Instant messaging secret key determination method and device and storage medium

By generating instant messaging keys using client identifiers and root keys, the problem of cached messages being unable to be decrypted due to key expiration is solved, key management is simplified, and communication security and storage efficiency are improved.

CN120915439APending Publication Date: 2025-11-07CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511101580.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In instant messaging scenarios, when a client goes offline, the key expires, causing cached messages to become undecryptable, which affects normal user experience. Furthermore, existing key management methods suffer from high storage overhead and complex management.

Method used

By generating keys using the client identifier and root key, the server does not need to store all keys. It only generates the keys required for instant communication based on the root key and client identifier, ensuring that the corresponding keys can still be generated during the key update transition period, simplifying key management and saving storage space.

Benefits of technology

It improves communication security, simplifies key management complexity, reduces storage overhead, and enhances key manageability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915439A_ABST
    Figure CN120915439A_ABST
Patent Text Reader

Abstract

The invention provides a secret key determination method and device for instant messaging and a storage medium, relates to the field of communication security, and can solve the problem that a secret key cannot be decrypted due to expiration. The method comprises the following steps: receiving a first request message, wherein the first request message is used for requesting a key; the first request message at least comprises respective identifiers of the two clients; determining root keys corresponding to the two clients based on the first request message; generating a key based on the root key and respective identifiers of the two clients; and sending a first response message, wherein the first response message comprises the key and the validity period of the key. The corresponding key can be generated under the condition that the key does not exist or expires, for the server, the key can be generated according to the root key and the respective identifiers of the two clients, all keys do not need to be stored, the complexity of key management is simplified, the storage space is saved, and the manageability of the key is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication security, and in particular to a method and device for determining a key for instant messaging and a storage medium. BACKGROUND

[0002] In the instant messaging scenario, a source encryption technique is usually used to ensure communication security. Generally, a first client encrypts information to be transmitted by using a key to obtain ciphertext. The first client forwards the ciphertext to a second client via a server, and the second client decrypts the ciphertext by using the key to obtain the information to be transmitted.

[0003] However, the second client cannot be ensured to be online in real time. When the second client is offline, the ciphertext is cached in the server. When the second client is online again, if the key has expired, the ciphertext cannot be decrypted, which affects normal use of the user. SUMMARY

[0004] The present application provides a method and device for determining a key for instant messaging and a storage medium, which can obtain the key in time.

[0005] To achieve the above object, the present application adopts the following technical solutions:

[0006] In a first aspect, the present application provides a method for determining a key for instant messaging, applied to a server, which comprises: receiving a first request message, the first request message being used to request a key, the key being used to encrypt and decrypt transmission information when communicating between clients of two instant messaging software; the first request message comprising at least the respective identifiers of the two clients; determining a root key corresponding to the two clients based on the first request message; generating the key based on the root key and the respective identifiers of the two clients; and sending a first response message, the first response message comprising the key and the validity period of the key.

[0007] In combination with the first aspect above, in a possible implementation manner, generating the key based on the root key and the respective identifiers of the two clients comprises: determining a request time of the first request message; comparing the request time with the validity period of the key, and determining a key identifier corresponding to the validity period of the key in the case that the request time is within the validity period of the key; and generating the key by using a key derivation algorithm based on the root key, the respective identifiers of the two clients and the key identifier.

[0008] In combination with the first aspect above, in a possible implementation manner, the first response message further comprises the key identifier.

[0009] With reference to the first aspect above, in a possible implementation form of the first aspect, the first request message further comprises a key identifier; and the key is generated based on the root key and the respective identifiers of the two clients, comprising: generating the key based on the root key, the respective identifiers of the two clients and the key identifier by using a key derivation algorithm.

[0010] With reference to the second aspect above, in a possible implementation form of the second aspect, the first response message further comprises a key identifier in a case that a request time of the first request message is within the validity period of the key.

[0011] With reference to the second aspect above, in a possible implementation form of the second aspect, the first request message further comprises a key identifier.

[0012] With reference to the second aspect above, in a possible implementation form of the second aspect, the first request message further comprises a key identifier.

[0013] With reference to the third aspect above, in a possible implementation form of the third aspect, the first request message further comprises a key identifier.

[0014] In a possible design, the apparatus can comprise a processing module and a communication module. The communication module is configured to perform the sending actions and the receiving actions in the method described in the first aspect or any possible implementation form of the first aspect, or perform the sending actions and the receiving actions in the method described in the second aspect or any possible implementation form of the second aspect. The processing module is configured to perform the actions related to processing in the method described in the first aspect or any possible implementation form of the first aspect, or perform the actions related to processing in the method described in the second aspect or any possible implementation form of the second aspect.

[0015] In a fourth aspect, the present application provides a key determination apparatus for instant communication, comprising: a processor and a communication interface; the communication interface is coupled to the processor, and the processor is configured to run computer programs or instructions to implement the key determination method for instant communication as described in the first aspect and any possible implementation manner of the first aspect, or implement the key determination method for instant communication as described in the second aspect and any possible implementation manner of the second aspect.

[0016] In a fifth aspect, the present application provides a computer readable storage medium, which stores instructions, and when the instructions are run on a computer, the computer is caused to execute the key determination method for instant communication as described in the first aspect and any possible implementation manner of the first aspect, or execute the key determination method for instant communication as described in the second aspect and any possible implementation manner of the second aspect.

[0017] In a sixth aspect, the present application provides a computer program product comprising instructions, and when the computer program product is run on a computer, the computer is caused to execute the key determination method for instant communication as described in the first aspect and any possible implementation manner of the first aspect, or execute the key determination method for instant communication as described in the second aspect and any possible implementation manner of the second aspect.

[0018] In a seventh aspect, the present application provides a chip, which comprises a processor and a communication interface, the communication interface is coupled to the processor, and the processor is configured to run computer programs or instructions to implement the key determination method for instant communication as described in the first aspect and any possible implementation manner of the first aspect, or implement the key determination method for instant communication as described in the second aspect and any possible implementation manner of the second aspect.

[0019] Specifically, the chip provided in the present application further comprises a memory for storing the computer programs or instructions.

[0020] It should be noted that the above computer instructions can be stored on the computer readable storage medium in whole or in part. The computer readable storage medium can be packaged together with the processor of the apparatus, or packaged separately from the processor of the apparatus, and the present application does not make any limitation in this regard.

[0021] In an eighth aspect, the present application provides a key determination system for instant communication, comprising: a server and a client of instant communication software, wherein the server is configured to execute the key determination method for instant communication as described in the first aspect and any possible implementation manner of the first aspect, and the client of instant communication software is configured to execute the key determination method for instant communication as described in the second aspect and any possible implementation manner of the second aspect.

[0022] The description of the second aspect to the eighth aspect in the present application can refer to the detailed description of the first aspect; and the beneficial effects of the description of the second aspect to the eighth aspect can refer to the beneficial effect analysis of the first aspect, which will not be repeated here.

[0023] In the present application, the names of the key determination apparatuses described above do not constitute a limitation on the devices or functional modules themselves, and in actual implementation, these devices or functional modules can appear with other names. As long as the functions of each device or functional module are similar to those in the present application, they belong to the scope of the claims of the present application and equivalent technologies.

[0024] These aspects or other aspects of the present application will be more apparent in the following description.

[0025] The above-mentioned scheme at least brings the following beneficial effects: based on the technical scheme, the key determination method for instant messaging provided by the present application generates a key through the respective identifiers of the two clients included in the first request message and the corresponding root keys, even in the key update transition period, that is, in the case where the key does not exist or the key is expired, the corresponding key can be generated, and the client of the instant messaging software can obtain the transmission message according to the key, which can improve the security of communication. For the server, the key can be generated according to the root key and the respective identifiers of the two clients, without the need to store all the keys, which simplifies the complexity of key management, saves storage space, and increases the manageability of the key. BRIEF DESCRIPTION OF DRAWINGS

[0026] Figure 1 An architecture schematic diagram of a key determination system for instant messaging provided by an embodiment of the present application;

[0027] Figure 2 A hardware structure schematic diagram of a key determination apparatus for instant messaging provided by an embodiment of the present application;

[0028] Figure 3 A flowchart of a key determination method for instant messaging provided by an embodiment of the present application;

[0029] Figure 4 A flowchart of another key determination method for instant messaging provided by an embodiment of the present application;

[0030] Figure 5 A structure schematic diagram of a key determination apparatus for instant messaging provided by an embodiment of the present application. DETAILED DESCRIPTION

[0031] With reference to the drawings and the embodiments of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by a person of ordinary skill in the art without creative effort are within the scope of the present application.

[0032] The term “and / or” used herein is only used to describe an association relationship of associated objects, and can represent three relationships, for example, A and / or B can represent three cases of A existing alone, A and B existing simultaneously, and B existing alone.

[0033] The terms “first” and “second” and the like in the description of the present application and the drawings are used to distinguish different objects or different treatments of the same object, and are not used to describe a specific order of the objects.

[0034] In addition, the terms “include” and “have” and any variations thereof mentioned in the description of the present application are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include other steps or units not listed or can optionally include other steps or units inherent to the process, method, product or device.

[0035] It should be noted that in the embodiments of the present application, the words “exemplary” or “for example” are used to represent an example, illustration or description. Any embodiment or design scheme described as “exemplary” or “for example” in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the words “exemplary” or “for example” are intended to present the relevant concept in a specific manner.

[0036] In the description of the present application, the meaning of “a plurality of” is two or more, unless otherwise specified.

[0037] Currently, instant messaging software has become an indispensable tool for people's daily communication and work cooperation. For example, the instant messaging software can be WeChat, WhatsApp, etc. Such instant messaging software usually adopts channel encryption technology to ensure communication security. For example, the channel encryption technology can be secure sockets layer (SSL), transport layer security (TLS), message queuing telemetry transport secure (MQTTS), etc.

[0038] Specifically, the client of the instant messaging software does not directly encrypt the original message content, but builds a secure channel between the client and the center server. With the channel encryption technology, it is ensured that the message is transmitted in the encrypted transmission channel, so as to prevent the message from being stolen or tampered with during transmission. However, in this mechanism, different clients cannot directly establish a connection, and the transmission of the message needs to pass through the forwarding of the center server. This means that the center server can receive the original message content during the message transmission, thereby bringing certain security risks. Once the center server is attacked or has internal management loopholes, the original message content may face the risk of leakage.

[0039] In view of the above security risks, in some higher security requirement scenarios, the communication security is ensured by using source encryption technology. For example, in the government-enterprise, military and other scenarios, the source encryption technology is usually used. The source encryption technology refers to encrypting the message content before transmission. In this way, even if the communication channel is intercepted, the message content cannot be obtained because the message content has been encrypted, thereby ensuring the communication security.

[0040] However, in the actual application of the source encryption technology, due to the uncertainty of the message data volume, especially when encrypting data with large data volume such as files, a symmetric encryption algorithm needs to be used. This is because the symmetric encryption algorithm has high efficiency when processing a large amount of data. However, when using the symmetric encryption algorithm, the management of the symmetric encryption key needs to be considered. At present, there are mainly two ways of key management: the first way is to use a fixed key; the second way is to update the key according to the demand, time or scene.

[0041] For the first way, if a fixed key is selected and not updated, there will inevitably be a security risk of key leakage or cracking. Because once the key is leaked, all messages encrypted with the key will lose confidentiality.

[0042] For the second way, the one-time key scheme is used according to the demand, time or scene, which can significantly improve the security, but the one-time key scheme requires a random key to be generated each time a message is sent, and the key needs to be sent to the receiver. Specifically, the sender needs to randomly generate a symmetric key each time a message is sent, encrypt the message using the symmetric key, and encrypt the symmetric key using asymmetric encryption to generate a digital envelope. The digital envelope and the encrypted message are sent to the receiver. The receiver needs to decrypt according to the corresponding decryption process after receiving the digital envelope and the encrypted message.

[0043] This way will increase the storage overhead and communication overhead. In the multi-client communication or group communication scenario, the increase of such overhead will be more obvious. The number of instant messages is huge, and often involves one-to-many sending of messages, or the same account is logged in on multiple devices. As the number of communication parties grows, the number of keys will grow exponentially, and the overhead for storing the keys will also grow.

[0044] If it is desired to not rely on the server to participate in encryption and decryption operations in such a scenario, the problem of asymmetric encryption key expiration management will be faced. Since asymmetric encryption keys have a certain validity period, if not properly managed, it may lead to the use of invalid keys for encryption or decryption operations, thereby affecting the normal transmission and security of messages.

[0045] In addition to the above two key management methods, there are other key update schemes. However, these schemes also have problems, the most prominent of which is the key synchronization acquisition problem during the key update transition period. In the instant messaging scenario, the client cannot be guaranteed to be online in real time. When the client is offline, the message will be cached on the server. After the client is online again, the cached message needs to be decrypted using the new key. However, during the key update transition period, the client may not be able to obtain the new key in time, which causes the cached message to be unable to be decrypted normally, affecting the normal use of the user.

[0046] The key determination method for instant messaging provided by the present application generates a key through the respective identifiers of the two clients included in the first request message and the corresponding root keys, even in the case of key update transition period, that is, in the case of key non-existence or key expiration, the corresponding key can be generated, and the client of the instant messaging software can obtain the transmission message according to the key, which can improve the security of communication. For the server, the key can be generated according to the root key and the respective identifiers of the two clients, without the need to store all the keys, simplifying the complexity of key management, saving storage space, and increasing the manageability of the keys.

[0047] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0048] Figure 1 An architecture diagram of a key determination system for instant messaging provided by an embodiment of the present application is shown in FIG. 1. As shown in the figure, the architecture includes a client 101 of instant messaging software and a server 102. Figure 1

[0049] The client 101 of instant messaging software can be at least one of a smart phone, a smart watch, a desktop computer, a laptop computer, a virtual reality terminal, an augmented reality terminal, a wireless terminal, and a laptop computer, and the like, and the present application does not limit this. ​

[0050] In some embodiments, the instant messaging software client 101 runs instant messaging software. For example, the instant messaging software client 101 can communicate with other clients running instant messaging software through the instant messaging software.

[0051] In other embodiments, the instant messaging client 101 has communication capabilities. For example, the instant messaging client 101 obtains a key through communication with the server 102.

[0052] Server 102 can be a standalone physical server, a server cluster consisting of multiple physical servers, or at least one of the following cloud servers that provide basic cloud computing services: cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data or artificial intelligence platforms. This application embodiment does not limit this specific type. Of course, server 102 can also include other functions to provide more comprehensive and diversified services.

[0053] In some embodiments, server 102 has communication capabilities. For example, server 102 can receive a first request message from client 101 of instant messaging software. As another example, server 102 can send a first response message to client 101 of instant messaging software.

[0054] The first request message is used to request a key, and it includes at least the identifiers of the two clients. The first response message includes the key and its validity period.

[0055] In other embodiments, server 102 has processing capabilities. For example, server 102 determines the root keys corresponding to the two clients based on the first request message. As another example, server 102 generates keys based on the root keys and the respective identifiers of the two clients.

[0056] The server 102 can be one or more, and this embodiment of the application does not limit this. For ease of understanding, Figure 1 Only one is shown in the image.

[0057] The instant messaging software client 101 and server 102 are connected via a communication link. This communication link can be a wired communication link or a wireless communication link, and this embodiment of the application does not limit it.

[0058] When implemented in hardware, the key determination device for instant messaging can provide, for example... Figure 2 The hardware structure shown is, specifically, Figure 2 This is a schematic diagram of the hardware structure of a key determination device for instant messaging provided in an embodiment of this application.Figure 2 As shown, the key determination apparatus for instant communication comprises at least one processor 201, a communication line 202, and at least one communication interface 204, and can further comprise a memory 203. The processor 201, the memory 203, and the communication interface 204 can be connected through the communication line 202.

[0059] The processor 201 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement one or more embodiments of the present application, such as one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0060] The communication line 202 is used to transmit information between the above-mentioned components.

[0061] The communication interface 204 is used to communicate with other devices or communication networks, and can use any transceiver device, such as an Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc.

[0062] The memory 203 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.

[0063] In a possible design, the memory 203 can exist independently of the processor 201, that is, the memory 203 can be an external memory of the processor 201, and the memory 203 can be connected to the processor 201 through the communication line 202, for storing execution instructions or application codes and being controlled by the processor 201 to perform the method for determining an instant communication key provided in the embodiments of the present application. In another possible design, the memory 203 can also be integrated with the processor 201, that is, the memory 203 can be an internal memory of the processor 201, for example, the memory 203 can be a cache, and can be used to temporarily store some data and instruction information, etc.

[0064] As a possible implementation, the processor 201 can include one or more CPUs, for example, the CPUs 0 and 1 in FIG. 2. Figure 2 As another possible implementation, the apparatus for determining an instant communication key can include multiple processors, for example, the processors 201 and 207 in FIG. 2. Figure 2 As still another possible implementation, the apparatus for determining an instant communication key can further include the output device 205 and the input device 206.

[0065] It should be noted that the embodiments of the present application can be mutually referenced, for example, the same or similar steps, method embodiments, system embodiments and apparatus embodiments can be mutually referenced, and are not limited.

[0066] Figure 3 A flowchart of a method for determining an instant communication key provided in the embodiments of the present application is shown in FIG. 3, and the method can be applied to the apparatus for determining an instant communication key as shown in FIG. 2. As shown in FIG. 3, the method can be implemented through S301 to S304. Figure 2 Figure 3 S301, a client of an instant communication software sends a first request message to a server.

[0067] The first request message is used to request a key. The key is used to encrypt and decrypt transmission information when communicating between two clients of instant communication software.

[0068] The first request message at least includes respective identities of the two clients.

[0069] The client of the instant communication software can be understood as a sender of the transmission information, or can be understood as a receiver of the transmission information.

[0070]

[0071] Correspondingly, the server receives the first request message.

[0072] ​​It can be understood that the client of the instant messaging software needs to encrypt the transmission information by the key before sending the transmission information, or decrypt the transmission information by the key after receiving the transmission information. In the case that the client of the instant messaging software needs the key, the client of the instant messaging software can first query whether the key exists and whether the key is expired through the corresponding interface. When the information returned by the interface is that the key does not exist or the key is expired, a first request message is sent to the server.

[0073] It should be noted that when the client of the instant messaging software is the sender of the transmission information, the first request message includes the respective identifiers of the two clients.

[0074] When the client of the instant messaging software is the receiver of the transmission information, the first request message further includes the key identifier, that is, the first request message includes the respective identifiers of the two clients and the key identifier. When the client of the instant messaging software is the receiver of the transmission information, the key identifier of the client of the instant messaging software cannot determine the corresponding key, or the key is expired after determining the corresponding key, in which case the client of the instant messaging software sends the first request message to the server.

[0075] The identifier of the client and the key identifier can be a specific field agreed in advance, or can be a randomly generated field, or can be obtained by calculation, and the embodiments of the application do not limit this.

[0076] In this way, the content included in the first request message in different cases can be determined, and the server can generate a corresponding first response message according to the content carried by the first request message.

[0077] S302, the server determines the root key corresponding to the two clients based on the first request message.

[0078] The root key is used to derive the key for clients of the same type, or clients within the same enterprise, or clients under the same organization. That is, the clients of the same type, the same enterprise or the same organization have the same root key.

[0079] For example, the server includes a quantum random number generator, and the root key can be generated by the quantum random number generator. The root key can be managed by an enterprise or an organization or a designated level administrator.

[0080] S303, the server generates a key based on the root key and the respective identifiers of the two clients.

[0081] In a possible implementation, the server generates the key based on the root key and the respective identifiers of the two clients by a key derivation algorithm.

[0082] Exemplarily, the key derivation algorithm can be an SM3 kdf algorithm or the like.

[0083] S304, the server sends a first response message.

[0084] The first response message includes a key and a validity period of the key.

[0085] Correspondingly, the client of the instant messaging software receives the first response message.

[0086] The key determination method for instant messaging provided in the application generates a key through the respective identifiers of the two clients included in the first request message and the corresponding root keys, and can generate a corresponding key even in a key update transition period, i.e., in the case where the key does not exist or the key is expired. The client of the instant messaging software can obtain a transmission message according to the key, and the security of communication can be improved. For the server, the key can be generated according to the root key and the respective identifiers of the two clients, without the need to store all keys, so that the complexity of key management is simplified, the storage space is saved, and the manageability of the key is increased.

[0087] The process of generating the key in S303 shown in the above Figure 3 will be described below. The process of generating the key has the following two modes.

[0088] Mode 1: In the case where the first request message includes the respective identifiers of the two clients, the above S303 can also be implemented through the following steps 11 to 13.

[0089] Step 11: The server determines the request time of the first request message.

[0090] In a possible implementation manner, the request time is included in the message body of the first request message, and the server determines the request time by parsing the first request message.

[0091] Step 12: The server compares the request time with the validity period of the key, and determines the key identifier corresponding to the validity period of the key in the case where the request time is within the validity period of the key.

[0092] Understandably, when the two clients of the instant messaging software communicate, there are multiple keys for encrypting and decrypting the transmission information, each key corresponds to a different validity period, and the keys with different validity periods are distinguished by the key identifier.

[0093] For example, the update period of the key is agreed in advance, and 1 to n are taken as the key identifiers, where n is a positive integer. That is, the keys are sorted in ascending order according to the effective time of the keys, the key identifier of the first key is 1, the key identifier of the second key is 2, and so on. The server stores the effective time of the first key between the clients of the instant messaging software and the update period of the key. The server can determine the validity period of the plurality of keys according to the update period of the key agreed in advance and the effective time of the first key. After the request time is determined, the request time and the validity period of the plurality of keys are compared to determine that the request time is within the validity period of a key, and the key identifier corresponding to the validity period of the key is determined. In this case, the key identifier can also be used to identify the validity period of the key, the scenario of the key, and the like.

[0094] Step 13: The server generates the key based on the root key, the respective identifiers of the two clients, and the key identifier through a key derivation algorithm.

[0095] In this way, the key identifier is determined according to the time of the first request message, and then the key is obtained according to the root key, the respective identifiers of the two clients, and the key identifier, so that the key can be obtained in the case where the first request message does not include the key identifier.

[0096] It can be understood that in the case where the request time of the first request message is within the validity period of the key, that is, in the case where the first request message includes the respective identifiers of the two clients, the first response message also includes the key identifier. That is, the first response message includes the key, the validity period of the key, and the key identifier.

[0097] Method two: in the case where the first request message includes the respective identifiers of the two clients and the key identifier, the above S303 can also be implemented through the following step 21.

[0098] Step 21: The server generates the key based on the root key, the respective identifiers of the two clients, and the key identifier through a key derivation algorithm.

[0099] In this way, in the case where the first request message includes the key identifier, the determination method of the key can be determined. That is, the corresponding key can be generated by the server through the respective identifiers of the two clients and the key identifier, which are key derivation factor information.

[0100] It can be understood that in the case where the first request message includes the respective identifiers of the two clients and the key identifier, the first response message includes the key and the validity period of the key.

[0101] In this way, the content included in the first response message in different cases of the first request message can be determined.

[0102] The aboveFigure 3 The process of determining the root key in S302 is described. As a possible implementation, S302 can also be implemented through the following steps 31 to 32.

[0103] Step 31: The server determines the communication permission between the two clients of the instant messaging software.

[0104] For example, the server stores the friend relationship of each client of the instant messaging software. If the two clients of the instant messaging software have a friend relationship, it indicates that the two clients of the instant messaging software have communication permission. The communication permission between the two clients of the instant messaging software is determined by querying the friend relationship between the two clients.

[0105] For another example, the server stores the affiliation of each client of the instant messaging software. The affiliation can refer to which enterprise, organization, project, etc. the client belongs to. If the affiliations of the two clients of the instant messaging software are the same, it indicates that the two clients of the instant messaging software have communication permission. The communication permission between the two clients of the instant messaging software is determined by querying the affiliations of the two clients.

[0106] Step 32: The server determines the root keys corresponding to the two clients based on the respective identities of the two clients in the case that the two clients of the instant messaging software have communication permission.

[0107] For example, the server stores the identity of the client and the root key corresponding to the identity of the client. The server determines the root keys corresponding to the two clients by keyword matching based on the identity of the client.

[0108] In this way, the root key can be determined for the client with communication permission, which facilitates the determination of the key based on the root key and ensures the security of the communication.

[0109] Figure 4 Another flowchart of the key determination method of the instant messaging provided by the embodiment of the present application is provided. Taking the two clients of the instant messaging software as the first client and the second client for example, as shown in the figure, the method can be implemented through S401-S422. Figure 4

[0110] S401, the server generates a root key for the client of the instant messaging software with communication permission.

[0111] S402, in the case that the first client needs to send transmission information to the second client, the first client determines whether there is a key in the local and the key is not expired. If yes, S411 is executed; if no, S403 is executed. ​

[0112] The key is used to encrypt and decrypt the transmission information when the first client and the second client communicate.

[0113] It can be understood that before judging whether the local has the key and the key is not expired, the first client needs to register and log in first.

[0114] S403, the first client sends a first request message to the server in the case that the key does not exist or the key is expired. The first request message includes the identity of the first client and the identity of the second client.

[0115] Correspondingly, the server receives the first request message.

[0116] S404, the server determines the communication authority between the first client and the second client.

[0117] S405, the server judges whether the first client and the second client have the communication authority. If yes, S406 is executed.

[0118] S406, the server determines the root key corresponding to the two clients based on the identity of the first client and the identity of the second client in the case that the first client and the second client have the communication authority.

[0119] S407, the server determines the request time of the first request message.

[0120] S408, the server compares the request time with the validity period of the key, and determines the key identity corresponding to the validity period of the key in the case that the request time is within the validity period of the key.

[0121] S409, the server generates the key through the key derivation algorithm based on the root key, the respective identities of the two clients and the key identity.

[0122] S410, the server sends a first response message to the first client. The first response message includes the key, the validity period of the key and the key identity.

[0123] Correspondingly, the first client receives the first response message.

[0124] The first client can store the key, the validity period of the key and the key identity.

[0125] S411, the first client sends a first message to the second client.

[0126] The first message includes the ciphertext and the key identity, and the ciphertext is obtained by encrypting the transmission information and the transmission time of the first client through the key.

[0127] Correspondingly, the second client receives the first message.

[0128] In this way, the content contained in the first message can be determined, and the communication security of the sender and the receiver in the communication process can be ensured.

[0129] Understandably, before receiving the first message, the second client needs to be registered and logged in.

[0130] S412, the second client determines whether the corresponding key exists and the key is not expired based on the key identifier. If yes, S419 is executed; if no, S413 is executed.

[0131] S413, the second client sends a first request message to the server in the case that the key does not exist or the key is expired. The first request message includes the identifier of the first client, the identifier of the second client and the key identifier.

[0132] Correspondingly, the server receives the first request message.

[0133] S414, the server determines the communication authority between the first client and the second client.

[0134] S415, the server determines whether the first client and the second client have the communication authority. If yes, S416 is executed.

[0135] S416, the server determines the root key corresponding to the two clients based on the identifier of the first client and the identifier of the second client in the case that the first client and the second client have the communication authority.

[0136] S417, the server generates the key through the key derivation algorithm based on the root key, the identifier of the two clients and the key identifier.

[0137] S418, the server sends a first response message to the second client. The first response message includes the key and the validity period of the key.

[0138] It should be noted that the first response message can also include the key identifier.

[0139] Correspondingly, the second client receives the first response message.

[0140] The second client can store the key, the validity period of the key and the key identifier.

[0141] S419, the second client decrypts the ciphertext through the key to obtain the transmission time and the transmission information.

[0142] S420, the second client determines whether the transmission time is within the validity period of the key. If yes, S421 is executed; if no, S422 is executed.

[0143] S421, the second client confirms that the transmission information is correct in response to the transmission time being within the validity period of the key.

[0144] S422, the second client confirms that the transmission information is illegal in response to the transmission time not being within the validity period of the key, and gives a security risk prompt.

[0145] It can be understood that if the transmission time is not within the validity period of the key, it indicates that the transmission information may be tampered with in the transmission process, and the transmission information is not trustworthy. At this time, the user can be reminded that the transmission information is illegal through a warning, and a security risk prompt is given.

[0146] In this way, by encrypting the transmission message and the transmission time, not only the security in the information transmission process can be ensured, but also the receiving party can determine the legality of the transmission information through the decrypted transmission time after receiving the first message.

[0147] The key determination method for instant messaging provided by the embodiments of the present application does not require the server to store all the keys between the clients, but only needs to store the root key and the identifier of the client, and the key can be generated according to the root key and the identifier of the client, thereby reducing the number of key storage, reducing the key maintenance cost and difficulty. In addition, the period, update scene and different root keys of key update can be updated and configured in real time in the server, different enterprises can have different security strategies to dynamically adjust, thereby improving the security and flexibility of the overall management.

[0148] The embodiments of the present application can divide the function modules or function units of the key determination device for instant messaging according to the above-mentioned method examples. For example, each function module or function unit can be divided according to each function, or two or more functions can be integrated in one processing module. The integrated module can be realized in the form of hardware or in the form of software function module or function unit. The division of modules or units in the embodiments of the present application is illustrative, and is only a logical function division. In actual implementation, there can be another division mode.

[0149] Figure 5 A structure diagram of a key determination device 50 for instant messaging provided by the embodiments of the present application. The key determination device 50 for instant messaging includes a communication unit 501 and a processing unit 502. The key determination device 50 for instant messaging can be used to realize the functions of the server or the client of the instant messaging software.

[0150] In some embodiments, the instant messaging key determination apparatus 50 can further comprise a storage unit (not shown in the figure) for storing program instructions and data. Figure 5

[0151] In some embodiments, the communication unit 501, which can also be referred to as a transceiver unit, is configured to implement the transmitting and / or receiving functions. The communication unit 501 can be constituted by a transceiver circuit, a transceiver, a transceiver, or a communication interface.

[0152] In some embodiments, the communication unit 501 can comprise a receiving unit and a transmitting unit, which are respectively configured to perform the receiving and transmitting steps performed by the server or the client of the instant messaging software in the above method embodiments, and / or other processes for supporting the techniques described herein.

[0153] In the case where the instant messaging key determination apparatus 50 is configured to implement the functions of a server, in one possible implementation, the communication unit 501 is configured to receive a first request message, the first request message being configured to request a key, the key being configured to be used for encrypting and decrypting transmission information when communicating between two clients of instant messaging software; the first request message at least comprises respective identities of the two clients; the processing unit 502 is configured to determine a root key corresponding to the two clients based on the first request message; the processing unit 502 is configured to generate the key based on the root key and the respective identities of the two clients; and the communication unit 501 is configured to send a first response message, the first response message comprising the key and a validity period of the key.

[0154] In one possible implementation, the processing unit 502 is configured to: determine a request time of the first request message; compare the request time with the validity period of the key, and in the case where the request time is within the validity period of the key, determine a key identifier corresponding to the validity period of the key; and generate the key based on the root key, the respective identities of the two clients, and the key identifier, through a key derivation algorithm.

[0155] In one possible implementation, the first response message further comprises the key identifier.

[0156] In one possible implementation, the first request message further comprises the key identifier; and the processing unit 502 is configured to generate the key based on the root key, the respective identities of the two clients, and the key identifier, through a key derivation algorithm.

[0157] ​In the case that the key determination apparatus 50 is used to implement the function of a client of the instant messaging software, in a possible implementation, the communication unit 501 is configured to send a first request message to a server, the first request message being used to request a key, the key being used to encrypt and decrypt transmission information when the client communicates with another client; the first request message at least comprises respective identities of the two clients; the communication unit 501 is configured to receive a first response message sent by the server, the first response message comprising the key and a validity period of the key; the key is generated by the server according to respective root keys of the two clients and the respective identities of the two clients.

[0158] In a possible implementation, in the case that the request time of the first request message is within the validity period of the key, the first response message further comprises a key identifier.

[0159] In a possible implementation, the first request message further comprises a key identifier.

[0160] Those skilled in the art can clearly understand the implementation of the above-described embodiments from the above description. For the convenience and brevity of description, only the division of the above-described functional modules is taken as an example. In actual applications, the above-described functions can be completed by different functional modules according to requirements, that is, the internal structure of the apparatus is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, apparatus and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here again.

[0161] The embodiment of the present application provides a computer program product containing instructions, when the computer program product is run on a computer, the computer is caused to execute the key determination method of instant messaging in the method embodiments.

[0162] The embodiment of the present application further provides a computer readable storage medium, the computer readable storage medium stores instructions, when the instructions are run on a computer, the computer is caused to execute the key determination method of instant messaging in the method flow shown in the method embodiments.

[0163] The computer readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a register, a hard disk, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing, or any other medium from which a processor can read and write information. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Of course, the disclosure is not limited to a particular storage medium. The processor and the storage medium can be located in an ASIC. In some embodiments, the computer readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.

[0164] The key determination apparatus for instant messaging, the computer readable storage medium, and the computer program product of the embodiments of the present application can be applied to the above method, and the technical effects that can be obtained thereby can be referred to the above method embodiments, which will not be described herein again.

[0165] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, another division manner can be used, for example, a plurality of units or components can be combined or integrated into another system, or some features can be omitted or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0166] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may also be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0167] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0168] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for determining a key for instant communication, characterized by, The method applied to a server comprises: receiving a first request message, the first request message being used to request a key, the key being used to encrypt and decrypt transmission information when communication is performed between two clients of instant messaging software; the first request message comprising at least respective identities of the two clients; determining root keys corresponding to the two clients based on the first request message; generating the key based on the root keys and the respective identities of the two clients; sending a first response message, the first response message comprising the key and a validity period of the key.

2. The method of claim 1, wherein, The generating of the key based on the root keys and the respective identities of the two clients comprises: determining a request time of the first request message; comparing the request time with the validity period of the key, and determining a key identity corresponding to the validity period of the key in a case where the request time is within the validity period of the key; generating the key by a key derivation algorithm based on the root keys, the respective identities of the two clients and the key identity.

3. The method of claim 2, wherein, The first response message further comprises the key identity.

4. The method of claim 1, wherein, The first request message further comprises a key identity. The generating of the key based on the root keys and the respective identities of the two clients comprises: generating the key by a key derivation algorithm based on the root keys, the respective identities of the two clients and the key identity.

5. A method for determining a key for instant communication, characterized by, The method applied to a client of instant messaging software comprises: sending a first request message to a server, the first request message being used to request a key, the key being used to encrypt and decrypt transmission information when communication is performed between the client and another client; the first request message comprising at least respective identities of the two clients; receiving a first response message sent by the server, the first response message comprising the key and a validity period of the key; the key being generated by the server based on root keys corresponding to the two clients and the respective identities of the two clients.

6. The method of claim 5, wherein, In a case where a request time of the first request message is within the validity period of the key, the first response message further comprises a key identity.

7. The method of claim 5, wherein, The first request message further comprises a key identity.

8. A key determination device for instant messaging, characterized in that, The apparatus comprises modules for performing the method of any one of claims 1-4, or modules for performing the method of any one of claims 5-7.

9. An apparatus for determining a key for instant communication, the apparatus comprising: a key generation unit configured to generate a key for instant communication; and a key storage unit configured to store the generated key in a storage unit. comprises: a processor and a communication interface; the communication interface and the processor are coupled, and the processor is configured to run computer programs or instructions, so that the instant messaging key determination apparatus performs the method of any one of claims 1-4, or performs the method of any one of claims 5-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions or programs, when the computer instructions or programs are run on a computer, so that the method of any one of claims 1-4 is performed, or the method of any one of claims 5-7 is performed.