A key management method, apparatus, electronic device, and storage medium

In the video network network conference, when the number of terminals changes, two cryptographic machines negotiate to generate new keys, the security risks in the key management server uniformly generates keys in the prior art are solved, and the security of network conferences is improved.

CN113824704BActive Publication Date: 2025-07-01VISIONVERA INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111037119.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-06
Publication Date
2025-07-01
Estimated Expiration
2041-09-06

AI Technical Summary

Technical Problem

In the existing video networking system, the unified fixed key generation by the key management server poses a security risk, making it difficult to effectively ensure the security of network meetings.

Method used

When the number of terminals participating in the network conference changes, the two cipher machines in the network conference negotiate to generate a new key for data transmission of the network conference to avoid the generation of the key management server uniformly.

Benefits of technology

By negotiating the generation of new keys when the number of terminals changes, the security of network conferences is improved and the security risks brought about by the unified generation of key management servers is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113824704B_ABST
    Figure CN113824704B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a key management method, apparatus, electronic device, and storage medium, which relate to the field of communication technologies. Applied to a first cryptographic machine, the method includes: when the number of terminals participating in a network conference changes, interacting with a second cryptographic machine to generate a first key; through the first key, performing data transmission of the network conference with cryptographic machines other than the first cryptographic machine in a target cryptographic machine; where the target cryptographic machine is a cryptographic machine connected to a terminal participating in the network conference, and the first cryptographic machine and the second cryptographic machine are two of the cryptographic machines in the target cryptographic machine. Therefore, in the embodiment of the present invention, when the number of terminals participating in the network conference changes, two cryptographic machines are randomly selected from the cryptographic machines connected to the terminals participating in the network conference at this time for key negotiation, instead of uniformly generating keys by a key management server, thereby improving the security of the network conference.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a key management method, apparatus, electronic device, and storage medium. Background Art

[0002] The Visual Networking uses the world's most advanced real-time high-definition video switching technology to achieve real-time transmission of full-network high-definition videos that cannot be achieved by the current Internet. It integrates dozens of services such as high-definition video conferencing, video surveillance, remote training, intelligent surveillance analysis, emergency command, video phone, live broadcast, TV mail, information release, etc., including videos, voices, pictures, texts, communications, data, etc., all in one system platform, and realizes real-time interconnection and intercommunication of high-definition video communications through various terminal devices.

[0003] Currently, the demand for holding Visual Networking video conferences is increasing. To ensure the security of Visual Networking conferences, in the current Visual Networking system, generally, a key management server generates keys, and a central cipher machine distributes them to edge cipher machines. However, there are certain security risks in uniformly and fixedly generating keys by the key management server. Summary of the Invention

[0004] In view of the above problems, embodiments of the present invention are proposed to provide a key management method and a corresponding key management apparatus that overcome the above problems or at least partially solve the above problems.

[0005] To solve the above problems, an embodiment of the present invention discloses a key management method applied to a first cipher machine. The method includes:

[0006] When the number of terminals participating in a network conference changes, interacting with a second cipher machine to generate a first key;

[0007] Using the first key to perform data transmission of the network conference with cipher machines other than the first cipher machine in a target cipher machine;

[0008] Wherein, the target cipher machine is a cipher machine connected to a terminal participating in the network conference, and the first cipher machine and the second cipher machine are two of the target cipher machines.

[0009] An embodiment of the present invention also discloses a key management apparatus applied to a first cipher machine. The apparatus includes:

[0010] A first key management module, configured to interact with a second cipher machine to generate a first key when the number of terminals participating in a network conference changes;

[0011] An information transmission module, configured to perform data transmission of the network conference with a cipher machine other than the first cipher machine in the target cipher machine through the first key;

[0012] Wherein, the target cipher machine is the cipher machine connected to the terminal participating in the network conference, and the first cipher machine and the second cipher machine are two of the cipher machines in the target cipher machine.

[0013] The embodiments of the present invention have the following advantages:

[0014] In the embodiments of the present invention, when the number of terminals participating in the network conference changes, the first cipher machine connected to one of the terminals in the network conference interacts with the second cipher machine connected to another terminal to generate a first key. Thus, through the first key, the first cipher machine performs data transmission of the network conference with cipher machines other than the first cipher machine in the target cipher machine, where the target cipher machine is the cipher machine connected to the terminal participating in the network conference. That is, in the embodiments of the present invention, when the number of terminals participating in the network conference changes, two of the cipher machines connected to the remaining terminals participating in the network conference will negotiate to generate a new key.

[0015] Therefore, in the embodiments of the present invention, when the number of terminals participating in the network conference changes, it triggers two of the cipher machines connected to the terminals participating in the network conference at this time to perform key negotiation, which has a certain degree of randomness, rather than uniformly generating keys by the key management server, thereby improving the security of the network conference. Description of the Drawings

[0016] Figure 1 It is a flowchart of the steps of a key management method according to an embodiment of the present invention;

[0017] Figure 2 It is a schematic diagram of the connection of a visual networking terminal in a visual networking according to an embodiment of the present invention;

[0018] Figure 3 It is a block diagram of the structure of a key management device according to an embodiment of the present invention. Detailed Embodiments

[0019] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments.

[0020] The embodiments of the present invention provide a key management method, device, electronic device, and storage medium, which relate to the field of communication technologies.

[0021] Among them, in the embodiments of the present invention, when the number of terminals participating in a network conference changes, two of the cryptographic machines connected by the remaining terminals participating in the network conference will negotiate to generate a new key. Therefore, in the embodiments of the present invention, when the number of terminals participating in the network conference changes, it triggers two of the cryptographic machines connected by the terminals participating in the network conference at this time to perform key negotiation, which has a certain degree of randomness, rather than uniformly generating keys by the key management server, thereby improving the security of the network conference.

[0022] Referring to Figure 1 , a flowchart of the steps of a key management method provided by an embodiment of the present invention is shown. This method can be applied to a first cryptographic machine and specifically may include the following steps:

[0023] Step 101: When the number of terminals participating in the network conference changes, interact with a second cryptographic machine to generate a first key.

[0024] Among them, the network conference can be a Visual Networking conference or an Internet conference, and the terminal can be a Visual Networking terminal or an Internet terminal. Specifically, when the network conference is a Visual Networking conference, the terminal is a Visual Networking terminal; when the network conference is an Internet conference, the terminal is an Internet terminal.

[0025] In addition, the situation where the number of terminals changes includes the situation where a terminal in the network conference exits the network conference and the situation where a terminal enters the network conference. Therefore, in the embodiments of the present invention, when there are new terminals joining or exiting the network conference, a key update will be performed, so that the terminals newly joining the network conference cannot receive the previous conference content, and the terminals exiting the network conference cannot receive the subsequent conference content, thereby further improving the security of the network conference.

[0026] Optionally, the network conference further includes a comprehensive management server, which can detect whether there is a terminal entering or exiting the network conference in the network conference, that is, the comprehensive management server detects whether the number of terminals participating in the network conference changes, and thus, when detecting that the number of participants in the network conference changes, it sends a notification message for indicating that the number of terminals participating in the network conference has changed to the cryptographic machines connected by the terminals participating in the network conference.

[0027] Step 102: Through the first key, perform data transmission of the network conference with the cryptographic machines other than the first cryptographic machine in the target cryptographic machine.

[0028] Among them, the target cipher machine is the cipher machine connected to the terminal participating in the network conference, and the first cipher machine and the second cipher machine are two of the target cipher machines. It should be noted here that when the number of terminals participating in the network conference changes, the cipher machines connected to the remaining terminals in this network conference are the target cipher machines.

[0029] In addition, the data transmission of the above-mentioned network conference includes the transmission of at least one of the video stream, audio data, and instructions in the network conference.

[0030] For example, in a Visual Networking conference, the process of the first cipher machine transmitting the video stream to the cipher machines other than the first cipher machine in the target cipher machine through the first key includes:

[0031] The first cipher machine receives the video stream sent by the Visual Networking terminal connected to it, so the first cipher machine encrypts the video stream using the first key, and sends the encrypted video stream to the cipher machines other than the first cipher machine in the target cipher machine, so that these cipher machines decrypt it using the first key, and then transmit the decrypted video stream to the Visual Networking terminals connected to them.

[0032] Among them, after the Visual Networking terminal receives the decrypted video stream, it can play the video picture according to the decrypted video stream.

[0033] In addition, each terminal participating in the network conference is connected to a corresponding cipher machine.

[0034] In addition, in the embodiments of the present invention, before step 101, between the terminal participating in the network conference and the cipher machine connected to this terminal, the data transmission of the network conference is carried out through a pre-determined initial key. Among them, the initial key can be pre-set, or it can be generated by the interaction of the cipher machines connected to the two terminals that first join the network conference when the network conference is established.

[0035] From the above steps 101 to 102, it can be seen that in the embodiments of the present invention, when the number of terminals participating in the network conference changes, the first cipher machine connected to one terminal in the network conference interacts with the second cipher machine connected to another terminal to generate the first key, so that through the first key, the first cipher machine transmits the data of the network conference to the cipher machines other than the first cipher machine in the target cipher machine, where the target cipher machine is the cipher machine connected to the terminal participating in the network conference. That is, in the embodiments of the present invention, when the number of terminals participating in the network conference changes, two of the cipher machines connected to the remaining terminals participating in the network conference will negotiate to generate a new key.

[0036] Therefore, in the embodiments of the present invention, when the number of terminals participating in a network conference changes, two of the cryptographic machines connected by the terminals participating in the network conference at this time are triggered to perform key negotiation, which has a certain degree of randomness, rather than uniformly generating keys by the key management server, thereby enhancing the security of the network conference.

[0037] In addition, in the embodiments of the present invention, when the number of terminals participating in the network conference changes, key update is performed, so that the network terminals participating in the network conference no longer always use the same key, thereby further improving the security of the network conference. Moreover, in the embodiments of the present invention, when key update is performed, two of the cryptographic machines connected by the remaining terminals in the network conference perform key negotiation, rather than pairwise negotiation among the cryptographic machines connected by the terminals in the network conference, thereby saving resources.

[0038] Optionally, the interacting with the second cryptographic machine to generate the first key includes:

[0039] The first cryptographic machine sends a key negotiation request to the second cryptographic machine, or the first cryptographic machine receives a key negotiation request sent by the second cryptographic machine;

[0040] In response to the key negotiation request, the first cryptographic machine interacts with the second cryptographic machine to generate the first key;

[0041] Wherein, the second cryptographic machine is pre-determined.

[0042] It can be seen that after determining that the cryptographic machines for key interaction include the first cryptographic machine and the second cryptographic machine, the first cryptographic machine can send a key negotiation request to the second cryptographic machine, or the second cryptographic machine can send a key negotiation request to the first cryptographic machine. That is, the first cryptographic machine can be the active negotiator for key interaction, and the second can be the passive negotiator for key interaction; or the second cryptographic machine can be the active negotiator for key interaction, and the first cryptographic machine can be the passive negotiator for key interaction.

[0043] Wherein, when the first cipher machine is the active negotiator for key interaction, upon receiving a notification message sent by the comprehensive management server in the network conference (for indicating a change in the number of terminals participating in the network conference), the first cipher machine sends a key negotiation request to the second cipher machine. The second cipher machine receives the key negotiation request, and thus, in response to the key negotiation request, interacts with the first cipher machine to generate a first key. When the second cipher machine is the active negotiator for key interaction, upon receiving a notification message sent by the comprehensive management server in the network conference (for indicating a change in the number of terminals participating in the network conference), the second cipher machine sends a key negotiation request to the first cipher machine. The first cipher machine receives the key negotiation request, and thus, in response to the key negotiation request, interacts with the second cipher machine to generate a first key.

[0044] Optionally, before interacting with the second cipher machine to generate the first key when the number of terminals participating in the network conference changes, the method includes:

[0045] Determine the second cipher machine;

[0046] Wherein, the determining the second cipher machine includes:

[0047] Randomly select one cipher machine from the cipher machines other than the first cipher machine among the target cipher machines as the second cipher machine;

[0048] Or

[0049] Select the cipher machine connected to the terminal that first participated in the network conference from the cipher machines other than the first cipher machine among the target cipher machines as the second cipher machine.

[0050] As can be seen from the above, in the embodiments of the present invention, the second cipher machine for key interaction with the first cipher machine can be determined in the following manner 1 or manner 2:

[0051] Manner 1: Randomly select one cipher machine from the target cipher machines other than the first cipher machine to perform key interaction with the first cipher machine.

[0052] Manner 2: Select the cipher machine connected to the terminal that first joined the network conference from the target cipher machines other than the first cipher machine in the order of the time when the terminals joined the network conference to interact with the first cipher machine.

[0053] In addition, it can be understood that the cipher machine connected to the terminal that last joined the network conference can also be selected from the target cipher machines other than the first cipher machine in the order of the time when the terminals joined the network conference to interact with the first cipher machine.

[0054] Optionally, the interaction with the second cipher machine to generate the first key includes:

[0055] The first cipher machine receives at least one key negotiation request, where the at least one key negotiation request is sent by at least one cipher machine other than the first cipher machine in the target cipher machines;

[0056] In response to the key negotiation request, the first cipher machine selects one cipher machine from the target cipher machines that sent the key negotiation request as the second cipher machine, and interacts with the second cipher machine to generate the first key.

[0057] Among them, the first cipher machine can be pre-determined as the passive negotiator for key interaction, and the passive negotiator selects the active negotiator for key interaction with it. Then, when the number of terminals participating in the network conference changes, the cipher machines connected to the terminals in the remaining network conferences can send key negotiation requests to each other (that is, any cipher machine sends key negotiation requests to other cipher machines), or at least one cipher machine other than the first cipher machine among the cipher machines connected to the terminals in the remaining network conferences sends a key negotiation request to the first cipher machine; then, the first cipher machine selects one cipher machine from the cipher machines corresponding to the key negotiation requests it receives for key interaction, so as to generate the first key.

[0058] For example, when the integrated management server detects that the number of terminals participating in the network conference changes, it can send notification messages indicating the change in the number of terminals participating in the network conference to the cipher machines connected to the terminals in the network conference respectively, triggering these cipher machines to send key negotiation requests to each other, and then the first cipher machine pre-determined as the passive negotiator selects the second cipher machine for key interaction with it from the cipher machines corresponding to the key negotiation requests it receives.

[0059] Alternatively, when the integrated management server detects that the number of terminals participating in the network conference changes, it can send notification messages indicating the change in the number of terminals participating in the network conference to the cipher machines other than the first cipher machine among the cipher machines connected to the terminals in the network conference respectively, triggering these cipher machines to send key negotiation requests to the first cipher machine, and then the first cipher machine selects the second cipher machine for key interaction with it from the cipher machines corresponding to the key negotiation requests it receives.

[0060] In addition, the first cipher machine can randomly select one cipher machine from the cipher machines corresponding to the key negotiation requests it receives as the second cipher machine; or select the cipher machine connected to the terminal that first participated in the network conference from the cipher machines corresponding to the key negotiation requests it receives as the second cipher machine.

[0061] Optionally, the first cipher machine is the cipher machine connected to the terminal of the chairperson party in the network conference.

[0062] Among them, in the embodiments of the present invention, the cipher machine connected to the terminal of the chairperson party in the network conference can be used as the active initiator of key interaction, and one of the cipher machines connected to the remaining terminals participating in the network conference can be used as the corresponding party of key interaction, so as to interact through two cipher machines to generate a key.

[0063] Optionally, when the integrated management server in the network conference detects a change in the number of terminals participating in the network conference, it can send a notification message indicating the change in the number of terminals participating in the network conference to the cipher machine connected to the terminal of the chairperson party, so as to trigger the cipher machine connected to the terminal of the chairperson party to select one cipher machine from the cipher machines connected to the remaining terminals in the network conference as the second cipher machine, and interact with the second cipher machine to generate the first key.

[0064] In addition, during the process of the network conference, the terminal of the chairperson party may change. Then, when the terminal serving as the chairperson party changes, the process of key interaction can be initiated by the changed terminal of the chairperson party. For example, if the terminal of the chairperson party at time t1 is terminal A and the terminal of the chairperson party changes to terminal B at time t2, the process of key interaction can be initiated by terminal B.

[0065] In addition, it should be noted that after the terminal of the chairperson party exits the network conference, the cipher machines connected to the remaining terminals participating in the network conference can also interact to generate a new key.

[0066] Optionally, before performing data transmission of the network conference with the cipher machines other than the first cipher machine in the target cipher machine through the first key, the method further includes:

[0067] The first cipher machine sends the first key to a third cipher machine; where the third cipher machine is the cipher machine other than the first cipher machine and the second cipher machine in the target cipher machine;

[0068] Or,

[0069] The first cipher machine sends the first key to at least some of the third cipher machines, and the first key is sent to the cipher machines other than the at least some of the third cipher machines through the second cipher machine.

[0070] It can be seen from this that in the embodiments of the present invention, whether the first cryptographic machine is the active negotiator or the passive negotiator for key interaction, after the first cryptographic machine interacts with the second cryptographic machine to generate the first key, the first key can be sent by the first cryptographic machine to the above-mentioned third cryptographic machine; or, the first key can also be sent by the second cryptographic machine to the above-mentioned third cryptographic machine; or, the first cryptographic machine sends the first key to some of the third cryptographic machines, and the second cryptographic machine sends the first key to the remaining third cryptographic machines. For example, if the third cryptographic machines include three cryptographic machines A, B, and C, the first cryptographic machine can send the first key to cryptographic machine A, and the second cryptographic machine can send the key to cryptographic machines B and C.

[0071] That is, after the first cryptographic machine interacts with the second cryptographic machine to generate the first key, if the first cryptographic machine sends the first key to the above-mentioned third cryptographic machine, then after the third cryptographic machine receives the first key, among the cryptographic machines connected to the terminals participating in the network conference that have learned the first key, the cryptographic machines can perform data transmission of the network conference through the first key;

[0072] If the second cryptographic machine sends the first key to the above-mentioned third cryptographic machine, then there is no need for the first cryptographic machine to send the first key to the third cryptographic machine again. After the third cryptographic machine receives the first key sent by the second cryptographic machine, among the cryptographic machines connected to the terminals participating in the network conference that have learned the first key, the cryptographic machines can perform data transmission of the network conference through the first key;

[0073] If the first cryptographic machine sends the first key to some of the third cryptographic machines, then it is also necessary to send the first key to the remaining third cryptographic machines. Among the cryptographic machines connected to the terminals participating in the network conference that have learned the first key, the cryptographic machines can perform data transmission of the network conference through the first key.

[0074] Among them, before the first cryptographic machine sends the first key to some of the third cryptographic machines and the second cryptographic machine sends the first key to the remaining third cryptographic machines, the first cryptographic machine and the second cryptographic machine can interact to negotiate the recipients of the first key they send respectively.

[0075] Optionally, the first cryptographic machine can randomly select N cryptographic machines from the third cryptographic machines and send the identification information of these N cryptographic machines to the second cryptographic machine, so that the second cryptographic machine uses the cryptographic machines other than these N identification information in the third cryptographic machines as the recipients of the first key it sends, where N is greater than 0 and less than the total number of the third cryptographic machines; or, the first cryptographic machine and the second cryptographic machine can be sorted respectively according to the time order in which the third cryptographic machines join the network conference, and then the first cryptographic machine sends the first key to the cryptographic machines in the odd positions in the ranking, and the second cryptographic machine sends the first key to the cryptographic machines in the even positions in the ranking.

[0076] In addition, in the embodiments of the present invention, when the number of terminals participating in the network conference changes, it triggers two cryptographic machines, which are used as the first cryptographic machine and the second cryptographic machine in the cryptographic machines connected by the terminals participating in the network conference at this time, to perform key negotiation, and the generated key is sent by the first cryptographic machine or the second cryptographic machine to the remaining cryptographic machines in the network conference at this time. There is a certain degree of randomness, rather than uniformly sent from the central cryptographic machine to the edge cryptographic machine by the central cryptographic machine, which further improves the security of the network conference.

[0077] Optionally, the method further includes:

[0078] The first cryptographic machine receives a second key sent by the second cryptographic machine or the third cryptographic machine, where the third cryptographic machine is a cryptographic machine other than the first cryptographic machine and the second cryptographic machine in the target cryptographic machines, and the second key is generated by the second cryptographic machine and the third cryptographic machine interacting with each other when the number of terminals participating in the network conference changes;

[0079] The first cryptographic machine uses the second key to perform data transmission of the network conference with the cryptographic machines other than the first cryptographic machine in the target cryptographic machines.

[0080] As can be seen from the above, when the first cryptographic machine is a cryptographic machine other than the cryptographic machine for key interaction, it can receive the second key sent by other cryptographic machines for key interaction, so as to perform data transmission of the network conference with other cryptographic machines in the network conference through the second key.

[0081] Optionally, in the case where the number of terminals participating in the network conference changes, interacting with the second cryptographic machine to generate a first key includes:

[0082] In the case where the number of terminals participating in the network conference changes after the target moment, interacting with the second cryptographic machine to generate a first key;

[0083] Wherein, the target moment is a moment after the start moment of the network conference and at a preset time length from the start moment.

[0084] For example, if the above preset time length is 1 minute, then in the embodiments of the present invention, 1 minute after the start moment t of the network conference, in the case where a terminal newly joins the network conference or a terminal exits the network conference, a key update process is executed (that is, when the number of terminals participating in the network conference changes, two of the cryptographic machines connected by the remaining terminals participating in the network conference will negotiate to generate a new key, and then send the key to the cryptographic machines connected by other terminals).

[0085] Optionally, when the number of terminals participating in the network conference changes after the target time, before interacting with the second cipher machine to generate the first key, the method further includes:

[0086] When the target time arrives, interact with the fourth cipher machine to generate a second key;

[0087] Send the second key to the fifth cipher machine;

[0088] Wherein, the fourth cipher machine is the cipher machine connected to the terminal in the network conference at the target time, and the fifth cipher machine is the cipher machine other than the fourth cipher machine among the cipher machines connected to the terminal in the network conference at the target time.

[0089] It can be seen that in the embodiment of the present invention, within the preset duration from the network conference initiation time, key update is not performed, that is, a preset duration is reserved for terminal entry after the initiation time, and when the preset duration after the initiation time arrives, key update is performed. For example, if the preset duration is 1 minute, then at the moment 1 minute after the network conference initiation time t arrives, two of the cipher machines connected to the terminals participating in the network conference will negotiate to generate a key, and then send the key to the cipher machines connected to other terminals.

[0090] Optionally, interacting with the second cipher machine to generate the first key includes:

[0091] According to the key exchange protocol of the elliptic curve public key cryptography algorithm SM2, the first cipher machine interacts with the second cipher machine to generate the first key.

[0092] Wherein, SM2 is the public key cryptography algorithm standard. The SM2 algorithm includes: digital signature algorithm, key exchange protocol, and public key encryption algorithm.

[0093] In addition, the SM2 key exchange protocol is that two objects A and B transmit information through interaction, and use their respective private keys and the public key of the other party to agree on a secret key known only to A and B.

[0094] To sum up, as Figure 2 shown, in the vision network, it includes: vision network terminals 201, 202, 203, and 204;

[0095] Based on Figure 2 , the specific implementation of the key management method in the embodiment of the present invention can be as described in the following steps H1 - H4:

[0096] Step H1: When the Visual Networking Conference is established, the cryptographic machines 205 to 206 connected to the Visual Networking Terminals 201 to 204 in the Visual Networking Conference perform data transmission of the Visual Networking Conference through a pre-determined initial key; among them, the determination method of the initial key is as described in the foregoing text and will not be elaborated here;

[0097] Step H2: Before the preset duration (for example, 1 minute) after the establishment moment of the Visual Networking Conference arrives, key update is not performed. After the preset duration after the establishment moment of the Visual Networking Conference arrives, if the Comprehensive Management Server 209 detects that a Visual Networking Terminal exits or joins the Visual Networking Conference, it sends a notification message to the cryptographic machine 205 connected to the Chairman Party Visual Networking Terminal 201 in the Visual Networking Conference, where the notification message is used to indicate that the number of Visual Networking Terminals participating in the Visual Networking Conference has changed;

[0098] In this step, the cryptographic machine 205 is the first cryptographic machine described in the foregoing text.

[0099] Step H3: After the cryptographic machine 205 receives the above notification message, it selects one of the cryptographic machines connected to the Visual Networking Terminals 202, 203, and 204 for interaction to generate the first key; among them, the cryptographic machine 205 can randomly select one of the cryptographic machines connected to the Visual Networking Terminals 202, 203, and 204, or in the order of joining the conference time, select the cryptographic machine connected to the first joined Visual Networking Terminal among the cryptographic machines connected to the Visual Networking Terminals 202, 203, and 204 for interaction;

[0100] In this step, the selected cryptographic machine for interaction by the cryptographic machine 205 is the second cryptographic machine described in the foregoing text.

[0101] Step H4: The cryptographic machine 205 or the cryptographic machine negotiated with the cryptographic machine 205 sends the first key to the cryptographic machines connected to other Visual Networking Terminals, or the cryptographic machine 205 sends the first key to some of the cryptographic machines connected to other Visual Networking Terminals, and the cryptographic machine negotiated with the cryptographic machine 205 sends the first key to the remaining cryptographic machines connected to other Visual Networking Terminals; for example, if the cryptographic machine 205 interacts with the cryptographic machine 206 to generate the first key, then the first key can be sent by the cryptographic machine 205 or the cryptographic machine 206 to the cryptographic machines 207 and 208; or the cryptographic machine 205 sends the first key to the cryptographic machine 207, and the cryptographic machine 206 sends the first key to the cryptographic machine 208.

[0102] Alternatively, the specific implementation of the key management method of the embodiment of the present invention can be as described in the following steps K1-K5:

[0103] Step K1: When the Visual Networking Conference is established, the cryptographic machines 205 to 206 connected to the Visual Networking Terminals 201 to 204 in the Visual Networking Conference perform data transmission for the Visual Networking Conference through a pre-determined initial key; among them, the determination method of the initial key is as described in the previous text and will not be elaborated here;

[0104] Step K2: Before the preset duration (for example, 1 minute) after the establishment moment of the Visual Networking Conference arrives, key update is not performed. After the preset duration after the establishment moment of the Visual Networking Conference arrives, if the Comprehensive Management Server 209 detects that a Visual Networking Terminal exits or joins the Visual Networking Conference, it sends notification messages to the cryptographic machines other than the cryptographic machine 205 connected to the chairman-side Visual Networking Terminal 201 in the Visual Networking Conference (i.e., the cryptographic machines 206 to 207). Among them, the notification message is used to indicate that the number of terminals participating in the Visual Networking Conference has changed;

[0105] In this step, the cryptographic machine 205 is the first cryptographic machine described in the previous text.

[0106] Step K3: After receiving the notification message, the cryptographic machines 206 to 207 respectively send key negotiation requests to the cryptographic machine 205;

[0107] Step K4: The cryptographic machine 205 selects one cryptographic machine from the cryptographic machines corresponding to the received key negotiation requests for interaction, thereby generating the first key; among them, the cryptographic machine 205 can randomly select one cryptographic machine from the cryptographic machines 206 to 207, or select the cryptographic machine connected to the terminal that joined the conference first in the order of joining the conference time for interaction;

[0108] In this step, the cryptographic machine selected by the cryptographic machine 205 for interaction is the second cryptographic machine described in the previous text.

[0109] Step K5: The cryptographic machine 205 or the cryptographic machine that negotiates with the cryptographic machine 205 sends the first key to the cryptographic machines connected to other Visual Networking Terminals, or the cryptographic machine 205 sends the first key to some of the cryptographic machines connected to other Visual Networking Terminals, and the cryptographic machine that negotiates with the cryptographic machine 205 sends the first key to the remaining cryptographic machines connected to other Visual Networking Terminals.

[0110] As can be seen from the above, in the embodiments of the present invention, when the number of terminals participating in a network conference changes, two of the cryptographic machines connected by the terminals participating in the network conference at this time are triggered to perform key negotiation, which has a certain degree of randomness, rather than uniformly generating keys by the key management server, thereby enhancing the security of the network conference. Moreover, in the embodiments of the present invention, when the number of terminals participating in the network conference changes, key update is performed, so that the network terminals participating in the network conference no longer always use the same key, thereby further improving the security of the network conference. In addition, in the embodiments of the present invention, when performing key update, two of the cryptographic machines connected by the remaining terminals in the network conference perform key negotiation, rather than pairwise negotiation among the cryptographic machines connected by the terminals in the network conference, thereby saving resources.

[0111] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0112] Referring to Figure 3 , a structural block diagram of a key management device according to an embodiment of the present invention is shown. The key management device 300 can be applied to a first cryptographic machine and specifically can include the following modules:

[0113] A first key management module 301, configured to interact with a second cryptographic machine and generate a first key when the number of terminals participating in the network conference changes;

[0114] An information transmission module 302, configured to perform data transmission of the network conference with the cryptographic machines other than the first cryptographic machine in the target cryptographic machine through the first key;

[0115] Wherein, the target cryptographic machine is the cryptographic machine connected by the terminal participating in the network conference, and the first cryptographic machine and the second cryptographic machine are two of the target cryptographic machines.

[0116] Optionally, the first key management module 301 includes:

[0117] A first key negotiation request sub-module, configured to send a key negotiation request to the second cryptographic machine, or receive a key negotiation request sent by the second cryptographic machine;

[0118] The first key generation sub-module is configured to, in response to the key negotiation request, interact with the second cipher machine to generate the first key;

[0119] Wherein, the second cipher machine is pre-determined.

[0120] Optionally, the key management device 300 further includes:

[0121] The second cipher machine determination module is configured to determine the second cipher machine;

[0122] Wherein, the second cipher machine determination module is specifically configured to: randomly select a cipher machine from the cipher machines other than the first cipher machine in the target cipher machines as the second cipher machine;

[0123] Or

[0124] Select the cipher machine connected to the terminal that first participates in the network conference from the cipher machines other than the first cipher machine in the target cipher machines as the second cipher machine.

[0125] Optionally, the first key management module 301 includes:

[0126] The second key negotiation request sub-module is configured to receive at least one key negotiation request, wherein the at least one key negotiation request is sent by at least one cipher machine other than the first cipher machine in the target cipher machines;

[0127] The second key generation sub-module is configured to, in response to the key negotiation request, select a cipher machine from the target cipher machines that send the key negotiation request as the second cipher machine, and interact with the second cipher machine to generate the first key.

[0128] Optionally, the first cipher machine is the cipher machine connected to the terminal of the chair party in the network conference.

[0129] Optionally, the key management device 300 further includes:

[0130] The first sending module is configured to send the first key to the third cipher machine; wherein, the third cipher machine is the cipher machine other than the first cipher machine and the second cipher machine in the target cipher machines;

[0131] Or

[0132] The second sending module is configured to send the first key to at least some of the third cipher machines, wherein the first key is sent to the cipher machines other than the at least some of the third cipher machines through the second cipher machine.

[0133] Optionally, the key management device 300 further includes:

[0134] A receiving module, configured to receive a second key sent by the second cryptographic machine or the third cryptographic machine, where the third cryptographic machine is a cryptographic machine other than the first cryptographic machine and the second cryptographic machine in the target cryptographic machines, and the second key is generated by interaction between the second cryptographic machine and the third cryptographic machine when the number of terminals participating in the network conference changes;

[0135] A data transmission module, configured to perform data transmission of the network conference with cryptographic machines other than the first cryptographic machine in the target cryptographic machines through the second key.

[0136] As can be seen from the above, in the embodiment of the present invention, when the number of terminals participating in the network conference changes, two of the cryptographic machines connected to the remaining terminals participating in the network conference will negotiate to generate a new key. Therefore, in the embodiment of the present invention, when the number of terminals participating in the network conference changes, it triggers two of the cryptographic machines connected to the terminals participating in the network conference at this time to perform key negotiation, which has a certain degree of randomness, rather than uniformly generating keys by the key management server, thereby improving the security of the network conference.

[0137] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the related parts, please refer to the partial description of the method embodiment.

[0138] On the other hand, the embodiment of the present invention further provides an electronic device, including a memory, a processor, a bus, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps in the above key management method.

[0139] On the other hand, the embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps in the above key management method.

[0140] Each embodiment in this specification is described in a progressive manner. The key points of each embodiment are the differences from other embodiments. For the same and similar parts between the embodiments, please refer to each other.

[0141] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present invention can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0142] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0143] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal devices to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0144] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal devices, such that a series of operation steps are executed on the computer or other programmable terminal devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal devices provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0145] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the embodiments of the present invention.

[0146] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the said element.

[0147] The above has introduced in detail a key management method, device, electronic device and storage medium provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A key management method, applied to a first cipher machine, characterized in that, The method includes: When the number of terminals participating in the network conference changes, interact with a second cipher machine to generate a first key; Through the first key, perform data transmission of the network conference with cipher machines in the target cipher machine except the first cipher machine; Wherein, the target cipher machine is the cipher machine connected to the terminal participating in the network conference, and the first cipher machine and the second cipher machine are two of the cipher machines in the target cipher machine.

2. The method according to claim 1, wherein The interacting with the second cipher machine to generate a first key includes: The first cipher machine sends a key negotiation request to the second cipher machine, or the first cipher machine receives a key negotiation request sent by the second cipher machine; In response to the key negotiation request, the first cipher machine interacts with the second cipher machine to generate the first key; Wherein, the second cipher machine is pre-determined.

3. The method according to claim 1 or 2, characterized in that, Before interacting with the second cipher machine to generate a first key when the number of terminals participating in the network conference changes, the method includes: Determine the second cipher machine; Wherein, the determining the second cipher machine includes: Randomly select a cipher machine from the cipher machines in the target cipher machine except the first cipher machine as the second cipher machine; Or Select the cipher machine connected to the terminal that first participates in the network conference from the cipher machines in the target cipher machine except the first cipher machine as the second cipher machine.

4. The method according to claim 1, characterized in that, The interacting with the second cipher machine to generate a first key includes: The first cipher machine receives at least one key negotiation request, where the at least one key negotiation request is sent by at least one cipher machine in the target cipher machine except the first cipher machine; In response to the key negotiation request, the first cipher machine selects a cipher machine from the target cipher machines that send the key negotiation request as the second cipher machine, and interacts with the second cipher machine to generate the first key.

5. The method according to claim 1 or 2 or 4, characterized in that, The first cipher machine is the cipher machine connected to the terminal of the chair party in the network conference.

6. The method according to claim 1 or 2 or 4, characterized in that Before performing data transmission of the network conference with cipher machines in the target cipher machine except the first cipher machine through the first key, the method further includes: The first cipher machine sends the first key to a third cipher machine, where the third cipher machine is the cipher machine in the target cipher machine except the first cipher machine and the second cipher machine; Or The first cipher machine sends the first key to at least some of the third cipher machines, and the first key is sent to the third cipher machines except the at least some cipher machines through the second cipher machine.

7. The method according to claim 1 or 2 or 4, characterized in that, The method further includes: The first cipher machine receives a second key sent by the second cipher machine or the third cipher machine, where the third cipher machine is a cipher machine in the target cipher machines other than the first cipher machine and the second cipher machine, and the second key is generated by the interaction between the second cipher machine and the third cipher machine when the number of terminals participating in the network conference changes; The first cipher machine performs data transmission of the network conference with cipher machines in the target cipher machines other than the first cipher machine through the second key.

8. A key management device is applied to a first cipher machine, characterized in that, The device includes: A first key management module, configured to interact with a second cipher machine to generate a first key when the number of terminals participating in the network conference changes; An information transmission module, configured to perform data transmission of the network conference with cipher machines in the target cipher machines other than the first cipher machine through the first key; where the target cipher machine is a cipher machine connected to the terminal participating in the network conference, and the first cipher machine and the second cipher machine are two of the target cipher machines.

9. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements the steps in the key management method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The stored computer program causes the processor to execute the key management method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Key negotiation method, terminal and gateway in Mesh network

    CN109756324A

  • Group chat construction method, group message sending method, group message receiving method and system

    CN109962924A