A method and apparatus for generating a secret key

By using specular parameters in key management to generate random vectors and generating a new target key in combination with the initial key, the problem of insecure key management in the prior art is solved, and the security of encrypted communication is improved.

CN115333727BActive Publication Date: 2025-06-24CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210820923.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-13
Publication Date
2025-06-24
Estimated Expiration
2042-07-13

AI Technical Summary

Technical Problem

In the management of encryption keys, fixed generation and timing replacement are easily intercepted and cracked, resulting in the security of encrypted communication being threatened.

Method used

By obtaining the initial key and specular parameters, when the initial key expires, a random vector is generated based on the specular parameters, and a new target key is generated in combination with the initial key.

Benefits of technology

It improves the complexity and randomness of key generation, enhances the security of encrypted communication, and reduces the possibility of key cracking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115333727B_ABST
    Figure CN115333727B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a key generation method and apparatus. The method includes: obtaining an initial key and a specular reflection parameter; when it is detected that the initial key exceeds a preset expiration time, generating a random vector based on the specular reflection parameter; and generating a target key based on the initial key and the random vector. The embodiment of the present invention can generate a random vector by using the specular reflection principle, improve the randomness of the random vector. At the same time, since the random vector is not directly applied to the key, but is combined with the previous key to generate a new key, the complexity of key generation is increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption algorithms, and in particular, to a key generation method and a key generation device. Background Art

[0002] With the rapid development of the Internet, a huge amount of network transmission and storage data is generated every day, and the security of data has received unprecedented attention. Once data such as personal information, business information, and confidential information is cracked, it will have a great impact on society and people's lives.

[0003] With the advent of the data explosion era, the encrypted transmission and storage of data have received more and more extensive attention. Among them, encryption algorithms and encryption keys are the core of the security system. Most modern cryptography is based on the public transparency of encryption algorithms and relies on the secure management of passwords to ensure data security. Key management includes processes such as key generation, distribution, storage, update, and destruction. Designing a key management system that forms a secure closed loop and can resist attacks in various links requires very professional knowledge and capabilities.

[0004] Currently, the management of encryption keys generally adopts fixed generation and regular replacement, and it is easy to be intercepted and cracked during the generation and replacement processes, bringing unsafe factors to production and life. Summary of the Invention

[0005] In view of the above problems, embodiments of the present invention are proposed to provide a key generation method and a corresponding key generation device that overcome the above problems or at least partially solve the above problems.

[0006] To solve the above problems, embodiments of the present invention disclose a key generation method, and the method includes:

[0007] Obtain an initial key and a specular reflection parameter;

[0008] When it is detected that the initial key exceeds a preset expiration time, generate a random vector based on the specular reflection parameter;

[0009] Generate a target key based on the initial key and the random vector.

[0010] Optionally, the specular reflection parameter includes a specular rotation speed, an irradiation angle, an irradiation time interval, and a key length.

[0011] Optionally, the generating a random vector based on the specular reflection parameter includes:

[0012] Rotate a preset virtual mirror according to the specular rotation speed;

[0013] Control a preset virtual light source to output virtual light rays to the virtual mirror surface according to the irradiation time interval and the irradiation angle;

[0014] Determine that the virtual light rays reach multiple target light points in a preset coordinate system after being reflected by the rotating virtual mirror surface; the number of the target light points matches the key length;

[0015] Generate a random vector based on the target light points.

[0016] Optionally, the generating a random vector based on the key length and the target light points includes:

[0017] Calculate the distance between each of the target light points and the origin of the coordinate axis;

[0018] Generate a random vector with the distances corresponding to each target light point as elements.

[0019] Optionally, the generating a target key based on the initial key and the random vector includes:

[0020] Encrypt the random vector with the initial key to obtain a first key to be verified;

[0021] Verify the first key to be verified according to a preset rule;

[0022] If the first key to be verified passes the verification, determine that the first key to be verified is the target key.

[0023] Optionally, the method is applied to a first terminal, and the first terminal is connected to a second terminal for communication; the second terminal is used to generate a second key to be verified based on the initial key and the mirror reflection parameters, and generate a second hash value corresponding to the second verification key; the verifying the key to be verified according to a preset rule includes:

[0024] Perform a hash calculation on the first key to be verified to obtain a second hash value;

[0025] Send the second hash value to the second terminal; the second terminal is used to output a verification passed message when the first hash value is the same as the second hash value;

[0026] When receiving the verification passed message, determine that the first hash value passes the verification.

[0027] Optionally, after generating the target key, the method includes:

[0028] Determine that the target key is the new initial key;

[0029] Determine the expiration time corresponding to the new initial key.

[0030] An embodiment of the present invention also discloses a key generation device, which is applied to an encryption end. The device includes:

[0031] An acquisition module, configured to acquire an initial key and a specular reflection parameter;

[0032] A random vector generation module, configured to generate a random vector based on the specular reflection parameter when it is detected that the initial key exceeds a preset expiration time;

[0033] A target key generation module, configured to generate a target key based on the initial key and the random vector.

[0034] An embodiment of the present invention also discloses an electronic device, including a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the steps of the key generation method described above are implemented.

[0035] An embodiment of the present invention also discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the key generation method described above are implemented.

[0036] The embodiments of the present invention have the following advantages:

[0037] By acquiring an initial key and a specular reflection parameter; generating a random vector based on the specular reflection parameter when it is detected that the initial key exceeds a preset expiration time; generating a target key based on the initial key and the random vector, both the encryption party and the decryption party of the encrypted communication replace the initial key with the target key and perform encrypted communication. The random vector is generated by using the specular reflection principle, which improves the randomness of the random vector. At the same time, since the random vector is not directly applied to the key, but is combined with the previous key to generate a new key, the complexity of key generation is increased, and it is necessary to obtain the previous key and the random vector at the same time to implement cracking, which improves the security of encrypted communication. Description of the Drawings

[0038] Figure 1 is a flowchart of the steps of an embodiment of a key generation method of the present invention;

[0039] Figure 2 is a schematic diagram of a rotating specular reflection light source of the present invention;

[0040] Figure 3 is a schematic diagram of a key generation and dynamic update process based on a rotating mirror of the present invention;

[0041] Figure 4 It is a structural block diagram of an embodiment of a key generation device of the present invention. Specific embodiments

[0042] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0043] In the field of encrypted data transmission, generally, the encrypting party encrypts the data according to a key and transmits the encrypted data to the decrypting party. The decrypting party decrypts the data according to the key received and adapted to the encrypted data, so as to obtain the encrypted data. That is, both the encrypting party and the decrypting party need a key to complete data encryption and decryption. The embodiments of the present invention are applicable to both the encrypting party and the decrypting party. Hereinafter, taking the encrypting party as an example, the embodiments of the present invention will be described.

[0044] Refer to Figure 1 , which shows a step flowchart of an embodiment of a key generation method of the present invention, and specifically may include the following steps:

[0045] Step 101, obtain an initial key and a specular reflection parameter;

[0046] The encrypting party can obtain an initial key M0 of a specified length by means of random generation, and pre-determine the specular reflection parameter based on the specular reflection principle.

[0047] In practical applications, the encryption method is delivered offline to the decrypting party. The encrypting party and the decrypting party read the initial key at the same time, and both parties can perform encrypted communication based on the initial key.

[0048] Step 102, when it is detected that the initial key exceeds a preset expiration time, generate a random vector based on the specular reflection parameter;

[0049] To improve the security of the key, a valid time period is set for the key, for example: 1 week, 10 days, etc. A corresponding expiration time is set for the initial key, for example: 0:00 on February 2, 2022. When it is detected that the current time reaches the expiration time corresponding to the initial key, the key needs to be updated to continue the encrypted communication between the encrypting party and the decrypting party.

[0050] In the embodiments of the present invention, the key is updated based on the random vector. Therefore, when it is detected that the initial key M0 exceeds the preset expiration time, a random vector is generated based on the specular reflection parameter, so as to generate a random vector based on the specular reflection principle and improve the randomness of the random vector.

[0051] At the same time, the encrypting party sends the specular reflection parameter to the decrypting party, and the decrypting party also generates a corresponding random vector.

[0052] Step 103: Generate a target key based on the initial key and the random vector.

[0053] Based on the initial key, the encryptor combines the random vector to generate the target key, increasing the complexity of key generation. One needs to obtain both the previous key and the random vector simultaneously to implement cracking, reducing the likelihood of the target key being cracked.

[0054] Meanwhile, the decryptor generates the target key in the same way. When it is determined that the keys generated by both parties are the same, the encryptor and the decryptor update the initial key with the target key and perform encrypted communication according to the target key (i.e., the updated initial key).

[0055] In the embodiment of the present invention, by obtaining the initial key and the specular reflection parameters; when it is detected that the initial key exceeds the preset expiration time, a random vector is generated based on the specular reflection parameters; based on the initial key and the random vector, a target key is generated. Both the encryptor and the decryptor of the encrypted communication replace the initial key with the target key and perform encrypted communication. The random vector is generated by using the specular reflection principle, improving the randomness of the random vector. At the same time, since the random vector is not directly applied to the key but combined with the previous key to generate a new key, the complexity of key generation is increased. One needs to obtain both the previous key and the random vector simultaneously to implement cracking, improving the security of encrypted communication.

[0056] In an alternative embodiment of the present invention, the specular reflection parameters include the specular rotation speed, the irradiation angle, the irradiation time interval, and the key length.

[0057] The encryptor and the decryptor can simulate the specular rotation algorithm based on the specular rotation speed and the irradiation angle, and then collect a number of discrete data at the irradiation time interval based on the specular reflection principle, and generate a random vector from the number of discrete data according to the key length.

[0058] Refer to Figure 2 , which shows a schematic diagram of a rotating specular reflection light source of the present invention. In an alternative embodiment of the present invention, the generating the random vector based on the specular reflection parameters includes: rotating a preset virtual specular according to the specular rotation speed; determining the number of irradiations according to the key length; controlling a preset virtual light source to output virtual light to the virtual specular according to the number of irradiations, the irradiation time interval, and the irradiation angle; determining a plurality of target light points where the virtual light reaches a preset coordinate system after being reflected by the rotated virtual specular; generating a random vector based on the target light points.

[0059] Figure 2 In, the X-axis and the Y-axis form a plane coordinate system, and the encryptor simulates a preset virtual specular according to the specular rotation speed (Figure 2 Rotate the multi - mirror (in ) and control the preset virtual light source to emit virtual light rays towards the virtual mirror surface according to the number of irradiations, the irradiation time interval, and the irradiation angle. After the virtual light rays are specularly reflected by the virtual mirror surface, they reach the plane coordinate system, and the target light points (x i , y i ) where the virtual light rays irradiate on the coordinate system are determined. Then, a random vector is generated based on the number of target light points corresponding to the key length. For example, if the key length is 3, a random vector is generated based on 3 target light points.

[0060] In an alternative embodiment of the present invention, generating a random vector based on the target light points includes: calculating the distance between each of the target light points and the origin of the coordinate axis; generating a random vector with the distances corresponding to each target light point as elements.

[0061] Calculate the distance between the target light point (x i , x i ) and the origin of the coordinate axis (0, 0). After n irradiations, a sequence D = [d1, d2,... d n is formed with the distances corresponding to each target light point as elements. The larger the value of the key length, the better the randomness and hashability, and the more secure the key.

[0062] In practical applications, the sequence D can be used as the random vector, or multiple sequences can be obtained in the above - mentioned manner, and a random vector is obtained based on the combination of several sequences.

[0063] In an alternative embodiment of the present invention, step 104 includes: encrypting the random vector with the initial key to obtain a first key to be verified; verifying the first key to be verified according to a preset rule; if the first key to be verified passes the verification, determining the first key to be verified as the target key.

[0064] Encrypt the random vector with the initial key to obtain a first encrypted key to be verified. When the first encrypted key to be verified passes the verification rule jointly executed by the encrypting party and the decrypting party, determine the first key to be verified as the target key, so as to synchronize the target key between the encrypting party and the decrypting party. Then, both parties can use the target key for subsequent encrypted communication.

[0065] When encrypting the random vector with the initial key, the encryption rule used can be determined according to actual needs to generate keys of different strengths and be applicable to various production environments.

[0066] The encrypting party and the decrypting party are two different terminals. The specific verification process can be executed at the encrypting party or the decrypting party. The embodiments of the present invention do not limit this.

[0067] Taking the first terminal as the encrypting party as an example, the embodiments of the present invention are applied to the first terminal, and the first terminal is connected and communicates with a second terminal (i.e., the decrypting party); the second terminal is configured to generate a second key to be verified and a first hash value corresponding to the second verification key based on the initial key and the specular reflection parameter; the verification of the key to be verified according to a preset rule includes: performing a hash calculation on the first key to be verified to obtain a second hash value; sending the second hash value to the second terminal; the second terminal is configured to output a verification passed message when the first hash value is the same as the second hash value; when receiving the verification passed message, it is determined that the first hash value passes the verification.

[0068] The decrypting party obtains a random vector in the same manner as the above encrypting party, and then uses the initial key and the random vector received earlier to generate a second key to be verified, and performs a hash calculation on the second key to be verified to obtain a first hash value. After generating the first key to be verified, the encrypting party performs a hash calculation on the first key to be verified to obtain a second hash value, and sends the first hash value to the decrypting party.

[0069] The decrypting party verifies whether the first hash value is the same as the second hash value, and feeds back the verification result to the encrypting party. If the first hash value and the second hash value are the same, the first key to be verified is the same as the second key to be verified. The encrypting party uses the first key to be verified as the target key, and the decrypting party simultaneously uses the second key to be verified as the target key, and both parties perform encrypted communication according to the determined target key.

[0070] By verifying the keys to be verified obtained by the encrypting party and the decrypting party to determine that the target keys of the encrypting party and the decrypting party are the same, it is avoided that the decrypting party cannot decrypt the encrypted data transmitted by the encrypting party due to different keys used by both parties.

[0071] It can be understood that the first terminal can also be the decrypting party, and the decrypting party can execute specific verification steps and feed back the verification result to the encrypting party.

[0072] In an optional embodiment of the present invention, after step 104, the method includes:

[0073] Determine that the target key is the new initial key; determine the expiration time corresponding to the new initial key.

[0074] Both parties use the target key for encryption and decryption, and use the target key as the new initial key, and reset the expiration time of the new key. When the new expiration time is reached, the target key is updated again. Thus, the periodic replacement of key Mn with key Mn-1 is realized, and the generation of key Mn must depend on Mn-1, forming a set of key update chains, and the overall reliability of the keys is greatly improved.

[0075] In an embodiment of the present invention, an initial key and specular reflection parameters are obtained; when it is detected that the initial key exceeds a preset expiration time, a random vector is generated based on the specular reflection parameters; based on the initial key and the random vector, a target key is generated, and both the encrypting party and the decrypting party of the encrypted communication replace the initial key with the target key and perform encrypted communication. The random vector is generated by using the specular reflection principle, which improves the randomness of the random vector. At the same time, since the random vector is not directly applied to the key, but is combined with the previous key to generate a new key, the complexity of key generation is increased. It is necessary to obtain both the previous key and the random vector to implement cracking, which improves the security of encrypted communication. The key has strong randomness and high complexity, and the complexity of the key can be dynamically adjusted through parameters, reducing the crackability of the key. Different strengths of keys can be generated according to the requirements of encrypted transmission, and it is applicable to various production environments. There can be a fully automatic key generation and update mechanism, reducing the risk of human participation.

[0076] The following further illustrates an embodiment of the present invention with an example, referring to Figure 3 , which shows a schematic diagram of a key generation and dynamic update process based on a rotating mirror of the present invention, including the following steps:

[0077] Step 301, the encrypting party generates an initial key M0 through a computer and transmits M0 to the decrypting party.

[0078] Step 302, the encrypting party determines whether the key needs to be updated. If so, steps 303-307 are executed; if not, step 308 is executed.

[0079] Step 303, the encrypting party simultaneously transmits the mirror rotation speed V, the irradiation angle θ, the irradiation time interval T, and the key length N to the decrypting party.

[0080] Step 304, both the encrypting and decrypting parties respectively simulate and run the mirror rotation algorithm inside the computer according to the parameters, mark points on the coordinate axis, and generate coordinates (x, y).

[0081] Step 305, calculate the value d according to the distance between the coordinates. After N times of marking points, a random vector D1 = [d1, d2,... dn] is formed.

[0082] Step 306, encrypt and perform a hash operation on D1 through M0 to form a new key M1 and sh1.

[0083] Step 307, the encrypting party transmits sh1 to the decrypting party for comparison. If the comparison is successful, the new key M1 replaces M0; otherwise, it is regenerated and compared again until the comparison is successful.

[0084] Step 308, use the key M1 to encrypt and transmit the data.

[0085] It should be noted that, for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0086] Referring to Figure 4 , a structural block diagram of an embodiment of a key generation device according to the present invention is shown, which may specifically include the following modules:

[0087] An initial acquisition module 401, configured to acquire an initial key and a specular reflection parameter;

[0088] A random vector generation module 402, configured to generate a random vector based on the specular reflection parameter when it is detected that the initial key exceeds a preset expiration time;

[0089] A target key generation module 403, configured to generate a target key based on the initial key and the random vector.

[0090] In an alternative embodiment of the present invention, the specular reflection parameter includes a specular rotation speed, an irradiation angle, an irradiation time interval, and a key length.

[0091] In an alternative embodiment of the present invention, the random vector generation module 402 includes:

[0092] A specular rotation sub-module, configured to rotate a preset virtual specular according to the specular rotation speed;

[0093] A light source control sub-module, configured to control a preset virtual light source to output virtual light to the virtual specular according to the irradiation time interval and the irradiation angle;

[0094] A target light point determination sub-module, configured to determine a plurality of target light points that the virtual light reaches a preset coordinate system after being reflected by the rotated virtual specular; the number of the target light points matches the key length;

[0095] A vector generation sub-module, configured to generate a random vector according to the target light points.

[0096] In an alternative embodiment of the present invention, the vector generation sub-module includes:

[0097] A distance calculation unit, configured to calculate the distance between each of the target light points and the origin of the coordinate axis;

[0098] A vector generation unit, configured to generate a random vector with the distances corresponding to respective target light points as elements.

[0099] In an alternative embodiment of the present invention, the target key generation module 403 includes:

[0100] A key-to-be-verified generation sub-module, configured to encrypt the random vector with the initial key to obtain a first key-to-be-verified.

[0101] A verification sub-module, configured to verify the first key-to-be-verified according to a preset rule.

[0102] A target key determination sub-module, configured to determine the first key-to-be-verified as the target key if the first key-to-be-verified passes the verification.

[0103] In an alternative embodiment of the present invention, the device is applied to a first terminal, and the first terminal is communicatively connected to a second terminal; the second terminal is configured to generate a second key-to-be-verified based on the initial key and the specular reflection parameter, and generate a second hash value corresponding to the second verification key; the verification sub-module includes:

[0104] A hash value generation unit, configured to perform a hash calculation on the first key-to-be-verified to obtain a second hash value.

[0105] A hash value sending unit, configured to send the second hash value to the second terminal; the second terminal is configured to output a verification passed message when the first hash value is the same as the second hash value.

[0106] A verification result determination unit, configured to determine that the first hash value passes the verification when receiving the verification passed message.

[0107] In an alternative embodiment of the present invention, the device includes:

[0108] A key replacement module, configured to determine the target key as a new initial key.

[0109] An expiration time reset module, configured to determine the expiration time corresponding to the new initial key.

[0110] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, please refer to the partial description of the method embodiment.

[0111] An embodiment of the present invention further discloses an electronic device, including a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the steps of the key generation method as described above are implemented.

[0112] An embodiment of the present invention also discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the key generation method described above are implemented.

[0113] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other.

[0114] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0115] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the method, terminal device (system), and computer program product according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0116] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0117] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide for implementing the functions specified in Figure 1 one process or multiple processes and / or blocksFigure 1 Steps of functions specified in one or more boxes.

[0118] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.

[0119] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the said element.

[0120] The above has introduced in detail a key generation method and device provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A key generation method, characterized in that, The method includes: Obtaining an initial key and specular reflection parameters; When it is detected that the initial key exceeds a preset expiration time, generating a random vector based on the specular reflection parameters, where the specular reflection parameters include a specular rotation speed, an irradiation angle, an irradiation time interval, and a key length. The generating a random vector based on the specular reflection parameters includes: rotating a preset virtual mirror according to the specular rotation speed; controlling a preset virtual light source to output virtual light to the virtual mirror according to the irradiation time interval and the irradiation angle; determining a plurality of target light points on a preset coordinate system after the virtual light is reflected by the rotated virtual mirror; the number of the target light points matching the key length; generating a random vector according to the target light points; Generating a target key based on the initial key and the random vector.

2. The method according to claim 1, wherein Generating a random vector according to the target light points includes: Calculating the distance between each of the target light points and the origin of the preset coordinate system; Generating a random vector with the distances corresponding to each target light point as elements.

3. The method according to claim 1 or 2, characterized in that, The generating a target key based on the initial key and the random vector includes: Encrypting the random vector with the initial key to obtain a first key to be verified; Verifying the first key to be verified according to a preset rule; If the first key to be verified passes the verification, determining the first key to be verified as the target key.

4. The method according to claim 3, wherein The method is applied to a first terminal, and the first terminal is connected and communicates with a second terminal; the second terminal is used to generate a second key to be verified based on the initial key and the specular reflection parameters, and generate a first hash value corresponding to the second key to be verified; The verifying the first key to be verified according to a preset rule includes: Performing a hash calculation on the first key to be verified to obtain a second hash value; Sending the second hash value to the second terminal; the second terminal is used to output a verification passed message when the first hash value is the same as the second hash value; When receiving the verification passed message, determining that the first hash value passes the verification.

5. The method according to claim 1, characterized in that, After generating the target key, the method includes: Determining the target key as a new initial key; Determining the expiration time corresponding to the new initial key.

6. A key generation device, characterized in that, Applied to an encryption end, the device includes: An obtaining module, configured to obtain an initial key and specular reflection parameters; A random vector generating module, configured to generate a random vector based on the specular reflection parameters when it is detected that the initial key exceeds a preset expiration time; A target key generation module, configured to generate a target key based on the initial key and the random vector, where the specular reflection parameters include a specular rotation speed, an irradiation angle, an irradiation time interval, and a key length, and the random vector generation module includes: a specular rotation sub-module, configured to rotate a preset virtual specular according to the specular rotation speed; a light source control sub-module, configured to control a preset virtual light source to output virtual light to the virtual specular according to the irradiation time interval and the irradiation angle; a target light point determination sub-module, configured to determine a plurality of target light points on a preset coordinate system after the virtual light is reflected by the rotated virtual specular; the number of the target light points matches the key length; and a vector generation sub-module, configured to generate a random vector according to the target light points.

7. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the steps of the key generation method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps of the key generation method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Method and system for network secret key distribution based on calculation correlated imaging

    CN103973433A

  • Wireless channel key generation method and device based on intelligent reflector phase assistance

    CN113179513A