value of the content of the setting table item in DeviceTable is 0 for Login and 0 for Version, indicating that the initial shared key has not been set.

[0105] For example, the DeviceTable may be the following table.

[0106] Table 1. IoT devices

[0107]

[0108] S22. The key management server determines whether the first identity information is the same as the second identity information of the device to be updated in the database; and generates a new shared key if the first identity information is the same as the second identity information.

[0109] In this embodiment, the key management server compares the obtained IDs (first identity information) of the IoT device with the IDs (second identity information) of the device to be updated stored in the DeviceTable (database, or data table). If they are different, the process ends; if they are the same, PSKeyGen is called to generate a new shared key PSKnew for the device.

[0110] As an optional implementation manner, the key management server determines whether the first identity information is the same as the second identity information of the device to be updated in the database; and when the first identity information is the same as the second identity information, the step of generating a new shared key includes:

[0111] The key management server determines whether the first identity information is the same as the second identity information of the device to be updated in the database;

[0112] When the first identity information is the same as the second identity information, the key management server performs multiple hash calculations on the preset total key to obtain a calculation result; and calculates a key hash value based on the calculation result and the second identity information, and determines the key hash value as a new shared key.

[0113] In this embodiment, the method can use the MasterKey (total key) as the initial seed, and hash the seed multiple times so that a different seed value (calculation result) can be obtained each time it is called; and then a new shared key is generated according to the method Key = hash (seed + ids). The hash algorithm in the above calculation is the MD5 algorithm.

[0114] S23. The key management server generates a reply message according to the new shared key, the second identity information and the random value, and encrypts the reply message using the second Hash value to obtain an encrypted reply.

[0115] In this embodiment, the key management server sends a ReplyKey message (encrypted reply) to PSKeyUpdateClient through PSKeyUpdateService. The message contains the IDs (second identity information), nonce (random value) and PSKnew (new shared key) of the device to be updated. It is encrypted using KsetupServer (second hash value), and the encryption algorithm used is a symmetric encryption algorithm.

[0116] S24. The key management server sends an encrypted reply to the IoT device.

[0117] S13. The IoT device uses the first hash value to decrypt the encrypted reply to obtain a new shared key, the second identity information, and a random value.

[0118] In this embodiment, after the IoT device receives the ReplyKey message (encrypted reply) through PSKeyUpdateClient, it uses KsetupClient (first hash value) to decrypt the ReplyKey message (encrypted reply) to obtain the IDs (second identity information), nonce (random value) and PSKnew (new shared key) of the device to be updated.

[0119] S14. The IoT device determines whether the second identity information is the same as the first identity information; and if the second identity information is the same as the first identity information, uses the new shared key to update the shared key.

[0120] In this embodiment, the IoT device checks whether the IDs (second identity information) of the device to be updated in the message and the IDs (first identity information) of the IoT device are the same. If they are different, the process ends. If they are the same, the PSK (shared key) is updated to PSKnew (new shared key).

[0121] S15. The IoT device uses the new shared key to encrypt the random value and the first identity information to obtain verification information.

[0122] In this embodiment, the IoT device sends a ConfirmKey message (verification information) to PSKeyUpdateService through PSKeyUpdateClient. The message contains the IDs (first identity information) of the IoT device and the nonce (random value) in the ReplyKey, and is encrypted using PSKnew (new shared key).

[0123] S16. The IoT device sends verification information to the key management server.

[0124] S25. The key management server decrypts the verification information using the new shared key to obtain a random value and the first identity information;

[0125] S26. The key management server determines whether the first identity information is the same as the second identity information and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, updates the shared key version number corresponding to the second identity information in the database.

[0126] In this embodiment, after the key management server receives the ConfirmKey message (verification information) through PSKeyUpdateService, it uses PSKnew (new shared key) for decryption; then checks the nonce (random value) and the IDs (first identity information) of the IoT device to confirm that the IoT device has successfully received PSKnew (new shared key); and then updates the shared key version number Version=Version+1 in the DeviceTable.

[0127] In this embodiment, the bearer protocol of PSKeyUpdateProtocol is TCP.

[0128] By implementing this embodiment, the method can set an initial pre-shared key PSK0 for the IoT device; and update the pre-shared key of the IoT device in the production environment.

[0129] For example, the method can set an initial pre-shared key PSK0 for an IoT device: Setting the initial pre-shared key PSK0 of an IoT device is done in a secure environment. When executed in a secure environment, the IDs information of the real IoT device can be obtained, and the pre-shared key PSK0 can be associated with the identity information of the IoT device, such as IDs. Since the pre-shared key of the IoT device, including PSK0, contains the device IDs information, and SetupKeyGenerationClient and SetupKeyGenerationServer rely on the pre-shared key PSK and DeviceIDs of the IoT device to generate SetupKey, SetupKey can realize the authentication of the authenticity of the IoT device. Among them, the IoT device can be initialized first in the method. Install the shared key update program PSKeyUpdateClient and the update key generation program SetupKeyGenerationClient on the IoT device; set the pre-shared key on the IoT device to the unconfigured state PSK=NULL; obtain the identification information DeviceIDs of the IoT device. Then, a new table entry is allocated to the IoT device in the IoT device management database DeviceTable on the key management server and initialized with DeviceIDs, Login=0, Version=0 (the state is that the key is not set). Finally, the IoT device is connected to the key management server node through the network. This method can be used to set the initial shared key PSK0 for the IoT device through the PSKeyUpdateProtocol process initiated by PSKeyUpdateClient.

[0130] For example, when updating the pre-shared key of an IoT device in a production environment. The method can set a key update time period on the IoT device and the key management server, and the set key update time period is the same. The period for updating the pre-shared key can be set to: every hour, every day, every week, or every month, etc. Then, the PSKeyUpdateClient in the IoT device will periodically initiate the IoT device pre-shared key update process within the set time period, thereby achieving the purpose of periodic and automatic pre-shared key update of the IoT device. Then, the IoT system administrator can actively update the pre-shared key of the IoT device through the key management server. It can be seen that this type of IoT system administrator can update the master key MasterKey of the key management server; the IoT administrator actively replaces the new pre-shared key of the IoT device under its control.

[0131] It can be seen that the shared key update method described in this embodiment can be applied to the shared key update system to enable multiple IoT devices to communicate with the key management server, and enable the physical network device to perform corresponding multi-step operations with the key management server, including requesting updates, verifying identities, issuing new shared keys, and verifying key issuance results. It can be seen that the implementation of this implementation method can achieve stable issuance of new shared keys through two-way interaction between IoT devices and key management servers, thereby avoiding the situation where the shared keys of IoT devices cannot be updated by verifying and confirming updates; at the same time, the IoT devices correspond one-to-one with the new shared keys, which can avoid a large number of IoT devices from using the same pre-shared key, thereby solving the problem of large-scale theft of pre-shared keys.

[0132] Example 2

[0133] Please see Figure 2 , Figure 2 A flow chart of a shared key update method is provided for an embodiment of the present application. The shared key update method is applied to a shared key update system, the shared key update system includes an Internet of Things device and a key management server, and the shared key update method includes:

[0134] S41. The key management server searches the database for the historical shared key of the device to be updated, and generates a new shared key.

[0135] In this embodiment, the key management server searches the DeviceTable (database) to obtain the IDs (second identity information) and Version (shared key version number) of the device to be updated. Use PSKeyGen (MasterKey, IDs, Version) to generate the current shared key PSKcurrent (historical shared key) of the managed device; use PSKeyGen (IDs, Version+1) to generate a new shared key PSKnew (new shared key).

[0136] S42. The key management server encrypts the key update information using the historical shared key to obtain an update notification; the key update request includes the second identity information of the device to be updated, the random value and the new shared key.

[0137] In this embodiment, PSKeyUpdateService sends UpdateKey (update notification) to PSKeyUpdateClient. UpdateKey (update notification) contains the IDs (second identity information), Nonce (random value), and PSKnew (new shared key) of the device to be updated, and PSKcurrent (historical shared key) is used to encrypt the key update information.

[0138] S43. The key management server sends an update notification to the IoT device.

[0139] S31. The IoT device uses the historical shared key to decrypt the update notification to obtain the second identity information, the random value, and the new shared key.

[0140] S32: The IoT device determines whether the second identity information is the same as the first identity information of the IoT device; and when the second identity information is the same as the first identity information, uses a new shared key to update the shared key.

[0141] In this embodiment, after receiving UpdateKey (update notification), PSKeyUpdateClient uses the currently held PSK (historical shared key) to decrypt, checks the IDs of the devices to be updated in UpdateKey, and when it is found that the IDs of the devices to be updated are the same as the IDs of the IoT devices, updates PSK=PSKnew.

[0142] S33. The IoT device uses the new shared key to encrypt the random value and the first identity information to obtain verification information.

[0143] In this embodiment, PSKeyUpdateClient sends ConfirmUpdateKey (verification information) to PSKeyUpdateService. ConfirmUpdateKey (verification information) contains the IDs (first identity information) and Nonce (random value) of the IoT device and is encrypted using PSKnew (new shared key).

[0144] S34. The IoT device sends verification information to the key management server.

[0145] S44. The key management server uses the new shared key to decrypt the verification information to obtain a random value and the first identity information.

[0146] S45. The key management server determines whether the first identity information is the same as the second identity information and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, updates the shared key version number corresponding to the second identity information in the database.

[0147] In this embodiment, after receiving the ConfirmUpdateKey message, PSKeyUpdateService uses PSKnew to decrypt; checks the IDs (first identity information) and Nonce (random value) of the IoT device to confirm that the device has received PSKnew; and updates Version=Version+1 in DeviceTable.

[0148] The two implementation methods of Example 1 and Example 2 can solve the problem that the pre-shared key cannot be updated during the life cycle of the IoT device in the IoT application scenario and the key generated by all IoT devices using the same pre-shared key is stolen, and effectively ensure that the IoT devices use different pre-shared keys and are continuously updated according to a certain strategy. Among them, the method uses the master key MasterKey of the key management server to generate the pre-shared key of the device and the key distribution protection key, which can greatly reduce the number of keys to be protected.

[0149] It can be seen that by implementing the shared key update method described in this embodiment, the key management server can send a key update request, thereby achieving the effect of the key management server commanding the IoT device to update the shared key. It can be seen that by implementing this implementation method, the key management server can command the IoT device to update the shared key, thereby ensuring the diversity of methods for the IoT device to update the shared key.

[0150] Example 3

[0151] Please see Figure 3 , Figure 3 A schematic diagram of the system structure of a shared key update system provided in an embodiment of the present application. Figure 3 As shown, the shared key update system includes an Internet of Things device and a key management server, wherein:

[0152] The IoT device 50 is configured to generate a first hash value, and use the first hash value to encrypt the shared key update request to obtain an encrypted request; the shared key update request includes the first identity information of the IoT device 50;

[0153] The IoT device 50 is also used to send an encryption request to the key management server 60;

[0154] The key management server 60 is used to generate a second hash value and use the second hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request;

[0155] The key management server 60 is further used to determine whether the first identity information is the same as the second identity information of the device to be updated in the database; and generate a new shared key when the first identity information is the same as the second identity information;

[0156] The key management server 60 is further used to generate a reply message according to the new shared key, the second identity information and the random value, and encrypt the reply message using the second Hash value to obtain an encrypted reply;

[0157] The key management server 60 is also used to send an encrypted reply to the IoT device 50;

[0158] The IoT device 50 is further configured to decrypt the encrypted reply using the first hash value to obtain a new shared key, the second identity information, and the random value;

[0159] The Internet of Things device 50 is further used to determine whether the second identity information is the same as the first identity information; and when the second identity information is the same as the first identity information, use the new shared key to update the shared key.

[0160] As an optional implementation, the IoT device 50 is further configured to encrypt the random value and the first identity information using the new shared key to obtain verification information;

[0161] The IoT device 50 is also used to send verification information to the key management server 60;

[0162] The key management server 60 is further used to decrypt the verification information using the new shared key to obtain a random value and the first identity information;

[0163] The key management server 60 is also used to determine whether the first identity information is the same as the second identity information and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, update the shared key version number corresponding to the second identity information in the database.

[0164] As an optional implementation, the key management server 60 is used to search the database for the historical shared key of the device to be updated and generate a new shared key;

[0165] The key management server 60 is further used to encrypt the key update information using the historical shared key to obtain an update notification; the key update request includes the second identity information of the device to be updated, the random value and the new shared key;

[0166] The key management server 60 is also used to send update notifications to the IoT device 50;

[0167] The IoT device 50 is used to decrypt the update notification using the historical shared key to obtain the second identity information, the random value and the new shared key;

[0168] The IoT device 50 is also used to determine whether the second identity information is the same as the first identity information of the IoT device 50; and when the second identity information is the same as the first identity information, use the new shared key to update the shared key.

[0169] In the embodiments of the present application, the explanation of the shared key update system can refer to the description of any one of Embodiment 1 or Embodiment 2, and will not be further elaborated in this embodiment.

[0170] It can be seen that the shared key update system described in this embodiment can achieve the effects of identification, verification, update, and re-verification through a two-end interaction. Specifically, the shared key update system can enable the physical network device to request the update of the shared key and complete the corresponding shared key update, and can also enable the key management server to control the Internet of Things device to update the shared key. It can be seen that by implementing this implementation method, the shared key of the Internet of Things device can be updated in a variety of ways.

[0171] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0172] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0173] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0174] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0175] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0176] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

Claims

1. A shared key updating method, characterized in that: The method is applied to a shared key update system, wherein the shared key update system includes an Internet of Things device and a key management server, and the method includes: The IoT device generates a first Hash value, and uses the first Hash value to encrypt a shared key update request to obtain an encrypted request; the shared key update request includes the first identity information of the IoT device; The Internet of Things device sends the encryption request to the key management server; The key management server generates a second Hash value, and uses the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request; The key management server determines whether the first identity information is the same as the second identity information of the device to be updated in the database; When the first identity information and the second identity information are the same, the key management server performs multiple hash calculations on the preset total key to obtain a calculation result; and calculates a key hash value according to the calculation result and the second identity information, and determines the key hash value as a new shared key; The key management server generates a reply message according to the new shared key, the second identity information and the random value, and encrypts the reply message using the second Hash value to obtain an encrypted reply; The key management server sends the encrypted reply to the IoT device; The IoT device decrypts the encrypted reply using the first hash value to obtain the new shared key, the second identity information and the random value; The Internet of Things device determines whether the second identity information is the same as the first identity information; and when the second identity information is the same as the first identity information, uses the new shared key to update the shared key.

2. The shared key updating method according to claim 1, characterized in that: After the step of determining, by the IoT device, whether the second identity information is the same as the first identity information; and updating the shared key using the new shared key when the second identity information is the same as the first identity information, the method further includes: The IoT device encrypts the random value and the first identity information using the new shared key to obtain verification information; The Internet of Things device sends the verification information to the key management server; The key management server uses the new shared key to decrypt the verification information to obtain the random value and the first identity information; The key management server determines whether the first identity information is the same as the second identity information, and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, updates the shared key version number corresponding to the second identity information in the database.

3. The shared key updating method according to claim 1, characterized in that: The IoT device generates a first Hash value, and uses the first Hash value to encrypt the shared key update request, and the step of obtaining the encrypted request includes: The IoT device determines whether it has a historical shared key; when it has the historical shared key, it obtains the encryption time, the first identity information of the IoT device and the historical shared key, and calculates a first Hash value according to the encryption time, the first identity information and the historical shared key; when it does not have the historical shared key, it obtains the encryption time and the first identity information, and calculates a first Hash value according to the encryption time and the first identity information; The Internet of Things device encrypts the shared key update request using the first hash value to obtain an encrypted request.

4. The shared key updating method according to claim 1, characterized in that: The step of the key management server generating a second Hash value and using the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request includes: The key management server determines whether the device to be updated has a historical shared key in the database; if the device has the historical shared key, obtains the decryption time, the second identity information of the device to be updated and the historical shared key, and calculates a second hash value according to the decryption time, the second identity information and the historical shared key; if the device does not have the historical shared key, obtains the decryption time and the second identity information, and calculates a second hash value according to the decryption time and the second identity information; The key management server uses the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request.

5. A shared key updating method, characterized in that: The method is applied to a shared key update system, wherein the shared key update system includes an Internet of Things device and a key management server, and the method includes: The key management server searches for the historical shared key of the device to be updated in the database and generates a new shared key; The key management server encrypts the key update information using the historical shared key to obtain an update notification; the key update request includes the second identity information of the device to be updated, the random value and the new shared key; The key management server sends the update notification to the Internet of Things device; The IoT device decrypts the update notification using the historical shared key to obtain the second identity information, the random value and the new shared key; The Internet of Things device determines whether the second identity information is the same as the first identity information of the Internet of Things device; and when the second identity information is the same as the first identity information, uses the new shared key to update the shared key.

6. The shared key updating method according to claim 5, characterized in that: After the step of determining, by the IoT device, whether the second identity information is the same as the first identity information of the IoT device; and updating the shared key using the new shared key when the second identity information is the same as the first identity information, the method further includes: The IoT device encrypts the random value and the first identity information using the new shared key to obtain verification information; The Internet of Things device sends the verification information to the key management server; The key management server uses the new shared key to decrypt the verification information to obtain the random value and the first identity information; The key management server determines whether the first identity information is the same as the second identity information, and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, updates the shared key version number corresponding to the second identity information in the database.

7. A shared key update system, characterized in that: The shared key update system includes an Internet of Things device and a key management server, wherein: The IoT device is configured to generate a first hash value, and use the first hash value to encrypt a shared key update request to obtain an encrypted request; the shared key update request includes first identity information of the IoT device; The Internet of Things device is further used to send the encryption request to the key management server; The key management server is configured to generate a second Hash value, and use the second Hash value to decrypt the encrypted request to obtain the first identity information in the shared key update request; The key management server is further configured to determine whether the first identity information is the same as the second identity information of the device to be updated in the database; and when the first identity information is the same as the second identity information, perform multiple hash calculations on the preset total key to obtain a calculation result; and calculate a key hash value based on the calculation result and the second identity information, and determine the key hash value as a new shared key; The key management server is further configured to generate a reply message according to the new shared key, the second identity information and the random value, and encrypt the reply message using the second Hash value to obtain an encrypted reply; The key management server is further used to send the encrypted reply to the Internet of Things device; The IoT device is further configured to decrypt the encrypted reply using the first hash value to obtain the new shared key, the second identity information and the random value; The Internet of Things device is further used to determine whether the second identity information is the same as the first identity information; and when the second identity information is the same as the first identity information, use the new shared key to update the shared key.

8. The shared key updating system according to claim 7, characterized in that: The IoT device is further configured to encrypt the random value and the first identity information using the new shared key to obtain verification information; The Internet of Things device is further used to send the verification information to the key management server; The key management server is further configured to use the new shared key to decrypt the verification information to obtain the random value and the first identity information; The key management server is also used to determine whether the first identity information is the same as the second identity information, and whether the random value has not changed; and when the first identity information is the same as the second identity information and the random value has not changed, update the shared key version number corresponding to the second identity information in the database.

9. A shared key update system, characterized in that: The shared key update system includes an Internet of Things device and a key management server, wherein: The key management server is used to search the database for the historical shared key of the device to be updated and generate a new shared key; The key management server is further used to encrypt the key update information using the historical shared key to obtain an update notification; the key update request includes the second identity information of the device to be updated, the random value and the new shared key; The key management server is further used to send the update notification to the Internet of Things device; The IoT device is configured to decrypt the update notification using the historical shared key to obtain the second identity information, the random value, and the new shared key; The Internet of Things device is also used to determine whether the second identity information is the same as the first identity information of the Internet of Things device; and when the second identity information is the same as the first identity information, use the new shared key to update the shared key.

Citation Information

Patent Citations

  • Data interaction method and device based on Internet of Things operating system

    CN110519052A

  • Secure transmission method and system based on SM2 key negotiation mechanism

    CN113079022A