A method, apparatus, and electronic device for generating an identifier
The UUID of the trusted terminal is generated and encrypted by the server, and the problem of trusted terminal identification being tampered with or cloned in the zero-trust system is solved, realizing the uniqueness and anti-collision of UUIDs.
Patent Information
- Application Number
- CN202210336701.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-03-31
AI Technical Summary
Under the zero-trust system, trusted terminal identifiers are at risk of being tampered with when generating terminal management platform, and there is a problem of hot cloning causing identification conflicts when generating trusted terminals.
The UUID of the trusted terminal is generated through the server, and the encryption and sharing key mechanism is used to determine whether the UUID has been tampered with or cloned, and the UUID is regenerated to ensure uniqueness.
It realizes that when the UUID of any trusted terminal is tampered with or cloned, the UUID is automatically regenerated to ensure the uniqueness of asset identification of each trusted terminal and prevent identification conflicts.
Smart Images

Figure CN114647856B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of cloud servers, and particularly to an identifier generation method, apparatus, and electronic device. Background Art
[0002] With the development of the zero-trust industry, in the zero-trust system, a trusted terminal needs to have a unique identifier, that is, a trusted terminal identifier. The trusted terminal identifier can be generated either on the terminal management platform or on the trusted terminal. When generating a trusted terminal identifier on the terminal management platform, the trusted terminal identifier needs to be written to the local disk, and there is a risk that the trusted terminal identifier can be tampered with in the way of writing to the disk. When generating a trusted terminal identifier on the trusted terminal, if there is a hot cloning scenario, the same trusted terminal identifier will exist simultaneously. Summary of the Invention
[0003] This application provides an identifier generation method, apparatus, and electronic device, which generate a UUID corresponding to each trusted terminal through a server, do not depend on any attributes of the trusted terminal, and when the UUID corresponding to any trusted terminal is tampered with or cloned, regenerate the UUID to ensure the uniqueness of the UUID, and further make the asset identifiers corresponding to each trusted terminal unique.
[0004] In a first aspect, this application provides an identifier generation method, and the method includes:
[0005] Generate a first target program package, where the first target program package is deployed on a trusted terminal;
[0006] In response to a registration request corresponding to the first target program package, generate a first Universally Unique Identifier (UUID) corresponding to the first target program package, where the first UUID is obtained by encrypting a first shared key in a local database and a second shared key corresponding to the first target data packet;
[0007] Determine whether the first UUID is tampered with and / or determine whether the first UUID is cloned;
[0008] When the first UUID is tampered with and / or cloned, regenerate the UUID corresponding to the first target program package.
[0009] Through the above method, generate UUIDs corresponding to each trusted terminal based on a server, do not depend on any attributes of the trusted terminal, and when the UUID corresponding to any trusted terminal is tampered with or cloned, regenerate the UUID to ensure the uniqueness of the UUID, and further make the asset identifiers corresponding to each trusted terminal unique.
[0010] In a possible design, generating a first Universally Unique Identifier (UUID) corresponding to the first target program package in response to a registration request corresponding to the first target program package includes:
[0011] When receiving a first registration request sent by the first target program package, generating a second UUID, a primary key identifier (PKID), and a third shared key corresponding to the first target program package;
[0012] Sending a first registration response to the first target program package, where the first registration response at least includes the second UUID, the PKID, and a first piece of information signed with the third shared key, and the first piece of information at least includes an exchange key pair generated by the first target program package and a public key;
[0013] When receiving a second registration request sent by the first target program package, decrypting a second piece of information in the second registration request based on the first shared key corresponding to the PKID in the second registration request, where the second piece of information is obtained by encrypting the second UUID and the first piece of information with a second shared key by the first target program package;
[0014] Sending a second registration response to the first target program package, and using the UUID carried in the second registration response as the first UUID, where the UUID carried in the second registration response is obtained by encrypting the second UUID with the first shared key.
[0015] By the above method, generating a corresponding UUID for the target program package in the trusted terminal on the server side and encrypting the UUID helps prevent the UUID from being tampered with.
[0016] In a possible design, determining whether the first UUID is tampered with includes:
[0017] When receiving a third registration request sent by the first target program package, querying for the exchange public key, the local exchange private key, and the first UUID corresponding to the first target program package according to the PKID corresponding to the third registration request;
[0018] Generating a fourth shared key according to the exchange public key corresponding to the first target program package and the local exchange private key, and decrypting the third UUID carried in the third registration request using the fourth shared key;
[0019] When the first UUID is inconsistent with the decrypted third UUID, determining that the first UUID is tampered with.
[0020] Through the above method, it is determined whether the UUID corresponding to the trusted terminal is tampered with according to whether the UUID corresponding to the trusted terminal is consistent with the UUID stored on the server side. Furthermore, it helps to perform the next processing on the UUID corresponding to the trusted terminal, and further makes the asset identifiers corresponding to each trusted terminal unique.
[0021] In a possible design, determining whether the first UUID is cloned includes:
[0022] When receiving the handshake request corresponding to the first target program package, send a first parameter to the first target program package, where the first parameter is bound to the first UUID;
[0023] When receiving the handshake request corresponding to the second target program package, send a second parameter to the second target program package, where the UUID corresponding to the second target program package is consistent with the first UUID, and the difference between the second parameter and the first parameter is a preset value;
[0024] When receiving the first parameter returned by the first target program package, generate a third parameter, where the third parameter is bound to the first UUID;
[0025] When the third parameter is not equal to the first parameter and the third parameter is not equal to the second parameter, determine that the first UUID is cloned.
[0026] Through the above method, it is determined whether the UUID corresponding to the trusted terminal is tampered with, which helps to perform the next processing on the UUID corresponding to the trusted terminal and improves the uniqueness of the trusted terminal identifier.
[0027] In a second aspect, the present application further provides an identifier generation device, and the device includes:
[0028] A generation module, configured to generate a first target program package, where the first target program package is deployed on a trusted terminal;
[0029] A response module, configured to generate a first Universally Unique Identifier (UUID) corresponding to the first target program package in response to a registration request corresponding to the first target program package, where the first UUID is obtained by encrypting a first shared key in a local database and a second shared key corresponding to the first target data packet;
[0030] A determination module, configured to determine whether the first UUID is tampered with and / or determine whether the first UUID is cloned;
[0031] A regeneration module, configured to regenerate the UUID corresponding to the first target program package when the first UUID is tampered with and / or cloned.
[0032] In a possible design, the response module is specifically configured to:
[0033] When receiving a first registration request sent by the first target package, generate a second UUID, a primary key identifier PKID, and a third shared key corresponding to the first target package;
[0034] Send a first registration response to the first target package, where the first registration response at least includes the second UUID, the PKID, and a first piece of information signed with the third shared key, and the first piece of information at least includes an exchange key pair and a public key generated by the first target package;
[0035] When receiving a second registration request sent by the first target package, decrypt the second piece of information in the second registration request based on the first shared key corresponding to the PKID in the second registration request, where the second piece of information is obtained by the first target package encrypting the second UUID and the first piece of information with the second shared key;
[0036] Send a second registration response to the first target package, and use the UUID carried in the second registration response as the first UUID, where the UUID carried in the second registration response is obtained by encrypting the second UUID with the first shared key.
[0037] In a possible design, the determination module is specifically configured to:
[0038] When receiving a third registration request sent by the first target package, query the exchange public key, the local exchange private key, and the first UUID corresponding to the first target package according to the PKID corresponding to the third registration request;
[0039] Generate a fourth shared key according to the exchange public key corresponding to the first target package and the local exchange private key, and decrypt the third UUID carried in the third registration request with the fourth shared key;
[0040] When the first UUID is inconsistent with the decrypted third UUID, determine that the first UUID has been tampered with.
[0041] In a possible design, the determination module is further configured to:
[0042] When receiving a handshake request corresponding to the first target package, send a first parameter to the first target package, where the first parameter is bound to the first UUID;
[0043] When receiving a handshake request corresponding to a second target package, send a second parameter to the second target package, where the UUID corresponding to the second target package is the same as the first UUID, and the difference between the second parameter and the first parameter is a preset value;
[0044] When receiving the first parameter returned by the first target package, generate a third parameter, where the third parameter is bound to the first UUID;
[0045] When the third parameter is not equal to the first parameter and the third parameter is not equal to the second parameter, determine that the first UUID has been cloned.
[0046] In a third aspect, the present application provides an electronic device, including:
[0047] A memory for storing a computer program;
[0048] A processor for implementing the steps of the above-mentioned identity generation method when executing the computer program stored on the memory.
[0049] In a fourth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned identity generation method are implemented.
[0050] Based on the above-mentioned identity generation method, the UUIDs corresponding to each trusted terminal are generated through a terminal management platform, without relying on any attributes of the trusted terminal, and when the UUID corresponding to any trusted terminal is tampered with or cloned, a new UUID is generated to ensure the uniqueness of the UUID, and thus the asset identifiers corresponding to each trusted terminal are unique.
[0051] For the various aspects in the above second to fourth aspects and the possible technical effects that each aspect may achieve, refer to the technical effects that can be achieved by the above-mentioned first aspect or various possible solutions in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 It is a flowchart of an identity generation method provided by the present application;
[0053] Figure 2 It is a schematic diagram of generating a UUID provided by the present application;
[0054] Figure 3 It is a schematic diagram of a method for determining whether a UUID has been tampered with provided by the present application;
[0055] Figure 4Schematic diagram of a method for determining whether a UUID is cloned provided by this application;
[0056] Figure 5 Schematic diagram of the structure of an identity generation device provided by this application;
[0057] Figure 6 Schematic diagram of the structure of an electronic device provided by this application. Detailed implementation manners
[0058] In order to make the objectives, technical solutions, and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "a plurality of" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B can represent: the direct connection between A and B and the connection between A and B through C. In addition, in the description of this application, words such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.
[0059] The following will describe the embodiments of this application in detail with reference to the accompanying drawings.
[0060] At present, the trusted terminal identifier can be generated either on the terminal management platform or on the trusted terminal. When generating the trusted terminal identifier on the terminal management platform, the trusted terminal identifier needs to be written into the local disk, and there is a risk that the trusted terminal identifier will be tampered with during this writing process. When generating the trusted terminal identifier on the trusted terminal, if there is a hot cloning scenario, it will lead to conflicts in the trusted terminal identifiers.
[0061] To solve the above problems, this application provides an identity generation method. The UUID corresponding to each trusted terminal is generated by the server, without relying on any attributes of the trusted terminal. And when the UUID corresponding to any trusted terminal is tampered with or cloned, a new UUID is generated to ensure the uniqueness of the UUID, and thus the asset identifiers corresponding to each trusted terminal are unique. Among them, the methods and devices in the embodiments of this application are based on the same technical concept. Since the principles of the problems solved by the method and the device are similar, the embodiments of the device and the method can be referred to each other, and the repeated parts will not be elaborated.
[0062] As Figure 1 shown, it is a flowchart of an identity generation method provided by this application, which specifically includes the following steps:
[0063] S11, generate a first target program package;
[0064] In the embodiments of the present application, the first target program package is the Agent program package deployed on each trusted terminal. Of course, it can also be other program packages, such as Android Package (APK), Red-Hat Package Manager (RPM), etc. Taking the Agent program package as an example, when generating the Agent program package, at least the built-in root certificate of the Agent program package, the public key of the terminal management platform, and the exchange public key of the terminal management platform are generated. Among them, the built-in root certificate of the Agent program package is used to verify whether the terminal management platform for generating the Agent installation package has been tampered with. The public key of the terminal management platform and the exchange public key of the terminal management platform are both the public keys of the terminal management platform carried in the Agent installation package configuration information.
[0065] Specifically, the method for generating the above first target program package includes:
[0066] Generate the public key of the terminal management platform and the private key of the terminal management platform;
[0067] Generate the exchange public key of the terminal management platform and the exchange private key of the terminal management platform;
[0068] Generate the first target program package according to the public key of the terminal management platform and the private key of the terminal management platform.
[0069] Based on the above method, the first target program package corresponding to the trusted terminal can be generated.
[0070] S12, in response to the registration request corresponding to the first target program package, generate the first Universally Unique Identifier (UUID) corresponding to the first target program package;
[0071] In the embodiments of the present application, after generating the first target program package corresponding to the trusted terminal, the trusted terminal needs to be registered. After successful registration, the first Universally Unique Identifier (UUID) corresponding to the trusted terminal can be generated. Among them, the first UUID is obtained by encrypting the first shared key in the local database and the second shared key corresponding to the first target data packet. The first shared key is generated based on the exchange public key corresponding to the first target program package and the exchange private key in the local database, while the second shared key is generated based on the exchange private key corresponding to the first target program package and the exchange public key in the local database.
[0072] Specifically, the method for generating the first UUID corresponding to the first target program package includes:
[0073] When receiving the first registration request sent by the first target program package, generate the second UUID, the primary key identifier (PKID), and the third shared key corresponding to the first target program package;
[0074] Send a first registration response to the first target package, where the first registration response at least includes the second UUID, the PKID, and the first information signed with the third shared key, and the first information at least includes the exchange key pair generated by the first target package and the public key;
[0075] When receiving the second registration request sent by the first target package, decrypt the second information in the second registration request based on the first shared key corresponding to the PKID in the second registration request, and store the decrypted second information and the PKID bound in the local database, where the second information is obtained by the first target package encrypting the second UUID and the first information with the second shared key;
[0076] Send a second registration response to the first target package, and use the UUID carried in the second registration response as the first UUID, where the UUID carried in the second registration response is obtained by encrypting the second UUID with the first shared key.
[0077] For example, as Figure 2 shown, it is a schematic diagram for generating the first UUID corresponding to the Agent package. In Figure 2 , after the Agent package generates the Agent public key, the Agent private key, and the Agent exchange key pair, it sends a first registration request to the terminal management platform, where the Agent exchange key pair includes the Agent exchange public key and the Agent exchange private key;
[0078] After receiving the first registration request, the terminal management platform generates the UUID corresponding to the Agent package as the unique identifier of the trusted terminal, and generates the shared key corresponding to the terminal management platform according to the Agent exchange public key and the terminal management platform exchange private key, and uses this shared key to sign the Agent public key and the Agent exchange key pair carried in the first registration request. In addition, it also calculates and generates the primary key identifier (PKID) according to the Agent exchange key pair, and then sends a first registration response to the Agent package, where the first registration response carries the generated UUID, the signed Agent public key, the signed Agent exchange key pair, and the PKID;
[0079] After the Agent package receives the first registration response, it generates a shared key corresponding to the Agent package based on the Agent's exchanged private key and the management platform's exchanged public key, and saves the signed Agent public key and the signed Agent exchange key pair carried in the first registration response in the trusted terminal. Then, it encrypts the UUID in the first registration response using the second shared key and sends a second registration request to the terminal management platform, where the second registration request carries the PKID and the UUID encrypted using the second shared key;
[0080] After the terminal management platform receives the second registration request, it queries the Agent public key and the terminal management platform's exchanged private key in the local database according to the PKID carried in the second registration request, and generates a shared key. Then, it decrypts the UUID carried in the second registration request using this shared key, associates the signed UUID of the Agent package, the Agent exchange key pair, and the Agent public key, and stores them in the local database. It encrypts the UUID signed by the second shared key using the first shared key, and then sends a second registration response to the Agent package, where the second registration response carries the UUID information encrypted by the second shared key.
[0081] Based on the above method, generating the UUID corresponding to the trusted terminal by the terminal management platform, without relying on any attributes of the trusted terminal, helps to ensure the uniqueness of the UUIDs corresponding to each trusted terminal, and further makes the asset identifiers corresponding to each trusted terminal unique.
[0082] S13, determine whether the first UUID is tampered with and / or determine whether the first UUID is cloned;
[0083] In the embodiment of the present application, after completing the registration of the trusted terminal and generating the first UUID corresponding to the trusted terminal, the identifier of the trusted terminal is written into the local disk, and there is a risk that the first UUID is tampered with during this writing process. At the same time, there may also be a scenario of hot cloning inside the trusted terminal, which will cause the first UUID to be cloned. Therefore, it is necessary to determine whether the first UUID is tampered with and / or cloned. The method for determining whether the first UUID is tampered with includes:
[0084] When receiving the third registration request sent by the first target package, query the exchanged public key, the local exchanged private key, and the first UUID corresponding to the first target package according to the PKID corresponding to the third registration request;
[0085] Generate a fourth shared key according to the exchanged public key corresponding to the first target package and the local exchanged private key, and decrypt the third UUID carried in the third registration request using the fourth shared key;
[0086] When the first UUID is inconsistent with the decrypted third UUID, it is determined that the first UUID has been tampered with.
[0087] For example, as Figure 3 shown, it is a schematic diagram of a method for determining whether the first UUID has been tampered with. In Figure 3 , the Agent package reads the Agent public key and the Agent exchange key pair signed by the terminal management platform, decrypts them using the terminal management platform public key, then generates a shared key based on the Agent exchange private key and the terminal management platform exchange public key, encrypts the first UUID using the shared key, and then sends a third registration request to the terminal management platform. Among them, the encrypted UUID and the data packet header KPID corresponding to the third registration request are carried in the third registration request;
[0088] When the terminal management platform receives the third registration request, it parses the data packet header to obtain the KPID, and queries the local database according to the KPID to obtain the Agent exchange public key, the terminal management platform exchange private key, and the encrypted first UUID. Then, a fourth shared key is generated based on the Agent exchange public key and the terminal management platform exchange private key, and the data packet is decrypted using the fourth shared key to obtain the UUID corresponding to the Agent package;
[0089] Furthermore, the terminal management platform compares the UUID corresponding to the Agent package with the first UUID in the local database. If they are inconsistent, it indicates that the first UUID has been tampered with.
[0090] Through the above method, it can be determined whether the UUID generated by the terminal management platform has been tampered with. In addition, in the embodiments of the present application, a method for determining whether the first UUID has been cloned is also provided. The specific determination method includes:
[0091] When receiving the handshake request corresponding to the first target package, send a first parameter to the first target package, where the first parameter is randomly generated and bound to the first UUID;
[0092] When receiving the handshake request corresponding to the second target package, send a second parameter to the second target package, where the UUID corresponding to the second target package is the same as the first UUID, and the difference between the second parameter and the first parameter is a preset value;
[0093] When receiving the first parameter returned by the first target package, generate a third parameter, where the third parameter is bound to the first UUID;
[0094] When the third parameter is not equal to the first parameter and the third parameter is not equal to the second parameter, it is determined that the first UUID is cloned.
[0095] In the above process, when the UUIDs corresponding to any two trusted terminals are the same, it cannot be determined that there is cloning between these two trusted terminals. At this time, it is necessary to further handshake between the two terminals and the terminal management platform to determine whether there is cloning.
[0096] For example, as Figure 4 shown, it is a schematic diagram of a method for determining whether the first UUID is cloned. In Figure 4 , the first Agent package sends a heartbeat packet to the terminal management platform to request a handshake. After receiving the heartbeat packet, the terminal management platform randomly generates auxid = 15, associates auxid with the UUID corresponding to the first Agent package, then records auxid1 = auxid - 1 = 14 and auxid2 = auxid = 15, and sends auxid = 15 to the first Agent package;
[0097] The second Agent package sends a heartbeat packet to the terminal management platform to request a handshake, where the UUID corresponding to the second Agent package is the same as the UUID corresponding to the first Agent package. After receiving the heartbeat packet, the terminal management platform can obtain that auxid = 15 at this time by querying the UUID. Therefore, when sending a reply packet to the second Agent, auxid = 16, auxid1 = auxid - 1 = 15, and auxid2 = auxid = 16, and sends auxid = 16 to the second Agent package.
[0098] In the above process, when the first Agent package receives auxid = 15, it returns auxid = 15 to the terminal management platform. When the second Agent package receives auxid = 16, it returns auxid = 16 to the terminal management platform. At this time, in the terminal management platform, the auxid1 corresponding to the second Agent package is equal to the randomly generated auxid by the terminal management platform, both are 15, and then it is determined that there is a cloned host in the host corresponding to the first Agent package and the host corresponding to the second Agent package;
[0099] Furthermore, the terminal management platform randomly generates auxid = 100 again, binds auxid = 100 to the same UUID corresponding to the two Agent packages, records auxid1 = auxid - 1 = 99 and auxid2 = auxid = 100, and then sends auxid = 100 to the first Agent package.
[0100] The first Agent package feeds back the received auxid = 100 to the terminal management platform. At this time, both auxid1 = auxid - 1 = 15 and auxid2 = auxid = 16 corresponding to the second Agent package are not equal to auxid = 100. Then, it is determined that the trusted terminal corresponding to the second Agent is a cloned host.
[0101] Through the above method, it can be determined whether the UUID generated by the terminal management platform is cloned, and then subsequent processing of the cloned UUID can be implemented to avoid UUID conflicts.
[0102] S14. When the first UUID is tampered with and / or cloned, regenerate the UUID corresponding to the first target package.
[0103] In the embodiment of the present application, in order to ensure the uniqueness of the UUIDs of each trusted terminal, when the first UUID is tampered with and / or cloned, the Agent package corresponding to the first UUID needs to initiate a re-registration process to the terminal management platform, and then regenerate the UUID to ensure the uniqueness of the UUID corresponding to the trusted terminal.
[0104] Based on the above identification generation method, the terminal management platform generates the UUIDs corresponding to each trusted terminal, which does not depend on any attributes of the trusted terminal, and when the UUID corresponding to any trusted terminal is tampered with or cloned, the UUID is regenerated to ensure the uniqueness of the UUID.
[0105] Based on the same inventive concept, the embodiment of the present application further provides an identification generation device, as Figure 5 shown, which is a schematic structural diagram of an identification generation device in the present application. The device includes:
[0106] A generation module 51, configured to generate a first target package, where the first target package is deployed on a trusted terminal;
[0107] A response module 52, configured to generate a first Universally Unique Identifier (UUID) corresponding to the first target package in response to a registration request corresponding to the first target package, where the first UUID is obtained by encrypting a first shared key in a local database and a second shared key corresponding to the first target data packet;
[0108] A determination module 53, configured to determine whether the first UUID is tampered with and / or determine whether the first UUID is cloned;
[0109] A regeneration module 54, configured to regenerate the UUID corresponding to the first target package when the first UUID is tampered with and / or cloned.
[0110] In a possible design, the response module 52 is specifically configured to:
[0111] When receiving a first registration request sent by the first target package, generate a second UUID, a primary key identifier PKID, and a third shared key corresponding to the first target package;
[0112] Send a first registration response to the first target package, where the first registration response at least includes the second UUID, the PKID, and the first information signed with the third shared key, and the first information at least includes an exchange key pair and a public key generated by the first target package;
[0113] When receiving a second registration request sent by the first target package, decrypt the second information in the second registration request based on the first shared key corresponding to the PKID in the second registration request, where the second information is obtained by the first target package encrypting the second UUID and the first information with the second shared key;
[0114] Send a second registration response to the first target package, and use the UUID carried in the second registration response as the first UUID, where the UUID carried in the second registration response is obtained by encrypting the second UUID with the first shared key.
[0115] In a possible design, the determination module 53 is specifically configured to:
[0116] When receiving a third registration request sent by the first target package, query the exchange public key, the local exchange private key, and the first UUID corresponding to the first target package according to the PKID corresponding to the third registration request;
[0117] Generate a fourth shared key according to the exchange public key corresponding to the first target package and the local exchange private key, and decrypt the third UUID carried in the third registration request with the fourth shared key;
[0118] When the first UUID is inconsistent with the decrypted third UUID, determine that the first UUID has been tampered with.
[0119] In a possible design, the determination module 53 is further configured to:
[0120] When receiving a handshake request corresponding to the first target package, send a first parameter to the first target package, where the first parameter is bound to the first UUID;
[0121] When receiving a handshake request corresponding to a second target program package, send a second parameter to the second target program package, where the UUID corresponding to the second target program package is the same as the first UUID, and the difference between the second parameter and the first parameter is a preset value;
[0122] When receiving the first parameter returned by the first target program package, generate a third parameter, where the third parameter is bound to the first UUID;
[0123] When the third parameter is not equal to the first parameter and the third parameter is not equal to the second parameter, determine that the first UUID is cloned.
[0124] Based on the above identity generation device, the terminal management platform generates UUIDs corresponding to each trusted terminal, which does not depend on any attributes of the trusted terminal, and when the UUID corresponding to any trusted terminal is tampered with or cloned, a new UUID is generated to ensure the uniqueness of the UUID, and thus the asset identifiers corresponding to each trusted terminal are unique.
[0125] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present application. The electronic device can implement the functions of the foregoing identity generation device. Refer to Figure 6 , the electronic device includes:
[0126] At least one processor 61, and a memory 62 connected to at least one processor 61. In the embodiment of the present application, the specific connection medium between the processor 61 and the memory 62 is not limited. Figure 6 In, it is taken as an example that the processor 61 and the memory 62 are connected through a bus 60. The bus 60 is represented by a thick line in Figure 6 . The connection manners between other components are only for illustrative purposes and are not limited thereto. The bus 60 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 6 only a thick line is used to represent it in, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 61 can also be called a controller, and the name is not limited.
[0127] In the embodiment of the present application, the memory 62 stores instructions executable by at least one processor 61. By executing the instructions stored in the memory 62, at least one processor 61 can execute the foregoing identity generation method. The processor 61 can implement Figure 5 the functions of each module in the device shown.
[0128] Among them, the processor 61 is the control center of the device, which can connect various parts of the entire control device through various interfaces and circuits. By running or executing the instructions stored in the memory 62 and calling the data stored in the memory 62, various functions of the device and data processing are performed, thereby monitoring the device as a whole.
[0129] In a possible design, the processor 61 may include one or more processing units. The processor 61 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 61. In some embodiments, the processor 61 and the memory 62 may be implemented on the same chip, and in some embodiments, they may also be separately implemented on independent chips.
[0130] The processor 61 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the identification generation method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0131] The memory 62 serves as a non-volatile computer-readable storage medium and can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 62 can include at least one type of storage medium. For example, it can include flash memory, hard disks, multimedia cards, card-type memories, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memories, magnetic disks, optical disks, etc. The memory 62 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 62 in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0132] By designing and programming the processor 61, the code corresponding to the identity generation method described in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 1 the steps of the identity generation method of the illustrated embodiment. How to design and program the processor 61 is a well-known technology to those skilled in the art and will not be elaborated here.
[0133] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, which, when run on a computer, cause the computer to execute the identity generation method discussed above.
[0134] In some possible implementation manners, each aspect of the identity generation method provided in the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in the identity generation method according to various exemplary embodiments of the present application described above in this specification.
[0135] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0136] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0137] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0138] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0139] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these changes and modifications.
Claims
1. A method for generating an identifier, characterized in that, Applied to a terminal management platform, the method includes: Generate a first target program package, where the first target program package is deployed on a trusted terminal; When receiving a first registration request sent by the first target program package, generate a second UUID, a primary key identifier PKID, and a third shared key corresponding to the first target program package, where the PKID is calculated based on an exchange key pair corresponding to the first target program package, and the exchange key pair corresponding to the first target program package includes: an exchange public key and an exchange private key corresponding to the first target program package, and the third shared key is generated based on the exchange public key corresponding to the first target program package and a local exchange private key; Send a first registration response to the first target program package, where the first registration response at least includes the second UUID, the PKID, and a first piece of information signed with the third shared key, and the first piece of information at least includes an exchange key pair and a public key corresponding to the first target program package; When receiving a second registration request sent by the first target program package, based on the PKID carried in the second registration request, query the local database to obtain the exchange public key and the local exchange private key corresponding to the first target program package, generate a first shared key, and based on the first shared key, decrypt the second piece of information in the second registration request, and store the decrypted second piece of information and the PKID after binding in the local database, where the second piece of information is obtained by encrypting the second UUID and the first piece of information with a second shared key, and the second shared key is generated based on the exchange private key corresponding to the first target program package and a local exchange public key; Send a second registration response to the first target program package, and use the UUID carried in the second registration response as the first UUID, where the UUID carried in the second registration response is obtained by encrypting the second UUID with the first shared key; Determine whether the first UUID is tampered with and / or determine whether the first UUID is cloned; When the first UUID is tampered with and / or cloned, regenerate the UUID corresponding to the first target program package.
2. The method according to claim 1, wherein Determining whether the first UUID is tampered with includes: When receiving a third registration request sent by the first target program package, query the local database according to the PKID corresponding to the third registration request to obtain the exchange public key, the local exchange private key, and the first UUID corresponding to the first target program package; Generate a fourth shared key according to the exchange public key corresponding to the first target program package and the local exchange private key, and decrypt the third UUID carried in the third registration request with the fourth shared key, where the third UUID is obtained by encrypting the first UUID with the exchange private key corresponding to the first target program package and the local exchange public key; When the first UUID is inconsistent with the decrypted third UUID, it is determined that the first UUID has been tampered with.
3. The method according to claim 1, characterized in that, Determining whether the first UUID has been cloned includes: When receiving a handshake request corresponding to the first target package, sending a first parameter to the first target package, where the first parameter is bound to the first UUID; When receiving a handshake request corresponding to a second target package, sending a second parameter to the second target package, where the UUID corresponding to the second target package is the same as the first UUID, and the difference between the second parameter and the first parameter is 1; When receiving the first parameter returned by the first target package, generating a third parameter, where the third parameter is bound to the first UUID; When the third parameter is not equal to the first parameter and the third parameter is not equal to the second parameter, it is determined that the first UUID has been cloned.
4. An identification generation device, characterized in that, Applied to a terminal management platform, the device includes: A generation module for generating a first target package, where the first target package is deployed on a trusted terminal; A response module for generating a second UUID, a primary key identifier PKID, and a third shared key corresponding to the first target package when receiving a first registration request sent by the first target package, where the PKID is calculated based on an exchange key pair corresponding to the first target package, and the exchange key pair corresponding to the first target package includes: an exchange public key and an exchange private key corresponding to the first target package, and the third shared key is generated based on the exchange public key corresponding to the first target package and a local exchange private key; Sending a first registration response to the first target package, where the first registration response at least includes the second UUID, the PKID, and the first information signed with the third shared key, and the first information at least includes an exchange key pair and a public key corresponding to the first target package; When receiving a second registration request sent by the first target package, based on the PKID carried in the second registration request, querying in the local database to obtain the exchange public key and the local exchange private key corresponding to the first target package, generating a first shared key, and based on the first shared key, decrypting the second information in the second registration request, and storing the decrypted second information and the PKID after binding in the local database, where the second information is obtained by encrypting the second UUID and the first information with a second shared key, and the second shared key is generated based on the exchange private key corresponding to the first target package and the local exchange public key; Sending a second registration response to the first target package, and using the UUID carried in the second registration response as the first UUID, where the UUID carried in the second registration response is obtained by encrypting the second UUID with the first shared key; A determination module, configured to determine whether the first UUID is tampered with and / or determine whether the first UUID is cloned; A regeneration module, configured to regenerate the UUID corresponding to the first target program package when the first UUID is tampered with and / or cloned.
5. The device according to claim 4, characterized in that The determination module is specifically configured to: When receiving a third registration request sent by the first target program package, query the local database according to the PKID corresponding to the third registration request to obtain the exchange public key, the local exchange private key, and the first UUID corresponding to the first target program package; Generate a fourth shared key according to the exchange public key corresponding to the first target program package and the local exchange private key, and use the fourth shared key to decrypt the third UUID carried in the third registration request, where the third UUID is obtained by encrypting the first UUID with the exchange private key corresponding to the first target program package and the local exchange public key; When the first UUID is inconsistent with the decrypted third UUID, determine that the first UUID is tampered with.
6. The device according to claim 4, characterized in that The determination module is further configured to: When receiving a handshake request corresponding to the first target program package, send a first parameter to the first target program package, where the first parameter is bound to the first UUID; When receiving a handshake request corresponding to a second target program package, send a second parameter to the second target program package, where the UUID corresponding to the second target program package is the same as the first UUID, and the difference between the second parameter and the first parameter is 1; When receiving the first parameter returned by the first target program package, generate a third parameter, where the third parameter is bound to the first UUID; When the third parameter is not equal to the first parameter and the third parameter is not equal to the second parameter, determine that the first UUID is cloned.
7. An electronic device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to implement the method steps described in any one of claims 1-3 when executing the computer program stored on the memory.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements the method steps described in any one of claims 1-3.
Citation Information
Patent Citations
Method and device for obtaining equipment identity
CN108429740A
Lightweight authentication method based on equipment identity label and gateway
CN111835752A