Mechanism, method and device for generating a consistent encryption label based on a synchronous state machine
By negotiating the synchronous state machine to generate a consistent encryption tag on the blockchain, the security and communication overhead of the symmetric cryptographic system in key distribution and management is solved, the security of communication and message integrity are achieved, and the key negotiation process is reduced.
Patent Information
- Application Number
- CN202111269007.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-29
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2041-10-29
AI Technical Summary
The existing symmetric cryptographic system has security and communication overhead problems in key distribution and management, and it is difficult to ensure the confidentiality, integrity and immutability of communication.
By negotiating the initial state and algorithm of the synchronization state machine based on blockchain technology, a consistent encryption tag is generated, and a time synchronization protocol is used to drive state transitions, an encryption tag is generated as a communication key, and the integrity and immutability of messages are ensured through the state machine.
It reduces the overhead of key negotiation, ensures the security of communication and the integrity of messages, prevents tampering and forgery, and reduces the overhead of encryption and decryption during communication.
Smart Images

Figure CN114139172B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer network information security, and particularly relates to a mechanism method and device for generating a consistent encryption tag based on a synchronous state machine. Background Art
[0002] In modern cryptography, ensuring information security mainly considers five aspects, namely the confidentiality, integrity, availability, authenticity, and non-repudiation of information and information systems. Confidentiality can be achieved by transforming plaintext into ciphertext through an encryption algorithm to implement access control; integrity is ensured through a digest algorithm to prevent information from being tampered with; authenticity can be simply divided into entity authentication and message authentication.
[0003] Cryptography mainly includes two major parts, namely cryptography and cryptanalysis. In cryptography, according to the strategy of using keys, it can be divided into symmetric cryptosystems and asymmetric cryptosystems. Cryptanalysis requires that the design and use of a cryptographic system must comply with Kerckhoff's principle, which requires the public disclosure of algorithms and ensures the security of data information based on the confidentiality of keys.
[0004] Compared with asymmetric cryptosystems, symmetric cryptosystems have the following major advantages: fast encryption speed, good security, and being based on standardization. They are usually used for secure transmission and encrypted storage. However, they also have some drawbacks. The most important one is how to securely distribute the key to the required entities, organizations, or individuals. At the same time, it is very difficult for symmetric cryptosystems to manage passwords, ensure the integrity of messages, and provide non-repudiation. On the other hand, asymmetric cryptosystems can better solve key distribution and management, and support digital signatures, making messages tamper-proof and non-repudiable, ensuring the integrity of messages. In an asymmetric cryptosystem, the key used for encryption and the key used for decryption are not the same. The public key is made public, and the private key is kept by oneself. The public key is used for encryption and the private key for decryption, and the private key is used for signing and the public key for authentication. However, the operation speed of asymmetric cryptosystems is generally much slower than that of symmetric cryptosystems. Therefore, modern communication generally uses an asymmetric cryptosystem protocol to generate a symmetric key, and then the two communicating parties use the symmetric key for communication.
[0005] With the improvement of computer computing power, previously designed encryption algorithms all face a certain risk of being cracked. Communicating with the same symmetric key for a long time may lead to an attacker cracking the used key, thereby causing information insecurity. The best encryption method is to adopt the "one-time pad" (One-Time Password, OTP) method. However, frequently changing keys will bring a very large additional communication overhead, which is basically infeasible in practice.
[0006] A state machine is an abstraction of the operating rules of real-world things. It is a mathematical model that can be used to design algorithms. The state machine receives a series of inputs and, through internal processing, causes the system state to migrate and generates certain outputs. State machines can be divided into two categories. If the output is only related to the state and has nothing to do with the input, then this state machine is a Moore state machine; if the output is related not only to the state but also to the input, then this state machine is a Mealy state machine. A state machine system can be described by a directed graph, where the vertices of the directed graph are the states of the state machine system, and the edges of the directed graph are the inputs required for the state machine system to migrate from one state to another and the generated outputs.
[0007] The so-called "state" is a position where the state machine system is located. At this time, the system is stable and waits for input for state transition. State transition occurs when the state waited for by the state machine system is satisfied or the waited event has occurred, and a series of actions are triggered thereafter. According to the number of states of the state machine, state machines can be divided into finite state machines (FSM) and non-finite state machines.
[0008] A state machine system contains a set of states, and there is one and only one starting state of the state machine system, which is also denoted as the initial state. At the same time, the state machine system also contains a set of input symbol sets, an input symbol set, and a transition function for transitioning from the current state to the next state. When the system starts, it is in the initial state. When the system receives a certain set of inputs, it will transition to the next state.
[0009] Blockchain technology is essentially a decentralized database, but it is different from a distributed database. It realizes a jointly maintained distributed ledger through decentralization and de-trust. By executing the process of negotiating the initial state of the state machine on the blockchain, the synchronization of the state machine and the immutability of messages can be guaranteed. Summary of the Invention
[0010] The present invention aims to solve at least one of the technical problems in the related art to some extent.
[0011] To this end, an object of the present invention is to propose a mechanism method for generating a consistent encryption tag based on a synchronous state machine. This method stores the public information of both communication parties using blockchain technology, negotiates information such as the initial state of the state machine and the algorithms used. The state machine triggers state transitions over time and generates tags. The tags can be used as keys for a period of time and are continuously updated as the state of the state machine changes. Using the tags can ensure the security, confidentiality, non-forgery, and non-tampering of the messages of both communication parties.
[0012] Another object of the present invention is to propose a mechanism device for generating a consistent encryption tag based on a synchronous state machine.
[0013] To achieve the above object, on the one hand, the present invention proposes a mechanism method for generating a consistent encryption tag based on a synchronous state machine, including the following steps: determining the two entity parties to communicate in the communication system, generating respective public and private keys based on the two entity parties; respectively storing the identification information and public key information of the two entity parties into the blockchain; querying the information of the communication peer from the blockchain, and determining the master-slave relationship according to the size relationship of the identification information; negotiating and determining the synchronous state machine information based on the master-slave relationship, the two entity parties perform time synchronization through the time synchronization protocol, and start running the synchronous state machine; the synchronous state machine uses time as an input, triggers a state transition, and generates an encryption tag as the key for communication between the two entity parties or an immutable proof to realize the communication between the two entity parties.
[0014] In the mechanism method for generating a consistent encryption tag based on a synchronous state machine according to an embodiment of the present invention, by determining the two entity parties to communicate in the communication system, generating respective public and private keys based on the two entity parties; respectively storing the identification information and public key information of the two entity parties into the blockchain; querying the information of the communication peer from the blockchain, and determining the master-slave relationship according to the size relationship of the identification information; negotiating and determining the synchronous state machine information based on the master-slave relationship, the two entity parties perform time synchronization through the time synchronization protocol, and start running the synchronous state machine; the synchronous state machine uses time as an input, triggers a state transition, and generates an encryption tag as the key for communication between the two entity parties or an immutable proof to realize the communication between the two entity parties. The present invention can ensure the integrity of messages during communication, no tampering and forgery, and ensure the security of communication through the state machine.
[0015] In addition, the mechanism method for generating a consistent encryption tag based on a synchronous state machine according to the above embodiment of the present invention may further have the following additional technical features:
[0016] Further, in an embodiment of the present invention, the two entity parties to communicate include: nodes or a set of nodes, and all nodes in the set of nodes share the tag generated by the same synchronous state machine.
[0017] Further, in an embodiment of the present invention, generating respective public and private keys based on the two entity parties includes: using a public key infrastructure for the generation and selection of the public and private keys, wherein each entity in the two entity parties has a pair of public and private keys, the public key is used for encryption and the private key is used for decryption, and the private key is used for signing and the public key is used for verification.
[0018] Further, in an embodiment of the present invention, storing the identification information and public key information of each of the two entities in the blockchain respectively includes: each of the two entities serves as a node in the blockchain, and through a consensus contract, completes the verification and block storage of the information to be stored on the chain.
[0019] Further, in an embodiment of the present invention, determining the master-slave relationship according to the size relationship of the identification information includes: negotiating and synchronizing the initial state and other information of the state machine before communication, one of the two entities determines, and the other confirms whether to accept. The entity with the larger identification is the master party, and the entity with the smaller identification is the slave party.
[0020] Further, in an embodiment of the present invention, negotiating and determining the synchronous state machine information based on the master-slave relationship, the two entities perform time synchronization through a time synchronization protocol and start running the state machine, including: the master entity among the two entities to be communicated sends an Init message to start negotiating the synchronous state machine information. The Init message carries the algorithm for generating tags and the tag length range of the master entity. The slave entity determines the synchronous state machine information used by the synchronous state machine; the synchronous state machine information includes: initial state length, initial state, state transition algorithm, state transition time interval, tag length, effective time, and expiration time information; the two entities to be communicated synchronize to the same clock. After time synchronization, the two entities to be communicated make the synchronous state machine take effect and be used within a specified time.
[0021] Further, in an embodiment of the present invention, for the tag generated by using the synchronous state machine, the usage method of the tag includes: the tag is used as a key after being encrypted. The two entities each have the same tag as a symmetric key, and the two entities use the symmetric key for encryption; the tag is used as a mark of the message. After receiving the message with the tag, the peer entity believes that the message has not been forged or tampered with, and the tag is used as a guarantee of integrity and signature.
[0022] Further, in an embodiment of the present invention, the synchronous state machine includes: state, tag, algorithm box, trigger, state transition, and tag generation.
[0023] Further, in an embodiment of the present invention, it further includes: defining an initial state, a state cycle period, a tag cycle period, a state sequence, a tag sequence, a serial number, a sequence length, a state transition time interval, a tag validity period, and a state machine validity period; and, the synchronous state machine adapts to the requirements of generating tags and satisfies determinism, diversity, and algorithm inverse derivation complexity.
[0024] To achieve the above object, on the other hand, the present invention proposes a mechanism device for generating a consistent encryption tag based on a synchronization state machine, including: a generation module for determining the two entity parties to be communicated in a communication system and generating respective public and private keys based on the two entity parties; a storage module for respectively storing the identification information and public key information of the two entity parties into a blockchain; a determination module for querying the information of the communication peer from the blockchain and determining the master-slave relationship according to the size relationship of the identification information; a negotiation module for negotiating and determining the synchronization state machine information based on the master-slave relationship, the two entity parties performing time synchronization through a time synchronization protocol and starting to run the synchronization state machine; and a communication module for using time as an input by the synchronization state machine to trigger a state transition and generate an encryption tag as the key or an immutable proof for the communication between the two entity parties, so as to realize the communication between the two entity parties.
[0025] In the mechanism device for generating a consistent encryption tag based on a synchronization state machine according to an embodiment of the present invention, by using blockchain technology, the public information of the two communication parties is stored on the blockchain for all communication entities to query; secondly, according to the information of the peer entity queried, the present end and the peer communicate and negotiate to determine the initial state, initial state length, state transition algorithm, state transition time interval, tag length, effective time, and expiration time to be used; then, the present end and the peer perform time synchronization and respectively run the state machine; finally, the present end and the peer will generate a consistent tag, and the tag can be used as the key within the state transition time interval.
[0026] The beneficial effects of the present invention are as follows:
[0027] 1) By negotiating the synchronization state machine between the two communication parties to generate a consistent tag, the present invention reduces the overhead for negotiating the key before communication.
[0028] 2) By using the state machine, the present invention can ensure the integrity of the message during communication and prevent tampering and forgery, thus ensuring the security of communication.
[0029] 3) When using the tag as the proof of message integrity and prevention of forgery and tampering, the present invention only needs to compare whether the tags are consistent to verify the tag, further reducing the encryption and decryption overhead during communication.
[0030] The additional aspects and advantages of the present invention will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The above and / or additional aspects and advantages of the present invention will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where:
[0032] Figure 1Flowchart of the mechanism method for generating a consistent encryption label based on a synchronous state machine according to an embodiment of the present invention;
[0033] Figure 2 Schematic diagram of the state machine system according to an embodiment of the present invention;
[0034] Figure 3 Schematic diagram of time-driven state transition and label validity period according to an embodiment of the present invention;
[0035] Figure 4 Schematic diagram of the label validity period with shared time slices added according to an embodiment of the present invention;
[0036] Figure 5 Schematic diagram of the corrected shared time slices and label validity period according to an embodiment of the present invention;
[0037] Figure 6 Topological schematic diagram of the mechanism for generating a consistent encryption label based on a synchronous state machine according to an embodiment of the present invention;
[0038] Figure 7 Schematic diagram of the Init message format of the mechanism method for generating a consistent encryption label based on a synchronous state machine according to an embodiment of the present invention;
[0039] Figure 8 Schematic diagram of the Hello message format of the mechanism method for generating a consistent encryption label based on a synchronous state machine according to an embodiment of the present invention;
[0040] Figure 9 Schematic diagram of the ACK message format of the mechanism method for generating a consistent encryption label based on a synchronous state machine according to an embodiment of the present invention;
[0041] Figure 10 Schematic diagram of the device structure of the mechanism for generating a consistent encryption label based on a synchronous state machine according to an embodiment of the present invention. Detailed implementation manners
[0042] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions from beginning to end. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the present invention, but should not be construed as limiting the present invention.
[0043] The present invention discloses a mechanism for generating a consistent encryption label based on a synchronous state machine. This label can be used as a key for a period of time and eliminates the process of negotiating symmetric keys multiple times.
[0044] This mechanism includes how to negotiate the initial state through the blockchain and generate the tag algorithm using the state machine, the working principle of the state machine, the conditions for state generation and migration, and the generation of tags.
[0045] The following describes a mechanism method and apparatus for generating a consistent encryption tag based on a synchronous state machine according to an embodiment of the present invention. First, the mechanism method for generating a consistent encryption tag based on a synchronous state machine according to an embodiment of the present invention will be described with reference to the accompanying drawings.
[0046] Figure 1 It is a flowchart of a mechanism method for generating a consistent encryption tag based on a synchronous state machine according to an embodiment of the present invention.
[0047] This mechanism can be simply illustrated as follows: 1) Entity A and Entity B perform time synchronization through the NTP protocol; 2) Entity A and Entity B negotiate the initial state through the blockchain; 3) Entity A and Entity B negotiate the tag generation algorithm through the blockchain; 4) Entity A and Entity B run the state machine, migrate the state over time, and generate a consistent encryption tag; 5) Entity A and Entity B use the tag for communication.
[0048] As Figure 1 shown, the mechanism method for generating a consistent encryption tag based on a synchronous state machine includes the following steps:
[0049] Step S101, determine the two entities to communicate in the communication system, and generate their respective public and private keys based on the two entities.
[0050] It can be understood that the entities at both ends of the communication system can be physically reachable and can communicate.
[0051] Specifically, the two entities or subsystems to communicate in the communication system (for the sake of convenience of narration, we will uniformly refer to them as entities below) respectively use the public key cryptosystem to generate asymmetric keys, that is, public keys and private keys. The private key is used for signing, the public key is used for verification, the public key is used for encryption, and the private key is used for decryption. That is, the present invention uses a public key infrastructure to generate and select public and private keys. Each entity in the network has a pair of public and private keys. The public key and its own information need to be published, and the private key needs to be saved by itself. The public key encrypts and the private key decrypts, and the private key signs and the public key verifies. Ensure the encryption security of information transmission.
[0052] As an example, the exemplary topology of the communication system adopted by the present invention is as Figure 6 shown. The entities to communicate in the communication system can be a node or a set of nodes. All nodes in the set of nodes share the tag generated by the same state machine.
[0053] Step S102, store the respective identification information and public key information of the two entities into the blockchain.
[0054] Specifically, entities in the communication system respectively publish their own identification information and public key information to the blockchain. The present invention uses blockchain technology to ensure the immutability and trustworthy viewing of information. Each entity acts as a node in the blockchain, and through a consensus contract, completes the verification of the information to be uploaded to the blockchain and packages it into blocks for storage.
[0055] Step S103: Query the information of the communication peer from the blockchain, and determine the master-slave relationship based on the size relationship of the identification information.
[0056] Specifically, two entities to communicate in the communication system query the information of the communication peer from the blockchain, and determine the master-slave relationship based on the size relationship of the identification information. It is stipulated that the party with the larger identification information is the master, and the party with the smaller identification information is the slave.
[0057] It can be understood that two entities in the communication system need to negotiate the initial state of the state machine and other information before communication, which is completed by one of the entities, and the other entity only confirms whether to accept it. Therefore, it is necessary to determine which entity is the master and which entity is the slave. Here, we adopt a common method in computer networks, that is, the end with the larger identifier is the master, and the end with the smaller identifier is the slave. The identification information can uniquely identify an entity in the communication system, and here we only stipulate that its length is 32 bits.
[0058] Step S104: Negotiate and determine the synchronous state machine information based on the master-slave relationship. The two entities synchronize time through the time synchronization protocol and start running the synchronous state machine.
[0059] It can be understood that after determining the master-slave relationship, the master initiates the negotiation of the state machine information to the slave. The slave determines the initial state length, initial state, state transition algorithm, state transition time interval, tag length, effective time, expiration time information of the state machine used during communication, and the master confirms it. This communication process needs to be protected by a public key cryptosystem.
[0060] After determining the state machine information, the two entities to communicate in the communication system synchronize time through the time synchronization protocol and start running the state machine.
[0061] Furthermore, the master entity in the communication system sends an Init message to start negotiating the state machine information. The message carries the algorithm for generating tags (i.e., state transitions) supported by the master entity and the tag length range, and its message format is as Figure 7 shown. The slave entity determines the initial state length, initial state, state transition algorithm, state transition time interval, tag length, effective time, expiration time information of the state machine used for this state machine. These information are encapsulated into a Hello message, asFigure 8 As shown, it is sent from the entity slave to the entity master. When the entity master receives the Hello message, it will reply with an Ack message, as Figure 9 shown.
[0062] It can be understood that in the communication system, the two communication parties synchronize the time to the same clock. Only after the time is synchronized can the two communication parties make the state machine take effect and be used at the specified time.
[0063] Step S105, the synchronization state machine takes the time as the input, triggers the state transition, and generates an encryption tag as the key for the communication between the two entities or an immutable proof to realize the communication between the two entities.
[0064] It can be understood that the realization of the communication between the two entities in the present invention is how to use the tag generated by the synchronization state machine. There are two ways to use this tag. Specifically as follows:
[0065] Way 1: The tag is used as a key. The tag has been encrypted, and the two entities in the communication system each have the same tag. Therefore, the tag can be used as a symmetric key, and the two parties use this key for encryption. The tag changes with time, eliminating the need for synchronization before each communication.
[0066] Way 2: The tag is used as a mark for the message. Only when the peer entity receives the message with this tag can it be considered that the message has not been forged or tampered with, that is, the tag is used as a guarantee of integrity and signature.
[0067] The following is a further explanation of the embodiments of the present invention through exemplary embodiments described with reference to the accompanying drawings, but not limited thereto.
[0068] The state machine system (State Machine, SM) of the present invention is as Figure 2 shown, where
[0069] State: S n and S n+1 in the figure represent states, which represent the current state and the next state respectively.
[0070] Tag: Tag n in the figure represents the tag, which is the current tag generated by the current state S n
[0071] Algorithm Box: A-Box in the figure represents the algorithm box, which is used for state transition and tag generation. It takes the current state as the input and the next state and the current tag as the output. The algorithm box consists of two parts. One is the transfer function Transit(), S n+1 =Transit(S n ); Second, the function Generate() for generating tags, Tag n = Generate(S n ).
[0072] Trigger: In the figure, Trigger represents the trigger, which is used to trigger the state transition.
[0073] Transition: In the figure, Transition represents the state transition, which is used to represent the transition process from the current state to the next state.
[0074] Generation: In the figure, Generation represents the tag generation, which is used to represent the process of calculating the current tag from the current state.
[0075] The above are the necessary components of the state machine. To introduce how the state machine works and analyze its properties, we also need to define the following concepts:
[0076] Initial State: That is, S0.
[0077] Cycle Period of States: The minimum period of the state cycle of the state machine.
[0078] Cycle Period of Tags: The minimum period of the tag cycle of the state machine.
[0079] State Sequence: The sequence of all states experienced during the operation of the state machine, S0, …, S N .
[0080] Tag Sequence: The sequence of all tags experienced during the operation of the state machine, Tag0, …, Tag N .
[0081] Sequence Number: The position serial number of a certain state (or tag) in the sequence, 0, …, N.
[0082] Sequence Length: The maximum serial number N of the state (or tag), that is, the total number of states (or tags) minus 1.
[0083] Transition Interval: The interval time between two triggers of the trigger.
[0084] Tag Lifecycle: The valid time of a tag when used for verification.
[0085] State Machine Lifecycle: The time from when a state machine starts to be enabled until the entire state sequence is used up. We call the situation where the state sequence is used up "the state machine expires".
[0086] In order to make the state machine meet the requirements for generating tags, the following several properties also need to be satisfied:
[0087] Determinism: When the algorithm, initial state, and sequence length of the state machine are determined, its entire state sequence and tag sequence are also uniquely determined accordingly.
[0088] Diversity: When the algorithm of the state machine is determined, by setting different initial states, many different tag sequences can be generated.
[0089] Complexity of algorithm reverse deduction: When obtaining a tag or a short tag sequence, the probability of reverse deducing the current state or the next tag is not much better than brute force cracking.
[0090] Among them, the A-Box determines the data structures of states and tags, the specific mode of the state machine implementation, and also determines its security, complexity, etc. Tag generation algorithms can be divided into two categories: pseudo-random number algorithms and hash chain algorithms.
[0091] In the pseudo-random number generation algorithm, usually an initial number or string is used as the "seed", which corresponds to the initial state of the state machine. Using the seed, through a certain algorithm, a pseudo-random number sequence is generated as the tag sequence. The basic design goals of the pseudo-random number generation algorithm are mainly long period, good distribution, etc., and little or no consideration is given to security factors. For example, whether the seed can be reverse deduced from one or several current random numbers, or the next random number can be predicted.
[0092] In the tag algorithm based on the hash chain, there is an encryption end and a verification end. The encryption end generates an initial W, and then uses a certain hash algorithm H() to perform iterative operations on W to obtain a string sequence, H 0 (W), H 1 (W),…, H N (W), where H n (W) represents performing n times of iterative operations of H() on W, and H 0 (W)=W. We define the state sequence {S} as the reverse order of the hash chain, that is, S n = H N-n (W). For example, the initial state S0 = H N (W), the final state SN = H 0 (W)=W, so the transfer function Transit() = H -1 (). Different from the pseudo-random number generation algorithm mentioned in the previous subsection, in a hash chain, the tag is the state itself, that is, the output of Generate() is the same as the input, Tag n =S n . The hash chain has high security and can well prevent reverse inference and prediction - not only can attackers not reverse infer or predict, but even the verification end cannot. The disadvantage of the hash chain is that before using the tag, the encryption end needs to calculate all the tag sequences and send the last one of the sequences to the verification end as the initial state. At the same time, the encryption end needs to store the entire tag sequence - although it can be deleted after each tag is used, the storage cost is indeed not negligible. In a communication system, there are multiple communicable entities. A secret state machine SM12 is shared between each ordered entity pair (E1, E2). E1 uses this state machine to generate a series of tags (the state machine changes over time, and the tags also change accordingly). When E1 sends a message, it can add the tag to the message sent from E1 to E2. E2 also uses the same state machine SM12 to generate tags. E2 checks all messages sent to E2 and originating from E1 to verify whether the tags in these messages are correct. If they are correct, it is considered that the message is indeed sent by E1; otherwise, it is considered that the message has been tampered with or forged, and the message is processed according to the policy. If E1 and E2 keep the state machine synchronized, the tag verification can be correctly implemented, thus realizing the secure communication between E1 and E2.
[0093] After the state machine is enabled, E1 uses the initial state S0 to transfer to state S1 through the algorithm box A-Box, and at the same time generates tag Tag1. During the subsequent state transition time interval (Transition Interval), E1 always uses the same tag (Tag1) and adds it to the message sent from E1 to E2 until after the time of Transition Interval, E1 transfers from state S1 to S2 and uses tag Tag2. This process repeats, experiencing the state sequence S1~S N and the tag sequence Tag1~Tag N , where Tag1~Tag NThey are successively used as tags and added by E1 to the message from E1 to E2. Similarly, E2 also calculates a tag sequence using the same state machine to verify the tags in the message. If E1 and E2 can ensure the synchronization of the state machines, that is, ensure the synchronization of the tags, correct tag verification can be carried out. Each state machine has an enabling time and an expiration time. After the expiration time arrives, the current state machine is deactivated; if a new state machine is available, the new state machine is activated to perform the same tag verification process.
[0094] The state transition of the state machine is time-driven. When a communication entity generates its own state machine, it also stipulates the state transition time interval of the state machine. The entities at both ends of the communication must abide by the stipulated state transition time interval to maintain the time state synchronization between the tag adding end and the verification end, so as to correctly verify the tags. The time-driven state transition and tag validity period are as Figure 3 shown.
[0095] Although the time synchronization between entities can be achieved through the time synchronization protocol, a small time error between entities is inevitable. Therefore, a shared time slice should be set on the message receiving end. Within this time slice, both the just-expired tags and the new tags are considered valid. The calculation method of the length of this time slice is as follows:
[0096] Assume that the maximum time error in the internal communication of the entity is te. We set a shared time slice (Shared Time Slice) with a length of 2te between two adjacent tags. Within this shared time slice, both the previous and the next tags are valid at the verification end. The tag validity period with the added shared time slice is shown in Figure 4.
[0097] In addition to the time error, the transmission delay of the message in the communication system should also be considered. Let the minimum delay be tdmin and the maximum delay be tdmax. Then the expiration time of the validity period of Tag n should be extended backward by tdmax, and the start time of the validity period of Tag n+1 should be delayed backward by tdmin. The shared time slice and tag validity period corrected according to the transmission delay are as Figure 5 shown.
[0098] The expiration time of the validity period of Tag n is extended backward by te + tdmax, and the start time of the validity period of Tag n+1 is extended forward by te - tdmin. Parameters such as te, tdmin, tdmax, the length of the shared time slice, and the validity period of the tag are determined by the verification end according to the actual communication system environment. Under the combined effect of these two "extensions", actually the validity period of a tag is:
[0099] Lifecycle = Transition Interval + 2te –tdmin + tdmax
[0100] Since communication works in duplex mode, it is also possible to verify the message tag at the tag addition end. Therefore, a shared time slice is also used at the tag addition end.
[0101] Then for Figure 7 description, Figure 7 FIG. shows the Init message format diagram of the mechanism method for generating a consistent encrypted tag based on a synchronous state machine in an embodiment of the present invention, as Figure 7 shown:
[0102] Packet Type === 1, that is, the Init message sent by the master party
[0103] Packet Length, packet length
[0104] Algorithm Num, the last field is the algorithms supported by each master entity, and this field represents the number thereof.
[0105] Sequence, sequence number, used to determine the master and slave parties through the sequence number (the sequence number of the master party will be used)
[0106] State Machine Identity, state machine ID
[0107] Minimum Tag Len, the shortest tag length supported by the master entity
[0108] Maximum Tag Len, the longest tag length supported by the master entity
[0109] Algorithm List, the state transition algorithms supported by the master entity
[0110] Then for Figure 8 description, Figure 8 FIG. shows the Hello message format of the mechanism method for generating a consistent encrypted tag based on a synchronous state machine in an embodiment of the present invention, as Figure 8 shown:
[0111] Packet Type === 2, that is, the Hello message sent by the slave party.
[0112] Packet Length, packet length
[0113] Trans Interval, state transition time interval, unit is seconds
[0114] Sequence, the serial number, which determines the master and slave parties through the serial number (the serial number of the master party will be used).
[0115] State Machine Identity, the state machine ID
[0116] Tag Len, the tag length determined by the slave party
[0117] Initial State Length, the initial state length of the state machine determined by the slave party.
[0118] Initial State, the initial state of the state machine
[0119] Algorithm, the state transition algorithm
[0120] Effecting Time, the effective time of the state machine
[0121] Expire Time, the expiration time of the state machine
[0122] Next, for Figure 9 description, Figure 9 It is the ACK message format of the mechanism method for generating a consistent encryption tag based on a synchronous state machine in an embodiment of the present invention, as Figure 9 shown:
[0123] Packet Type === 3, that is, the ACK message sent by the master party.
[0124] Packet Length, the packet length
[0125] ACK OR RACK, ACK is all 0, and RACK is non-0. ACK represents that the entity master party agrees to the selection of the entity slave party, and RACK represents that the entity master party does not agree to the selection of the entity slave party and needs to select again.
[0126] Sequence, the serial number, which determines the master and slave parties through the serial number (the serial number of the master party will be used).
[0127] State Machine Identity, the state machine ID.
[0128] The mechanism method for generating a consistent encryption tag based on a synchronization state machine according to an embodiment of the present invention determines the two entities to communicate in a communication system, generates respective public and private keys based on the two entities; stores the identification information and public key information of the two entities into a blockchain respectively; queries the information of the communication peer from the blockchain, and determines the master-slave relationship based on the size relationship of the identification information; negotiates and determines the synchronization state machine information based on the master-slave relationship, the two entities perform time synchronization through a time synchronization protocol, and start running the synchronization state machine; the synchronization state machine uses time as an input, triggers a state transition, and generates an encryption tag as the key for communication between the two entities or an immutable proof to implement the communication between the two entities. The present invention can ensure the integrity of messages during communication, no tampering and forgery, and ensure the security of communication through a state machine.
[0129] Next, a mechanism device for generating a consistent encryption tag based on a synchronization state machine according to an embodiment of the present invention will be described with reference to the accompanying drawings.
[0130] Figure 10 It is a schematic structural diagram of a mechanism device for generating a consistent encryption tag based on a synchronization state machine according to an embodiment of the present invention.
[0131] As Figure 10 shown, the mechanism device 10 for generating a consistent encryption tag based on a synchronization state machine includes: a generation module 100, a storage module 200, a determination module 300, a negotiation module 400, and a communication module 500.
[0132] The generation module 100 is used to determine the two entities to communicate in a communication system and generate respective public and private keys based on the two entities;
[0133] The storage module 200 is used to store the identification information and public key information of the two entities into a blockchain respectively;
[0134] The determination module 300 is used to query the information of the communication peer from the blockchain and determine the master-slave relationship based on the size relationship of the identification information;
[0135] The negotiation module 400 is used to negotiate and determine the synchronization state machine information based on the master-slave relationship, the two entities perform time synchronization through a time synchronization protocol, and start running the synchronization state machine;
[0136] The communication module 500 is used for the synchronization state machine to use time as an input, trigger a state transition, and generate an encryption tag as the key for communication between the two entities or an immutable proof to implement the communication between the two entities.
[0137] It should be noted that the foregoing explanation of the embodiment of the mechanism method for generating a consistent encryption tag based on a synchronization state machine is also applicable to this device, and will not be repeated here.
[0138] The mechanism device for generating a consistent encryption tag based on a synchronous state machine proposed according to an embodiment of the present invention uses blockchain technology to store the public information of both parties to be communicated on the blockchain for all communication entities to query. Secondly, according to the information of the peer entity queried, the local and peer communicate and negotiate to determine the initial state, initial state length, state transition algorithm, state transition time interval, tag length, effective time, and expiration time to be used. Then, the local and peer perform time synchronization and each runs a state machine. Finally, the local and peer will generate a consistent tag, which can be used as a key within the state transition time interval.
[0139] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, "a plurality" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0140] In the present invention, unless otherwise clearly specified and defined, terms such as "installed", "connected", "connected to", "fixed" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or integrated; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the internal connection of two components or the interaction relationship between two components, unless otherwise clearly defined. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0141] In the present invention, unless otherwise clearly specified and defined, the first feature being "on" or "under" the second feature can be that the first and second features are in direct contact, or the first and second features are indirectly in contact through an intermediate medium. Moreover, the first feature being "above", "over", and "on top of" the second feature can be that the first feature is directly above or obliquely above the second feature, or merely indicates that the first feature is at a higher horizontal height than the second feature. The first feature being "under", "below", and "beneath" the second feature can be that the first feature is directly below or obliquely below the second feature, or merely indicates that the first feature is at a lower horizontal height than the second feature.
[0142] In the description of this specification, the descriptions referring to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc., mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0143] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A mechanism method for generating a consistent encryption tag based on a synchronous state machine, characterized in that, Including the following steps: Determine the two entities to communicate in the communication system, and generate respective public and private keys based on the two entities; Respectively store the identification information and public key information of the two entities into the blockchain; Query the information of the communication peer from the blockchain, and determine the master-slave relationship based on the size relationship of the identification information; Negotiate and determine the synchronous state machine information based on the master-slave relationship. The two entities perform time synchronization through the time synchronization protocol and start running the synchronous state machine; The synchronous state machine uses time as the input, triggers state transitions, and generates an encrypted tag as the key for communication between the two entities or an immutable proof to realize the communication between the two entities.
2. The method for generating a consistent encryption tag based on a synchronous state machine according to claim 1, wherein The two entities to communicate include: Nodes or a set of nodes, and all nodes in the set of nodes share the tag generated by the same synchronous state machine.
3. The mechanism method for generating a consistent encryption tag based on a synchronous state machine according to claim 1, characterized in that, The generating of respective public and private keys based on the two entities includes: Use the public key infrastructure to select the generation of the public and private keys. Among them, each entity in the two entities has a pair of public and private keys. The public key is used for encryption and the private key is used for decryption. The private key is used for signing and the public key is used for verification.
4. The method for generating a consistent encryption tag based on a synchronous state machine according to claim 1, wherein The respectively storing the identification information and public key information of the two entities into the blockchain includes: Each entity in the two entities acts as a node in the blockchain, and through the consensus contract, completes the verification of the information to be uploaded to the chain and packs it into blocks for storage.
5. The method for generating a consistent encryption label based on a synchronous state machine according to claim 1, characterized in that, The determining of the master-slave relationship based on the size relationship of the identification information includes: Negotiate the initial state and other information of the synchronous state machine before communication. One of the two entities determines, and the other entity confirms whether to accept. The entity with the larger identification is the master party, and the entity with the smaller identification is the slave party.
6. The method for generating a consistent encryption tag based on a synchronous state machine according to claim 1, wherein The negotiating and determining the synchronous state machine information based on the master-slave relationship, and the two entities perform time synchronization through the time synchronization protocol and start running the state machine includes: The master entity among the two entities to communicate sends an Init message to start negotiating the synchronous state machine information. The Init message carries the algorithm for generating the tag by the master entity and the tag length range. The slave entity determines the synchronous state machine information used by the synchronous state machine. The synchronous state machine information includes: initial state length, initial state, state transition algorithm, state transition time interval, tag length, effective time, and expiration time information; The two entities to communicate synchronize time with the same clock. After time synchronization, the two entities to communicate make the synchronous state machine take effect and be used within a specified time.
7. The method for generating a consistent encryption label based on a synchronous state machine according to claim 1, characterized in that, Using the tag generated by the synchronous state machine, the usage method of the tag includes: The tag is used as a key after being encrypted. The two entities each have the same tag as the symmetric key, and the two entities use the symmetric key for encryption; The tag is used as a mark for the message. After receiving the message with the tag, the peer entity believes that the message has not been forged or tampered with, and uses the tag as a guarantee for integrity and signature.
8. The method for generating a consistent encryption tag based on a synchronous state machine according to claim 1, wherein The synchronous state machine includes: States, tags, algorithm boxes, triggers, state transitions, and tag generation.
9. The method for generating a consistent encryption tag based on a synchronous state machine according to claim 1, wherein It is characterized in that it further includes: defining an initial state, a state cycle period, a label cycle period, a state sequence, a label sequence, a serial number, a sequence length, a state transition time interval, a label validity period, and a state machine validity period; and, The synchronization state machine adapts to the requirements of generating labels and meets the requirements of determinism, diversity, and algorithm reverse inference complexity.
10. A mechanism device for generating a consistent encryption label based on a synchronous state machine, characterized in that, It includes: A generation module, configured to determine the two communicating entity parties of the communication system and generate respective public and private keys based on the two entity parties; A storage module, configured to store the identification information and public key information of the two entity parties into the blockchain respectively; A determination module, configured to query the information of the communication peer from the blockchain and determine the master-slave relationship according to the size relationship of the identification information; A negotiation module, configured to negotiate and determine the synchronization state machine information based on the master-slave relationship, and the two entity parties perform time synchronization through a time synchronization protocol and start running the synchronization state machine; A communication module, configured to use time as an input for the synchronization state machine, trigger a state transition, and generate an encrypted label as the key or non-tamperable proof for the communication between the two entity parties, so as to realize the communication between the two entity parties.
Citation Information
Patent Citations
A communication method between router nodes and a switching method thereof
CN109698792A
Double-agent cross-domain authentication method based on identification password and alliance chain
CN110138560A