Data communication method, device, distributed system and storage medium
By using the second device as the transit node to negotiate the target key in the IoT scenario, encrypted communication between the first device and the third device is realized, solving the confidentiality and reliability of data transmission in the prior art, and avoiding DoS attacks and computing resource consumption.
Patent Information
- Application Number
- CN202110435291.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-22
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-04-22
AI Technical Summary
In the IoT scenario, the existing technology has not yet provided an effective third-party data encryption authorization solution, resulting in the authorized service equipment consuming computing resources after long-term authorization, which is prone to DoS attacks and cannot effectively protect the confidentiality and reliability of data transmission.
By negotiating the target key with the second device, using the second device as a transit node for encrypted communication, ensuring that the interactive data between the first device and the third device is only known by both parties, and the third party data encryption protection is realized.
It realizes that the authorization of the terminal device of the authorization requester is completed without modifying the IoT device code, and the interactive data is encrypted and protected, preventing third-party theft, reducing the risk of computing resource consumption and DoS attacks, and ensuring the confidentiality and reliability of data transmission.
Smart Images

Figure CN115242395B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a data communication method, apparatus, distributed system, and storage medium. Background Art
[0002] A distributed system refers to a system in which data can be calculated on different devices, corresponding calculation results can be returned, and the devices can cooperate with each other. In a distributed system, a common application scenario is that a terminal device of an authorization requester (such as user A) needs to use a certain resource of an Internet of Things (IoT) device of an authorization service provider (such as user B). The IoT device includes, but is not limited to, a printer, an entertainment device, a medical device, or a computer.
[0003] In a distributed system, three-party authorization is a common research direction, aiming to protect device resources from being misused and the interacted data from being eavesdropped by the outside world. That is, the authorization service device is outside the interaction process between the user device and the service device. After the authorization service device completes the authentication of the user's identity and permissions, it will send a token indicating that the user authentication is completed. Then, the user device uses this token to directly authenticate the service device, thus avoiding interacting with the authorization service device again.
[0004] In this case, the location of the authorization service device is out-of-band. After authorization is completed, the user device and the service device directly interact, and the authorization service device no longer participates. This is applicable to long-term authorization. And the above solution requires the service device to forward the received access request to the authorization service device, which easily consumes computing resources and forms a Denial of Service (DoS) attack, and is not applicable to the IoT scenario. In related technologies, no suitable and effective third-party data encryption authorization solution in the IoT scenario has been provided. Summary of the Invention
[0005] In view of this, a data communication method, apparatus, distributed system, and storage medium are proposed. In an embodiment of this application, a first device negotiates a key with a third device through a second device, so that the first device and the third device establish a target key. Although the second device, as a relay node, can read the interaction data between the first device and the third device, it has no way to obtain the random numbers respectively generated by the first device and the third device, and thus cannot calculate the target key. Therefore, in the encryption communication process, the second device cannot obtain the plaintext data exchanged between the first device and the third device, realizing the authorization of third-party data encryption protection and ensuring the confidentiality and reliability of data transmission.
[0006] In a first aspect, an embodiment of the present application provides a data communication method for a distributed system. The distributed system includes a first device, a second device, and a third device. The second device is respectively communicatively connected to the first device and the third device. The method includes:
[0007] The first device sends an authorization request to the second device. The authorization request is used to request to obtain the device resources or capabilities of the third device;
[0008] When the first device is authorized by the second device, the first device negotiates a target key with the third device through the second device. The target key is determined based on the interaction data between the first device and the third device and the random numbers generated by each of them. The interaction data is determined according to the random numbers;
[0009] The first device performs encrypted communication with the third device through the second device based on the target key.
[0010] In this implementation, the second device serves as a relay node between the first device and the third device. The first device sends an authorization request to the second device. The authorization request is used to request to obtain the device resources or capabilities of the third device. When the first device is authorized by the second device, the first device negotiates a target key with the third device through the second device, so that subsequently the first device performs encrypted communication with the third device based on the target key; where in the key negotiation process, both the first device and the third device establish the target key according to the interaction data and the random numbers generated by each of them. Although the second device can read the interaction data between the first device and the third device, it has no way to obtain the random numbers generated by the first device and the third device respectively, and thus cannot calculate the target key. Therefore, in the subsequent encrypted communication process, the second device cannot obtain the plaintext data exchanged between the first device and the third device, realizing the authorization of third-party data encryption protection and ensuring the confidentiality and reliability of data transmission.
[0011] In a possible implementation, the first device is a terminal device of an authorization requester, the second device is a terminal device of an authorization service provider, and the third device is an IoT device of the authorization service provider.
[0012] In this implementation, the terminal device of the authorization service provider (i.e., the second device) is placed between the terminal device of the authorization requester (i.e., the first device) and the IoT device of the authorization service provider (i.e., the third device). The second device forwards the interaction data between the first device and the third device, can cut off the communication between both parties in real time, and recover the authorization. Moreover, when the first device and the third device interact through the Station to Station (STS) protocol, there is no need to modify the third device, and the first device only needs minor modifications when supporting the STS protocol to use the third device.
[0013] In another possible implementation, the interaction data includes first data and second data. When the first device is authorized by the second device, it negotiates a target key with the third device through the second device, including:
[0014] The first device sends the first data to the second device when authorized by the second device, and the first data is determined according to a first random number;
[0015] After the second device authenticates the identity of the first device, it forwards the first data to the third device;
[0016] After receiving the first data, the third device generates a first key according to the first data and a second random number;
[0017] The second device forwards the second data sent by the third device to the first device, and the second data is determined according to the second random number;
[0018] After the first device authenticates the identity of the second device, it generates a second key according to the second data and the first random number, and the second key is the same as the first key;
[0019] After the first device authenticates the identity of the third device, it determines the second key as the target key;
[0020] After the third device authenticates the identity of the second device, it determines the first key as the target key.
[0021] In this implementation, through the interaction between the above three devices, the key negotiation between the first device and the third device is realized. Although the second device can read the interaction data (i.e., the first data and the second data) between the first device and the third device, it cannot obtain the first random number or the second random number, and thus cannot calculate the target key, ensuring that the parameters for key negotiation come from the first device and the third device, and only the first device and the third device know the negotiated target key.
[0022] In another possible implementation, when authorized by the second device, the first device sends first data to the second device, including:
[0023] When authorized by the second device, the first device generates the first data according to the first random number, a preset generator of a finite cyclic group, and a preset prime number;
[0024] The first device signs the first data with the private key of the first device to obtain a first signature value. The private key and the public key of the first device are an asymmetric key pair, and the first signature value is used to verify the identity of the first device;
[0025] The first device sends the first data and the first signature value to the second device;
[0026] After the second device passes the authentication of the identity of the first device, it forwards the first data to the third device, including:
[0027] The second device verifies the signature of the first signature value with the public key of the first device stored therein, and forwards the first data to the third device after the verification passes.
[0028] In this implementation, the first device generates the first data according to the first random number, a preset generator of a finite cyclic group, and a preset prime number, signs the first data with the private key of the first device to obtain a first signature value, and sends the first data and the first signature value to the second device. Thus, the second device verifies the signature of the first signature value with the public key of the first device stored therein. After the verification passes, which means the authentication of the identity of the first device passes, the second device forwards the first data to the third device; through the above public-private key signature mechanism, it is further ensured that the parameters for key negotiation come from the first device.
[0029] In another possible implementation, after receiving the first data, the third device generates a first key according to the first data and a second random number, including:
[0030] After receiving the first data, the third device generates the second random number;
[0031] The third device generates the first key according to the first data, the second random number, and a preset prime number.
[0032] In this implementation, after receiving the first data, the third device generates the second random number, and generates the first key according to the first data, the second random number, and a preset prime number, further ensuring that the parameters for key negotiation come from the first device and the third device, and only the first device and the third device know the negotiated target key.
[0033] In another possible implementation, before the second device forwards the second data sent by the third device to the first device, it further includes:
[0034] The third device generates the second data according to the second random number, a generator of a preset finite cyclic group, and a preset prime number;
[0035] The third device signs the first concatenated data with the private key of the third device to obtain a second signature value, and the second signature value is used to verify the identity of the third device;
[0036] The third device encrypts the second signature value with the first key to obtain a first encrypted value, and the first concatenated data is the data obtained by concatenating the first data and the second data;
[0037] The third device sends the second data and the first encrypted value to the second device;
[0038] The second device forwards the second data sent by the third device to the first device, including:
[0039] After receiving the second data and the first encrypted value, the second device signs the second concatenated data with the private key of the second device to obtain a third signature value, and the second concatenated data is the data obtained by concatenating the second data and the first data;
[0040] The second device sends the second data, the first encrypted value, and the third signature value to the first device, and the third signature value is used to verify the identity of the second device;
[0041] After the first device passes the identity verification of the second device, it generates a second key according to the second data and the first random number, including:
[0042] The first device verifies the signature of the third signature value through the public key of the second device stored, and after the verification passes, generates the second key according to the second data, the first random number, and the preset prime number.
[0043] In this implementation, through the above public-private key signature mechanism, it is further ensured that the parameters for key negotiation come from the first device and the third device, and the target key negotiated is only known to the first device and the third device.
[0044] In another possible implementation, after the first device passes the identity verification of the third device, it determines the second key as the target key, including:
[0045] The first device decrypts the first encrypted value with the second key;
[0046] After successful decryption, the first device performs signature verification on the decrypted data with the public key of the third device stored therein;
[0047] After successful verification, the first device determines the second key as the target key.
[0048] In this implementation, after successful decryption and signature verification by the first device, which indicates successful authentication of the third device, the second key is determined as the target key, further ensuring the confidentiality and reliability of the key negotiation process.
[0049] In another possible implementation, before the third device determines the first key as the target key after successful authentication of the second device, it further includes:
[0050] The first device encrypts the third signature value with the second key to obtain a second encrypted value, and sends the second encrypted value to the second device;
[0051] After receiving the second encrypted value, the second device forwards the second encrypted value to the third device;
[0052] After the third device successfully authenticates the second device, determining the first key as the target key includes:
[0053] After receiving the second encrypted value, the third device decrypts the second encrypted value with the first key;
[0054] After successful decryption, the third device performs signature verification on the decrypted data with the public key of the second device stored therein;
[0055] After successful verification, the third device determines the first key as the target key.
[0056] In this implementation, after successful decryption and signature verification by the third device, which indicates successful authentication of the second device, the first key is determined as the target key, further ensuring the confidentiality and reliability of the key negotiation process.
[0057] In another possible implementation, before the first device negotiates the target key with the third device with the authorization of the second device, it further includes:
[0058] The second device and the third device exchange their respective public keys;
[0059] The first device exchanges its public key with the second device, and the first device receives the public key of the third device sent by the second device.
[0060] In this implementation, before the first device and the third device perform key negotiation, the second device and the third device exchange their respective public keys, the first device and the second device exchange their respective public keys, and the first device receives the public key of the third device sent by the second device to ensure the normal use of the subsequent public-private key signature mechanism.
[0061] In another possible implementation, the first device performs encrypted communication with the third device through the second device based on the target key, including:
[0062] The first device encrypts the first data with the target key to obtain the second data, and sends the second data to the second device. The first data is the plaintext data of the content to be processed.
[0063] The second device forwards the second data to the third device.
[0064] The third device decrypts the second data with the target key to obtain the first data.
[0065] In this implementation, the first device encrypts the first data with the target key to obtain the second data, sends the second data to the second device, the second device forwards the second data to the third device, and the third device decrypts the second data with the target key to obtain the first data; that is, the interactive data is only plaintext data at the first device and the third device, and the second device cannot know the plaintext data of the interactive data, so that the interactive data between the first device and the third device is encrypted and protected and is not leaked to a third party other than the two.
[0066] In another possible implementation, the first device is the terminal device of the first object, the second device is the terminal device of the second object, and the first object is different from the second object;
[0067] The third device is the printer device of the second object, and the content to be processed is the data content to be printed; or, the third device is the multimedia playback device of the second object, and the content to be processed is the multimedia content to be played.
[0068] In this implementation manner, the data communication method provided by the embodiments of the present application can be applied to a variety of application scenarios. For example, a scenario where the terminal device of a first object uses the printer of a second object through the terminal device of the second object, or a scenario where the terminal device of the first object uses the multimedia playback device of the second object through the terminal device of the second object, which ensures the universality of the data communication method provided by the embodiments of the present application and meets the usage requirements in various application scenarios.
[0069] In a second aspect, embodiments of the present application provide a data communication method for use in a first device. The first device is communicatively connected to a second device, and the second device is communicatively connected to a third device. The method includes:
[0070] Sending an authorization request to the second device, the authorization request being used to request access to the device resources or capabilities of the third device;
[0071] In the case of authorization by the second device, negotiating a target key with the third device through the second device, the target key being determined based on interaction data between the first device and the third device and respective generated random numbers, and the interaction data being determined according to the random numbers;
[0072] Based on the target key, performing encrypted communication with the third device through the second device.
[0073] In a possible implementation manner, the first device is the terminal device of the authorization requester, the second device is the terminal device of the authorization service provider, and the third device is the IoT device of the authorization service provider.
[0074] In another possible implementation manner, the interaction data includes first data and second data. In the case of authorization by the second device, negotiating a target key with the third device through the second device includes:
[0075] In the case of authorization by the second device, sending the first data to the second device, the first data being determined according to a first random number, and the first data instructing the second device to forward the first data to the third device after authenticating the identity of the first device; after receiving the first data, the third device generates a first key according to the first data and a second random number; the second device forwards the second data sent by the third device to the first device, the second data being determined according to the second random number;
[0076] After authenticating the identity of the second device, generating a second key according to the second data and the first random number, the second key being the same as the first key;
[0077] After the authentication of the third device is passed, the second key is determined as the target key. The third device is used to determine the first key as the target key after the authentication of the second device is passed.
[0078] In another possible implementation, the sending of the first data to the second device under the authorization of the second device includes:
[0079] Under the authorization of the second device, generate the first data according to the first random number, a preset generator of a finite cyclic group, and a preset prime number;
[0080] Sign the first data with the private key of the first device to obtain a first signature value. The private key and the public key of the first device are an asymmetric key pair, and the first signature value is used to verify the identity of the first device;
[0081] Send the first data and the first signature value to the second device. The first signature value instructs the second device to perform signature verification on the first signature value through the stored public key of the first device, and forward the first data to the third device after the verification passes.
[0082] In another possible implementation, the third device is further configured to generate the second data according to the second random number, a preset generator of a finite cyclic group, and a preset prime number; sign the first concatenated data with the private key of the third device to obtain a second signature value, and the second signature value is used to verify the identity of the third device; encrypt the second signature value with the first key to obtain a first encrypted value. The first concatenated data is the data obtained by concatenating the first data and the second data; send the second data and the first encrypted value to the second device;
[0083] The second device is further configured to, after receiving the second data and the first encrypted value, sign the second concatenated data with the private key of the second device to obtain a third signature value. The second concatenated data is the data obtained by concatenating the second data and the first data; send the second data, the first encrypted value, and the third signature value to the first device, and the third signature value is used to verify the identity of the second device;
[0084] After the authentication of the second device is passed, generating the second key according to the second data and the first random number includes:
[0085] Perform signature verification on the third signature value through the stored public key of the second device;
[0086] After the verification passes, generate the second key according to the second data, the first random number, and the preset prime number.
[0087] In another possible implementation, after the authentication of the third device passes, determining the second key as the target key includes:
[0088] Decrypt the first encrypted value with the second key;
[0089] After successful decryption, verify the signature of the decrypted data with the public key of the third device stored;
[0090] After the verification passes, determine the second key as the target key.
[0091] In another possible implementation, the method further includes:
[0092] Encrypt the third signature value with the second key to obtain a second encrypted value;
[0093] Send the second encrypted value to the second device, and the second encrypted value instructs the second device to forward the second encrypted value to the third device after receiving the second encrypted value; after receiving the second encrypted value, the third device decrypts the second encrypted value with the first key; after successful decryption, the third device verifies the signature of the decrypted data with the public key of the second device stored; after the verification passes, the third device determines the first key as the target key.
[0094] In another possible implementation, before negotiating the target key with the third device through the second device under the authorization of the second device, it further includes:
[0095] Exchange respective public keys with the second device and receive the public key of the third device sent by the second device, and the second device and the third device have exchanged their respective public keys.
[0096] In another possible implementation, based on the target key, performing encrypted communication between the second device and the third device includes:
[0097] Encrypt the first data with the target key to obtain second data, where the first data is the plaintext data of the content to be processed;
[0098] Send the second data to the second device, and the second data instructs the second device to forward the second data to the third device; the third device decrypts the second data with the target key to obtain the first data.
[0099] In another possible implementation, the first device is a terminal device of a first object, the second device is a terminal device of a second object, and the first object is different from the second object;
[0100] The third device is a printer device of the second object, and the content to be processed is data content to be printed; or, the third device is a multimedia playback device of the second object, and the content to be processed is multimedia content to be played.
[0101] In a third aspect, an embodiment of the present application provides a distributed system, which includes a first device, a second device, and a third device. The second device is respectively communicatively connected to the first device and the third device.
[0102] The first device is configured to send an authorization request to the second device, and the authorization request is used to request to obtain the device resources or capabilities of the third device;
[0103] The first device is further configured to, when authorized by the second device, negotiate a target key with the third device through the second device. The target key is determined based on the interaction data between the first device and the third device and their respective generated random numbers, and the interaction data is determined according to the random numbers.
[0104] The first device is further configured to perform encrypted communication with the third device through the second device based on the target key.
[0105] In a possible implementation, the first device is a terminal device of an authorization requester, the second device is a terminal device of an authorization service provider, and the third device is an IoT device of the authorization service provider.
[0106] In another possible implementation, the interaction data includes first data and second data;
[0107] The first device is further configured to send the first data to the second device when authorized by the second device, and the first data is determined according to a first random number;
[0108] The second device is configured to forward the first data to the third device after authenticating the identity of the first device;
[0109] The third device is configured to generate a first key according to the first data and a second random number after receiving the first data;
[0110] The second device is further configured to forward the second data sent by the third device to the first device, where the second data is determined according to the second random number;
[0111] The first device is further configured to, after passing the authentication of the second device, generate a second key according to the second data and the first random number, where the second key is the same as the first key;
[0112] The first device is further configured to, after passing the authentication of the third device, determine the second key as the target key;
[0113] The third device is further configured to, after passing the authentication of the second device, determine the first key as the target key.
[0114] In another possible implementation,
[0115] The first device is further configured to, with the authorization of the second device, generate the first data according to the first random number, a preset generator of a finite cyclic group, and a preset prime number;
[0116] The first device is further configured to sign the first data with the private key of the first device to obtain a first signature value, where the private key and the public key of the first device are an asymmetric key pair, and the first signature value is used to verify the identity of the first device;
[0117] The first device is further configured to send the first data and the first signature value to the second device;
[0118] The second device is further configured to verify the signature of the first signature value through the stored public key of the first device, and forward the first data to the third device after the verification passes.
[0119] In another possible implementation,
[0120] The third device is further configured to generate the second random number after receiving the first data;
[0121] The third device is further configured to generate the first key according to the first data, the second random number, and a preset prime number.
[0122] In another possible implementation,
[0123] The third device is further configured to generate the second data according to the second random number, a preset generator of a finite cyclic group, and a preset prime number;
[0124] The third device is further configured to sign the first concatenated data with the private key of the third device to obtain a second signature value, and the second signature value is used to verify the identity of the third device;
[0125] The third device is further configured to encrypt the second signature value with the first key to obtain a first encrypted value, and the first concatenated data is the data obtained by concatenating the first data and the second data;
[0126] The third device is further configured to send the second data and the first encrypted value to the second device;
[0127] The second device is further configured to, after receiving the second data and the first encrypted value, sign the second concatenated data with the private key of the second device to obtain a third signature value, where the second concatenated data is the data obtained by concatenating the second data and the first data;
[0128] The second device is further configured to send the second data, the first encrypted value, and the third signature value to the first device, and the third signature value is used to verify the identity of the second device;
[0129] The first device is further configured to verify the signature of the third signature value with the public key of the second device stored therein, and after the verification passes, generate the second key according to the second data, the first random number, and the preset prime number.
[0130] In another possible implementation,
[0131] The first device is further configured to decrypt the first encrypted value with the second key;
[0132] The first device is further configured to, after successful decryption, verify the signature of the decrypted data with the public key of the third device stored therein;
[0133] The first device is further configured to, after the verification passes, determine the second key as the target key.
[0134] In another possible implementation,
[0135] The first device is further configured to encrypt the third signature value with the second key to obtain a second encrypted value, and send the second encrypted value to the second device;
[0136] The second device is further configured to, after receiving the second encrypted value, forward the second encrypted value to the third device;
[0137] The third device is further configured to decrypt the second encrypted value by using the first key after receiving the second encrypted value;
[0138] The third device is further configured to, after successful decryption, perform signature verification on the decrypted data by using the public key of the second device stored therein;
[0139] The third device is further configured to determine the first key as the target key after the verification passes.
[0140] In another possible implementation,
[0141] The second device is further configured to exchange its respective public key with the third device;
[0142] The first device is further configured to exchange its respective public key with the second device and receive the public key of the third device sent by the second device.
[0143] In another possible implementation,
[0144] The first device is further configured to encrypt first data by using the target key to obtain second data, and send the second data to the second device, where the first data is the plaintext data of the content to be processed;
[0145] The second device is further configured to forward the second data to the third device;
[0146] The third device is further configured to decrypt the second data by using the target key to obtain the first data.
[0147] In a fourth aspect, an embodiment of the present application provides a data communication device, where the device includes:
[0148] A processor;
[0149] A memory for storing instructions executable by the processor;
[0150] Wherein, when the processor is configured to execute the instructions, the method provided by the second aspect or any one of the possible implementation manners in the second aspect is implemented.
[0151] In a fifth aspect, an embodiment of the present application provides a data communication device, where the device includes at least one unit, and the at least one unit is configured to implement the method provided by the second aspect or any one of the possible implementation manners in the second aspect.
[0152] Sixth aspect, an embodiment of the present application provides a non-volatile computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the methods provided by the second aspect or any possible implementation manner in the second aspect are implemented.
[0153] Seventh aspect, an embodiment of the present application provides a computer program product, which includes computer-readable code or a non-volatile computer-readable storage medium carrying the computer-readable code. When the computer-readable code runs in an electronic device, the processor in the electronic device executes the methods provided by the second aspect or any possible implementation manner in the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0154] The drawings included in the specification and constituting a part of the specification show exemplary embodiments, features, and aspects of the present application together with the specification, and are used to explain the principles of the present application.
[0155] Figure 1 FIG. shows a schematic diagram of the principle of a possible data communication method in the related art.
[0156] Figure 2 FIG. shows a schematic structural diagram of a distributed system provided by an exemplary embodiment of the present application.
[0157] Figure 3 FIG. shows a flowchart of a data communication method provided by an exemplary embodiment of the present application.
[0158] Figure 4 FIG. shows a flowchart of a data communication method provided by another exemplary embodiment of the present application.
[0159] Figure 5 FIG. shows a flowchart of a data communication method provided by another exemplary embodiment of the present application.
[0160] Figure 6a FIG. shows a schematic diagram of an application scenario involved in a data communication method provided by an exemplary embodiment of the present application.
[0161] Figure 6b FIG. shows a schematic diagram of a user interface involved in a data communication method provided by an exemplary embodiment of the present application.
[0162] Figure 7 FIG. shows a schematic diagram of an application scenario involved in a data communication method provided by another exemplary embodiment of the present application.
[0163] Figure 8 FIG. shows a schematic diagram of an application scenario involved in a data communication method provided by another exemplary embodiment of the present application.
[0164] Figure 9 The flowchart of the data communication method provided by another exemplary embodiment of the present application is shown.
[0165] Figure 10 The schematic structural diagram of the first device provided by an exemplary embodiment of the present application is shown. Detailed implementation manners
[0166] Various exemplary embodiments, features, and aspects of the present application will be described in detail below with reference to the accompanying drawings. The same reference numerals in the drawings denote elements having the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings do not have to be drawn to scale unless otherwise specified.
[0167] The term "exemplary" used herein means "serving as an example, embodiment, or illustration". Any embodiment described herein as "exemplary" is not necessarily to be construed as superior or better than other embodiments.
[0168] In addition, for a better illustration of the present application, numerous specific details are given in the following detailed implementation manners. Those skilled in the art should understand that the present application can also be implemented without some specific details. In some instances, methods, means, elements, and circuits well known to those skilled in the art are not described in detail so as to highlight the gist of the present application.
[0169] With the continuous growth in the number of IoT devices and the continuous enhancement of their functions, more and more IoT devices have entered personal life, bringing convenience to users' lives. IoT devices provide an application programming interface (API) for data interaction with terminal devices, facilitating data interaction between terminal devices and IoT devices. For example, when the terminal device is a mobile phone and the IoT device is a speaker, the speaker receives the audio stream data sent by the mobile phone. Another example is that when the terminal device is a mobile phone and the IoT device is a smart screen, the smart screen receives the video and audio stream data sent by the mobile phone.
[0170] To protect the data exchanged between the terminal device and the IoT device and enable the two parties to establish a trust relationship, during the initialization phase, the terminal device and the IoT device need to perform a point-to-point trust binding operation between the devices. In this operation, the user's terminal device can initiate the negotiation of the initial session key by entering the personal identification number (PIN) of the IoT device, scanning a QR code, or touching it via Near Field Communication (NFC). After that, the terminal device and the IoT device exchange their respective public keys and store the public key of the other party in their own key vaults. When the terminal device sends a request to the IoT device, both parties use the stored public key of the other party to establish a secure channel. To establish this secure channel, both parties need to perform key negotiation through the STS protocol and then conduct encrypted communication based on the negotiated key.
[0171] The STS protocol is widely used in the process of negotiating the keys for the secure channel between the IoT device and the terminal device. When the IoT device and the terminal device know each other's public keys, the STS protocol can protect the data exchanged between the IoT device and the terminal device and prevent man-in-the-middle attacks. Moreover, the STS protocol is simple and has low computational performance requirements for both end devices, making it suitable for the IoT scenario.
[0172] In a distributed system, a common application scenario is that the terminal device of an authorization requester (such as user A) needs to use a certain resource of the IoT device of an authorization service provider (such as user B). In a schematic example, as Figure 1 shown, after the user device 12 initiates an access request to the service device 14, the service device 14 forwards the access request to the authorization service device 16. After receiving the access request, the authorization service device 16 conducts an identity authentication interaction with the user device 12 and determines whether this user device has the permission to use the service. After completing the authentication, the authorization service device 16 returns the authorization result to the service device 14. If the authorization result indicates that the user device 12 has the permission, the service device 14 starts to negotiate a key with the user device 12 and establish a secure channel.
[0173] After the authorization service device 16 returns the authorization result to the service device 14, the authorization service device 16 no longer participates in the interaction between the service device 14 and the user device 12. In this case, the authorization service device 16 cannot recover the authorization for the user device 12 in real time, and the applicable scenario is long-term authorization. Moreover, the above solution requires the service device 14 to forward the received access request to the authorization service device 16, which easily consumes computing resources and forms a DoS attack, making it inapplicable to the IoT scenario.
[0174] In a possible IoT scenario, the terminal device of the authorization requester is Device A, the terminal device of the authorization service provider is Device B, and the IoT device of the authorization service provider is Device C. Device A hopes to use Device C, and Device B needs to authorize the request sent by Device A. Device A only wants to use the resources of Device C and hopes to protect the data it sends to Device C to prevent Device B from stealing, copying, or tampering with its data, thus returning incorrect results.
[0175] In the related art, no suitable and effective third-party data encryption authorization scheme in the IoT scenario has been provided.
[0176] The embodiment of the present application is extended based on the widely deployed STS protocol. Through the public-private key signature mechanism and the key negotiation mechanism, data encryption protection is achieved. Without modifying the code of the IoT device, the authorization of the terminal device of the authorization requester is completed, and the data exchanged between the terminal device of the authorization requester and the IoT device of the authorization service provider is encrypted and protected, solving the authorization problem for third-party data encryption protection.
[0177] First, the application scenario involved in the present application is introduced.
[0178] The embodiment of the present application provides a data communication method for a distributed system. Please refer to Figure 2 , which shows the structural schematic diagram of a distributed system provided by an exemplary embodiment of the present application.
[0179] The distributed system includes a first device 21, a second device 22, and a third device 23. The second device 22 is respectively communicatively connected to the first device 21 and the third device 23. This communication connection can be a wired network or a wireless network.
[0180] Optionally, the first device 21 is the terminal device of the authorization requester, the second device 22 is the terminal device of the authorization service provider, and the third device 23 is the IoT device of the authorization service provider.
[0181] The terminal device involved in the embodiments of the present application is a device with data communication functions. The terminal device may be a mobile terminal, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal. For example, the terminal device is a mobile phone, an in-vehicle terminal, an unmanned aerial vehicle, a tablet computer, an e-book reader, smart glasses, a smart watch, a Moving Picture Experts Group Audio Layer III (MP3) player, a Moving Picture Experts Group Audio Layer IV (MP4) player, a notebook computer, a laptop computer, and a desktop computer, etc.
[0182] The IoT device involved in the embodiments of the present application is a device connected to the IoT. For example, the IoT device is a printer, an entertainment device, a medical device, a computer, a refrigerator, a robot, a sensor, a water meter, a water meter, a floor cleaning robot, a socket, a mouse, a camera, etc.
[0183] For example, the first device 21 is the mobile phone of user A, the second device 22 is the mobile phone of user B, and the third device 23 is the printer of user B. The embodiments of the present application do not limit the types of devices (the first device 21, the second device 22, and the third device 23).
[0184] It should be noted that the network elements involved in the above distributed system include: at least one first device 21, at least one second device 22, and at least one third device 23, Figure 2 Only one first device 21, one second device 22, and one third device 23 are schematically shown, and the embodiments of the present application do not limit this.
[0185] In the embodiments of the present application, the first device 21 is used to send an authorization request to the second device 22, and the authorization request is used to request to obtain the device resources or capabilities of the third device 23; the first device 21 is also used to negotiate a target key with the third device 23 through the second device 22 when the second device 22 authorizes, and the target key is determined based on the interaction data between the first device and the third device and the respective generated random numbers, and the interaction data is determined according to the random numbers; the first device 21 is also used to perform encrypted communication with the third device 23 through the second device 22 based on the target key.
[0186] Please refer to Figure 3 , which shows a flowchart of a data communication method provided by an exemplary embodiment of the present application. This embodiment is used as an example in the Figure 2 distributed system shown. The method includes the following steps.
[0187] Step 301, the second device matches with the third device.
[0188] Optionally, before the first device sends an authorization request to the second device, the second device matches with the third device, that is, the second device and the third device exchange their respective public keys and certificates, so that when the second device and the third device interact later, they can use the matching public keys to verify each other's identities.
[0189] It should be noted that each device (the first device, the second device or the third device) stores its own public key and the corresponding private key. The public key and the private key are a key pair obtained through an algorithm (that is, a public key and a private key), one of which is made public to the outside world and is called the public key; the other is retained by itself and is called the private key. The key pair obtained through this algorithm can ensure that it is unique worldwide. When using this key pair, if one of the keys is used to encrypt a piece of data, the other key must be used to decrypt it. For example, if the public key in the key pair is used to encrypt the data, the private key in the key pair must be used to decrypt it, otherwise the decryption will not succeed; another example is that if the private key in the key pair is used to encrypt, the public key in the key pair must be used to decrypt it, otherwise the decryption will not succeed.
[0190] Step 302, the first device sends an authorization request to the second device, and the authorization request is used to request to obtain the device resources or capabilities of the third device.
[0191] Optionally, the second device sends broadcast information, and the broadcast information includes a device identifier list, and the device identifier list includes at least one device identifier of the third device; the first device receives the broadcast information and displays the device identifier list. When the first device receives a selection signal for a certain device identifier, it sends an authorization request to the second device, and the authorization request is used to request to obtain the device resources or capabilities of the third device corresponding to the device identifier.
[0192] Optionally, after the first device sends an authorization request to the second device, the first device and the second device exchange their respective public keys. And the first device receives the public key and certificate of the third device sent by the second device.
[0193] At this time, the first device stores the public key and private key of the first device, the public key of the second device and the public key of the third device. The second device stores the public key and private key of the second device, the public key of the first device and the public key of the third device. The third device stores the public key and private key of the third device and the public key of the second device.
[0194] Optionally, the first device and the second device also exchange their respective certificates. Schematically, the certificate of a device (the first device, the second device or the third device) includes the manufacturer and device number of the device.
[0195] Step 303, the second device determines whether to authorize the first device.
[0196] After receiving the authorization request sent by the first device, the second device performs authorization verification. If the second device authorizes the first device, step 304 is executed; if the second device does not authorize the first device, the process ends.
[0197] In a possible implementation, the second device performs authorization verification on the first device, including: the first device and the second device establish a Bluetooth connection. After the Bluetooth connection is successful, the second device performs authorization verification on the first device based on the account information of the first device and the identity authentication mechanism of the Bluetooth interaction protocol.
[0198] Optionally, the authorization request carries the account information of the first device. Alternatively, after sending the authorization request, the first device sends the account information of the first device to the second device. The account information of the first device is the account information of the first device in the system's built-in application or the account information of the first device in a third-party application.
[0199] In another possible implementation, the second device performs authorization verification on the first device, including: the second device generates a random number and sends the random number to the first device. The first device signs the random number with its own private key to obtain a signature value, and sends the signature value and the certificate to the second device. The second device performs signature verification on the signature value according to the public key in the certificate, and after the signature verification passes, verifies the certificate with the public key of the stored system (i.e., verifies the integrity and authenticity of the certificate). If the certificate verification passes, it is determined to authorize the first device; if the certificate verification fails, it is determined not to authorize the first device.
[0200] Step 304, when the first device is authorized by the second device, the first device negotiates a target key with the third device through the second device. The target key is determined based on the interaction data between the first device and the third device and the random numbers generated by each, and the interaction data is determined according to the random numbers.
[0201] Optionally, after the second device determines to authorize the first device, it sends the certificate of the third device to the first device. When the first device receives the certificate of the third device, it determines that the second device has authorized the first device.
[0202] Optionally, the certificate of the third device includes the manufacturer and device number of the third device. The first device receives and displays the certificate of the third device for human judgment as to whether the certificate is for the third device to be used.
[0203] Optionally, when the first device receives the confirmation signal of the certificate or does not receive the cancellation signal within the preset time period, it executes the subsequent steps, that is, the first device negotiates the target key with the third device through the second device.
[0204] Optionally, the random number generated by the first device is the first random number, and the random number generated by the third device is the second random number. The interaction data between the first device and the third device includes the first data determined according to the first random number and the second data determined according to the second random number. The first device negotiates the target key with the third device through the second device, including: the first device sends the first data to the third device through the second device under the authorization of the second device, and the first data is determined according to the first random number; the third device determines the target key according to the first data and the second random number; the third device sends the second data to the first device through the second device, and the second data is determined according to the second random number; the first device generates the second key according to the second data and the first random number.
[0205] Optionally, during the process of the first device negotiating the target key with the third device through the second device, the three devices of the first device, the second device, and the third device need to perform identity authentication. The first device needs to verify the identities of the second device and the third device. The second device needs to verify the identity of the first device. The third device needs to consider that the device with which it exchanges keys is the second device. In a possible implementation manner, the process of the first device negotiating the target key with the third device through the second device includes but is not limited to the following steps, such as Figure 4 shown as:
[0206] Step 401, the first device sends the first data to the second device, and the first data is determined according to the first random number.
[0207] The first device generates the first data according to the first random number and sends the first data to the second device. Optionally, the first device generates the first data according to the first random number, the generator of the preset finite cyclic group, and the preset prime number; the first device signs the first data with the private key of the first device to obtain the first signature value, and the private key and the public key of the first device are an asymmetric key pair, and the first signature value is used to verify the identity of the first device; the first device sends the first data and the first signature value to the second device.
[0208] Schematically, the first device generates the first data according to the first random number, the generator of the preset finite cyclic group, and the preset prime number through the following formula where r A is the first random number, p is the preset prime number, and g is the generator of the finite cyclic group G(p) of order p.
[0209] Among them, the preset prime number can be a large prime number. For example, the preset prime number is a prime number greater than 2 to the 164th power. The first random number is a positive random number. For example, the first random number is a 64-bit or 128-bit positive random number. The embodiments of the present application do not limit this.
[0210] Schematically, the first device signs the first data α with the private key of the first device to obtain the first signature value δ0 = sign A (α).
[0211] Step 402: After the second device authenticates the identity of the first device, it forwards the first data to the third device.
[0212] After receiving the first data sent by the first device, the second device authenticates the first device according to the first data. After the authentication is passed, the first data is forwarded to the third device.
[0213] Optionally, after receiving the first data and the first signature value sent by the first device, the second device verifies the signature of the first signature value through the public key of the first device stored. After the verification is passed (i.e., the identity authentication is passed), the first data is forwarded to the third device.
[0214] Optionally, the second device decrypts the first signature value through the public key of the first device stored to obtain the first hash value, and determines whether the first hash value is equal to the second hash value corresponding to the first data. If they are equal, it means the verification is passed and the first signature value is the signature from the first device. After the verification is passed, the second device forwards the first data to the third device.
[0215] Step 403: After receiving the first data, the third device generates the first key according to the first data and the second random number.
[0216] Optionally, after receiving the first data, the third device generates the second random number; the third device generates the first key according to the first data, the second random number and the preset prime number.
[0217] Schematically, the third device generates the first key according to the first data, the second random number and the preset prime number through the following formula where α is the first data, r C is the second random number, and p is the preset prime number.
[0218] Among them, the second random number is a positive random number. For example, the second random number is a 64-bit or 128-bit positive random number. This application embodiment does not limit this.
[0219] Step 404: The third device generates the second data according to the second random number and sends the second data to the second device.
[0220] Optionally, the third device generates second data based on a second random number, a generator of a preset finite cyclic group, and a preset prime number; the third device signs the first concatenated data with the private key of the third device to obtain a second signature value, which is used to verify the identity of the third device; the third device encrypts the second signature value with a first key to obtain a first encrypted value, where the first concatenated data is the data after concatenating the first data and the second data; the third device sends the second data and the first encrypted value to the second device.
[0221] Schematically, the third device generates second data according to the second random number, the generator of the preset finite cyclic group, and the preset prime number through the following formula where r C is the second random number, g is the generator of the preset finite cyclic group, and p is the preset prime number.
[0222] Schematically, the third device encrypts the second signature value with the first key to obtain a first encrypted value where the first concatenated data “α||β” is the data after concatenating the first data α and the second data β, sign C (α||β) is the second signature value, and k C is the first key.
[0223] Step 405: The second device forwards the second data sent by the third device to the first device.
[0224] Optionally, after receiving the second data and the first encrypted value, the second device signs the second concatenated data with the private key of the second device to obtain a third signature value, where the second concatenated data is the data after concatenating the second data and the first data; the second device sends the second data, the first encrypted value, and the third signature value to the first device, and the third signature value is used to verify the identity of the second device.
[0225] Schematically, the second device signs the second concatenated data with its own private key to obtain a third signature value δ B = sign B (β||α), where the second concatenated data “β||α” is the data after concatenating the second data β and the first data α.
[0226] Step 406: After the first device passes the authentication of the second device, it generates a second key according to the second data and the first random number, and the second key is the same as the first key.
[0227] Optionally, the first device verifies the signature of the third signature value through the public key of the second device stored, and after the verification passes, it generates a second key according to the second data, the first random number, and the preset prime number.
[0228] Optionally, the first device decrypts the third signature value using the public key of the second device stored therein to obtain a third hash value, and determines whether the third hash value is equal to the fourth hash value corresponding to the second concatenated data. If they are equal, it indicates that the verification is passed, the third signature value is the signature from the second device, and the value of the second data has not been changed. After the verification is passed, the first device generates a second key based on the second data, the first random number, and a preset prime number.
[0229] Schematically, the first device generates a second key based on the second data, the first random number, and a preset prime number through the following formula where β is the second data, r A is the first random number, and p is the preset prime number.
[0230] Step 407, after the first device authenticates the third device, it determines the second key as the target key.
[0231] Optionally, the first device decrypts the first encrypted value using the second key; after the first device decrypts successfully, it verifies the signature of the decrypted data using the public key of the third device stored therein; after the first device verifies successfully, it determines the second key as the target key.
[0232] Optionally, the first device decrypts the decrypted data using the public key of the third device stored therein to obtain a fifth hash value, and determines whether the fifth hash value is equal to the sixth hash value corresponding to the first concatenated data. If they are equal, it indicates that the verification is passed, and the decrypted data is the signature of the third device for the first concatenated data. After the verification is passed, the first device determines that the second key is the valid negotiated key, i.e., the target key.
[0233] Optionally, the first device encrypts the third signature value using the second key to obtain a second encrypted value, and sends the second encrypted value to the second device; after receiving the second encrypted value, the second device forwards the second encrypted value to the third device.
[0234] Schematically, the first device encrypts the third signature value using the second key to obtain a second encrypted value
[0235] Step 408, after the third device authenticates the second device, it determines the first key as the target key.
[0236] Optionally, after receiving the second encrypted value, the third device decrypts the second encrypted value using the first key; after the third device decrypts successfully, it verifies the signature of the decrypted data using the public key of the second device stored therein; after the third device verifies successfully, it determines the first key as the target key.
[0237] Optionally, the third device decrypts the decrypted data using the public key of the second device stored therein to obtain a seventh hash value, and determines whether the seventh hash value is equal to the eighth hash value corresponding to the second concatenated data. If they are equal, it indicates that the verification is passed, and the decrypted data is the signature of the second device for the second concatenated data. After the verification is passed, it is determined that the key negotiation is successful, and the third device determines that the first key is the effectively negotiated key, i.e., the target key.
[0238] Optionally, after the first device and the third device negotiate to obtain the target key through the second device, a secure channel is established based on the target key. After the establishment of the secure channel is completed, the first device and the third device perform encrypted communication through the secure channel. Among them, the secure channel is a secure channel between the first device, the second device, and the third device established based on the target key.
[0239] Optionally, after the third device determines the first key as the target key, a secure channel between the first device, the second device, and the third device is established based on the target key.
[0240] Optionally, the encrypted communication between the first device and the third device through the secure channel includes the following two possible implementation manners:
[0241] In one possible implementation manner, the first device encrypts the first data using the target key of the secure channel to obtain the second data, and sends the second data to the second device through the secure channel. The first data is the plaintext data of the content to be processed; the second device forwards the second data to the third device through the secure channel; the third device decrypts the second data using the target key of the secure channel to obtain the first data.
[0242] For example, the first device is the terminal device of the first object, the second device is the terminal device of the second object, the third device is the printer device of the second object, and the content to be processed is the data content to be printed. Another example is that the first device is the terminal device of the first object, the second device is the terminal device of the second object, the third device is the multimedia playback device of the second object, and the content to be processed is the multimedia content to be played. Among them, the first object is different from the second object. The embodiments of the present application do not limit this.
[0243] In another possible implementation manner, the third device encrypts the first data using the target key of the secure channel to obtain the second data, and sends the second data to the second device through the secure channel. The first data is the plaintext data of the content to be processed; the second device forwards the second data to the first device through the secure channel; the first device decrypts the second data using the target key to obtain the first data.
[0244] For example, the first device is the terminal device of the first object, the second device is the terminal device of the second object, and the third device is the medical detection device of the second object (such as a smart scale or a blood pressure monitor), and the content to be processed is the medical detection result to be displayed. Among them, the first object is different from the second object. The embodiments of the present application do not limit this.
[0245] It should be noted that the relevant description of the encrypted communication between the first device and the third device through the secure channel can refer to the relevant details in the following embodiments and will not be introduced here first.
[0246] Optionally, when the second device receives a preset trigger signal, it sends a notification message to the first device and the third device, and the notification message indicates the cancellation of the authorization for the first device. Or, when the second device receives a preset trigger signal, it no longer forwards the data from the first device and the third device.
[0247] Among them, the preset trigger signal is a user operation signal for triggering the cancellation of the authorization for the first device. Optionally, the preset trigger signal is a user operation signal acting on a specified control. Illustratively, the preset trigger signal includes any one or a combination of a click operation signal, a slide operation signal, a press operation signal, and a long press operation signal.
[0248] In other possible implementation manners, the preset trigger signal can also be implemented in a voice form. The embodiments of the present application do not limit this.
[0249] In a schematic example, as Figure 5 shown, the data communication method provided by the embodiments of the present application includes but is not limited to the following steps: Step 501, the second device sends the first information to the third device, and the first information includes the public key of the second device; Step 502, the third device sends the second information to the second device, and the second information includes the public key of the third device; Step 503, the first device sends an authorization request to the second device, and the authorization request includes the public key of the first device; Step 504, after receiving the authorization request, the second device sends the third information to the first device, and the third information includes the public key of the second device and the public key of the third device; Step 505, when authorized by the second device, the first device performs identity authentication and negotiation of the target key with the third device through the second device to establish a secure channel.
[0250] In summary, in the embodiment of the present application, the second device serves as a relay node between the first device and the third device. The first device sends an authorization request to the second device, and the authorization request is used to request to obtain the device resources or capabilities of the third device. The first device negotiates a target key with the third device through the second device under the authorization of the second device, so that subsequently, the first device can perform encrypted communication with the third device through the second device based on the target key. On the one hand, after the key negotiation process passes, the first device and the third device establish the target key. Although the second device can read the interaction data between the first device and the third device, it has no way to obtain the random numbers generated by the first device and the third device respectively, and thus has no way to calculate the target key. Therefore, in the subsequent encrypted communication process, the second device cannot obtain the plaintext data exchanged between the first device and the third device, realizing the encryption protection of third-party data and not leaking it to other devices except the two, ensuring the confidentiality and reliability of data transmission.
[0251] On the other hand, in the related art, after the authorization service device completes the authorization, it no longer participates in the subsequent interaction between the user device and the service device, resulting in additional installation or configuration operations (such as installing a printer driver or configuration) for the user device. In the embodiment of the present application, however, the second device of the authorization service party still serves as a relay node between the first device of the authorization request party and the third device of the authorization service party after the authorization is completed, that is, the direct interaction object of the first device during the encrypted communication with the third device is the second device, so that the first device does not need to install additional applications, configure or register an account when using the third device, and can directly use the authorized third device.
[0252] On the other hand, since the second device still serves as a relay node between the first device and the third device after the authorization is completed, that is, the direct interaction object of the third device during the encrypted communication between the first device and the third device is the second device, the third device does not need to expose its device information (such as IP address, port number, version number, etc.) to the outside (i.e., to the first device).
[0253] On the other hand, when the second device receives a preset trigger signal, it can send a notification message indicating cancellation of authorization to the first device and the third device, or can stop forwarding data from the first device and the third device, so that the second device, as a relay node between the first device and the third device, has the ability to cancel authorization at any time, that is, the second device can revoke the authorization for the first device.
[0254] On the other hand, considering that the update cycle of the third device is long and the difficulty of software system update is large, the solution provided in the embodiment of the present application does not require modification of the code of the third device and can be directly applied to the current third device, reducing the additional user operation burden.
[0255] The data communication method provided by the embodiments of the present application will be introduced below by several exemplary embodiments.
[0256] In a schematic example, the first device is the terminal device of user B, the second device is the terminal device of user A, and the third device is the printer of user A. When user B goes to user A's company and needs to print materials, since the materials involve sensitive information of user B, user B does not want the terminal device of user A to be able to save the printed materials. And since the terminal device of user B includes sensitive materials, user B does not want to install new software (such as a printer driver) on the terminal device. For user A, they do not want to randomly authorize the printing permission of the printer to prevent the abuse of printer resources and prevent the situation of being attacked due to the exposure of the printer IP address and port number.
[0257] As Figure 6a shown, when the terminal device 61 of user B, the terminal device 62 of user A, and the printer 63 of user A interact, the terminal device 62 of user A acts as a relay node, forwards the data between the terminal device 61 of user B and the printer 63 of user A according to the data communication method provided by the embodiments of the present application, and negotiates the target key of the secure channel. After that, the terminal device 61 of user B encrypts the data content to be printed with the target key of the secure channel (i.e., k A ) and sends it to the terminal device 62 of user A. The terminal device 62 of user A forwards the received encrypted data to the printer 63. After receiving the encrypted data, the printer 63 decrypts the encrypted data with the target key of the secure channel (i.e., k C ) and performs a printing operation. For example, the data content to be printed is three selected pictures. As Figure 6b shown, after the terminal device 61 of user B receives the selection signal of the three pictures, when it detects a click operation signal acting on the sharing control 64, it performs device discovery, and displays the device identifier "John's P40" of other discovered terminal devices and the device identifier "Living room printer" of the printer 63 of user A on the user interface 65. When the terminal device 61 of user B detects a click operation signal acting on the device identifier "Living room printer" on the user interface 65, it sends an authorization request to the terminal device 62 of user A. With the authorization of the terminal device 62 of user A, the terminal device 61 of user B negotiates the target key with the printer 63 of user A through the terminal device 62 of user A. After the key negotiation is completed, the terminal device 61 of user B encrypts the three selected pictures with the target key of the secure channel (i.e., k A)Encrypt to obtain the encrypted data, and send the encrypted data to the terminal device 62 of user A. After the encrypted data is successfully sent, the terminal device 61 of user B displays a prompt message "Sent successfully" on the user interface 65. The terminal device 62 of user A forwards the received encrypted data to the printer 63. After receiving the encrypted data, the printer 63 decrypts the encrypted data using the target key of the secure channel (i.e., k C )and performs a printing operation.
[0258] It should be noted that Figure 6a and Figure 6b only take the terminal device 61 of user B and the terminal device 62 of user A as mobile phones for introduction, and the embodiments of the present application are not limited thereto.
[0259] In this embodiment, the terminal device of user B only interacts with the terminal device of user A, and the printer of user A only interacts with the terminal device of user A. On the one hand, when the terminal device of user B uses the printer of user A for printing, the data sent is only in plaintext at the local and printer sides, and the terminal device of user A cannot obtain the plaintext data of the document content. On the other hand, when the terminal device of user B uses the printer of user A, it can enjoy the secure encrypted printing service without installing a printer driver or configuration. On the other hand, information such as the IP address, port number, and version number of the printer does not need to be visible to the outside. On the other hand, the terminal device of user A is between the terminal device of user B and the printer device and can terminate this authorization at any time.
[0260] In another illustrative example, the first device is the terminal device of user B, the second device is the terminal device of user A, and the third device is the speaker and smart screen of user A. When user B visits user A's home, since user B is a member of some video applications, user B hopes to use the speaker and smart screen of user A for video playback. However, user A does not want to display the information of his smart screen and speaker to user B to prevent attacks on the devices caused by the leakage of IP address and port number information.
[0261] As Figure 7 shown, when the terminal device 71 of user B, the terminal device 72 of user A, and the speaker and smart screen 73 of user A interact, the terminal device 72 of user A acts as a relay node, forwards the data between the terminal device 71 of user B and the speaker and smart screen 73 of user A according to the data communication method provided by the embodiments of the present application, and negotiates the target key of the secure channel. Then, the terminal device 71 of user B encrypts the multimedia content to be played using the target key of the secure channel (i.e., k A) Encrypt it and send it to the terminal device 72 of user A. The terminal device 72 of user A forwards the received encrypted data to the speaker and smart screen 73. After receiving the encrypted data, the speaker and smart screen 73 use the target key of the secure channel (i.e., k C ) to decrypt the encrypted data and perform media playback operations. For example, if the multimedia content to be played is a selected video, after the terminal device 71 of user B receives the selection signal of the video, when it detects a click operation signal on the sharing control, it performs device discovery and displays the device identifier "John's P40" of other discovered terminal devices and the device identifier "Speaker and Smart Screen" of the speaker and smart screen 73 of user A on the user interface. When the terminal device 71 of user B detects a click operation signal on the device identifier "Speaker and Smart Screen" on the user interface, it sends an authorization request to the terminal device 72 of user A. With the authorization of the terminal device 72 of user A, the terminal device 71 of user B negotiates the target key with the speaker and smart screen 73 of user A through the terminal device 72 of user A. After the key negotiation is completed, the terminal device 71 of user B encrypts the selected video using the target key of the secure channel (i.e., k A ) to obtain encrypted data, and sends the encrypted data to the terminal device 72 of user A. After the encrypted data is successfully sent, the terminal device 71 of user B displays a prompt message "Sent successfully" on the user interface. The terminal device 72 of user A forwards the received encrypted data to the speaker and smart screen 73 of user A. After receiving the encrypted data, the speaker and smart screen 73 use the target key of the secure channel (i.e., k C ) to decrypt the encrypted data and perform video playback operations.
[0262] It should be noted that Figure 7 only the terminal device 71 of user B and the terminal device 72 of user A are taken as mobile phones for introduction, and the embodiments of the present application are not limited thereto.
[0263] In the related art, some applications can also directly share the screen with other user devices and have the ability to reclaim the sharing permission. However, the terminal device 71 of user B must use this application and needs to log in to this application with a relevant account, which has high requirements for the terminal device 71 of user B and greatly limits the usage scenarios.
[0264] In this embodiment, the terminal device of User B only interacts with the terminal device of User A, and the speaker and smart screen of User A only interact with the terminal device of User A. On the one hand, while the terminal device of User B uses the speaker and smart screen of User A for media playback, the data sent over is only in plaintext at the local device, the speaker, and the smart screen, and the terminal device of User A cannot obtain the plaintext data of the multimedia content. On the other hand, when the terminal device of User B uses the speaker and smart screen of User A, the terminal device of User B does not need to install additional applications or configure and register accounts, and can directly use the authorized speaker and smart screen. On the other hand, information such as the IP address, port number, and version number of the speaker and smart screen of User A does not need to be visible to the outside. On the other hand, the terminal device of User A is between the terminal device of User B and the speaker and smart screen device, and can terminate this authorization at any time.
[0265] In another illustrative example, the first device is the terminal device of User B, the second device is the terminal device of User A, and the third device is the medical detection device of User A. When User B goes to User A's home and sees a medical detection device such as a smart scale or a blood pressure monitor and hopes to use it, but does not want to configure it, or the user does not want to install relevant applications or configure relevant accounts.
[0266] As Figure 8 shown, when the terminal device 81 of User B, the terminal device 82 of User A, and the medical detection device 83 of User A interact, the terminal device 82 of User A acts as a relay node and forwards the data between the terminal device 81 of User B and the medical detection device 83 according to the data communication method provided in the embodiments of the present application to negotiate the target key of the secure channel. After that, the medical detection device 83 of User A encrypts the medical detection result using the target key of the secure channel (i.e., k C ) and sends it to the terminal device 82 of User A. The terminal device 82 of User A forwards the received encrypted data to the terminal device 81 of User B. After receiving the encrypted data, the terminal device 81 of User B uses the target key of the secure channel (i.e., k A)Decrypt the encrypted data and display the medical test result. For example, when the terminal device 81 of user B detects a preset trigger signal, it performs device discovery, and displays the device identifiers of other detected terminal devices, "John's P40", and the device identifier of user A's medical test device 83, "Smart Scale", on the user interface. When the terminal device 81 of user B detects a click operation signal acting on the device identifier "Smart Scale" on the user interface, it sends an authorization request to the terminal device 82 of user A. With the authorization of the terminal device 82 of user A, the terminal device 81 of user B negotiates the target key with the medical test device 83 of user A through the terminal device 82 of user A. After the key negotiation is completed, the medical test device 83 of user A encrypts the detection result of the smart scale using the target key of the secure channel (i.e., k C )to obtain the encrypted data, and sends the encrypted data to the terminal device 82 of user A. The terminal device 82 of user A forwards the received encrypted data to the terminal device 81 of user B. After receiving the encrypted data, the terminal device 81 of user B decrypts the encrypted data using the target key of the secure channel (i.e., k A )and displays the detection result of the smart scale.
[0267] It should be noted that Figure 8 only the terminal device 81 of user B and the terminal device 82 of user A are taken as examples of mobile phones for introduction, and the embodiments of the present application are not limited thereto.
[0268] In this embodiment, the terminal device of user B only interacts with the terminal device of user A, and the medical test device of user A only interacts with the terminal device of user A. On the one hand, while the terminal device of user B is using the medical test device of user A for measurement, the data sent by the medical test device is only plaintext data locally and at the terminal device of user B, and the terminal device of user A cannot obtain the plaintext data of the medical test result. On the other hand, when the terminal device of user B is using the medical test device of user A, there is no need to install additional applications or configure and register accounts. On the other hand, information such as the IP address, port number, and version number of the medical test device does not need to be visible to the outside. On the other hand, the terminal device of user A is between the terminal device of user B and the medical test device, and can terminate this authorization at any time.
[0269] Please refer to Figure 9 , which shows a flowchart of a data communication method provided by another exemplary embodiment of the present application. This embodiment is used in the Figure 2 shown distributed system as an example. The method includes the following steps.
[0270] Step 901: The first device sends an authorization request to the second device. The authorization request is used to request access to the device resources or capabilities of the third device.
[0271] Step 902: When the second device authorizes, the first device negotiates a target key with the third device through the second device. The target key is determined based on the interaction data between the first device and the third device and their respective generated random numbers, and the interaction data is determined according to the random numbers.
[0272] Step 903: Based on the target key, the first device conducts encrypted communication with the third device through the second device.
[0273] It should be noted that for the relevant details of each step in this embodiment, reference can be made to the relevant descriptions in the above embodiments, which will not be elaborated here.
[0274] Please refer to Figure 10 , which shows a schematic structural diagram of the first device provided by an exemplary embodiment of the present application. The first device may be a mobile terminal. For example, the first device is a mobile phone. The embodiments of the present application do not limit this. The first device includes: a processor 101, a receiver 102, a transmitter 103, a memory 104, and a bus 105.
[0275] The processor 101 includes one or more processing cores. The processor 101 executes various functional applications and information processing by running software programs and modules.
[0276] The receiver 102 and the transmitter 103 may be implemented as a communication component. The communication component may be a communication chip, which may include a receiving module, a transmitting module, a modulation and demodulation module, etc., for modulating and / or demodulating information and receiving or transmitting the information through a wireless signal.
[0277] The memory 104 is connected to the processor 101 through the bus 105. The memory 104 stores the necessary program instructions and data of the first device.
[0278] The processor 101 is configured to execute the program instructions and data in the memory 104 to implement the functions of each step executed by the first device in various method embodiments of the present application.
[0279] The processor 101 controls the receiver 102 to implement the receiving function on the first device side in the above steps by running at least one program instruction in the memory 104; the processor 101 controls the transmitter 103 to implement the sending function on the first device side in the above steps by running at least one program instruction in the memory 104.
[0280] In addition, the memory 104 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0281] It can be understood that Figure 10 only a simplified design of the first device is shown. In other embodiments, the first device may include any number of transmitters, receivers, processors, controllers, memories, communication units, etc., and all first devices that can implement the present application are within the protection scope of the present application.
[0282] Embodiments of the present application provide a data communication device, which includes: a processor; a memory for storing processor-executable instructions; wherein, when the processor is configured to execute the instructions, the method executed by the above-mentioned first device is implemented.
[0283] Embodiments of the present application provide a data communication device, which includes at least one unit, and the at least one unit is used to implement the method executed by the above-mentioned first device.
[0284] Embodiments of the present application provide a non-volatile computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method executed by the above-mentioned first device is implemented.
[0285] Embodiments of the present application provide a computer program product, which includes computer-readable code, or a non-volatile computer-readable storage medium carrying the computer-readable code. When the computer-readable code runs in an electronic device, the processor in the electronic device executes the method executed by the above-mentioned first device.
[0286] A computer-readable storage medium can be a tangible device that holds and stores instructions for use by an instruction execution device. For example, computer-readable storage media include, but are not limited to: electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, mechanically encoded devices such as punch cards or raised structures in grooves having instructions stored thereon, and any suitable combination of the foregoing.
[0287] The computer-readable program instructions or code described herein can be downloaded from a computer-readable storage medium to various computing / processing devices, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.
[0288] The computer program instructions for performing the operations of the present application may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine - related instructions, microcode, firmware instructions, state - setting data, or source code or object code written in any combination of one or more programming languages, including object - oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer - readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand - alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer - readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field - programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer - readable program instructions to implement various aspects of the present application.
[0289] Aspects of the present application are described herein with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer - readable program instructions.
[0290] These computer - readable program instructions can be provided to a processor of a general - purpose computer, a special - purpose computer, or other programmable data - processing apparatus, thereby producing a machine such that when these instructions are executed by the processor of the computer or other programmable data - processing apparatus, a device is produced that implements the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer - readable program instructions can also be stored in a computer - readable storage medium, which causes a computer, a programmable data - processing apparatus, and / or other devices to operate in a specific manner. Thus, the computer - readable medium storing the instructions includes a manufacture, which includes instructions for implementing various aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0291] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0292] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of apparatus, systems, methods, and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram may represent a module, a segment of a program, or a portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the boxes may occur out of the order noted in the figures. For example, two consecutive boxes may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved.
[0293] It should also be noted that each box of the block diagrams and / or flowcharts, and combinations of boxes in the block diagrams and / or flowcharts, can be implemented by hardware (e.g., circuitry or an ASIC (Application Specific Integrated Circuit)) that performs the corresponding functions or acts, or can be implemented by a combination of hardware and software, such as firmware.
[0294] Although the present application has been described in connection with the various embodiments, it will be understood by those skilled in the art that various changes in the disclosed embodiments can be understood and effected while practicing the claimed application. In the claims, the term "comprising" does not exclude other elements or steps, and the singular forms "a" or "an" do not exclude a plurality. A single processor or other unit may implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not indicate that these measures cannot be combined to produce a favorable effect.
[0295] The embodiments of the present application have been described above. The above description is exemplary and not exhaustive, and is also not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of the terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A data communication method, characterized in that, In a distributed system, the distributed system includes a first device, a second device, and a third device, and the second device is respectively communicatively connected to the first device and the third device. The method includes: The first device sends an authorization request to the second device, and the authorization request is used to request to obtain the device resources or capabilities of the third device; When the first device is authorized by the second device, the first device negotiates a target key with the third device through the second device. The target key is determined based on the interaction data between the first device and the third device and their respective generated random numbers. The interaction data is determined according to the random numbers, and the interaction data does not include the random numbers; Based on the target key, the first device conducts encrypted communication with the third device through the second device.
2. The method according to claim 1, wherein The first device is a terminal device of the authorization requester, the second device is a terminal device of the authorization service provider, and the third device is an Internet of Things (IoT) device of the authorization service provider.
3. The method according to claim 1 or 2, characterized in that The interaction data includes first data and second data. When the first device is authorized by the second device, the first device negotiates a target key with the third device through the second device, including: When the first device is authorized by the second device, the first device sends the first data to the second device, and the first data is determined according to a first random number; After the second device authenticates the identity of the first device, the second device forwards the first data to the third device; After receiving the first data, the third device generates a first key according to the first data and a second random number; The second device forwards the second data sent by the third device to the first device, and the second data is determined according to the second random number; After the first device authenticates the identity of the second device, the first device generates a second key according to the second data and the first random number, and the second key is the same as the first key; After the first device authenticates the identity of the third device, the first device determines the second key as the target key; After the third device authenticates the identity of the second device, the third device determines the first key as the target key.
4. The method according to claim 3, wherein When the first device sends the first data to the second device when authorized by the second device, it includes: When the first device is authorized by the second device, the first device generates the first data according to the first random number, a preset generator of a finite cyclic group, and a preset prime number; The first device signs the first data with the private key of the first device to obtain a first signature value. The private key and the public key of the first device are an asymmetric key pair, and the first signature value is used to verify the identity of the first device; The first device sends the first data and the first signature value to the second device; After the second device authenticates the identity of the first device, the second device forwards the first data to the third device, including: The second device verifies the signature of the first signature value using the public key of the first device stored therein, and forwards the first data to the third device after successful verification.
5. The method according to claim 3, characterized in that, After receiving the first data, the third device generates a first key based on the first data and a second random number, including: The third device generates the second random number after receiving the first data; The third device generates the first key based on the first data, the second random number, and a preset prime number.
6. The method according to claim 3, wherein Before the second device forwards the second data sent by the third device to the first device, it further includes: The third device generates the second data based on the second random number, a generator of a preset finite cyclic group, and a preset prime number; The third device signs the first concatenated data using the private key of the third device to obtain a second signature value, which is used to verify the identity of the third device; The third device encrypts the second signature value using the first key to obtain a first encrypted value, where the first concatenated data is the data obtained by concatenating the first data and the second data; The third device sends the second data and the first encrypted value to the second device; The second device forwards the second data sent by the third device to the first device, including: After receiving the second data and the first encrypted value, the second device signs the second concatenated data using the private key of the second device to obtain a third signature value, where the second concatenated data is the data obtained by concatenating the second data and the first data; The second device sends the second data, the first encrypted value, and the third signature value to the first device, and the third signature value is used to verify the identity of the second device; After the first device successfully verifies the identity of the second device, it generates a second key based on the second data and a first random number, including: The first device verifies the signature of the third signature value using the public key of the second device stored therein, and after successful verification, generates the second key based on the second data, the first random number, and the preset prime number.
7. The method according to claim 6, characterized in that After the first device successfully verifies the identity of the third device, it determines the second key as the target key, including: The first device decrypts the first encrypted value using the second key; After successful decryption, the first device verifies the signature of the decrypted data using the public key of the third device stored therein; After successful verification, the first device determines the second key as the target key.
8. The method according to claim 6, characterized in that Before the third device determines the first key as the target key after successfully verifying the identity of the second device, it further includes: The first device encrypts the third signature value using the second key to obtain a second encrypted value, and sends the second encrypted value to the second device; After receiving the second encrypted value, the second device forwards the second encrypted value to the third device; After the third device authenticates the second device, determining the first key as the target key includes: After the third device receives the second encrypted value, decrypting the second encrypted value with the first key; After successful decryption, the third device performs signature verification on the decrypted data using the public key of the second device stored therein; After the verification passes, the third device determines the first key as the target key.
9. The method according to any one of claims 4 to 8, characterized in that Before the first device negotiates the target key with the third device through the second device under the authorization of the second device, it further includes: The second device and the third device exchange their respective public keys; The first device and the second device exchange their respective public keys, and the first device receives the public key of the third device sent by the second device.
10. The method according to claim 1, wherein Based on the target key, the first device performs encrypted communication with the third device through the second device, including: The first device encrypts the first data with the target key to obtain the second data, and sends the second data to the second device. The first data is the plaintext data of the content to be processed; The second device forwards the second data to the third device; The third device decrypts the second data with the target key to obtain the first data.
11. The method according to claim 10, wherein The first device is the terminal device of the first object, the second device is the terminal device of the second object, and the first object is different from the second object; The third device is the printer device of the second object, and the content to be processed is the data content to be printed; or, the third device is the multimedia playback device of the second object, and the content to be processed is the multimedia content to be played.
12. A data communication method, characterized in that, For use in a first device, where the first device has a communication connection with a second device, and the second device has a communication connection with a third device, the method includes: Sending an authorization request to the second device, where the authorization request is used to request access to the device resources or capabilities of the third device; Under the authorization of the second device, negotiating a target key with the third device through the second device. The target key is determined based on the interaction data between the first device and the third device and their respective generated random numbers. The interaction data is determined based on the random numbers, and the interaction data does not include the random numbers; Based on the target key, performing encrypted communication with the third device through the second device.
13. The method according to claim 12, characterized in that, The first device is the terminal device of the authorization requester, the second device is the terminal device of the authorization service provider, and the third device is the Internet of Things (IoT) device of the authorization service provider.
14. The method according to claim 12 or 13, characterized in that, The interaction data includes the first data and the second data. The step of negotiating the target key with the third device through the second device under the authorization of the second device includes: Send the first data to the second device under the authorization of the second device. The first data is determined according to a first random number. After the first data indicates that the second device has passed the authentication of the first device, forward the first data to the third device. After receiving the first data, the third device generates a first key according to the first data and a second random number. The second device forwards the second data sent by the third device to the first device. The second data is determined according to the second random number. After passing the authentication of the second device, generate a second key according to the second data and the first random number. The second key is the same as the first key. After passing the authentication of the third device, determine the second key as the target key. After the third device passes the authentication of the second device, determine the first key as the target key.
15. The method according to claim 14, wherein The sending the first data to the second device under the authorization of the second device includes: Under the authorization of the second device, generate the first data according to the first random number, a generator of a preset finite cyclic group, and a preset prime number. Sign the first data with the private key of the first device to obtain a first signature value. The private key and the public key of the first device are an asymmetric key pair. The first signature value is used to verify the identity of the first device. Send the first data and the first signature value to the second device. The first signature value instructs the second device to perform signature verification on the first signature value through the stored public key of the first device. After the verification passes, forward the first data to the third device.
16. The method according to claim 14, wherein The third device is further configured to generate the second data according to the second random number, a generator of a preset finite cyclic group, and a preset prime number; sign the first concatenated data with the private key of the third device to obtain a second signature value. The second signature value is used to verify the identity of the third device. Encrypt the second signature value with the first key to obtain a first encrypted value. The first concatenated data is the data after concatenating the first data and the second data. Send the second data and the first encrypted value to the second device. The second device is further configured to, after receiving the second data and the first encrypted value, sign the second concatenated data with the private key of the second device to obtain a third signature value. The second concatenated data is the data after concatenating the second data and the first data. Send the second data, the first encrypted value, and the third signature value to the first device. The third signature value is used to verify the identity of the second device. After passing the authentication of the second device, generating a second key according to the second data and the first random number includes: Perform signature verification on the third signature value through the stored public key of the second device. After the verification is passed, the second key is generated according to the second data, the first random number, and the preset prime number.
17. The method according to claim 16, characterized in that After the authentication of the third device is passed, determining the second key as the target key includes: Decrypting the first encrypted value with the second key; After successful decryption, verifying the signature of the decrypted data with the public key of the third device stored; After the verification is passed, determining the second key as the target key.
18. The method according to claim 16, wherein The method further includes: Encrypting the third signature value with the second key to obtain a second encrypted value; Sending the second encrypted value to the second device, where the second encrypted value instructs the second device to forward the second encrypted value to the third device after receiving the second encrypted value; after receiving the second encrypted value, the third device decrypts the second encrypted value with the first key; after successful decryption, the third device verifies the signature of the decrypted data with the public key of the second device stored; after the verification is passed, the third device determines the first key as the target key.
19. The method according to any one of claims 15 to 18, characterized in that, Before negotiating the target key with the third device through the second device under the authorization of the second device, it further includes: Exchanging respective public keys with the second device and receiving the public key of the third device sent by the second device, where the second device and the third device have exchanged their respective public keys.
20. The method according to claim 12, wherein Based on the target key, performing encrypted communication between the second device and the third device includes: Encrypting the first data with the target key to obtain second data, where the first data is the plaintext data of the content to be processed; Sending the second data to the second device, where the second data instructs the second device to forward the second data to the third device; the third device decrypts the second data with the target key to obtain the first data.
21. The method according to claim 20, characterized in that, The first device is the terminal device of the first object, the second device is the terminal device of the second object, and the first object is different from the second object; The third device is the printer device of the second object, and the content to be processed is the data content to be printed; or, the third device is the multimedia playback device of the second object, and the content to be processed is the multimedia content to be played.
22. A distributed system, characterized in that, The distributed system includes a first device, a second device, and a third device, and the second device is respectively in communication connection with the first device and the third device. The first device is configured to send an authorization request to the second device, and the authorization request is used to request to obtain the device resources or capabilities of the third device; The first device is further configured to, under the authorization of the second device, negotiate a target key with the third device through the second device, where the target key is determined based on the interaction data between the first device and the third device and the randomly generated numbers by each, the interaction data is determined according to the random numbers, and the interaction data does not include the random numbers. The first device is further configured to perform encrypted communication with the third device through the second device based on the target key.
23. A data communication device, characterized in that, The device includes: a processor; a memory for storing instructions executable by the processor; wherein, when the processor is configured to execute the instructions, the method according to any one of claims 12-21 is implemented.
24. A non-volatile computer-readable storage medium storing computer program instructions thereon, characterized in that, When the computer program instructions are executed by the processor, the method according to any one of claims 12-21 is implemented.
25. A computer program product, the computer program product comprising computer-readable code, or a non-volatile computer-readable storage medium carrying the computer-readable code, characterized in that, When the computer-readable code runs in an electronic device, the processor in the electronic device executes the method according to any one of claims 12-21.
Citation Information
Patent Citations
Method, device and system for key agreement
CN101895877A
System and method for internet of things (IOT) video camera implementations
US20170171607A1