Method and apparatus for improving communication security

By generating a third key that matches the target application scenario, the communication security problem caused by application key leakage or cracking is solved, data encryption security is achieved in different application scenarios, and communication security is improved.

CN115618374BActive Publication Date: 2026-05-29YUNDING NETWORK TECH BEIJING

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
YUNDING NETWORK TECH BEIJING
Filing Date
2022-01-18
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, when the application key of the communicating party is leaked or cracked, the security of transmitted data in various application scenarios cannot be guaranteed.

Method used

The first key is obtained based on the root key and identification information of the first communicating party. A third key matching the target application scenario is generated through pseudo-randomization and key length expansion. The target communication data is encrypted. Different keys are generated by using the user-bound key and application scenario characteristics to improve security.

Benefits of technology

When a key in one application scenario is leaked or cracked, keys in other scenarios remain unaffected, improving communication security and preventing data leakage and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115618374B_ABST
    Figure CN115618374B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a method and device for improving communication security. A specific embodiment of the method comprises: obtaining a first key based on a root key and first identification information saved by a first communication party; obtaining a second key based on the first key; obtaining a third key based on the second key and data information matching a target application scenario; and encrypting target communication data based on the third key. The embodiment generates different third keys based on different application scenarios, and encrypts the target communication data by using the third keys, which can improve the communication security. When the third key in one application scenario is leaked or cracked, the third keys in other scenarios are not affected, which is conducive to improving the communication security.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of application number 202210053353.2, filed on January 18, 2022, entitled "Method and apparatus for improving communication security". Technical Field

[0002] This application relates to the field of communication security technology, and in particular to methods and apparatus for improving communication security. Background Technology

[0003] With the continuous development of communication technology, communication security has become a major concern. Communication parties typically possess a root key. To ensure the security of the root key, they often generate an application key based on it, using this application key to encrypt transmitted data across various application scenarios. If the application key is leaked or cracked, the security of transmitted data across these scenarios will be compromised. Summary of the Invention

[0004] This application provides methods and apparatus for improving communication security.

[0005] In a first aspect, embodiments of this application provide a method for improving communication security, applied to a first communicating party, the method comprising:

[0006] The first key is obtained based on the root key and the first identification information stored by the first communicating party; the first identification information is the identification information of the first communicating party.

[0007] The second key is obtained based on the first key;

[0008] In response to the target communication data sent by the second communicating party, a third key is obtained based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data.

[0009] The target communication data is encrypted based on this third key.

[0010] In some embodiments, obtaining the third key based on the second key and data information matching the target application scenario specifically includes:

[0011] Based on this target application scenario, obtain the first string and the second string;

[0012] The first string is used to process the second key in a pseudo-random manner to obtain a pseudo-randomized key;

[0013] The second string is used to extend the key length of the pseudo-randomized key to obtain the extended key.

[0014] A third key is generated based on the extended key.

[0015] In some embodiments, the method further includes determining a target application scenario, including at least one of method one and method two;

[0016] Method 1: Extract the target application scenario identifier from the target communication data, and determine the target application scenario based on the target application scenario identifier;

[0017] Method 2: Perform data feature identification on the target communication data, and determine the target application scenario based on the data feature identification results.

[0018] In some embodiments, generating a third key based on the length-extended key specifically includes:

[0019] A third key is generated based on the user binding key stored by the first communicating party and the extended key.

[0020] In some embodiments, it also includes:

[0021] Storing encrypted target communication data and discarding unencrypted target communication data;

[0022] In response to the instruction to use the target communication data, the encrypted target communication data is decrypted based on the third key, the decrypted target communication data is obtained, and the target communication data is used based on the instruction to use it.

[0023] In some embodiments, the target communication data is sent by the authorized second communication party, and the method further includes authenticating the permissions of the second communication party, including:

[0024] Obtain the second identification information of the second communication party, and determine whether the second identification information matches the target identification information in the data group stored by the first communication party; wherein, the data group includes: the corresponding first identification information, the root key and the target identification information;

[0025] If they match, the second communication party's authorization is successful, and a response is made to the target communication data sent by the second communication party.

[0026] In some embodiments, obtaining the second identification information of the second communicating party and determining whether the second identification information matches the target identification information in the data group stored by the first communicating party specifically includes:

[0027] Obtain test data;

[0028] Send the test data to the second communicating party;

[0029] Receive encrypted data sent by the second communicating party; the encrypted data is obtained by the second communicating party encrypting the verification data using the second identification information;

[0030] The encrypted data is decrypted using the target identification information to obtain decrypted data.

[0031] Compare the decrypted data with the verification data to see if they match;

[0032] If they match, it is determined that the second identification information of the second communicating party matches the target identification information in the data group stored by the first communicating party.

[0033] Secondly, embodiments of this application provide an apparatus for improving communication security, the apparatus comprising:

[0034] The first key acquisition module is configured to acquire a first key based on the root key and first identification information stored by the first communicating party; the first identification information is the identification information of the first communicating party.

[0035] The second key acquisition module is configured to acquire the second key based on the first key;

[0036] The third key acquisition module is configured to execute a response to the target communication data sent by the second communication party, and acquire a third key based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data.

[0037] The encryption module is configured to perform encryption of the target communication data based on the third key.

[0038] Thirdly, embodiments of this application provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method as described in any of the implementations of the first aspect.

[0039] Fourthly, embodiments of this application provide a processor for running a program, wherein the program executes a method as described in any implementation of the first aspect.

[0040] Fifthly, embodiments of this application provide an electronic device, including: one or more processors; a storage device having one or more programs stored thereon; and when the one or more programs are executed by the one or more processors, causing the one or more processors to implement the method described in any implementation of the first aspect.

[0041] The method and apparatus for improving communication security provided in this application involve obtaining a first key based on a root key and first identification information stored by a first communicating party, obtaining a second key based on the first key, obtaining a third key based on the second key and data information matching a target application scenario, and encrypting the target communication data based on the third key. This application generates different third keys under different target application scenarios and different data information matching the target application scenario, and uses the third key to encrypt the target communication data. This ensures that if the third key in one application scenario is leaked or cracked, the third keys in other scenarios remain unaffected, thus improving communication security.

[0042] Of course, implementing any product or method of this application does not necessarily require achieving all of the advantages described above at the same time. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0044] Figure 1 A flowchart of one embodiment of the method for improving communication security according to this application;

[0045] Figure 2 A flowchart of yet another embodiment of the method for improving communication security according to this application;

[0046] Figure 3 This is a timing diagram of one embodiment of a system for improving communication security according to this application;

[0047] Figure 4 This is a timing diagram of another embodiment of a system for improving communication security according to this application;

[0048] Figure 5 This is a timing diagram of another embodiment of a system for improving communication security according to this application;

[0049] Figure 6 This is a schematic diagram of one embodiment of the apparatus for improving communication security according to this application;

[0050] Figure 7 This is a schematic diagram of one embodiment of the apparatus for improving communication security according to this application;

[0051] Figure 8This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of this application. Detailed Implementation

[0052] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. The described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0053] It should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this application can be combined with each other.

[0054] It should be understood that the terms "system," "apparatus," "unit," and / or "module" used in this application are a method of distinguishing different components, elements, parts, sections, or assemblies at different levels. However, if other terms can achieve the same purpose, they may be replaced by other expressions.

[0055] As indicated in this application and claims, unless the context clearly indicates otherwise, the words "a," "an," "a," and / or "the" are not specifically singular and may include the plural. Generally, the terms "comprising" and "including" only indicate the inclusion of expressly identified steps and elements, which do not constitute an exclusive list, and the method or apparatus may also include other steps or elements. An element defined by the phrase "comprising an..." does not exclude the presence of other identical elements in the process, method, product, or apparatus that includes the element.

[0056] In the description of the embodiments of this application, unless otherwise stated, " / " means "or", for example, A / B can mean A or B; "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more.

[0057] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.

[0058] Flowcharts are used in this application to illustrate the operations performed by the system according to embodiments of this application. It should be understood that the preceding or following operations are not necessarily performed precisely in sequence. Instead, the steps can be processed in reverse order or simultaneously. Furthermore, other operations can be added to these processes, or one or more steps can be removed from them.

[0059] This application provides a method for improving communication security, applied to a first communicating party, such as... Figure 1 As shown, the method includes:

[0060] Step 101: Obtain the first key based on the root key and the first identification information stored by the first communicating party; the first identification information is the identification information of the first communicating party.

[0061] In this embodiment, the first communication device used to improve communication security can be either hardware or software. When the first communication device is hardware, it can be various types of electronic devices, such as smartphones, tablets, desktop computers, wearable devices, in-vehicle devices, augmented reality (AR) / virtual reality (VR) devices, e-book readers, audio and video players, electronic locks, etc. When the first communication device is software, it can be installed in the electronic devices listed above. This application embodiment does not impose any restrictions on the specific type of electronic device. Optionally, the first communication device has a chip, and the first identification information can be the chip's identification information. The first identification information can be various types of identification information, such as identity identification information (Chip ID), etc.

[0062] As an optional implementation, the security domain of the first communicating party may store a root key and / or first identification information. Since the security domain is not allowed to be read by external devices, the security of the information stored in the security domain can be guaranteed. The security domain can be a TrustZone or EFUSE in the chip. To improve the security of the root key, instead of directly using the root key to encrypt the communication data, another key can be generated based on the root key and used to encrypt the communication data. Step 101 can obtain the first key based on the first identification information and the root key stored in the security domain of the first communicating party.

[0063] Optionally, in order to avoid the problem of reduced communication security caused by different first communication parties having the same first key, this application can make the first key obtained by different first communication parties based on the first identification information and the root key different by having different root keys stored by different first communication parties and / or having different first identification information stored by different first communication parties.

[0064] As an optional implementation, the first key obtained based on the root key and the first identification information stored by the first communicating party can be a key that conforms to AES requirements, namely AesKey (Advanced Encryption Standard Key). The first key can be obtained by taking the root key as input, using the first identification information as a salt, and processing it with a derived algorithm. Of course, other methods can also be used to obtain the first key, such as embedding the first identification information into the root key.

[0065] In some optional implementations of this embodiment, the first communicating party may have a biometric algorithm chip. The biometric identification can be one or more of fingerprint recognition, finger vein recognition, face recognition, iris recognition, voiceprint recognition, palmprint recognition, and palm vein recognition. The root key and chip ID of the biometric algorithm chip can be programmed into its security domain. When the chip is powered on, the root key and chip ID in the security domain can be loaded, and a derived algorithm can be run to obtain the first key of the algorithm chip, which can be AesKey. In addition to biometric identification functions, the biometric algorithm chip may also have communication functions with external electronic devices and / or firmware upgrade functions.

[0066] Step 102: Obtain the second key based on the first key.

[0067] In this embodiment, the first communicating party can obtain the second key based on the first key. Since the data is encrypted directly without using the first key, communication security issues caused by the leakage or cracking of the first key can be prevented. Furthermore, compared to obtaining the first key based on the root key and first identification information stored by the first communicating party, obtaining the second key based on the first key is more flexible and applicable to application scenarios with high key change frequencies.

[0068] As an optional implementation, the method for obtaining the second key based on the first key can be to generate the second key by encrypting the first key. Optionally, the method for generating the second key by encrypting the first key can be to process the first key using a message digest algorithm, and use the digest of the processed first key as the second key. Of course, other methods can also be used to encrypt the first key to generate the second key, such as using a hash algorithm to generate the second key from the first key.

[0069] Step 103: In response to the target communication data sent by the second communication party, obtain the third key based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data.

[0070] In this embodiment, the second communication party can be either hardware or software. When the second communication party is hardware, it can be various types of electronic devices, such as smartphones, tablets, desktop computers, wearable devices, in-vehicle devices, augmented reality (AR) / virtual reality (VR) devices, e-book readers, audio and video players, electronic locks, and other electronic devices. When the second communication party is software, it can be installed in the electronic devices listed above. This application embodiment does not impose any limitations on the specific type of electronic device.

[0071] As an optional implementation, the first communicating party receives target communication data sent by the second communicating party, and the first communicating party can encrypt the target communication data. In this embodiment, the first communicating party can obtain a third key based on a second key and data information matching the target application scenario. This data information can be a string, text, graphics, or other information. Since the third key is generated based on data information matching the target application scenario, the data information matching the target application scenario can be different for different target application scenarios. Therefore, the first communicating party can generate different third keys for different application scenarios, avoiding the problem that directly using the second key to encrypt communication data in all application scenarios would compromise the security of transmitted data across multiple application scenarios if the second key is leaked or cracked. This application's generation of different third keys for different application scenarios improves communication security; if the third key corresponding to one application scenario is leaked or cracked, the third keys corresponding to other scenarios remain unaffected.

[0072] As an optional implementation, the method by which the first communicating party obtains the third key based on the second key and data information matching the target application scenario may include: obtaining a first string and a second string based on the target application scenario; processing the second key using the first string in a pseudo-random manner to obtain a pseudo-randomized key; extending the key length of the pseudo-randomized key using the second string to obtain a length-extended key; and generating the third key based on the length-extended key.

[0073] Optionally, based on the target application scenario, the required key length for the application scenario is obtained, and the extended key is obtained through the HKDF algorithm. The extended key is used as the key value of HMAC, and an HMAC message integrity authentication code is generated based on the HMAC algorithm. This message integrity authentication code is used as the third key.

[0074] Optionally, the method of processing the second key using the first string in a pseudo-random manner can be to embed a pseudo-random number into the second key to obtain a pseudo-randomized key. Alternatively, the method can also be to process the second key using a hash function, where the length of the first string is used as the length of the hash value generated by the hash function.

[0075] As an optional implementation, a target application scenario corresponds to two strings: a first string and a second string. The first string and the second string can be different for different target application scenarios, ensuring that the third key corresponding to different target application scenarios is also different. Optionally, when the first communicating party uses the first string to perform pseudo-randomization processing on the second key, a hash function can be used. The first string can be used as the salt for the salting operation, and its length is the length of the hash value of the hash function. Optionally, when the first communicating party uses the second string (info) to perform key length extension processing on the pseudo-randomized key, a series of hash operations can be used to extend the pseudo-randomized key to the required length. In some optional implementations of this embodiment, the length of the pseudo-randomized key can be no less than the output digest length of the hash algorithm used, and the length of the second string can be no longer than 255 times the output digest length of the hash algorithm used.

[0076] As an optional implementation, the first communicating party can generate a third key based on the user-bound key and the length-extended key stored by the first communicating party. Since different users can have different user-bound keys, the third key generated based on the user-bound key can also be different. This allows for differentiation of the third key for different users even in the same target application scenario, improving the flexibility of key generation. Optionally, the method for generating the third key can be the HMAC-sha256 algorithm. In some optional implementations of this embodiment, a user-bound key (which can be a key bound to a user ID) is implanted into the security domain of the chip possessed by the first communicating party using a client with user management functions (such as a mobile terminal APP). The user ID is the identity identifier of the user entered in the client with user management functions. In this way, a third key can be generated based on the user-bound key and the length-extended key.

[0077] As an optional implementation, the first communicating party can also generate a third key using other methods. For example, the third key can be generated based on a random string generated by the first communicating party after receiving the target communication data and a key with an extended length. This way, if different target communication data are received, different random strings will be generated, resulting in different third keys, enhancing the flexibility of third key generation and improving communication security. Optionally, the method for generating the third key can be the HMAC-sha256 algorithm.

[0078] As an optional implementation, the method for determining the target application scenario can be: extracting a target application scenario identifier from the target communication data, and determining the target application scenario based on the target application scenario identifier. In this method, the target communication data may carry a target application scenario identifier. The first communicating party can extract the target application scenario identifier from the target communication data, determine the target application scenario using the identifier, and then obtain a first string and a second string based on the target application scenario, thereby generating a third key.

[0079] As another optional implementation method, the target application scenario can be determined by: performing data feature identification on the target communication data, and determining the target application scenario based on the data feature identification results. Under this method, the first communicating party can distinguish the target application scenario by utilizing the different data features of the target communication data transmitted under different application scenarios.

[0080] In some optional implementations of this embodiment, the target application scenario can be a biometric recognition scenario. The biometric recognition scenario can be determined by using a biometric recognition scenario identifier, or the biometric recognition scenario can be determined by using biometrics.

[0081] In some optional implementations of this embodiment, the target application scenario can be a firmware upgrade scenario. The firmware upgrade scenario can be determined by using a firmware upgrade scenario identifier or by using program data in the firmware.

[0082] In some optional implementations of this embodiment, the target application scenario can be a data communication scenario. The data communication scenario can be determined by using a data communication scenario identifier or by using the encryption parameters of the communication key.

[0083] This application uses the second key to derive several third keys (the third keys can be used as application master keys). These application master keys are different based on different application scenarios, and the application master keys are also different for the same application scenario when the users are different. This can realize the function of one key for one communication party and multiple application master keys for one communication party with multiple users.

[0084] Step 104: Encrypt the target communication data based on the third key.

[0085] As an optional implementation, when the first communicating party encrypts the target communication data based on the third key, it may use a symmetric encryption algorithm, such as the AES algorithm, to encrypt the target communication data. The AES algorithm may be the AES-ECB-128 algorithm.

[0086] In some optional implementations of this embodiment, the target application scenario can be a biometric identification scenario, the target communication data can be the user's biometrics, and the first communication party encrypts the biometrics based on a third key to prevent attackers from obtaining the user's real biometrics.

[0087] In some optional implementations of this embodiment, the target application scenario can be a firmware upgrade scenario, the target communication data can be the upgrade firmware, and the first communication party encrypts the upgrade firmware based on a third key to prevent attackers from maliciously tampering with the upgrade firmware.

[0088] In some optional implementations of this embodiment, the target application scenario can be a data communication scenario, the target communication data can be a communication key, and the first communication party encrypts the communication key based on a third key to prevent attackers from stealing the communication key.

[0089] As an optional implementation, the method for improving communication security provided in this application can also store encrypted target communication data and discard unencrypted target communication data; in response to a usage instruction for the target communication data, decrypt the encrypted target communication data based on a third key, obtain the decrypted target communication data, and use the target communication data based on the usage instruction.

[0090] In this embodiment, after encrypting the target communication data using the third key, the first communicating party can store the encrypted target communication data. Considering the security issues of unencrypted target communication data, the unencrypted target communication data can be discarded. Since the third key is a symmetric key, the first communicating party can directly decrypt the encrypted target communication data based on the third key after responding to the instruction to use the target communication data, and then use the decrypted target communication data (i.e., the target communication data).

[0091] In some optional implementations of this embodiment, when the target application scenario is a biometric identification scenario, the instruction for using the target communication data can be a biometric comparison instruction. When the target application scenario is a firmware upgrade scenario, the instruction for using the target communication data can be a bootloader to upgrade the firmware. When the target application scenario is a data communication scenario, the instruction for using the target communication data can be an instruction for encrypting or decrypting the transmitted data using a communication key.

[0092] This application also provides a method for improving communication security, applied to a first communicating party, such as... Figure 2 As shown, the method includes:

[0093] Step 201: Obtain the first key based on the root key and the first identification information stored by the first communicating party; the first identification information is the identification information of the first communicating party.

[0094] Step 201 and Figure 1 Step 101 is similar and will not be repeated here.

[0095] Step 202: Obtain the second key based on the first key.

[0096] Step 202 and Figure 1 Step 102 is similar and will not be repeated here.

[0097] Step 203: Obtain the second identification information of the second communicating party, and determine whether the second identification information matches the target identification information in the data group stored by the first communicating party. The data group includes: the corresponding first identification information, the root key, and the target identification information.

[0098] As an optional implementation, before encrypting the target communication data sent by the second communication party, the first communication party can use the second identification information of the second communication party to perform permission verification. It can process the target communication data sent by the authorized second communication party and not process the target communication data sent by the unauthorized second communication party, thereby reducing the impact of malicious attacks by the second communication party on the first communication party and improving the communication security of the first communication party.

[0099] As an optional implementation, the method for determining whether the second identification information matches the target identification information in the data group stored by the first communicating party can be: receiving the second identification information sent by the second communicating party; comparing whether the second identification information is consistent with the target identification information; if consistent, then determining that the second identification information of the second communicating party matches the target identification information in the data group stored by the first communicating party. If inconsistent, then determining that the second identification information of the second communicating party does not match the target identification information in the data group stored by the first communicating party.

[0100] In some optional implementations of this embodiment, the data set can be a Root Key, a Chip ID, and a Second Communicator ID (target identification information). The Second Communicator ID can be stored in the security domain of the First Communicator. The Second Communicator can send target communication data to the First Communicator. Upon receiving the target communication data, the First Communicator can send an authorization verification command to the Second Communicator. This authorization verification command can carry an instruction to verify the Second Communicator's Second Identification Information. After receiving the authorization verification command from the First Communicator, the Second Communicator sends its Second Identification Information to the First Communicator. The First Communicator can compare the Second Identification Information with the Second Communicator ID. If the Second Identification Information matches the Second Communicator ID, it can be determined that the Second Identification Information matches the target identification information stored in the data set by the First Communicator.

[0101] As another optional implementation, the method for determining whether the second identification information matches the target identification information in the data group stored by the first communicating party can be as follows: acquiring verification data; sending the verification data to the second communicating party; receiving encrypted data sent by the second communicating party; the encrypted data is obtained by the second communicating party encrypting the verification data using the second identification information; decrypting the encrypted data using the target identification information to obtain decrypted data; comparing whether the decrypted data and the verification data are consistent; if they are consistent, then it is determined that the second identification information of the second communicating party matches the target identification information in the data group stored by the first communicating party. Optionally, the encryption method in this process is a symmetric encryption method.

[0102] As another optional implementation, the method for determining whether the second identification information matches the target identification information in the data group stored by the first communicating party can further include: acquiring verification data; encrypting the verification data using the target identification information to obtain encrypted verification data, and sending the encrypted verification data to the second communicating party; receiving decrypted data sent by the second communicating party; the decrypted data is obtained by the second communicating party decrypting the encrypted verification data using the second identification information; comparing whether the decrypted data and the verification data are consistent; if they are consistent, it is determined that the second identification information of the second communicating party matches the target identification information in the data group stored by the first communicating party; if they are inconsistent, it is determined that the second identification information of the second communicating party does not match the target identification information in the data group stored by the first communicating party. Optionally, the encryption method in this process is a symmetric encryption method.

[0103] In some optional implementations of this embodiment, the data set can be a Root Key, a Chip ID, and a user-bound key (target identification information). The user-bound key can be stored in the security domain of the first communicating party. The second communicating party can send target communication data to the first communicating party. When the first communicating party receives the target communication data, it can send an authorization verification instruction to the second communicating party. This authorization verification instruction can carry an instruction to verify the user-bound key of the second communicating party and encrypted verification data. The authorization verification instruction can also carry verification data and an instruction to encrypt the verification data based on the second identification information. After receiving the instruction sent by the first communicating party, the second communicating party sends corresponding data back to the first communicating party so that the first communicating party can determine whether the second identification information matches the target identification information in the data set stored by the first communicating party.

[0104] It should be noted that the order of steps 201-203 is not limited. Step 203 can be placed before steps 201 and / or 202, or step 202 can be placed before steps 201 and / or 203.

[0105] Step 204: If they match, the second communication party's authorization is successful. In response to the target communication data sent by the second communication party, the third key is obtained based on the second key and data information matching the target application scenario. The target application scenario is the application scenario represented by the target communication data.

[0106] Step 204 and Figure 1 Step 103 is similar and will not be repeated here.

[0107] Step 205: Encrypt the target communication data based on the third key.

[0108] Step 205 and Figure 1 Step 104 is similar and will not be repeated here.

[0109] As an optional implementation, the method for improving communication security provided in this application can also store encrypted target communication data and discard unencrypted target communication data; in response to a usage instruction for the target communication data, decrypt the encrypted target communication data based on a third key, obtain the decrypted target communication data, and use the target communication data based on the usage instruction.

[0110] Figure 3 This is a timing diagram of one embodiment of a system for improving communication security according to this application, as shown below. Figure 3 As shown, it illustrates a timeline diagram for a biometric recognition scenario.

[0111] In this embodiment, the first communication partner in the biometric identification scenario can be an algorithm chip. Optionally, the algorithm chip can have biometric storage functionality or biometric identification functionality. The second communication partner in the biometric identification scenario can be a sensor, which can have the function of collecting user biometric features. Biometric identification can be fingerprint, finger vein, face, iris, etc. Based on this, in this embodiment, the system for improving communication security includes an algorithm chip and a sensor.

[0112] like Figure 3 As shown, in step 301, the algorithm chip derives the AesKey of the algorithm chip based on the Root Key and Chip ID, and obtains the second key based on the AesKey.

[0113] The root key and chip ID of the algorithm chip are burned into its security domain. When the algorithm chip powers on, the key management software inside the chip can load the root key and chip ID from the security domain and run a derived algorithm to obtain the AesKey of the algorithm chip. A second key is then generated based on the AesKey using a hash algorithm.

[0114] In step 302, the sensor sends the first biometric data to the algorithm chip.

[0115] Optionally, the first biometric data may be the biometric data sent by the sensor to the algorithm chip for the first time, and the algorithm chip may encrypt and store the first biometric data. Of course, the first biometric data may not be the first biometric data sent by the sensor to the algorithm chip. If the algorithm chip has biometric storage space, the algorithm chip may encrypt and store the first biometric data.

[0116] In step 303, the algorithm chip sends an authentication command to the sensor.

[0117] The security domain of the algorithm chip can store the sensor's ID number, i.e., the Sensor ID. For a biometric module, the module can include both an algorithm chip and a sensor. To achieve a matching setup between the algorithm chip and the sensor within a biometric module, a one-to-one binding relationship can be established between the algorithm chip's Root Key and Chip ID and the sensor's Sensor ID. That is, the sensor ID corresponding to the chip is burned into the security domain of the algorithm chip. When the sensor sends biometric data to the algorithm chip, the algorithm chip can receive only the biometric data transmitted by the sensor corresponding to its own chip. At this point, the sensor ID number stored in the algorithm chip can be used to authenticate the sensor sending the biometric data. Optionally, the authentication command can carry a command to verify the sensor's ID.

[0118] In step 304, the sensor sends its identity information to the algorithm chip.

[0119] In an alternative implementation, the sensor identification information can be a sensor ID.

[0120] In step 305, the algorithm chip compares the received sensor identity information with the stored Sensor ID. If the comparison results match, in response to the first biometric data sent by the sensor, it obtains symmetric key 1 based on the second key and data information matching the biometric recognition scenario. The biometric data is then encrypted based on symmetric key 1 and stored to obtain the recorded biometric data.

[0121] As an optional implementation, one method for obtaining data information matching a biometric recognition scenario is to parse a biometric recognition scenario identifier from the first biometric data sent from the sensor to the algorithm chip, and then obtain the corresponding data information based on this identifier. Alternatively, another method for obtaining data information matching a biometric recognition scenario is to perform feature recognition using the first biometric data sent from the sensor to the algorithm chip, and then determine the data information matching the biometric recognition scenario based on the feature recognition results.

[0122] As another optional implementation, a derived algorithm can be used to obtain symmetric key 1 based on the second key and data information matching the biometric recognition scenario. In obtaining symmetric key 1 using the derived algorithm, the HKDF algorithm can be used to obtain the first HMAC key based on the algorithm chip's AesKey and the data information matching the biometric recognition scenario. Then, the HMAC-sha256 algorithm is used to obtain symmetric key 1 based on the first HMAC key and the user-bound key. Obtaining symmetric key 1 through the user-bound key can prevent attacks on the algorithm chip from unauthorized clients or clients with malicious devices. Symmetric key 1 can be used to encrypt the biometric features transmitted by the sensor; optionally, the biometric features can be encrypted using the AES-ECB-128 algorithm based on symmetric key 1.

[0123] As an optional implementation, if the comparison results are inconsistent, the algorithm chip may not respond to the first biometric data sent by the sensor. Inconsistent comparison results may indicate that the sensor has been replaced. When a sensor is replaced, attackers may be able to overlay forged biometric features onto the sensor or eavesdrop on the bus data between the sensor and the algorithm chip to obtain the user's true biometric features. Therefore, the algorithm chip may not store biometric features transmitted by sensors that have not passed authentication, or may not generate a biometric verification pass command. For scenarios where the algorithm chip needs to transmit biometric verification pass commands to load certain functions of application software, this application's approach of performing a legality check on the biometric module can improve communication security.

[0124] In some optional implementations of this embodiment, after storing the encrypted biometrics, the algorithm chip may discard the unencrypted biometrics to prevent attackers from obtaining the user's real biometrics, taking into account the security issues of the unencrypted biometrics.

[0125] In some optional implementations of this embodiment, when the algorithm chip does not store biometric information, the algorithm chip can store biometric data; when the algorithm chip stores biometric information but still has space to store biometric information, the algorithm chip can choose to store biometric data or identify biometric data based on the scenario; when the algorithm chip does not have space to store biometric information, the algorithm chip can identify biometrics.

[0126] In step 306, the sensor sends the second biometric data to the algorithm chip.

[0127] Optionally, the second biometric data may match the first biometric data, or it may not match the first biometric data. When the second biometric data matches the first biometric data, the algorithm chip can identify the second biometric data.

[0128] In step 307, the algorithm chip responds to the usage instruction of the recorded biometric features by decrypting the encrypted biometric features based on symmetric key 1, and comparing the recorded biometric features with the second biometric feature data based on the usage instruction.

[0129] In an optional implementation, the instruction for using the recorded biometrics can be a biometric comparison instruction based on the second biometric data sent by the sensor. Before performing biometric comparison, the algorithm chip can decrypt the encrypted biometrics based on symmetric key 1. The algorithm chip then compares the currently received second biometric data with the recorded biometrics.

[0130] Figure 4This is a timing diagram of another embodiment of the system for improving communication security according to this application, as shown below. Figure 4 As shown, it illustrates a timing diagram based on a firmware upgrade scenario.

[0131] In this embodiment, the first communication party in the firmware upgrade scenario can be an algorithm chip. Optionally, the algorithm chip can have firmware upgrade functionality. The second communication party in the firmware upgrade scenario can be a client, which can have user management functionality and can also transmit upgrade firmware. The upgrade firmware can be biometric recognition algorithm upgrade firmware. Based on this, in this embodiment, the system for improving communication security includes an algorithm chip and a client.

[0132] like Figure 4 As shown, in step 401, the algorithm chip derives the AesKey of the algorithm chip based on the Root Key and Chip ID, and obtains the second key based on the AesKey.

[0133] Step 401 and Figure 3 Step 301 is similar and will not be repeated here.

[0134] In step 402, the client sends upgrade firmware to the algorithm chip.

[0135] Optionally, the upgrade firmware may contain a biometric identification program or a biometric storage program.

[0136] In step 403, the algorithm chip sends an authorization verification command to the client.

[0137] As an optional implementation, the authorization verification instruction may carry verification data and instructions to encrypt the verification data based on second identification information. The second identification information may be a user binding key stored on the client, and the verification data may be a random number generated by the algorithm chip.

[0138] In step 404, the client encrypts the verification data based on the second identification information.

[0139] As an optional implementation, the verification data can be encrypted using AES-ECB-128 based on the second identification information.

[0140] In step 405, the client sends encrypted data to the algorithm chip.

[0141] In step 406, the algorithm chip decrypts the encrypted data based on the stored user-bound key, compares the decrypted data with the verification data to see if they are consistent. If the comparison results are consistent, in response to the upgrade firmware sent by the client, it obtains symmetric key 2 based on the second key and data information matching the firmware upgrade scenario, encrypts the upgrade firmware based on symmetric key 2, and stores the encrypted upgrade firmware.

[0142] The algorithm chip's security domain can store user-bound keys. These keys are implanted into the algorithm chip's security domain using a client with user management capabilities, and are bound to a user ID. The key management software inside the algorithm chip can establish a one-to-one correspondence between the security domain's root key, chip ID, and user-bound key, and store this correspondence within the security domain.

[0143] As an optional implementation, one method for obtaining data information matching the firmware upgrade scenario is to parse the firmware upgrade scenario identifier from the upgrade firmware sent by the client to the algorithm chip, and then obtain the corresponding data information based on the identifier. Alternatively, another method for obtaining data information matching the firmware upgrade scenario is to perform program feature recognition on the upgrade firmware sent by the client to the algorithm chip, and then determine the data information matching the firmware upgrade scenario based on the program feature recognition results.

[0144] As another optional implementation, a derived algorithm can be used to obtain symmetric key 2 based on the second key and data information matching the firmware upgrade scenario. In obtaining symmetric key 2 using the derived algorithm, the HKDF algorithm can be used to obtain the second HMAC key based on the algorithm chip's AesKey and the data information matching the firmware upgrade scenario, and then symmetric key 2 can be obtained based on the second HMAC key. Symmetric key 2 can be used to encrypt the upgrade firmware transmitted by the client; optionally, the AES-ECB-128 algorithm can be used to encrypt the upgrade firmware based on symmetric key 2.

[0145] In some optional implementations of this embodiment, the method for obtaining symmetric key 2 based on the second HMAC key can be to obtain symmetric key 2 using the HMAC-sha256 algorithm based on the second HMAC key and the user-bound key. Alternatively, the method can also be to obtain symmetric key 2 based on the second HMAC key and a random number generated by the algorithm chip using the HMAC-sha256 algorithm. Different random numbers generated by the algorithm chip will result in different symmetric keys 2, improving the flexibility of generating symmetric key 2. Obtaining different symmetric keys 2 using random numbers generated by the algorithm chip during different firmware upgrades improves communication security.

[0146] As an optional implementation, if the comparison results are consistent, the algorithm chip can first perform an integrity check on the received upgrade firmware before encrypting the upgrade firmware. After confirming that the upgrade firmware is complete, the algorithm chip uses symmetric key 2 to encrypt the upgrade firmware to prevent attackers from maliciously tampering with the upgrade firmware.

[0147] As an optional implementation, if the comparison results are inconsistent, the algorithm chip may not respond to the upgrade firmware sent by the client. Inconsistent comparison results may indicate that the user binding key held by the client is invalid, potentially allowing attackers to use the algorithm chip without a client or with a client equipped with a malicious device. Therefore, the algorithm chip may not store or boot upgrade firmware transmitted by unverified clients to improve communication security.

[0148] In some optional implementations of this embodiment, after storing the encrypted upgrade firmware, the algorithm chip may discard the unencrypted upgrade firmware to avoid the problem of upgrade firmware leakage, considering the security issues of the unencrypted upgrade firmware.

[0149] In step 407, the algorithm chip responds to the instruction to use the upgrade firmware by decrypting the encrypted upgrade firmware based on symmetric key 2 and booting the decrypted upgrade firmware.

[0150] As an optional implementation, before booting the decrypted upgrade firmware, an integrity check can be performed on the decrypted firmware. The upgrade firmware can only be started after the check passes, thus avoiding the problem of incomplete upgrade firmware caused by power failure during storage, which could lead to upgrade firmware startup failure. Optionally, the encrypted upgrade firmware can be decrypted using the AES-ECB-128 algorithm based on symmetric key 2.

[0151] Figure 5 This is a timing diagram of another embodiment of the system for improving communication security according to this application, as shown below. Figure 5 As shown, it illustrates a timing diagram based on a data communication scenario.

[0152] In this embodiment, the first communication party in the data communication scenario can be an algorithm chip. Optionally, the algorithm chip can have the function of communicating with external electronic devices. The second communication party in the data communication scenario can be a client, and the external electronic device can be an MCU (Microcontroller Unit). To ensure the communication security between the algorithm chip and the MCU, a communication key can be written to the algorithm chip and the MCU based on the client. Based on this, in this embodiment, the system for improving communication security includes an algorithm chip, an MCU, and a client. To prevent attackers from using the algorithm chip without a client or with a client equipped with an attack device, the client's permissions can be verified first. The specific process is as follows:

[0153] like Figure 5 As shown, in step 501, the algorithm chip derives the AesKey of the algorithm chip based on the Root Key and Chip ID, and obtains the second key based on the AesKey.

[0154] Step 501 and Figure 4 Step 401 is similar and will not be repeated here.

[0155] In step 502, the client sends a communication key to the algorithm chip.

[0156] As an optional implementation, the client can send a communication key to the MCU. The communication key sent by the client to the algorithm chip and the communication key sent by the client to the MCU can be the same.

[0157] As an alternative implementation, the MCU may store the communication key that the client sends to the algorithm chip.

[0158] In step 503, the algorithm chip sends an authorization verification command to the client.

[0159] Step 503 and Figure 4 Step 403 is similar and will not be repeated here.

[0160] In step 504, the client encrypts the verification data based on the second identification information.

[0161] Step 504 and Figure 4 Step 404 is similar and will not be repeated here.

[0162] In step 505, the client sends encrypted data to the algorithm chip.

[0163] Step 505 and Figure 4 Step 405 is similar and will not be repeated here.

[0164] In step 506, the algorithm chip decrypts the encrypted data based on the stored user-bound key, compares the decrypted data with the verification data to see if they are consistent. If the comparison results are consistent, in response to the communication key sent by the client, it obtains symmetric key 3 based on the second key and data information matching the data communication scenario, encrypts the communication key based on symmetric key 3, and stores the encrypted communication key.

[0165] The algorithm chip's security domain can store user-bound keys. These keys are implanted into the algorithm chip's security domain using a client with user management capabilities, and are bound to a user ID. The key management software inside the algorithm chip can establish a one-to-one correspondence between the security domain's root key, chip ID, and user-bound key, and store this correspondence within the security domain.

[0166] As an optional implementation, obtaining data information matching the data communication scenario can involve parsing the data communication scenario identifier from the communication information sent by the client to the algorithm chip, and then obtaining the corresponding data information based on this identifier. Alternatively, another method for obtaining data information matching the data communication scenario can be to use the communication key sent by the client to the algorithm chip to identify encryption parameters, and then determine the data information matching the data communication scenario based on the encryption parameter identification result.

[0167] As another optional implementation, a derived algorithm can be used to obtain symmetric key 3 based on the second key and data information matching the data communication scenario. In obtaining symmetric key 3 using the derived algorithm, the HKDF algorithm can be used to obtain the third HMAC key based on the algorithm chip's AesKey and the data information matching the data communication scenario. Then, the HMAC-sha256 algorithm is used to obtain symmetric key 3 based on the third HMAC key and the user-bound key. Obtaining symmetric key 3 through the user-bound key can prevent attacks on the algorithm chip from unauthorized clients or clients with malicious devices. Symmetric key 3 can be used to encrypt the communication key transmitted by the client; optionally, the AES-ECB-128 algorithm can be used to encrypt the communication key based on symmetric key 3.

[0168] As an optional implementation, if the comparison results are inconsistent, the algorithm chip may not respond to the communication key sent by the client. Inconsistent comparison results may indicate that the user-bound key held by the client is invalid, potentially allowing attackers to use the algorithm chip without a client or with a client equipped with an attack device. Therefore, the algorithm chip may not store or encrypt the communication key transmitted by an unverified client to improve communication security.

[0169] In some optional implementations of this embodiment, after storing the encrypted communication key, the algorithm chip may discard the unencrypted communication key to avoid the problem of communication key leakage, considering the security issues of the unencrypted communication key.

[0170] In step 507, the MCU uses the stored communication key to encrypt the data to be communicated.

[0171] Optionally, the data to be communicated can be at least one of information entry data, information identification data, and information deletion data.

[0172] In step 508, the MCU sends encrypted communication data to the algorithm chip.

[0173] In step 509, the algorithm chip responds to the instruction to use the communication key by decrypting the encrypted communication key based on symmetric key 3, and then uses the decrypted communication key to decrypt the encrypted communication data.

[0174] This application also provides a device for improving communication security, such as... Figure 6 As shown, the device includes: a first key acquisition module 601, a second key acquisition module 602, a third key acquisition module 603, and an encryption module 604.

[0175] The first key acquisition module 601 is configured to acquire a first key based on the root key and first identification information stored by the first communicating party. The first identification information is the identification information of the first communicating party.

[0176] The second key acquisition module 602 is configured to acquire the second key based on the first key.

[0177] The third key acquisition module 603 is configured to execute a response to the target communication data sent by the second communication party, and acquire a third key based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data.

[0178] The third key acquisition module 603 specifically includes:

[0179] The string retrieval unit is configured to retrieve the first string and the second string based on the target application scenario.

[0180] The pseudo-randomization processing unit is configured to use the first string to perform pseudo-randomization processing on the second key to obtain a pseudo-randomized key.

[0181] The length extension processing unit is configured to extend the key length of the pseudo-randomized key using the second string to obtain the extended key.

[0182] The third key acquisition unit is configured to generate a third key based on the length-extended key.

[0183] The third key acquisition unit is specifically configured to generate a third key based on the user binding key and the extended key stored by the first communicator.

[0184] The third key acquisition module 603 also includes:

[0185] The target application scenario determination unit is configured to determine the target application scenario using at least one of method one and method two:

[0186] Method 1: Extract the target application scenario identifier from the target communication data, and determine the target application scenario based on the target application scenario identifier;

[0187] Method 2: Perform data feature identification on the target communication data, and determine the target application scenario based on the data feature identification results.

[0188] Encryption module 604 is configured to perform encryption of target communication data based on a third key.

[0189] The device for improving communication security provided in this application also includes:

[0190] The storage module is configured to store encrypted target communication data and discard unencrypted target communication data.

[0191] The module is configured to decrypt the encrypted target communication data based on a third key in response to a usage instruction for the target communication data, obtain the decrypted target communication data, and use the target communication data based on the usage instruction.

[0192] In this embodiment, the specific processing of the first key acquisition module 601, the second key acquisition module 602, the third key acquisition module 603, and the encryption module 604, and the resulting technical effects, can be found in reference to [the relevant documentation]. Figure 1 The relevant descriptions of the embodiments of steps 101, 102, 103 and 104 in the corresponding embodiments will not be repeated here.

[0193] This application also provides a device for improving communication security, such as... Figure 7 As shown, the device includes: a first key acquisition module 701, a second key acquisition module 702, an authorization verification module 703, a third key acquisition module 704, and an encryption module 705.

[0194] The first key acquisition module 701 is configured to acquire a first key based on the root key and first identification information stored by the first communicating party. The first identification information is the identification information of the first communicating party.

[0195] First key acquisition module 701 and Figure 6 The first key acquisition module 601 shown is similar and will not be described in detail again.

[0196] The second key acquisition module 702 is configured to acquire the second key based on the first key.

[0197] The second key acquisition module 702 and Figure 6 The second key acquisition module 602 shown is similar and will not be described in detail again.

[0198] The authorization verification module 703 is configured to obtain the second identification information of the second communicating party and determine whether the second identification information matches the target identification information in the data group stored by the first communicating party. The data group includes: the corresponding first identification information, the root key, and the target identification information.

[0199] The authorization verification module 703 is specifically configured to: acquire verification data; send the verification data to the second communication party; receive encrypted data sent by the second communication party; the encrypted data is obtained by the second communication party encrypting the verification data using second identification information; decrypt the encrypted data using target identification information to obtain decrypted data; compare whether the decrypted data and the verification data are consistent; if they are consistent, determine that the second identification information of the second communication party matches the target identification information in the data group stored by the first communication party.

[0200] The authorization verification module 703 can also be configured to receive second identification information sent by the second communication party; compare whether the second identification information is consistent with the target identification information; if they are consistent, determine that the second identification information of the second communication party matches the target identification information in the data group stored by the first communication party. If they are inconsistent, determine that the second identification information of the second communication party does not match the target identification information in the data group stored by the first communication party.

[0201] The third key acquisition module 704 is configured to execute the second identification information and the target identification information are consistent, the second communication party's authorization authentication is passed, and in response to the target communication data sent by the second communication party, acquire the third key based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data.

[0202] The third key acquisition module 704 and Figure 6 The third key acquisition module 603 shown is similar and will not be described in detail again.

[0203] Encryption module 705 is configured to encrypt target communication data based on a third key.

[0204] Encryption module 705 and Figure 6The encryption module 604 shown is similar and will not be described in detail.

[0205] In this embodiment, the specific processing of the first key acquisition module 701, the second key acquisition module 702, the authorization verification module 703, the third key acquisition module 704, and the encryption module 705, and the resulting technical effects, can be found in reference to [the relevant documentation]. Figure 2 The relevant descriptions of the embodiments of steps 201, 202, 203, 204 and 205 in the corresponding embodiments will not be repeated here.

[0206] It should be noted that the device for communication security can be a chip, component or module. The device for communication security can include a processor and a memory. The first key acquisition module 701, the second key acquisition module 702, the authorization verification module 703, the third key acquisition module 704 and the encryption module 705 are all stored as program units in the memory. The processor executes the above program units stored in the memory to realize the corresponding functions.

[0207] A processor may contain a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and communication security can be improved by adjusting kernel parameters.

[0208] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0209] The device for pushing information provided in the above embodiments of this application generates different third keys under different target application scenarios and different data information matching the target application scenarios. The target communication data is encrypted using these third keys, ensuring that if the third key in one application scenario is leaked or cracked, the third keys in other scenarios remain unaffected, thus improving communication security. Furthermore, by using second identification information to authenticate the second communication party, and only after successful authentication can the device receive the target communication data sent by the second communication party, the security performance of the communication is further improved.

[0210] The following is for reference. Figure 8 It shows a schematic diagram of the structure of an electronic device 800 suitable for implementing some embodiments of the present application. Figure 8 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0211] like Figure 8As shown, the electronic device 800 may include a processor 801, a memory 802, a communication interface 803, an input unit 804, an output unit 805, and a communication bus 806. The processor 801 and the memory 802 are interconnected via the communication bus 806. The communication interface 803, the input unit 804, and the output unit 805 are also connected to the communication bus 806.

[0212] The communication interface 803 can be an interface for a communication module, such as a GSM module. The communication interface 803 can be used by the user to acquire biometric data sent by the sensor, or to acquire firmware upgrades and communication keys sent by the client. The communication interface 803 is also used to send authorization verification commands to the sensor or client.

[0213] In this embodiment of the application, the processor 801 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices.

[0214] In one possible implementation, the memory 802 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function (such as biometric identification). The data storage area may store data created during computer use, such as user data, user access data, and encrypted data.

[0215] In addition, memory 802 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device or other volatile solid-state storage device.

[0216] Processor 801 can call programs stored in memory 802. Specifically, processor 801 can execute programs such as... Figures 1 to 5 The method for improving communication security shown in any of the embodiments.

[0217] The memory 802 is used to store one or more programs. The programs may include program code, which includes computer operation instructions. In this embodiment, the memory 802 stores at least a program for implementing the following functions:

[0218] A first key is obtained based on the root key and first identification information stored by the first communicating party; the first identification information is the identification information of the first communicating party; a second key is obtained based on the first key; in response to the target communication data sent by the second communicating party, a third key is obtained based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data; the target communication data is encrypted based on the third key.

[0219] This application may also include an input unit 805, which may include at least one of the following devices: a touch sensing unit for sensing touch events on a touch display panel, a keyboard, a mouse, a camera, a microphone, etc.

[0220] The output unit 804 may include at least one of the following devices: a display, a speaker, a vibration mechanism, and a lamp. The display may include a display panel, such as a touch display panel. In one possible implementation, the display panel may be configured using a liquid crystal display (LCD) or an organic light-emitting diode (OLED). The vibration mechanism can displace the electronic device 800 during operation. In one possible implementation, the vibration mechanism includes a motor and an eccentric oscillator; the motor drives the eccentric oscillator to rotate, thereby generating vibration. The brightness and / or color of the lamp is adjustable. In one possible implementation, different information can be displayed through at least one of the lamp's on / off state, brightness, and color, such as using a red light to display an alarm message.

[0221] certainly, Figure 8 The structure of the electronic device 800 shown does not constitute a limitation on the electronic device in the embodiments of this application. In practical applications, the electronic device may include more than Figure 8 More or fewer components as shown, or combinations of certain components.

[0222] This application provides a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the methods for improving communication security described in the above method embodiments.

[0223] This application provides a processor for running a program, wherein the program implements the methods for improving communication security described in the above method embodiments.

[0224] This application also provides a computer program product that, when executed on a data processing device, causes the data processing device to implement the methods for improving communication security described in the above method embodiments.

[0225] In this application, the electronic device, processor, computer-readable medium, or computer program product provided in the above embodiments can all be used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0226] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0227] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0228] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0229] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0230] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0231] Computer-readable media include both permanent and non-permanent, removable and non-removable media, which can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0232] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0233] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed, and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. The scope of the invention involved in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. A method for improving communication security, characterized in that, Applied to the first communicating party, the method includes: The first key is obtained based on the root key and the first identification information stored by the first communication party; the first identification information is the identification information of the first communication party; the first communication party has a chip, and the root key and the first identification information are stored in the security domain of the first communication party, the security domain being TrustZone or EFUSE in the chip; Obtain the second key based on the first key; In response to target communication data sent by the second communicating party, a third key is obtained based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data; wherein, the data information can be at least one of string, text, or graphic information; The target communication data is encrypted based on the third key; The process of obtaining the third key based on the second key and data information matching the target application scenario specifically includes: Obtain the first string and the second string based on the target application scenario; The second key is processed using the first string in a pseudo-random manner to obtain a pseudo-randomized key; The pseudo-randomized key is extended using the second string to obtain the extended key. A third key is generated based on the length-extended key.

2. The method for improving communication security according to claim 1, characterized in that, The method further includes determining the target application scenario, including at least one of method one and method two; Method 1: Extract the target application scenario identifier from the target communication data, and determine the target application scenario based on the target application scenario identifier; Method 2: Perform data feature identification on the target communication data, and determine the target application scenario based on the data feature identification results.

3. The method for improving communication security according to claim 1, characterized in that, The generation of the third key based on the length-extended key specifically includes: A third key is generated based on the user binding key stored by the first communicating party and the extended key.

4. The method for improving communication security according to claim 1, characterized in that, Also includes: Storing encrypted target communication data and discarding unencrypted target communication data; In response to the instruction to use the target communication data, the encrypted target communication data is decrypted based on the third key to obtain the decrypted target communication data and to use the target communication data based on the instruction to use it.

5. The method for improving communication security according to claim 1, characterized in that, The target communication data is sent by the second communication party after authorization. The method further includes authenticating the authorization of the second communication party, including: Obtain the second identification information of the second communicating party, and determine whether the second identification information matches the target identification information in the data group stored by the first communicating party; wherein, the data group includes: the corresponding first identification information, the root key, and the target identification information; If they match, the second communication party's authorization is successful, and it responds to the target communication data sent by the second communication party.

6. The method for improving communication security according to claim 5, characterized in that, The step of obtaining the second identification information of the second communicating party and determining whether the second identification information matches the target identification information in the data group stored by the first communicating party includes: Obtain test data; Send the test data to the second communicating party; Receive encrypted data sent by the second communicating party; the encrypted data is obtained by the second communicating party encrypting the verification data using the second identification information; The encrypted data is decrypted using the target identification information to obtain decrypted data. Compare whether the decrypted data and the verification data are consistent; If they match, then the second identification information of the second communicating party is determined to match the target identification information in the data group stored by the first communicating party.

7. A device for improving communication security, characterized in that, The device includes: The first key acquisition module is configured to acquire a first key based on the root key and first identification information stored by the first communication party; the first identification information is the identification information of the first communication party. The second key acquisition module is configured to acquire a second key based on the first key. The third key acquisition module is configured to execute a response to target communication data sent by the second communicating party, and acquire a third key based on the second key and data information matching the target application scenario; the target application scenario is the application scenario represented by the target communication data; wherein, the data information can be at least one of string, text or graphic information; The encryption module is configured to perform encryption of the target communication data based on the third key; The third key acquisition module specifically includes: The string retrieval unit is configured to retrieve a first string and a second string based on the target application scenario; The pseudo-randomization processing unit is configured to use the first string to perform pseudo-randomization processing on the second key to obtain a pseudo-randomized key; The length extension processing unit is configured to use the second string to perform key length extension processing on the pseudo-randomized key to obtain the length-extended key. The third key acquisition unit is configured to generate a third key based on the length-extended key.

8. A computer-readable medium having a computer program stored thereon, wherein, When the program is executed by the processor, it implements the method for improving communication security as described in any one of claims 1-6.

9. A processor for running a program, wherein, When the program runs, it implements the method for improving communication security as described in any one of claims 1-6.

10. An electronic device, comprising: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method for improving communication security as described in any one of claims 1-6.