Resource viewing methods, devices, and computer-readable storage media
By generating and managing static and dynamic master keys through an authentication server, the issues of CA centralization and key escrow are resolved, thereby improving the security of key management and the protection of digital resources.
Patent Information
- Application Number
- CN202410005197.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2044-01-02
AI Technical Summary
When existing key management technologies are attacked, all keys in the system are affected, resulting in low security for digital resources protected by keys. This is especially true in certificate-based public key systems and identity-based encryption systems, where CA centralization and key escrow issues are serious.
The system uses an authentication server to generate and manage static and dynamic master keys. It generates content to protect the master key through preset rules, avoiding CA centralization and key escrow. Attackers need to obtain multiple keys and rules to crack the system, which improves the security of key management.
It improves the security of key management, reduces the impact of single points of failure and key escrow risks, and enhances the security of digital resources.
Smart Images

Figure CN118827114B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of key management technology, and in particular to a resource viewing method, device, and computer-readable storage medium. Background Technology
[0002] With the development of information technologies such as 5G and mobile internet, the digital resource industry is experiencing a period of rapid growth, and digital copyright protection is receiving increasing attention. Implementing digital copyright protection and preventing the copying and dissemination of digital resources requires encryption, and key management technology is a crucial element in this process.
[0003] Key management technology refers to the management techniques involved in the generation, distribution, updating, and storage of keys. Currently, the main key management technologies include certificate-based public key systems and identity-based encryption systems (IBE). However, the inherent management characteristics of these technologies mean that once the system is attacked, all keys within it will be affected. For example, in certificate-based public key systems, the high degree of centralization of the CA (Certificate Authority) and the significant impact of single-point failures, coupled with the complexity of certificate management when there are many certificates on authentication devices, mean that if the CA is controlled or attacked by an attacker, or if the CA itself issues malicious certificates, the security of all keys in the system will be compromised. Similarly, in identity-based encryption systems, users' private keys are generated and centrally managed by the KGC (Key Generation Center). If an attacker attacks the KGC, all hosted keys are at risk, resulting in low key management security and consequently compromising the security of digital resources protected by these keys. Summary of the Invention
[0004] The main objective of this application is to provide a resource viewing method, device, and computer-readable storage medium, which aims to improve the security of key management and thus enhance the security of key-protected digital resources.
[0005] To achieve the above objectives, this application provides a resource viewing method, which is applied to an authentication server and includes the following steps:
[0006] Obtain the root key corresponding to the user terminal, receive the encrypted password sent by the user terminal, generate a static master key based on the root key and the encrypted password, and send the static master key to the user terminal for the user terminal to receive and store the static master key;
[0007] When it is determined that the user client requests to view the content protection server, a dynamic master key is generated, and a content protection master key is generated using the static master key and the dynamic master key according to preset rules;
[0008] The content protection master key is sent to the content protection server, so that the content protection server can encrypt the digital resources requested by the user based on the content protection master key, obtain encrypted resources, and send the encrypted resources to the user.
[0009] The dynamic master key is sent to the user terminal, so that the user terminal can generate the content protection master key based on the dynamic master key and the stored static master key according to the preset rules, and decrypt the received encrypted resource to obtain the digital resource using the content protection master key.
[0010] Optionally, the step of obtaining the root key corresponding to the user terminal includes:
[0011] When the authentication server generates the static master key corresponding to the user terminal for the first time, it obtains the user identity information and the terminal device information of the user terminal, generates the root key corresponding to the user terminal based on the terminal device information and the user identity information, and stores the root key.
[0012] When the authentication server updates the static master key corresponding to the user terminal, the root key stored by the authentication server is obtained.
[0013] Optionally, the step of storing the root key includes:
[0014] The root key is encrypted using the encryption password to obtain the encrypted root key, and the encrypted root key is stored.
[0015] The step of obtaining the root key stored on the authentication server includes:
[0016] Obtain the encrypted root key stored on the authentication server;
[0017] The root key is obtained by decrypting the encrypted root key using the encrypted password.
[0018] Optionally, before the step of receiving the encrypted password sent by the user terminal when the authentication server updates the static master key corresponding to the user terminal, the method further includes:
[0019] An authentication request is sent to the user terminal so that the user terminal can send its corresponding identity authentication information and terminal behavior data to the authentication server.
[0020] Receive the identity authentication information and the terminal behavior data, and verify the identity of the current user of the user terminal based on the identity authentication information and the terminal behavior data;
[0021] If the current user's identity verification is successful, then the step of receiving the encrypted password sent by the user terminal is executed.
[0022] Optionally, when there are multiple static master keys, the preset rules include preset key usage rules and preset key generation rules;
[0023] The step of generating a content protection master key using the static master key and the dynamic master key according to preset rules includes:
[0024] The target static master key is extracted from the plurality of static master keys according to the key usage rules;
[0025] The content protection master key is obtained by combining the target static master key and the dynamic master key according to the key generation rules.
[0026] Furthermore, to achieve the above objectives, this application also provides a resource viewing method, which is applied to a content protection server and includes the following steps:
[0027] Receive viewing requests sent by the user client;
[0028] The system receives a content protection master key sent by an authentication server and uses the content protection master key to encrypt the digital resource requested by the user to view, thus obtaining the encrypted resource. The content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules. The static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password. The dynamic master key in the authentication server is generated by the authentication server when it determines that the user requests to view the content protection server.
[0029] The encrypted resource is sent to the user terminal so that the user terminal can use the content protection master key to decrypt the encrypted resource to obtain the digital resource; wherein, the content protection master key in the user terminal is generated by the user terminal according to the preset rules using the static master key and the dynamic master key in the user terminal, and the static master key and the dynamic master key in the user terminal are generated by the authentication server and then sent.
[0030] To achieve the above objectives, this application also provides a resource viewing method, which is applied to a user terminal and includes the following steps:
[0031] The encrypted password is obtained and sent to the authentication server, so that the authentication server can generate a static master key based on the received encrypted password and the obtained root key and send it to the user terminal.
[0032] Receive and store the static master key;
[0033] A viewing request is sent to a content protection server, which uses a content protection master key to encrypt the digital resource requested by the user and sends the encrypted resource to the user. The content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules. The static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password. The dynamic master key in the authentication server is generated by the authentication server when it determines that the user has requested to view the content protection server.
[0034] Receive the dynamic master key sent by the authentication server, and generate a content protection master key using the static master key and the dynamic master key according to the preset rules;
[0035] The encrypted resource is received from the content protection server, and the digital resource is obtained by decrypting the encrypted resource using the content protection master key.
[0036] Optionally, the resource viewing method further includes:
[0037] Detect whether a password update request has been received from the authentication server, and detect whether all static master keys have been used;
[0038] Upon receiving the password update request, and / or if the static master key has been used, the step of obtaining the encrypted password and sending it to the authentication server is performed.
[0039] In addition, to achieve the above objectives, this application also provides a resource viewing device, which includes: a memory, a processor, and a resource viewing program stored in the memory and executable on the processor. When the resource viewing program is executed by the processor, it implements the steps of the resource viewing method described above.
[0040] In addition, to achieve the above objectives, this application also provides a computer-readable storage medium storing a resource viewing program, which, when executed by a processor, implements the steps of the resource viewing method described above.
[0041] In this application, the authentication server obtains the root key corresponding to the user terminal and the encrypted password sent by the user terminal, generates a static master key based on the root key and the encrypted password, and sends the static master key to the user terminal. The user terminal receives and stores the static master key.
[0042] When the authentication server determines that the user client is requesting to view the content protection server, it generates a dynamic master key and, according to preset rules, uses the static master key and the dynamic master key to generate a content protection master key, which is then sent to the content protection server. The content protection server encrypts the digital resource requested by the user client based on the content protection master key, obtaining encrypted resources, and then sends the encrypted resources to the user client.
[0043] The authentication server sends the dynamic master key to the user terminal. The user terminal generates the content protection master key based on the dynamic master key and the stored static master key according to the preset rules, and decrypts the received encrypted resource to obtain the digital resource using the content protection master key.
[0044] In this application, the authentication server is responsible for generating and managing both static and dynamic master keys. Compared to certificate-based public key systems, the authentication server in this application does not rely on a third-party Certificate Authority (CA), avoiding the problems of CA centralization. Furthermore, since key management is centralized on the authentication server, if the authentication server fails, it only needs to be repaired or replaced without affecting the user end or content protection server, reducing the impact of single points of failure and improving the security of key management, thereby enhancing the security of the digital resources protected by the keys. Compared to identity-based encryption systems, in this application, key management is entirely handled by the authentication server, without the need for user or other third-party tools, reducing the risk of key escrow and thus improving the security of the digital resources protected by the keys.
[0045] Furthermore, in this application, the communication process between the authentication server and the user does not involve the direct transmission of the content protection master key. Attackers need to obtain the dynamic master key, the static master key, and the preset rules for key combinations in order to obtain the content protection master key. This increases the difficulty for attackers to obtain the content protection master key, enhances the security of key management, and thus improves the security of digital resources protected by the key. Attached Figure Description
[0046] Figure 1 This is a schematic diagram of the hardware operating environment involved in the embodiments of this application;
[0047] Figure 2 This is a flowchart illustrating the first embodiment of the resource viewing method of this application;
[0048] Figure 3 This is a flowchart illustrating the second embodiment of the resource viewing method of this application;
[0049] Figure 4 This is a flowchart illustrating the third embodiment of the resource viewing method of this application;
[0050] Figure 5 This is a flowchart illustrating the fourth embodiment of the resource viewing method of this application;
[0051] Figure 6 This is a schematic diagram illustrating the scenario involving the management of a static master key in one embodiment of the resource viewing method of this application;
[0052] Figure 7 This is a schematic diagram illustrating a scenario involving the transmission of digital resources in one embodiment of the resource viewing method of this application;
[0053] Figure 8 This is a timing diagram illustrating the resource viewing process in one embodiment of the resource viewing method of this application.
[0054] The realization of the purpose of this application, its functional features and advantages will be further explained in conjunction with the accompanying drawings. Detailed Implementation
[0055] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.
[0056] like Figure 1 As shown, Figure 1 This is a schematic diagram of the device structure of the hardware operating environment involved in the embodiments of this application.
[0057] It should be noted that the resource viewing device in this application embodiment can be an authentication server, a content protection server, or a user terminal.
[0058] like Figure 1As shown, the resource viewing device may include: a processor 1001, such as a CPU; a network interface 1004; a user interface 1003; a memory 1005; and a communication bus 1002. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen and an input unit such as a keyboard. Optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as a disk drive. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0059] Those skilled in the art will understand that Figure 1 The device structure shown does not constitute a limitation on the resource viewing device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0060] like Figure 1 As shown, the memory 1005, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a resource viewing program. The operating system is a program that manages and controls the device's hardware and software resources, supporting the operation of the resource viewing program and other software or programs. Figure 1 In the device shown, the user interface 1003 is mainly used for data communication with the client; the network interface 1004 is mainly used for establishing a communication connection with the server; and the processor 1001 can be used to call the resource viewing program stored in the memory 1005 and execute the operation corresponding to the resource viewing device.
[0061] Specifically, when the resource viewing device is an authentication server, the processor 1001 can be used to call the resource viewing program stored in the memory 1005 and perform the following operations:
[0062] Obtain the root key corresponding to the user terminal, receive the encrypted password sent by the user terminal, generate a static master key based on the root key and the encrypted password, and send the static master key to the user terminal for the user terminal to receive and store the static master key;
[0063] When it is determined that the user client requests to view the content protection server, a dynamic master key is generated, and a content protection master key is generated using the static master key and the dynamic master key according to preset rules;
[0064] The content protection master key is sent to the content protection server, so that the content protection server can encrypt the digital resources requested by the user based on the content protection master key, obtain encrypted resources, and send the encrypted resources to the user.
[0065] The dynamic master key is sent to the user terminal, so that the user terminal can generate the content protection master key based on the dynamic master key and the stored static master key according to the preset rules, and decrypt the received encrypted resource to obtain the digital resource using the content protection master key.
[0066] Furthermore, the step of obtaining the root key corresponding to the user terminal includes:
[0067] When the authentication server generates the static master key corresponding to the user terminal for the first time, it obtains the user identity information and the terminal device information of the user terminal, generates the root key corresponding to the user terminal based on the terminal device information and the user identity information, and stores the root key.
[0068] When the authentication server updates the static master key corresponding to the user terminal, the root key stored by the authentication server is obtained.
[0069] Further, the step of storing the root key includes:
[0070] The root key is encrypted using the encryption password to obtain the encrypted root key, and the encrypted root key is stored.
[0071] The step of obtaining the root key stored on the authentication server includes:
[0072] Obtain the encrypted root key stored on the authentication server;
[0073] The root key is obtained by decrypting the encrypted root key using the encrypted password.
[0074] Furthermore, before the step of receiving the encrypted password sent by the user terminal when the authentication server updates the static master key corresponding to the user terminal, the method further includes:
[0075] An authentication request is sent to the user terminal so that the user terminal can send its corresponding identity authentication information and terminal behavior data to the authentication server.
[0076] Receive the identity authentication information and the terminal behavior data, and verify the identity of the current user of the user terminal based on the identity authentication information and the terminal behavior data;
[0077] If the current user's identity verification is successful, then the step of receiving the encrypted password sent by the user terminal is executed.
[0078] Furthermore, when there are multiple static master keys, the preset rules include preset key usage rules and preset key generation rules;
[0079] The step of generating a content protection master key using the static master key and the dynamic master key according to preset rules includes:
[0080] The target static master key is extracted from the plurality of static master keys according to the key usage rules;
[0081] The content protection master key is obtained by combining the target static master key and the dynamic master key according to the key generation rules.
[0082] Specifically, when the resource viewing device is a content protection server, the processor 1001 can be used to call the resource viewing program stored in the memory 1005 and perform the following operations:
[0083] Receive viewing requests sent by the user client;
[0084] The system receives a content protection master key sent by an authentication server and uses the content protection master key to encrypt the digital resource requested by the user to view, thus obtaining the encrypted resource. The content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules. The static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password. The dynamic master key in the authentication server is generated by the authentication server when it determines that the user requests to view the content protection server.
[0085] The encrypted resource is sent to the user terminal so that the user terminal can use the content protection master key to decrypt the encrypted resource to obtain the digital resource; wherein, the content protection master key in the user terminal is generated by the user terminal according to the preset rules using the static master key and the dynamic master key in the user terminal, and the static master key and the dynamic master key in the user terminal are generated by the authentication server and then sent.
[0086] Specifically, when the resource viewing device is a user terminal, the processor 1001 can be used to call the resource viewing program stored in the memory 1005 and perform the following operations:
[0087] The encrypted password is obtained and sent to the authentication server, so that the authentication server can generate a static master key based on the received encrypted password and the obtained root key and send it to the user terminal.
[0088] Receive and store the static master key;
[0089] A viewing request is sent to a content protection server, which uses a content protection master key to encrypt the digital resource requested by the user and sends the encrypted resource to the user. The content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules. The static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password. The dynamic master key in the authentication server is generated by the authentication server when it determines that the user has requested to view the content protection server.
[0090] Receive the dynamic master key sent by the authentication server, and generate a content protection master key using the static master key and the dynamic master key according to the preset rules;
[0091] The encrypted resource is received from the content protection server, and the digital resource is obtained by decrypting the encrypted resource using the content protection master key.
[0092] Furthermore, the resource viewing method also includes:
[0093] Detect whether a password update request has been received from the authentication server, and detect whether all static master keys have been used;
[0094] Upon receiving the password update request, and / or if the static master key has been used, the step of obtaining the encrypted password and sending it to the authentication server is performed.
[0095] Based on the above structure, various embodiments of the resource viewing method are proposed.
[0096] Reference Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the resource viewing method of this application.
[0097] This application provides an embodiment of a resource viewing method. It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here. In this embodiment, the resource viewing method is applied to an authentication server. In this embodiment, the resource viewing method includes steps S10-S40.
[0098] Step S10: Obtain the root key corresponding to the user terminal, receive the encrypted password sent by the user terminal, generate a static master key based on the root key and the encrypted password, and send the static master key to the user terminal for the user terminal to receive and store the static master key.
[0099] With the development of information technologies such as 5G and mobile internet, the digital resource industry is experiencing a period of rapid growth, and digital copyright protection is receiving increasing attention. Implementing digital copyright protection and preventing the copying and dissemination of digital resources requires encryption, and key management technology is a crucial element in this process.
[0100] Key management technology encompasses the generation, distribution, updating, and storage of keys. Currently, the main key management technologies include: certificate-based public key systems (such as Public Key Infrastructure (PKI), key negotiation protocols, and blockchain-based PKI identity authentication) and identity-based encryption systems (IBE).
[0101] In certificate-based public key systems, the Certificate Authority (CA) is highly centralized and has a significant impact from single points of failure. When a CA is controlled or attacked by hackers, or even when the CA itself issues malicious certificates, the corresponding entity user identity becomes either unusable or untrustworthy, leading to serious trust issues.
[0102] In a certificate-based public key system, C certificate management addresses network trust issues. When the number of authentication device certificates is large, managing a large number of authentication device certificates will make the certificate management of the CA center extremely complex and inefficient. Once the network receives terminal requests exceeding its resource processing capacity, it can easily lead to trust problems throughout the entire network.
[0103] In identity-based encryption systems, key escrow and secure key distribution are inherently weak. IBE authentication mechanisms also require a trusted third-party Key Generation Center (KGC) to distribute and manage keys for users. Because user private keys are generated and centrally managed by the KGC, IBE inherently suffers from key escrow issues. Furthermore, when users request keys from the KGC, issues arise regarding user authentication trust and secure private key distribution. Whether for small-scale or large-scale IBE applications, key generation and updates require a key distribution step, thus presenting key security distribution problems. Compared to PKI, IBE also requires a core, trusted, authoritative third-party organization to manage keys, inevitably leading to a series of issues related to key updates and secure key distribution. However, the inherent management characteristics of these key management technologies mean that once the system is attacked, all keys within the system will be affected, resulting in low key management security and compromising the security of digital resources protected by these keys.
[0104] In this embodiment, the server used to generate and manage keys is called the authentication server, and the server storing digital resources is called the content protection server.
[0105] The authentication server obtains the root key corresponding to the user's client, receives the encrypted password sent by the user, and then generates a static master key based on the root key and the encrypted password. In this embodiment, the number of static master keys can be one or more, and there is no specific limitation.
[0106] The method by which the authentication server obtains the root key is not limited. In one feasible implementation, it can obtain a pre-stored root key; in another feasible implementation, it can generate the root key using an encryption algorithm based on data representing the user's identity and / or data representing the identity of the bound user sent by the user. The specific encryption algorithm used can be set according to actual needs. For example, in one feasible implementation, the authentication server can generate the root key using an encryption algorithm based on data representing the user's identity and / or data representing the identity of the bound user sent by the user when initially generating the static master key, and then store the root key. The authentication server retrieves the stored root key when updating the static master key.
[0107] The specific process by which the authentication server receives the encrypted password is not limited here; it can be configured according to actual needs. For example, in one feasible implementation, the authentication server can send a request to the user client, the user client sends an encrypted password based on the request, and the authentication server receives the encrypted password. In another feasible implementation, the user client can actively send an encrypted password under certain conditions, in which case the authentication server receives the encrypted password. It should be noted that the method by which the user client generates the encrypted password is not limited. The user client can receive a password entered by the user as the encrypted password, the user client can generate an encrypted password based on the user's input, or the user client can randomly generate an encrypted password. There are no restrictions here; it can be configured according to actual needs.
[0108] The method by which the authentication server generates a static master key based on the root key and encrypted password is not limited here. For example, in one approach, if a single static master key is to be generated, it can be generated using methods such as concatenation or XOR operations. In another feasible implementation, the authentication server can also generate multiple static master keys using algorithms such as key derivation algorithms and hash algorithms. Exemplarily, in one feasible implementation, when generating multiple static master keys, the authentication server can use a combination of HMAC (Keyed-Hashing for Message Authentication) and PBKDF2 (Password-Based Key Derivation Function 2). Specifically, the authentication server can use the root key and encrypted password as inputs to the HMAC algorithm to obtain the HMAC value, and then use this HMAC value as input to PBKDF2 to generate multiple static master keys.
[0109] The authentication server sends the static master key to the user terminal, which receives and stores it. In subsequent key management processes, the user terminal can directly use the locally stored static master key to view resources. This embodiment enables the separate transmission of the static and dynamic master keys that constitute the content protection master key. An attacker would need to disrupt the communication process between the static and dynamic master keys to obtain the complete content protection master key, thus improving its security.
[0110] The authentication server can compile the generated static master keys into a document and send it to the user terminal, which can then store the static master key on its local hardware. In this way, even if the user's password is stolen, as long as the user's hardware is not compromised, attackers will still be unable to access digital resources without the static master key, thus providing security for digital resources.
[0111] Step S20: When it is determined that the user requests to view the content protection server, a dynamic master key is generated, and a content protection master key is generated using the static master key and the dynamic master key according to preset rules.
[0112] When the authentication server determines that a user has requested to view the content protection server, it generates a dynamic master key. In one feasible implementation, the user can send a notification message or request a dynamic master key from the authentication server simultaneously with the request. Upon receiving the notification message or key request from the user, the authentication server can determine that the user has requested to view the content protection server. In another feasible implementation, the content protection server can request the content protection master key from the authentication server after receiving the user's request. Upon receiving the key request from the content protection server, the authentication server can determine that the user has requested to view the content protection server. The specific configuration can be adjusted according to actual needs and is not limited here. In yet another feasible implementation, the user's request to view the content protection server can also be determined when the user logs into the authentication server.
[0113] The authentication server pre-configures rules for combining static and dynamic master keys to obtain the content protection master key. These are referred to as preset rules for distinction. Preset rules can include concatenation, XOR operations, etc., and are not restricted here. The authentication server generates the content protection master key using the static and dynamic master keys according to the preset rules.
[0114] Step S30: The content protection master key is sent to the content protection server, so that the content protection server can encrypt the digital resources requested by the user based on the content protection master key to obtain encrypted resources, and send the encrypted resources to the user.
[0115] The authentication server sends the content protection master key to the content protection server.
[0116] The content protection server encrypts the digital resources requested by the user based on the content protection master key, obtains the encrypted resources, and then sends the encrypted resources to the user. Specifically, the encryption method used by the content protection server is not limited here.
[0117] In specific implementations, the content protection server can directly encrypt the digital resources requested by the user client using the content protection master key; the content protection server can also implement multi-layer encryption using the content protection master key, that is, use the content protection master key to encrypt a lower-level key, and use the lower-level key to encrypt the digital resources. The specific number of encryption layers can be set according to actual needs. Compared with directly encrypting digital resources using the content protection master key, multi-layer encryption can improve the security of digital resources.
[0118] Step S40: The dynamic master key is sent to the user terminal, so that the user terminal can generate the content protection master key based on the dynamic master key and the stored static master key according to the preset rules, and decrypt the received encrypted resource to obtain the digital resource using the content protection master key.
[0119] The authentication server sends the dynamic master key to the user client. The user client has pre-configured rules identical to those on the authentication server. Following these rules, the user client generates a content protection master key based on the dynamic master key and the stored static master key. In other words, the user client performs the same combination process on the static and dynamic master keys as the authentication server to obtain the content protection master key. After receiving the content protection master key, the user client uses it to decrypt the received encrypted resources to obtain the digital resources.
[0120] Furthermore, in a feasible implementation, when there are multiple static master keys, the preset rules include preset key usage rules and preset key generation rules. Step S20: Generate a content protection master key using the static master key and the dynamic master key according to the preset rules, including steps S201-S202.
[0121] Step S201: Extract the target static master key from the plurality of static master keys according to the key usage rules.
[0122] In this embodiment, the authentication server generates multiple static master keys. The pre-defined rules include: a key usage rule for extracting the static master key (hereinafter referred to as the target static master key for distinction) from the multiple static master keys used to generate the content protection master key; and a key generation rule for generating the content protection master key using the target static master key and the static master keys. The key usage rules can be set according to actual needs and are not limited here. For example, the target static master key can be selected each time from the static master keys in a specific order.
[0123] Step S202: Combine the target static master key and the dynamic master key according to the key generation rules to obtain the content protection master key.
[0124] The authentication server combines the target static master key and the dynamic master key according to the key generation rules to obtain the content protection master key. The specific combination process is not limited here, and can be a combination method such as concatenation, XOR, hashing, etc.
[0125] Furthermore, in one feasible implementation, after the authentication server has used the target static master key, it can delete the target static master key or mark the target static master key to avoid the reuse of the static master key, improve the security of the content protection master key, and thus improve the security of digital resources.
[0126] It should be noted that, in this embodiment, the preset rules on the user end include key usage rules and key generation rules that are consistent with those of the authentication server, so as to ensure that the content protection master key generated by the user end and the authentication server is consistent.
[0127] In this embodiment, the authentication server generates multiple static master keys at once. Compared to generating one static master key at a time, this embodiment can reduce the consumption of the authentication server's computing resources, reduce the number of times the static master key is transmitted, reduce the risk of the static master key being attacked, improve the security of key management, and thus improve the security of digital resources.
[0128] In this embodiment, the authentication server obtains the root key corresponding to the user's terminal and the encrypted password sent by the user. Based on the root key and the encrypted password, it generates a static master key and sends it to the user's terminal. The user's terminal receives and stores the static master key. When the authentication server determines that the user's terminal requests to view the content protection server, it generates a dynamic master key and, according to preset rules, uses the static and dynamic master keys to generate a content protection master key, which it then sends to the content protection server. The content protection server encrypts the digital resource requested by the user's terminal based on the content protection master key, obtaining the encrypted resource, and sends it to the user's terminal. The authentication server then sends the dynamic master key to the user's terminal. The user's terminal generates a content protection master key based on the dynamic master key and the stored static master key according to preset rules, and decrypts the received encrypted resource using the content protection master key to obtain the digital resource.
[0129] In this embodiment, the communication process between the authentication server and the user does not involve the direct transmission of the content protection master key. Attackers need to obtain the dynamic master key, the static master key, and the key combination rules to obtain the content protection master key, which increases the difficulty for attackers to obtain the content protection master key, enhances the security of key management, and thus improves the security of digital resources protected by the key.
[0130] In this embodiment, the authentication server is responsible for generating and managing both static and dynamic master keys. Compared to certificate-based public key systems, in this embodiment, the authentication server does not rely on a third-party Certificate Authority (CA), avoiding the problems of CA centralization. Furthermore, since key management is centralized on the authentication server, if the authentication server fails, it only needs to be repaired or replaced without affecting the user client and content protection server, reducing the impact of single points of failure and improving the security of key management, thereby enhancing the security of the digital resources protected by the keys. Compared to identity-based encryption systems, in this embodiment, key management is entirely handled by the authentication server, without the need for user or other third-party tools, reducing the risk of key escrow and thus improving the security of the digital resources protected by the keys.
[0131] Furthermore, in this embodiment, the authentication server is responsible for generating and managing both static and dynamic master keys. Compared to blockchain-based PKI, this embodiment avoids the problem of CA centralization by eliminating the need for multiple blocks, resulting in lower computing resource consumption and increased key management efficiency.
[0132] Furthermore, based on the first embodiment described above, a second embodiment of the resource viewing method of this application is proposed. In this embodiment, reference is made to... Figure 3 When the authentication server generates the static master key corresponding to the user terminal for the first time, step S10 includes obtaining the root key corresponding to the user terminal, including steps S101-S102.
[0133] Step S101: When the authentication server generates the static master key corresponding to the user terminal for the first time, it obtains the user identity information and the terminal device information of the user terminal, generates the root key corresponding to the user terminal based on the terminal device information and the user identity information, and stores the root key.
[0134] In this embodiment, a root key is pre-set in the authentication server. When the authentication server initially generates the static master key corresponding to the user terminal, it generates the root key based on the user's identity information and terminal device information for subsequent processing. Compared to pre-setting the root key in the authentication server, this embodiment generates the root key when the static master key is initially generated, based on the user's identity information and terminal device information. This makes the root key generation more flexible and its randomness stronger, increasing the difficulty for attackers to steal the root key and improving its security.
[0135] Specifically, in this embodiment, the information representing the identity of the user bound to the user terminal is called user identity information, and the information representing the identity of the user terminal device is called terminal device information. The specific content of the user identity information is not limited here; for example, it can be the user's ID card information or encoded information obtained by converting the user's biometric features. Terminal device information can be the user terminal's unique identifier, the user terminal's MAC address, etc., and is not limited here.
[0136] The authentication server obtains the user's identity information and terminal device information corresponding to the user's client. In a specific implementation, the authentication server may request the user's identity information and terminal device information from the user's client to obtain them; alternatively, the user may provide these information when registering with the authentication server, and there is no restriction on this.
[0137] The authentication server generates a root key corresponding to the user terminal based on the terminal device information and user identity information. The specific process for generating the root key is not limited. For example, in one feasible implementation, a hash-based message authentication code algorithm (HMAC) is used. The authentication server can use the user identity information as the key in the HMAC algorithm and the terminal device information as the message, then calculate an HMAC value as the generated root key. The calculation process of the HMAC algorithm is as follows:
[0138] HMAC(key, message)=Hash((key⊕opad)||Hash((key⊕ipad)||message))
[0139] Here, opad and ipad are specific constants, ⊕ represents the XOR operation, || represents the concatenation operation, and Hash represents the selected hash function, which can be SHA-256, SHA-512, etc.
[0140] In this embodiment, after generating the root key, the authentication server can store the root key for subsequent processing. Furthermore, in a feasible implementation, the authentication server can encrypt the root key when storing it to ensure its security, thereby improving the security of the static master key, the content protection master key, and the security of providing digital resources.
[0141] Step S102: When the authentication server updates the static master key corresponding to the user terminal, obtain the root key stored by the authentication server.
[0142] In this embodiment, the authentication server may also trigger the update of the static master key. The specific conditions for triggering the update of the static master key can be set according to actual needs. For example, in one feasible implementation, the static master key generated last time may have been used in the process of generating the content protection master key. In this case, in order to avoid generating the same content protection master key repeatedly and to improve the security of key management, the authentication server updates the static master key. In another feasible implementation, the static master key may also be updated when a request to update the static master key is received from the user.
[0143] Specifically, in this embodiment, when the authentication server triggers the update of the static master key, it obtains the root key stored in the authentication server. The user terminal in the authentication server receives the new encrypted password and uses the new encrypted password and the root key to generate a new static master key. The authentication server uses the new static master key to update the static master keys stored in the authentication server and the user terminal.
[0144] Further, in one feasible implementation, step S102: storing the root key includes steps S1021-S1022.
[0145] Step S1021: Encrypt the root key using the encryption password to obtain the encrypted root key, and store the encrypted root key.
[0146] In this embodiment, the authentication server encrypts the root key using an encrypted password to obtain an encrypted root key, and then stores the encrypted root key. Compared to directly storing the root key, encrypting the root key in this embodiment improves the security of the root key, thereby improving the security of the static master key, which in turn improves the security of the content protection master key, and ultimately enhances the security of digital resources.
[0147] In this embodiment, step S1022: obtaining the root key stored by the authentication server includes steps S10221-10222.
[0148] Step S10221: Obtain the encrypted root key stored on the authentication server.
[0149] In this embodiment, when updating the static master key, the authentication server obtains the encrypted root key stored on the authentication server.
[0150] Step S10222: Decrypt the encrypted root key using the encrypted password to obtain the root key.
[0151] The authentication server decrypts the encrypted root key using an encrypted password to obtain the root key. In this embodiment, the authentication server encrypts the root key when storing it to ensure its security, thereby improving the security of the static master key, the content protection master key, and the security of providing digital resources.
[0152] Furthermore, in one feasible implementation, when updating the static master key corresponding to the user terminal, the authentication server can encrypt the root key using the encrypted password received during the static master key update and store it. This implementation ensures that the encrypted password for the encrypted root key changes every time in the authentication server, increasing the difficulty for attackers to steal the root key and thus improving the security of digital resources. It should be noted that in this implementation, when the authentication server updates the static master key corresponding to the user terminal, the authentication server obtains the latest stored encrypted root key and decrypts it using the encrypted password corresponding to the latest stored encrypted root key to obtain the root key corresponding to the user terminal.
[0153] Furthermore, in one feasible implementation, when the authentication server updates the static master key corresponding to the user terminal, step S10, before receiving the encrypted password sent by the user terminal, further includes steps S50-S70.
[0154] Step S50: Send an authentication request to the user terminal so that the user terminal can send its corresponding identity authentication information and terminal behavior data to the authentication server.
[0155] In this embodiment, when the authentication server is updating the static master key corresponding to the user terminal, before receiving the encrypted password sent by the user terminal, the authentication server verifies the identity of the actual user of the user terminal to determine whether the user terminal is under attack. If the user terminal is not under attack, the authentication server obtains the root key corresponding to the user terminal and the encrypted password sent by the user terminal to update the static master key. This embodiment can prevent attackers from obtaining all information through the user terminal if the user terminal is attacked, potentially resulting in the loss of passwords and the terminal itself. If a significant change in the user's usage pattern is detected, the user terminal is prohibited from updating passwords. Thus, after the static master key is exhausted, attackers can no longer access system resources, reducing the loss of digital resources.
[0156] Specifically, when the authentication server is updating the static master key corresponding to the user's terminal, it sends an authentication request to the user's terminal before updating the static master key. The user's terminal sends the obtained identity authentication information and terminal behavior data to the authentication server. The identity authentication information is used to verify the user's identity, and may include user identity information such as the user's ID card number and biometric information. The identity authentication information may also include user behavior information generated when the user operates the terminal, such as the user's network protocol information, user operating habits, and frequency. The terminal behavior data is the user's behavioral data, such as access requests and access addresses.
[0157] Step S60: Receive the identity authentication information and the terminal behavior data, and verify the identity of the current user of the user terminal based on the identity authentication information and the terminal behavior data.
[0158] The authentication server receives identity authentication information and terminal behavior data, and verifies the identity of the current user on the user terminal based on the identity authentication information and terminal behavior data.
[0159] The specific verification process can be as follows: based on user identity authentication, determine whether the user's identity has changed; based on terminal behavior data, determine whether there has been a significant change in the user's behavior. If the user's identity has not changed and / or the user's behavior has not changed, then the current user's identity verification is considered successful. If the user's identity has changed and the user's behavior has changed, then the current user's identity verification is considered unsuccessful. The specific verification process can be configured according to actual needs and is not limited here.
[0160] Step S70: If the identity verification of the current user is successful, then the step of receiving the encrypted password sent by the user terminal is executed.
[0161] If the current user's identity is verified, the authentication server receives the encrypted password sent by the user for further processing. If the current user's identity is verified, the authentication server prohibits receiving encrypted passwords. Specifically, this could mean the authentication server stops requesting encrypted passwords from the user or stops receiving encrypted passwords sent by the user; details will not be elaborated here.
[0162] In this embodiment, the authentication server obtains the user's identity information and terminal device information corresponding to the user's client; it then generates a root key corresponding to the user's client based on the terminal device information and user identity information. Compared to obtaining a root key manually set by the user, the root key obtained in this embodiment has stronger randomness and higher security, improving the security of the content protection master key and thus enhancing the security of digital resources.
[0163] Furthermore, based on the first and / or second embodiments described above, a third embodiment of the resource viewing method of this application is proposed. In this embodiment, the resource viewing method is applied to a content protection server, referring to... Figure 4 The method for viewing resources includes steps A10-A30.
[0164] Step A10: Receive the viewing request sent by the user.
[0165] In this embodiment, when a user needs to view resources, they can send a viewing request to the content protection server through their client. The content protection server receives the viewing request sent by the client.
[0166] Step A20: Receive the content protection master key sent by the authentication server, and use the content protection master key to encrypt the digital resource requested by the user to view, thus obtaining the encrypted resource; wherein, the content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules; the static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password; and the dynamic master key in the authentication server is generated by the authentication server when it determines that the user requests to view the content protection server.
[0167] The authentication server obtains the root key and encrypted password, generates a static master key based on the root key and encrypted password, and generates a dynamic master key when a user requests to view the content protection server. The authentication server generates a content protection master key using the static and dynamic master keys according to preset rules and sends it to the content protection server. The content protection server receives the content protection master key sent by the authentication server and uses it to encrypt the digital resource requested by the user, thus obtaining the encrypted resource.
[0168] Step A30: Send the encrypted resource to the user terminal so that the user terminal can use the content protection master key to decrypt the encrypted resource to obtain the digital resource; wherein, the content protection master key in the user terminal is generated by the user terminal according to the preset rules using the static master key and the dynamic master key in the user terminal, and the static master key and the dynamic master key in the user terminal are generated and sent by the authentication server.
[0169] The content protection server sends encrypted resources to the user terminal. When the authentication server determines that the user terminal has requested to view the content protection server, it generates a dynamic master key and sends it to the user terminal. The user terminal uses the static master key and the dynamic master key to generate a content protection master key, and then uses the content protection master key to decrypt the encrypted resources to obtain the digital resources. In this embodiment, the implementation methods of the authentication server, content protection server, and user terminal can all refer to the first embodiment, and will not be elaborated further here.
[0170] Furthermore, in one feasible implementation, after receiving a viewing request from the user, the content protection server sends a content protection request to the authentication server, so that the authentication server can generate a content protection master key based on the content protection request. Compared to the user simultaneously sending requests to both the authentication protection server and the content protection server, so that the authentication server can determine whether the user has requested to view digital resources, this implementation can avoid the complexity of the user interacting with both the authentication protection server and the content protection server at the same time.
[0171] In this embodiment, the authentication server obtains the root key corresponding to the user terminal and the encrypted password sent by the user terminal. Based on the root key and the encrypted password, it generates a static master key and sends the static master key to the user terminal. The user terminal receives and stores the static master key.
[0172] When the authentication server determines that a user is requesting to view the content protection server, it generates a dynamic master key and, according to preset rules, uses the static and dynamic master keys to generate a content protection master key, which is then sent to the content protection server. The content protection server uses the content protection master key to encrypt the digital resource requested by the user, obtaining the encrypted resource, and then sends the encrypted resource to the user.
[0173] The authentication server sends the dynamic master key to the user's client. The user's client generates a content protection master key based on the dynamic master key and the stored static master key according to preset rules, and uses the content protection master key to decrypt the received encrypted resource to obtain the digital resource.
[0174] In this embodiment, the communication process between the authentication server and the user does not involve the direct transmission of the content protection master key. Attackers need to obtain the dynamic master key, the static master key, and the preset rules for key combinations in order to obtain the content protection master key. This makes it more difficult for attackers to obtain the content protection master key, enhances the security of key management, and thus improves the security of digital resources protected by the key.
[0175] In this embodiment, the authentication server is responsible for generating and managing both static and dynamic master keys. Compared to certificate-based public key systems, in this embodiment, the authentication server does not rely on a third-party Certificate Authority (CA), avoiding the problems of CA centralization. Furthermore, since key management is centralized on the authentication server, if the authentication server fails, it only needs to be repaired or replaced without affecting the user client and content protection server, reducing the impact of single points of failure and improving the security of key management, thereby enhancing the security of the digital resources protected by the keys. Compared to identity-based encryption systems, in this embodiment, key management is entirely handled by the authentication server, without the need for user or other third-party tools, reducing the risk of key escrow and thus improving the security of the digital resources protected by the keys.
[0176] Furthermore, based on the first, second, and / or third embodiments described above, a fourth embodiment of the resource viewing method of this application is proposed. In this embodiment, the resource viewing method is applied to the user terminal, referring to... Figure 5 The method for viewing resources includes steps B10-B50.
[0177] Step B10: Obtain the encrypted password and send it to the authentication server, so that the authentication server can generate a static master key based on the received encrypted password and the obtained root key and send it to the user terminal.
[0178] In this embodiment, the user terminal obtains the encrypted password and sends it to the authentication server. Specifically, the user terminal can receive a password entered by the user as the encrypted password, or it can generate an encrypted password based on the user's input. The user terminal can also randomly generate an encrypted password; there are no restrictions, and the settings can be configured according to actual needs. The authentication server generates a static master key based on the received encrypted password and the obtained root key and sends it to the user terminal.
[0179] Step B20: Receive and store the static master key.
[0180] The client receives and stores the static master key.
[0181] Step B30: A viewing request is sent to the content protection server, so that the content protection server can use the content protection master key to encrypt the digital resource requested by the user to obtain the encrypted resource and send it to the user; wherein, the content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules, the static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password, and the dynamic master key in the authentication server is generated by the authentication server when it determines that the user requests to view the content protection server.
[0182] The client sends a viewing request to the content protection server. Upon confirming the client's request, the authentication server generates a dynamic master key and sends it to the client. Then, following preset rules, it generates a content protection master key using the static and dynamic master keys and sends it to the content protection server. The content protection server uses the content protection master key to encrypt the requested digital resource and sends the encrypted resource to the client.
[0183] Step B40: Receive the dynamic master key sent by the authentication server, and generate a content protection master key using the static master key and the dynamic master key according to the preset rules.
[0184] The client receives the dynamic master key sent by the authentication server and uses the static and dynamic master keys to generate content protection for the master key according to the same preset rules as the authentication server.
[0185] Step B50: Receive the encrypted resource sent by the content protection server, and decrypt the encrypted resource using the content protection master key to obtain the digital resource.
[0186] The user terminal receives encrypted resources sent by the content protection server and decrypts the encrypted resources using the content protection master key to obtain the digital resources. In this embodiment, the implementation methods of the authentication server, content protection server, and user terminal can all refer to the first embodiment, and will not be described in detail here.
[0187] Furthermore, in one feasible implementation, the resource viewing method further includes step B60.
[0188] Step B60: Detect whether a password update request has been received from the authentication server, and detect whether all static master keys have been used.
[0189] The client detects whether it has received a password update request from the authentication server and checks whether the static master key has been used to determine whether to trigger an update of the static master key, and then determines whether to send a new password to the authentication server.
[0190] In this embodiment, step B10: obtaining the encrypted password and sending it to the authentication server includes step B101.
[0191] Step B101: Upon receiving the password update request, and / or, if the static master key has been used, perform the step of obtaining the encrypted password and sending it to the authentication server.
[0192] Upon receiving a password update request, and / or when all static master keys have been used, the user client obtains an encrypted password and sends it to the authentication server. In this embodiment, the authentication server obtains the root key corresponding to the user client and the encrypted password sent by the user client, generates a static master key based on the root key and the encrypted password, and sends the static master key to the user client. The user client receives and stores the static master key. When the authentication server determines that the user client requests to view the content protection server, it generates a dynamic master key and generates a content protection master key using the static master key and the dynamic master key according to preset rules, and sends the content protection master key to the content protection server. The content protection server encrypts the digital resource requested by the user client based on the content protection master key, obtains the encrypted resource, and sends the encrypted resource to the user client. The authentication server sends the dynamic master key to the user client. The user client generates a content protection master key based on the dynamic master key and the stored static master key according to preset rules, and decrypts the received encrypted resource using the content protection master key to obtain the digital resource.
[0193] In this embodiment, the communication process between the authentication server and the user does not involve the direct transmission of the content protection master key. Attackers need to obtain the dynamic master key, the static master key, and the preset rules for key combinations in order to obtain the content protection master key. This makes it more difficult for attackers to obtain the content protection master key, enhances the security of key management, and thus improves the security of digital resources protected by the key.
[0194] In this embodiment, the authentication server is responsible for generating and managing both static and dynamic master keys. Compared to certificate-based public key systems, in this embodiment, the authentication server does not rely on a third-party Certificate Authority (CA), avoiding the problems of CA centralization. Furthermore, since key management is centralized on the authentication server, if the authentication server fails, it only needs to be repaired or replaced without affecting the user client and content protection server, reducing the impact of single points of failure and improving the security of key management, thereby enhancing the security of the digital resources protected by the keys. Compared to identity-based encryption systems, in this embodiment, key management is entirely handled by the authentication server, without the need for user or other third-party tools, reducing the risk of key escrow and thus improving the security of the digital resources protected by the keys.
[0195] Exemplarily, in one feasible implementation, reference is made to Figure 6 When the authentication server initially generates a static master key, the management process for the static master key can be as follows:
[0196] S1: The user client sends user identity information, terminal device information, and encrypted password to the authentication server. Specifically, the user client can send these information during or after registering with the authentication server. For example, in one feasible implementation, the user client can register with the authentication server using the user identity information and terminal device information, and then send the encrypted password to the authentication server after registration.
[0197] S2: The authentication server generates a root key based on the user's identity information and terminal device information. In this embodiment, the authentication server can also encrypt the root key using the encrypted password set by the user and store the encrypted root key in the server's database for use when updating the static master key later.
[0198] Specifically, authentication servers can use various encryption algorithms to generate a root key by combining user identity information and terminal device information. For example, they can use the HMAC (Keyed-Hashing for Message Authentication) algorithm, which combines a key and a message to generate an authentication code. Specifically, the authentication server can use the user's identity information as the key, the phone number as the message, and then calculate an HMAC value as the generated root key. The calculation process of the HMAC algorithm is as follows:
[0199] HMAC(key, message)=Hash((key⊕opad)||Hash((key⊕ipad)||message))
[0200] Here, opad and ipad are specific constants, ⊕ represents the XOR operation, || represents the concatenation operation, and Hash represents the selected hash function, which can be SHA-256, SHA-512, etc.
[0201] The authentication server uses the root key and encrypted password to generate a static master key.
[0202] Specifically, the authentication server can generate multiple static master keys based on the root key and encrypted password using common key derivation algorithms. The authentication server can then combine these multiple static master keys into a document and transmit it to the user's client, which resides on the client's hardware device used during user registration. In this way, even if the user's password is stolen, as long as the hardware is not lost, the attacker cannot obtain the original digital resources due to the lack of static master keys, thus achieving multi-factor authentication protection.
[0203] S3: The authentication server shares the static master key with the client, and the client stores the static master key.
[0204] In this embodiment, refer to Figure 7 The process by which a user views digital resources on a content protection server can be as follows:
[0205] S1: When a user needs to view digital resources on a content protection server, they log in to the authentication server.
[0206] S2: The authentication server generates a dynamic master key.
[0207] S3: The authentication server sends a dynamic master key to the user.
[0208] S4: The user sends a content viewing request to the content protection server.
[0209] S5: The content protection server requests the master key from the authentication server.
[0210] S6: The authentication server generates a content protection master key based on the dynamic master key and the static master key. Specifically, there are no restrictions on how the authentication server generates the content protection master key with the static master key; it can be a combination of methods such as concatenation, XOR, and hashing.
[0211] S7: The authentication server transmits the content protection master key to the content protection server.
[0212] S8: The authentication server transmits the content protection master key to the content protection server. The content protection server uses the content protection master key to encrypt the lower-level key, and the lower-level key encrypts the digital resource requested by the user to obtain the encrypted resource. Specifically, in this embodiment, the encryption method using the key can be a symmetric encryption algorithm such as AES.
[0213] S9: The content protection server delivers encrypted resources to the user.
[0214] S10: The user terminal generates a content protection master key based on the static master key and the dynamic master key, and uses the content protection master key to decrypt the encrypted resources to obtain the digital resources.
[0215] Furthermore, in this embodiment, when the static master key corresponding to an encrypted password is exhausted after several communications, the authentication server sends a key rotation request to the user client, and the user client sends an updated encrypted password for subsequent communication. In this embodiment, before updating the encrypted password, the authentication server verifies the identity of the current user on the user client; only after successful verification can the authentication server grant permission to update the encrypted password.
[0216] Exemplarily, in one feasible implementation, reference is made to Figure 8 The specific process for viewing resources can be as follows:
[0217] The user registers with the authentication server, sending their identity information, terminal device information, and encrypted password to the authentication server.
[0218] The authentication server generates a root key based on user identity information and terminal device information, and uses the root key and encrypted password to generate a static master key.
[0219] The authentication server shares the static master key with the client, and the client stores the static master key.
[0220] When the authentication server determines that a user is requesting to view digital resources on the content protection server, it generates a dynamic master key. The authentication server then generates a content protection master key based on the dynamic master key and a static master key. The authentication server sends the dynamic master key to the user and transmits the content protection master key to the content protection server.
[0221] The content protection server uses the content protection master key to encrypt the digital resources requested by the user, obtains the encrypted resources, and then transmits the encrypted resources to the user.
[0222] The client generates a content protection master key based on a static master key and a dynamic master key. After receiving the encrypted resource, the client uses the content protection master key to decrypt the encrypted resource to obtain the digital resource.
[0223] When the authentication server triggers an update to the static master key, it requests an encrypted password from the client and retrieves the stored root key.
[0224] The client sends the encrypted password to the authentication server, which generates an updated static master key based on the root key and the encrypted password. The authentication server then sends the updated static master key back to the client, which stores it. Both the authentication server and the client can use the updated static master key for subsequent resource viewing.
[0225] Furthermore, embodiments of this application also propose a computer-readable storage medium storing a resource viewing program, which, when executed by a processor, implements the steps of the resource viewing method described below.
[0226] The embodiments of the resource viewing device and computer-readable storage medium of this application can be referred to the embodiments of the resource viewing method of this application, and will not be repeated here.
[0227] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0228] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0229] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0230] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A method for viewing resources, characterized in that, The resource viewing method is applied to an authentication server, and the resource viewing method includes the following steps: Obtain the root key corresponding to the user terminal, receive the encrypted password sent by the user terminal, generate a static master key based on the root key and the encrypted password, and send the static master key to the user terminal for the user terminal to receive and store the static master key; When it is determined that the user client requests to view the content protection server, a dynamic master key is generated, and a content protection master key is generated using the static master key and the dynamic master key according to preset rules; The content protection master key is sent to the content protection server, so that the content protection server can encrypt the digital resources requested by the user based on the content protection master key, obtain encrypted resources, and send the encrypted resources to the user. The dynamic master key is sent to the user terminal, so that the user terminal can generate the content protection master key based on the dynamic master key and the stored static master key according to the preset rules, and decrypt the received encrypted resource to obtain the digital resource using the content protection master key.
2. The resource viewing method as described in claim 1, characterized in that, The step of obtaining the root key corresponding to the user terminal includes: When the authentication server generates the static master key corresponding to the user terminal for the first time, it obtains the user identity information and the terminal device information of the user terminal, generates the root key corresponding to the user terminal based on the terminal device information and the user identity information, and stores the root key. When the authentication server updates the static master key corresponding to the user terminal, the root key stored by the authentication server is obtained.
3. The resource viewing method as described in claim 2, characterized in that, The step of storing the root key includes: The root key is encrypted using the encryption password to obtain the encrypted root key, and the encrypted root key is stored. The step of obtaining the root key stored on the authentication server includes: Obtain the encrypted root key stored on the authentication server; The root key is obtained by decrypting the encrypted root key using the encrypted password.
4. The resource viewing method as described in claim 2, characterized in that, Before the step of receiving the encrypted password sent by the user terminal when the authentication server updates the static master key corresponding to the user terminal, the method further includes: An authentication request is sent to the user terminal so that the user terminal can send its corresponding identity authentication information and terminal behavior data to the authentication server. Receive the identity authentication information and the terminal behavior data, and verify the identity of the current user of the user terminal based on the identity authentication information and the terminal behavior data; If the current user's identity verification is successful, then the step of receiving the encrypted password sent by the user terminal is executed.
5. The resource viewing method as described in any one of claims 1 to 4, characterized in that, When there are multiple static master keys, the preset rules include preset key usage rules and preset key generation rules; The step of generating a content protection master key using the static master key and the dynamic master key according to preset rules includes: The target static master key is extracted from the plurality of static master keys according to the key usage rules; The content protection master key is obtained by combining the target static master key and the dynamic master key according to the key generation rules.
6. A method for viewing resources, characterized in that, The resource viewing method is applied to a content protection server, and the resource viewing method includes the following steps: Receive viewing requests sent by the user client; The system receives a content protection master key sent by an authentication server and uses the content protection master key to encrypt the digital resource requested by the user to view, thus obtaining the encrypted resource. The content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules. The static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password. The dynamic master key in the authentication server is generated by the authentication server when it determines that the user requests to view the content protection server. The encrypted resource is sent to the user terminal so that the user terminal can use the content protection master key to decrypt the encrypted resource to obtain the digital resource; wherein, the content protection master key in the user terminal is generated by the user terminal according to the preset rules using the static master key and the dynamic master key in the user terminal, and the static master key and the dynamic master key in the user terminal are generated by the authentication server and then sent.
7. A method for viewing resources, characterized in that, The resource viewing method is applied to the user terminal, and the resource viewing method includes the following steps: The encrypted password is obtained and sent to the authentication server, so that the authentication server can generate a static master key based on the received encrypted password and the obtained root key and send it to the user terminal. Receive and store the static master key; A viewing request is sent to a content protection server, which uses a content protection master key to encrypt the digital resource requested by the user and sends the encrypted resource to the user. The content protection master key in the content protection server is generated and sent by the authentication server using a static master key and a dynamic master key according to preset rules. The static master key in the authentication server is generated by the authentication server based on the obtained root key and the received encrypted password. The dynamic master key in the authentication server is generated by the authentication server when it determines that the user has requested to view the content protection server. Receive the dynamic master key sent by the authentication server, and generate a content protection master key using the static master key and the dynamic master key according to the preset rules; The encrypted resource is received from the content protection server, and the digital resource is obtained by decrypting the encrypted resource using the content protection master key.
8. The resource viewing method as described in claim 7, characterized in that, The resource viewing method also includes: Detect whether a password update request has been received from the authentication server, and detect whether all static master keys have been used; Upon receiving the password update request, and / or if the static master key has been used, the step of obtaining the encrypted password and sending it to the authentication server is performed.
9. A resource viewing device, characterized in that, The resource viewing device includes: a memory, a processor, and a resource viewing program stored in the memory and executable on the processor. When the resource viewing program is executed by the processor, it implements the steps of the resource viewing method as described in any one of claims 1 to 5, 6, or 7 to 8.
10. A computer-readable storage medium, characterized in that, The storage medium stores a resource viewing program, which, when executed by a processor, implements the steps of the resource viewing method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Three-factor identity authentication and key negotiation method in multi-server environment
CN108965338A
Software security barrier implementation method based on identification authentication
CN109992932A