Authentication encryption system, method and device and storage medium
Through the pre-trained session key prediction model and local cache mechanism, the session key is generated and encrypted, which solves the problems of high latency and low efficiency in the WAPI authentication process, and realizes fast access authentication and secure data transmission.
Patent Information
- Application Number
- CN202510970998.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-15
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-07-15
AI Technical Summary
The existing WAPI authentication process has high latency and low authentication efficiency in scenarios such as frequent device roaming, disconnection and reconnection, and AP restart.
The pre-trained session key prediction model is used to generate the terminal identity and session key structure, and encrypt and cache it to achieve fast access authentication, prepare the required session keys in advance through the key prediction mechanism, and quickly recover the key with local cached session keys, skipping the cumbersome and complete negotiation process.
It shortens the authentication time, improves network connection speed, improves authentication efficiency, and ensures the security of data transmission and network stability.
Smart Images

Figure CN120475376A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of wireless communication technology, and in particular to an authentication encryption system, method, device and storage medium. Background Art
[0002] As a wireless LAN security protocol, WAPI adopts symmetric encryption and digital certificate mechanisms such as SM1 / SM4, and is widely used in high-security scenarios such as government affairs, energy, electricity, and the military.
[0003] However, the WAPI authentication process is complex, and authentication delays can be significant in scenarios such as frequent device roaming, disconnection and reconnection, and AP reboots. This not only degrades the user experience but also hinders efficient network operation, failing to meet today's high demands for real-time and stability. Currently, most vendors only implement WAPI in a "standard" manner, lacking intelligent prediction and fast caching mechanisms, making it difficult to improve authentication efficiency while ensuring security. Summary of the Invention
[0004] The main purpose of this application is to provide an authentication encryption system, method, device and storage medium, aiming to solve the technical problems of high delay and low authentication efficiency in the existing WAPI authentication process.
[0005] To achieve the above-mentioned purpose, the present application proposes an authentication encryption system, which includes: a client terminal device and a network connection module; The network connection module is used to obtain the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model; The network connection module is further configured to generate a session key for the client terminal device based on the terminal identity and the session key structure upon receiving a connection request from the client terminal device; The network connection module is further configured to encrypt the session key and cache the encrypted session key; The network connection module is further configured to perform a quick access authentication on the client terminal device based on the cached encrypted session key when receiving a connection request initiated again by the client terminal device.
[0006] In one embodiment, the network connection module is further configured to encrypt the session key to obtain an encrypted session key; The network connection module is further configured to locally cache the encrypted session key and set a validity period and a re-authentication window for the encrypted session key.
[0007] In one embodiment, the network connection module is further configured to obtain the encrypted session key in the local cache upon receiving a connection request initiated again by the client terminal device; The network connection module is further configured to determine whether the encrypted session key is valid based on the validity period; The network connection module is further configured to perform fast access authentication based on the encrypted session key when the encrypted session key is valid.
[0008] In one embodiment, the network connection module is further configured to check whether the encrypted session key is valid when a re-authentication time corresponding to the re-authentication window arrives; The network connection module is further configured to delete the encrypted session key from the local cache and renegotiate the key with the client terminal device when the encrypted session key is invalid.
[0009] In one embodiment, the system further comprises: a key management module; The network connection module is further configured to initiate a communication request to the key management module at preset intervals; The key management module is configured to communicate with the network connection module based on the communication request; The network connection module is further configured to send key status information in the local cache to the key management module during communication with the key management module, wherein the key status information includes the encryption session key and association information of the encryption session key; The key management module is further used to perform risk management based on the key status information.
[0010] In one embodiment, the key management module is further configured to monitor data behavior in the network and an authentication policy of the network connection module based on the association information; The key management module is further configured to send a renegotiation instruction to the network connection module when the data behavior is abnormal or the authentication policy changes; The network connection module is configured to delete the encrypted session key from the local cache and renegotiate the key with the client terminal device upon receiving the renegotiation instruction.
[0011] In one embodiment, the client terminal device is used to record connection information; The client is further configured to send the connection information to the network connection module; The network connection module is used to train a session key prediction model based on the connection information.
[0012] In addition, to achieve the above-mentioned purpose, the present application also proposes an authenticated encryption method, which is used in the authenticated encryption system as described above, and the method includes: The network connection module obtains the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model; When receiving a connection request from a client terminal device, the network connection module generates a session key for the client terminal device according to the terminal identity and the session key structure; The network connection module encrypts the session key and caches the encrypted session key; When the network connection module receives a connection request initiated again by the client terminal device, it performs a quick access authentication on the client terminal device based on the cached encrypted session key.
[0013] In addition, to achieve the above-mentioned purpose, the present application also proposes an authentication encryption device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the computer program is configured to implement the steps of the authentication encryption method described above.
[0014] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by the processor, the steps of the authentication encryption method described above are implemented.
[0015] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the authentication encryption method described above.
[0016] One or more technical solutions proposed in this application have at least the following technical effects: The authentication and encryption system of the present application includes: a client terminal device and a network connection module; the network connection module obtains the terminal identity and session key structure of the client terminal device to be connected based on a pre-trained session key prediction model; upon receiving a connection request from the client terminal device, the session key of the client terminal device is generated based on the terminal identity and the session key structure; the session key is encrypted, and the encrypted session key obtained by the encryption is cached; upon receiving a connection request initiated by the client terminal device again, the client terminal device is quickly authenticated based on the cached encrypted session key. Since the required session key is prepared in advance through the key prediction mechanism, the time required for authentication is shortened; at the same time, by locally caching the session key, fast key recovery is achieved when reconnecting, skipping the tedious complete negotiation process, further shortening the authentication time, and improving the network connection speed. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0018] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0019] Figure 1 This is a functional module block diagram provided for the first embodiment of the authentication and encryption system of this application; Figure 2 A flowchart of the second embodiment of the authentication and encryption method of this application is provided; Figure 3 This is a functional module block diagram provided for Example 3 of the authentication and encryption method of this application; Figure 4 A schematic diagram of the process flow of the authentication and encryption method provided in an embodiment of the present application; Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the authentication and encryption method in the embodiment of the present application.
[0020] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0021] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0022] In order to better understand the technical solution of this application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0023] In the embodiment of the present application, an authentication encryption system is provided, referring to Figure 1 , Figure 1 This is a functional module block diagram provided for Example 1 of the authentication and encryption system of this application.
[0024] like Figure 1 As shown, in the embodiment of the present application, the authentication and encryption system includes: a client terminal device and a network connection module.
[0025] It should be noted that in a WAPI-based wireless communication network, the client terminal device can be a terminal node for network access, such as a smart phone, computer, vehicle-mounted IoT device, sensor, etc., and the embodiments of the present application do not limit this.
[0026] It should be explained that the above-mentioned network connection module is a bridge used to connect the client terminal device to the wireless communication network in the embodiment of the present application, such as a smart access point, a wireless gateway, etc.
[0027] The network connection module is used to obtain the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model; The network connection module is further configured to generate a session key for the client terminal device based on the terminal identity and the session key structure upon receiving a connection request from the client terminal device; The network connection module is further configured to encrypt the session key and cache the encrypted session key; The network connection module is further configured to perform a quick access authentication on the client terminal device based on the cached encrypted session key when receiving a connection request initiated again by the client terminal device.
[0028] In the embodiment of the present application, the client terminal can record multi-dimensional connection information such as its own terminal identity, connection history, roaming behavior and location information, key structure, etc. A session key prediction model can be obtained by training based on this multi-dimensional data (i.e., connection information).
[0029] In some implementations of the embodiments of the present application, the connection history may include access time, accessed AP information, etc.; roaming behavior may cover roaming frequency, roaming direction, etc.; and location information may be obtained through positioning technology.
[0030] In some implementations of the embodiments of the present application, when performing key generation, the user's connection frequency, connection mode (such as frequent switching of APs, connection time period), and other connection history data can directly affect the selection of the key generation protocol. The user's switching behavior between different APs during roaming will dynamically update the key, and the user's geographical location can affect the selection of the encryption algorithm. When the client successfully accesses the network connection terminal, the client terminal can send the recorded connection information (i.e., multi-dimensional data) to the network connection terminal, and train the session key prediction model based on these multi-dimensional data in combination with a machine learning algorithm. That is, the client terminal device is used to record the connection information; the client is also used to send the connection information to the network connection module; and the network connection module is used to train the session key prediction model based on the connection information.
[0031] It should be noted that the above-mentioned session key prediction model can be a prediction model obtained by pre-training based on a decision tree algorithm, a neural network algorithm or other algorithms. The specific training algorithm and training process can be selected based on the needs of actual applications, and the embodiments of this application are not limited to this.
[0032] It can be understood that through the session key prediction model, the key prediction mechanism of the authentication and encryption system of this application can be implemented, the required session keys can be prepared in advance and key negotiation can be performed, which shortens the time required for authentication access. Combined with the fast key recovery mechanism when re-accessing, the tedious complete negotiation process can be skipped, further shortening the authentication time and improving the network connection speed.
[0033] It should be noted that the specific process of the above-mentioned key negotiation can be implemented based on the needs of actual applications, and the embodiments of the present application are not limited to this.
[0034] It should be noted that the session key prediction model of this application can predict the terminal identity and session key structure of a client terminal device to be connected based on multi-dimensional data, thereby improving authentication efficiency. When the network connection module receives a connection request from a client terminal device, it can generate a session key with the client terminal device based on the terminal identity and session key structure predicted by the session key prediction model.
[0035] It should be noted that the aforementioned session key structure may be a key composition framework that defines the components, generation method, management policy, and security mechanism of a session key, and is used to encrypt and protect communication data. The session key structure can be used to determine the key type, key value, key validity period, encryption algorithm identifier, and other information of the client terminal device that is about to connect. The session key for the client terminal device is then generated based on the terminal identity and the session key structure.
[0036] In some implementations of the embodiments of the present application, the embodiments of the present application also locally encrypt and cache the session key through an optimized session key caching mechanism. When the session key is locally encrypted and cached through the local cache, when the client terminal device accesses again, the network connection module can first obtain the MAC address of the client terminal device and other identification identifiers that can be used to uniquely identify a client terminal device, and compare the identification identifier with the identification identifier corresponding to the locally cached session key. When the comparison passes, the network connection module can directly use the locally cached session key for fast access authentication, skipping the complete key negotiation process.
[0037] In some implementations of the present application, while performing the identification comparison, it is possible to check whether the authentication policy has changed and whether the locally cached session key has expired. If the authentication policy has not changed and the session key has also expired, a fast access authentication can be performed based on the locally cached session key if the comparison passes. The locally cached session key enables fast key recovery.
[0038] In some implementations of the embodiments of the present application, the authentication encryption system of the embodiments of the present application may further include a key management module, and the network connection module may communicate with the key management module to achieve synchronization of key status.
[0039] The authentication and encryption system of the embodiment of the present application includes: a client terminal device and a network connection module; the network connection module obtains the terminal identity and session key structure of the client terminal device to be connected based on a pre-trained session key prediction model; upon receiving a connection request from the client terminal device, the session key of the client terminal device is generated based on the terminal identity and the session key structure; the session key is encrypted and the encrypted session key obtained by the encryption is cached; upon receiving a connection request initiated by the client terminal device again, the client terminal device is quickly authenticated based on the cached encrypted session key. Since the required session key is prepared in advance through the key prediction mechanism, the time required for authentication is shortened; at the same time, by locally caching the session key, fast key recovery is achieved when reconnecting, skipping the tedious complete negotiation process, further shortening the authentication time, and improving the network connection speed.
[0040] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 2 , Figure 2 A flowchart provided for an embodiment of the authentication and encryption system of this application.
[0041] like Figure 2As shown, in the embodiment of the present application, the network connection module is further used to encrypt the session key to obtain an encrypted session key; The network connection module is further configured to locally cache the encrypted session key and set a validity period and a re-authentication window for the encrypted session key.
[0042] It should be noted that in this embodiment of the present application, the network connection module can encrypt and store the locally cached session key. The encryption algorithm used can be the SM4 algorithm or other algorithms, which is not limited in this embodiment of the present application. During the data transmission process, the key chain is generated using the SM4 algorithm and the transmitted data is encrypted, which can effectively prevent key leakage and man-in-the-middle attacks, and ensure data transmission security.
[0043] It is understandable that when the session key is obtained through the session key prediction model, a validity period and a re-authentication window can also be set for the session key. The validity period is also the validity period of the session key. When the survival time of the session key is greater than the validity period, it can be regarded as invalid; in the re-authentication window, that is, the detection window for re-authenticating the session key, when the re-authentication time corresponding to the re-authentication window is reached, it can be checked based on the validity period whether the session key is valid. If valid, you can continue to wait for the client terminal device to access again; if invalid, you can delete the session key in the local cache and renegotiate a new session key with the client terminal device.
[0044] It should be understood that, since the encrypted session key is obtained by encrypting the session key, it has the same validity period and re-authentication window as the session key. That is, the network connection module is also used to obtain the encrypted session key in the local cache when receiving a connection request initiated again by the client terminal device; the network connection module is also used to determine whether the encrypted session key is valid based on the validity period; the network connection module is also used to perform fast access authentication based on the encrypted session key when the encrypted session key is valid. The network connection module is also used to check whether the encrypted session key is valid when the re-authentication time corresponding to the re-authentication window arrives; the network connection module is also used to delete the encrypted session key from the local cache when the encrypted session key is invalid, and renegotiate the key with the client terminal device.
[0045] It should be noted that when the network connection module receives a connection request initiated again by the client terminal device, a re-access check can be performed on the client terminal device. Specifically, the re-access check process may include: obtaining the identification identifier of the client terminal device based on the connection request, and comparing the identification identifier with the identification identifier corresponding to each encrypted session key in the local cache; at the same time, checking whether the authentication policy has changed and whether the cached encrypted session key has expired. If the identification identifiers are consistent, the authentication policy has not changed, and the session key has not expired, it can be said that the re-access check has passed, and the network connection module can directly use the locally cached session key for fast authentication, skipping the complete key negotiation process; if the identification identifiers are inconsistent and / or the authentication policy has changed and / or the session key has expired, it can be said that the re-access check has failed, and it is necessary to delete the session key and related associated information in the local cache, and enable the network connection module to renegotiate the key with the client terminal device. The embodiment of the present application balances security and efficiency by locally encrypting and caching the session key and setting the validity period and re-authentication window.
[0046] In this embodiment, a session key is encrypted by a network connection module to obtain an encrypted session key. The encrypted session key is cached locally, and a validity period and re-authentication window are set for the encrypted session key. Because the session key is locally encrypted and cached, and a validity period and re-authentication window are set, the entire negotiation process can be skipped when certain conditions are met, and the locally cached session key can be used directly for rapid access authentication, greatly improving authentication and access efficiency.
[0047] Based on the first embodiment and / or the second embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the first embodiment and / or the second embodiment can be referred to the above introduction and will not be described in detail later. Figure 3 , Figure 3 This is a functional module block diagram provided for Example 3 of the authentication and encryption system of this application.
[0048] like Figure 3 As shown, in the embodiment of the present application, the system also includes: a key management module.
[0049] It should be noted that the key management module in the embodiment of the present application can be a functional module that can be used to manage the session keys cached in the network connection module and associated information related to the session keys, such as a key management center, an access controller, etc.
[0050] The network connection module is further configured to initiate a communication request to the key management module at preset intervals; The key management module is configured to communicate with the network connection module based on the communication request; The network connection module is further configured to send key status information in the local cache to the key management module during communication with the key management module, wherein the key status information includes the encryption session key and association information of the encryption session key; The key management module is further used to perform risk management based on the key status information.
[0051] It should be noted that the above-mentioned preset time can be set based on the needs of actual applications, and the embodiments of the present application are not limited to this.
[0052] In an embodiment of the present application, the network connection module can communicate with the key management module regularly and synchronize the key status information to the key management module. The communication interval is also the preset time mentioned above. The specific value of the preset time can be set according to the actual application situation, such as one minute, five minutes, etc., and the embodiment of the present application does not limit this. By synchronizing the key status information of all client terminals stored in the local cache of the network connection module to the key management module, the key management module can update its own recorded key status database when receiving this information to ensure that it is consistent with the key status of each network connection module, thereby realizing risk control of various data and behaviors in the network (such as data behavior monitoring, authentication policy monitoring, renegotiation instruction issuance, etc.).
[0053] It should be noted that the above-mentioned key status information may include the encrypted session key and associated information related to the encrypted session key, such as the identification identifier of the client terminal device corresponding to the encrypted session key, authentication policy, network traffic information, key usage frequency information, login location information, etc. The embodiments of the present application do not limit this.
[0054] In an embodiment of the present application, the key management module can perform security risk detection based on the key status information to determine whether there is abnormal key usage behavior, signs of network attack, or whether the user has modified the authentication policy (such as changing the password, adjusting access permissions, etc.). If there is abnormal key usage behavior and / or signs of network attack and / or the user has modified the authentication policy, the key management module can send a mandatory renegotiation instruction to the network connection module, forcing the network connection module to renegotiate the session key with the client terminal device to ensure network security. Specifically, upon receiving the renegotiation instruction, the network connection module can delete the key status information corresponding to the renegotiation instruction from the local cache and send a renegotiation notification to the client terminal device corresponding to the key status information to renegotiate the session key. In other words, the key management module is further configured to monitor data behavior in the network and the authentication policy of the network connection module based on the associated information; the key management module is further configured to send a renegotiation instruction to the network connection module when the data behavior is abnormal or the authentication policy changes; and the network connection module is configured to delete the encrypted session key from the local cache and renegotiate the key with the client terminal device upon receiving the renegotiation instruction.
[0055] It is understood that the above-mentioned data behavior detection may include key usage behavior detection, network attack sign detection, etc., and the embodiments of the present application are not limited to this. When data behavior is abnormal (such as frequent use of different keys for login within a short period of time, or a large number of access requests from abnormal IP addresses), the network connection module can be forced to perform key renegotiation.
[0056] It should be understood that during the process of renegotiating the session key between the client terminal device and the network connection module, the network connection module may delete the previously cached session key. Upon successful negotiation of a new session key, the network connection module may obtain the newly generated session key, encrypt it, and cache it locally. Furthermore, the module may set a new validity period and reauthentication window to facilitate subsequent rapid access authentication.
[0057] The system of the embodiment of the present application also includes a key management module. The network connection module initiates a communication request to the key management module at preset intervals; the key management module communicates with the network connection module based on the communication request; during the communication process with the key management module, the network connection module sends the key status information in the local cache to the key management module, and the key status information includes the encrypted session key and the associated information of the encrypted session key; the key management module performs risk management based on the key status information. Since the key management module performs security monitoring and risk management on the key status information cached in the network connection module, it can effectively determine whether there is abnormal data or behavior in the network, thereby ensuring the security of the network.
[0058] This application also provides an authentication encryption method, please refer to Figure 4 , Figure 4 This is a schematic diagram of the workflow of the authentication encryption method according to an embodiment of the present application. The authentication encryption method is used in the authentication encryption system described above, and the method includes: Step S10, the network connection module obtains the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model; Step S20, when the network connection module receives the connection request from the client terminal device, it generates a session key for the client terminal device according to the terminal identity and the session key structure; Step S30: the network connection module encrypts the session key and caches the encrypted session key; Step S40: When the network connection module receives a connection request initiated again by the client terminal device, the network connection module performs a fast access authentication on the client terminal device based on the cached encrypted session key.
[0059] In some implementations of the embodiments of the present application, the network connection module encrypts the session key and caches the encrypted session key, including: The network connection module encrypts the session key to obtain an encrypted session key; The network connection module locally caches the encrypted session key and sets a validity period and a re-authentication window for the encrypted session key.
[0060] In some implementations of the embodiments of the present application, the method further includes: When the network connection module receives the connection request initiated again by the client terminal device, it obtains the encrypted session key in the local cache; The network connection module determines whether the encrypted session key is valid based on the validity period; When the encrypted session key is valid, the network connection module performs fast access authentication based on the encrypted session key.
[0061] In some implementations of the embodiments of the present application, the system further includes: a key management module; the method further includes: The network connection module initiates a communication request to the key management module at a preset interval; The key management module communicates with the network connection module based on the communication request; The network connection module sends the key status information in the local cache to the key management module during the communication process with the key management module, wherein the key status information includes the encryption session key and the association information of the encryption session key; The key management module performs risk management based on the key status information.
[0062] In some implementations of the embodiments of the present application, the step of the key management module performing risk control based on the key status information includes: The key management module monitors data behavior in the network and the authentication strategy of the network connection module based on the association information; The key management module sends a renegotiation instruction to the network connection module when the data behavior is abnormal or the authentication policy changes; When receiving the renegotiation instruction, the network connection module deletes the encrypted session key from the local cache and renegotiates the key with the client terminal device.
[0063] In some implementations of the embodiments of the present application, before the step of obtaining the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model, the network connection module further includes: The client terminal device records the connection information; The client sends the connection information to the network connection module; The network connection module trains a session key prediction model based on the connection information.
[0064] The authentication and encryption method provided in this application, which utilizes the authentication and encryption method in the above-mentioned embodiments, can address the technical issues of high latency and low authentication efficiency in the existing WAPI authentication process. Compared with the prior art, the authentication and encryption method provided in this application has the same beneficial effects as those provided in the above-mentioned embodiments, and the other technical features of the authentication and encryption method are the same as those disclosed in the above-mentioned embodiments, and are not further described here.
[0065] The present application provides an authentication encryption device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the authentication encryption method in the above-mentioned embodiment one.
[0066] Reference below Figure 5, which shows a schematic diagram of the structure of an authentication and encryption device suitable for implementing embodiments of the present application. The authentication and encryption device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The authentication and encryption device shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0067] like Figure 5 As shown, the authenticated encryption device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 1002 or programs loaded from a storage device 1003 into a random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the authenticated encryption device. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems may be connected to I / O interface 1006: input devices 1007, such as a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008, such as a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003, such as a magnetic tape or hard disk; and communication devices 1009. Communication device 1009 can allow the authentication and encryption device to communicate with other devices wirelessly or wired to exchange data. Although the figure shows an authentication and encryption device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems can be implemented or have alternatively.
[0068] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0069] The authentication and encryption device provided in this application, employing the authentication and encryption method of the aforementioned embodiment, can address the technical issues of high latency and low authentication efficiency in the existing WAPI authentication process. Compared to the prior art, the authentication and encryption device provided in this application has the same beneficial effects as the authentication and encryption method provided in the aforementioned embodiment. Other technical features of the authentication and encryption device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.
[0070] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0071] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0072] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, a computer program) stored thereon, wherein the computer-readable program instructions are used to execute the authentication encryption method in the above-mentioned embodiment.
[0073] The computer-readable storage medium provided herein may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including, but not limited to, wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0074] The computer-readable storage medium may be included in the authentication and encryption device; or it may exist independently without being assembled into the authentication and encryption device.
[0075] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the authentication and encryption device, the authentication and encryption device: The network connection module obtains the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model; When receiving a connection request from a client terminal device, the network connection module generates a session key for the client terminal device according to the terminal identity and the session key structure; The network connection module encrypts the session key and caches the encrypted session key; When the network connection module receives a connection request initiated again by the client terminal device, it quickly authenticates the client terminal device based on the cached encrypted session key. The computer program code for performing the operations of the present application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user computer, partially on the user computer, as a standalone software package, partially on the user computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0076] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0077] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0078] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned authentication and encryption method. This computer-readable storage medium can address the technical issues of high latency and low authentication efficiency in existing WAPI authentication processes. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are similar to those of the authentication and encryption method provided in the aforementioned embodiments and are not further elaborated here.
[0079] The present application also provides a computer program product, comprising a computer program, which implements the steps of the above-mentioned authentication encryption method when executed by a processor.
[0080] The computer program product provided in this application can solve the technical problems of high latency and low authentication efficiency in the existing WAPI authentication process. Compared with the existing technology, the beneficial effects of the computer program product provided in this application are the same as those of the authentication and encryption method provided in the above embodiment, and will not be repeated here.
[0081] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. An authentication encryption system, characterized in that: The system includes: a client terminal device and a network connection module; The network connection module is used to obtain the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model; The network connection module is further configured to generate a session key for the client terminal device based on the terminal identity and the session key structure upon receiving a connection request from the client terminal device; The network connection module is further configured to encrypt the session key and cache the encrypted session key; The network connection module is further configured to perform a quick access authentication on the client terminal device based on the cached encrypted session key when receiving a connection request initiated again by the client terminal device.
2. The authenticated encryption system according to claim 1, wherein: The network connection module is further configured to encrypt the session key to obtain an encrypted session key; The network connection module is further configured to locally cache the encrypted session key and set a validity period and a re-authentication window for the encrypted session key.
3. The authenticated encryption system according to claim 2, wherein: The network connection module is further configured to obtain the encrypted session key in the local cache upon receiving a connection request initiated again by the client terminal device; The network connection module is further configured to determine whether the encrypted session key is valid based on the validity period; The network connection module is further configured to perform fast access authentication based on the encrypted session key when the encrypted session key is valid.
4. The authenticated encryption system according to claim 2, wherein: The network connection module is further configured to check whether the encrypted session key is valid when the re-authentication time corresponding to the re-authentication window arrives; The network connection module is further configured to delete the encrypted session key from the local cache and renegotiate the key with the client terminal device when the encrypted session key is invalid.
5. The authenticated encryption system according to claim 2, wherein: The system further includes: a key management module; The network connection module is further configured to initiate a communication request to the key management module at preset intervals; The key management module is configured to communicate with the network connection module based on the communication request; The network connection module is further configured to send key status information in the local cache to the key management module during communication with the key management module, wherein the key status information includes the encryption session key and association information of the encryption session key; The key management module is further used to perform risk management based on the key status information.
6. The authenticated encryption system according to claim 5, wherein: The key management module is further configured to monitor data behavior in the network and the authentication strategy of the network connection module based on the associated information; The key management module is further configured to send a renegotiation instruction to the network connection module when the data behavior is abnormal or the authentication policy changes; The network connection module is configured to delete the encrypted session key from the local cache and renegotiate the key with the client terminal device upon receiving the renegotiation instruction.
7. The authenticated encryption system according to claim 1, wherein: The client terminal device is used to record connection information; The client is further configured to send the connection information to the network connection module; The network connection module is used to train a session key prediction model based on the connection information.
8. An authentication encryption method, characterized in that: The authentication encryption method is used in the authentication encryption system according to any one of claims 1 to 7, and the method comprises: The network connection module obtains the terminal identity and session key structure of the client terminal device to be connected based on the pre-trained session key prediction model; When receiving a connection request from a client terminal device, the network connection module generates a session key for the client terminal device according to the terminal identity and the session key structure; The network connection module encrypts the session key and caches the encrypted session key; When the network connection module receives a connection request initiated again by the client terminal device, it performs a quick access authentication on the client terminal device based on the cached encrypted session key.
9. An authentication and encryption device, characterized in that: The device includes: a memory, a processor, and an authenticated encryption program stored in the memory and executable on the processor, wherein the authenticated encryption program is configured to implement the steps of the authenticated encryption method according to claim 8.
10. A storage medium, characterized in that: The storage medium stores an authentication encryption program, which, when executed by the processor, implements the steps of the authentication encryption method according to claim 8.
Citation Information
Patent Citations
Wireless switching network re-authentication method based on wireless LAN secure standard WAPI
CN101079891B
Method of access authentication and recertification in home NodeB system of user terminal
CN101854629A
Authentication key configuration method, equipment and system and storage medium
CN112118210A
Access authentication method and device and server
CN112260995A
Key generation method and device, equipment and storage medium
CN119766435A
Cited By
Wireless local area network two-way authentication and key negotiation method, device and equipment and storage medium
CN120857120A
Wireless local area network bidirectional authentication and key agreement method, device, equipment and storage medium
CN120857120B