Communication method, device, communication system, and storage medium
By designing a lightweight key negotiation algorithm in the MQTT protocol, generating shared communication keys and encrypting them between the proxy server and the client, the communication security and performance problems in the case of resource-constrained devices and a large number of clients in the prior art are solved, and efficient and secure Internet of Things communication is achieved.
Patent Information
- Application Number
- CN202211346244.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-10-31
AI Technical Summary
The prior art is difficult to implement on resource-constrained devices when using a lightweight SSL/TLS protocol solution, and under a large number of clients, offline certificate authentication cannot meet the requirements, making it difficult to take into account communication security and performance indicators.
A lightweight key negotiation algorithm is designed to generate symmetric shared communication keys based on this algorithm through the client and the authentication server, establish a secure communication channel, and perform secondary encryption between the proxy server and the client to ensure the security of messages during transmission and storage.
It realizes efficient communication encryption on resource-constrained devices, reduces the computing and storage overhead of MQTT clients, and improves the effectiveness of both communication security and performance indicators.
Smart Images

Figure CN115766119B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication security technologies, and particularly to a communication method, apparatus, communication system, and storage medium. Background Art
[0002] As a lightweight communication protocol, the MQTT (Message Queuing Telemetry Transport) protocol has the characteristics of small communication overhead and adaptability to unreliable networks, making it widely used in today's Internet of Things field. However, since the MQTT protocol itself does not provide measures to ensure data security, messages are default in plain text during push, forwarding, and cloud storage processing, which gives attackers an opportunity.
[0003] In related technologies, a method of embedding the SSL (Secure Sockets Layer) / TLS (Transport Layer Security) protocol between the MQTT protocol and the TCP (Transmission Control Protocol) is adopted. Further, the SSL / TLS protocol solution is lightweighted, that is, the certificate authentication step of SSL / TLS is placed offline to implement a lightweight communication encryption transmission method.
[0004] In the process of implementing the present application, the applicant found that the related technologies have at least the following problems:
[0005] First, for some resource-constrained devices, it is difficult to integrate SSL / TLS. Therefore, this method is not applicable to devices with limited computing resources or network resources. Second, for the lightweight protocol solution, although placing the certificate authentication of SSL / TLS offline can improve the situation for resource-constrained devices, when a large number of publishers and subscribers enter the system, this offline authentication method cannot meet the requirements. Summary of the Invention
[0006] In view of this, the present application provides a communication method, apparatus, communication system, and storage medium, mainly aiming to solve the problem that the current lightweight SSL / TLS protocol solution has large computing and storage overheads for devices with limited computing resources or network resources and in the presence of a large number of clients due to network resource constraints.
[0007] According to the first aspect of the present application, a communication method is provided, which is applicable to a communication system. The communication system includes a first client, a second client, a proxy server, and an authentication server. The method includes: in response to a communication request, obtaining the subject included in the communication request and the payload to be published on the subject; the first client encrypts the payload and the device identifier of the first client using the first session key to generate a first ciphertext; the first client encrypts the device identifier and the first session key using the first shared communication key to generate an encrypted device identifier and a second session key, and sends the second session key to the authentication server; the first client generates a message packet according to the first ciphertext, the subject, and the encrypted device identifier, and sends it to the proxy server; the proxy server determines the subject and the second client corresponding to the subject according to the message packet, and sends the subject, the second client, and the encrypted device identifier to the authentication server; the authentication server generates a third ciphertext according to the second shared communication key, the subject, the encrypted device identifier, and the first public key, and sends it to the proxy server; the proxy server encrypts the first ciphertext and the third ciphertext using the third shared communication key to generate a fourth ciphertext, and sends it to the second client; the second client decrypts the fourth ciphertext using the fourth shared communication key to obtain the first ciphertext and the third ciphertext; the second client decrypts the third ciphertext using the first private key to obtain the first session key and the device identifier; the second client decrypts the first ciphertext using the first session key to obtain the payload and the device identifier; the second client compares the device identifier decrypted using the first subscription private key with the device identifier decrypted using the first session key; if the device identifier decrypted using the first subscription private key is the same as the device identifier decrypted using the first session key, the payload is retained.
[0008] Optionally, the step that the authentication server generates a third ciphertext according to the second shared communication key, the subject, the encrypted device identifier, and the first public key, and sends it to the proxy server specifically includes: the authentication server decrypts the encrypted device identifier using the second shared communication key to obtain the device identifier of the first client; the authentication server determines the first session key using the subject and the device identifier; the authentication server generates a first public-private key pair according to the subject and the second client, where the first public-private key pair includes a first public key and a first private key; the authentication server encrypts the first private key using the third shared communication key and sends the encrypted first private key to the second client; the authentication server encrypts the first session key and the device identifier using the first public key to generate a third ciphertext; the authentication server sends the third ciphertext to the proxy server.
[0009] Optionally, before obtaining the topic included in the communication request and the payload to be published on the topic in response to the communication request, the method further includes: in response to a client registration request, obtaining the registration information of the target client included in the client registration request, where the target client is the first client or the second client; the authentication server determines whether the target client is registered according to the registration information and the client information in the authentication server; in the case where the target client is not registered, the authentication server generates an identity identifier of the target client according to the client device identifier, the first timestamp, and the preset parameter information to register the target client.
[0010] Optionally, after the authentication server generates the identity identifier of the target client based on the client device identifier, the first timestamp, and the preset parameter information to register the target client, the method further includes: The authentication server sends the first prime number, the second prime number, and the identity identifier corresponding to the target client to the target client; The target client generates a first hash value and a first hash digest according to the identity identifier, the device identifier, and the first timestamp; The target client sends the device identifier, the first timestamp, the first hash value, and the first hash digest to the authentication server; The authentication server generates a second hash digest according to the first hash value, the device identifier, and the first timestamp; When the first hash digest is the same as the second hash digest, the authentication server generates a second hash value according to the device identifier and the first timestamp; When the first hash value is the same as the second hash value, the authentication server generates a second public-private key pair, a third public-private key pair, and a first numerical value, where the second public-private key pair includes a second public key and a second private key, and the third public-private key pair includes a third public key and a third private key; The authentication server generates a third hash digest according to the third public key, the identity identifier, and the second timestamp; The authentication server sends the second public key, the third public key, the first numerical value, the second timestamp, and the third hash digest to the target client; The target client generates a fourth hash digest according to the second public key, the second timestamp, and the identity identifier; When the third hash digest is the same as the fourth hash digest, the target client generates a fourth public-private key pair, where the fourth public-private key pair includes a fourth public key and a fourth private key; The target client generates a fifth hash digest according to the fourth public key, the identity identifier, and the third timestamp; The target client sends the fourth public key, the fifth hash digest, a second numerical value, and the third timestamp to the authentication server; The authentication server generates a sixth hash digest according to the fourth public key, the identity identifier, and the third timestamp; When the fifth hash digest is the same as the sixth hash digest, the target client, in response to the verification passed instruction sent by the authentication server, generates a fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first numerical value, and the second numerical value; The authentication server, in response to the verification confirmation instruction sent by the target client, generates a sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first numerical value, and the second numerical value.
[0011] Optionally, the step of generating the fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first numerical value, and the second numerical value specifically includes: Calculating a first parameter according to the first hash digest, the third hash digest, and the fifth hash digest by using a first preset formula; The first preset formula is:
[0012] t = Hash(HD P1 || HD P2 || HD P3 );
[0013] Wherein, the above t is the first parameter; the above Hash is a hash function; the above HD P1 is the first hash digest; the above HD P2 is the third hash digest; the above HD P3 is the fifth hash digest; according to the first prime number and the second prime number, using the second preset formula, the second parameter is calculated; the second preset formula is:
[0014] M = m 1 × m 2 ;
[0015] Wherein, the above M is the second parameter; the above m 1 is the first prime number; the above m 2 is the second prime number; according to the second parameter, the first prime number and the second prime number, using the third preset formula, the third parameter is calculated; the third preset formula is:
[0016]
[0017] Wherein, the above M i is the third parameter, the above m i is the first prime number or the second prime number; according to the third parameter, the first prime number and the second prime number, using the fourth preset formula, the fourth parameter is calculated; the fourth preset formula is:
[0018] y i = M i -1 (mod(m i ))(i = 1, 2);
[0019] Wherein, the above y i is the fourth parameter; the above mod is a remainder function; according to the second parameter, the third parameter, the fourth parameter, the first value and the second value, using the fifth preset formula, the fifth parameter is calculated; the fifth preset formula is:
[0020] x = (a 1 y 1 M 1 + a 2 y 2 M 2 )(mod(M));
[0021] Wherein, the above x is the fifth parameter; the above a 1 is the first value; the above y 1 is the fourth parameter when i = 1; the above M1 is the third parameter when i = 1; the above a 2 is the second value; the above y 2 is the fourth parameter when i = 2; the above M 2 is the third parameter when i = 2; according to the fifth parameter, the second public key, the third public key, and the fourth private key, using the sixth preset formula, calculate the fifth shared communication key; the sixth preset formula is:
[0022] shareKey client = e(Fx + tR);
[0023] where, the above shareKey client is the fifth shared communication key; the above e is the fourth private key; the above F is the second public key; the above R is the third public key.
[0024] Optionally, the steps of generating the sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first value, and the second value specifically include: according to the first hash digest, the third hash digest, and the fifth hash digest, using the first preset formula, calculate the first parameter; according to the first prime number and the second prime number, using the second preset formula, calculate the second parameter; according to the second parameter, the first prime number, and the second prime number, using the third preset formula, calculate the third parameter; according to the third parameter, the first prime number, and the second prime number, using the fourth preset formula, calculate the fourth parameter; the fourth preset formula is:
[0025] y i = M i -1 (mod(m i ))(i = 1, 2);
[0026] According to the second parameter, the third parameter, the fourth parameter, the first value, and the second value, using the fifth preset formula, calculate the fifth parameter; according to the fifth parameter, the second private key, the third private key, and the fourth public key, using the sixth preset formula, calculate the fifth shared communication key; the sixth preset formula is:
[0027] shareKey broker = E(fx + tr);
[0028] where, the above shareKey broker is the sixth shared communication key; the above E is the fourth public key; the above f is the second private key; the above t is the third private key.
[0029] According to a second aspect of the present application, a communication device is provided, which is applicable to a communication system. The communication system includes a first client, a second client, a proxy server, and an authentication server. The device includes: an acquisition module, configured to acquire a subject included in a communication request and a payload to be published on the subject in response to the communication request; a generation module, configured to encrypt the payload and the device identifier of the first client by using a first session key by the first client to generate a first ciphertext; the generation module is further configured to encrypt the device identifier and the first session key by using a first shared communication key by the first client to generate an encrypted device identifier and a second session key, and send the second session key to the authentication server; the generation module is further configured to generate a message packet according to the first ciphertext, the subject, and the encrypted device identifier by the first client, and send the message packet to the proxy server; a determination module, configured to determine the subject and the second client corresponding to the subject according to the message packet by the proxy server, and send the subject, the second client, and the encrypted device identifier to the authentication server; the generation module is further configured to generate a third ciphertext according to a second shared communication key, the subject, the encrypted device identifier, and a first public key by the authentication server, and send the third ciphertext to the proxy server; the generation module is further configured to encrypt the first ciphertext and the third ciphertext by using a third shared communication key by the proxy server to generate a fourth ciphertext, and send the fourth ciphertext to the second client; the generation module is further configured to decrypt the fourth ciphertext by using a fourth shared communication key by the second client to obtain the first ciphertext and the third ciphertext; the generation module is further configured to decrypt the third ciphertext by using a first private key by the second client to obtain the first session key and the device identifier; the generation module is further configured to decrypt the first ciphertext by using the first session key by the second client to obtain the payload and the device identifier; a comparison module, configured to compare the device identifier decrypted by using the first private key by the second client with the device identifier decrypted by using the first session key; a storage module, configured to retain the payload if the device identifier decrypted by using the first subscription private key is the same as the device identifier decrypted by using the first session key.
[0030] Optionally, the generation module is specifically configured to: decrypt the encrypted device identifier by using the second shared communication key by the authentication server to obtain the device identifier of the first client; determine the first session key by using the subject and the device identifier by the authentication server; generate a first public-private key pair according to the subject and the second client by the authentication server, where the first public-private key pair includes a first public key and a first private key; encrypt the first private key by using the third shared communication key by the authentication server, and send the encrypted first private key to the second client; encrypt the first session key and the device identifier by using the first public key by the authentication server to generate a third ciphertext; send the third ciphertext to the proxy server by the authentication server.
[0031] Optionally, the obtaining module is further configured to obtain the registration information of the target client included in the client registration request in response to the client registration request, where the target client is the first client or the second client.
[0032] Optionally, the apparatus further includes: a judging module, configured to judge whether the target client is registered by the authentication server according to the registration information and the client information in the authentication server.
[0033] Optionally, the generating module is further configured to, when the target client is not registered, generate an identity identifier of the target client by the authentication server according to the client device identifier, the first timestamp, and the preset parameter information, so as to register the target client.
[0034] Optionally, the apparatus further includes: a sending module, configured to send the first prime number, the second prime number, and the identity identifier corresponding to the target client by the authentication server to the target client.
[0035] Optionally, the generating module is further configured to generate a first hash value and a first hash digest by the target client according to the identity identifier, the device identifier, and the first timestamp.
[0036] Optionally, the sending module is further configured to send the device identifier, the first timestamp, the first hash value, and the first hash digest by the target client to the authentication server.
[0037] Optionally, the generating module is further configured to, when the first hash digest is the same as the second hash digest, generate a second hash value by the authentication server according to the device identifier and the first timestamp; when the first hash value is the same as the second hash value, the authentication server generates a second public-private key pair, a third public-private key pair, and a first numerical value, where the second public-private key pair includes a second public key and a second private key, and the third public-private key pair includes a third public key and a third private key; the authentication server generates a third hash digest according to the third public key, the identity identifier, and the second timestamp.
[0038] Optionally, the sending module is further configured to send the second public key, the third public key, the first numerical value, the second timestamp, and the third hash digest by the authentication server to the target client.
[0039] Optionally, the generating module is further configured to generate a fourth hash digest by the target client according to the second public key, the second timestamp, and the identity identifier; when the third hash digest is the same as the fourth hash digest, the target client generates a fourth public-private key pair, where the fourth public-private key pair includes a fourth public key and a fourth private key; the target client generates a fifth hash digest according to the fourth public key, the identity identifier, and the third timestamp.
[0040] Optionally, the sending module is further configured to enable the target client to send the fourth public key, the fifth hash digest, the second numerical value, and the third timestamp to the authentication server.
[0041] Optionally, the generating module is further configured to enable the authentication server to generate a sixth hash digest according to the fourth public key, the identity identifier, and the third timestamp; in the case where the fifth hash digest is the same as the sixth hash digest, the target client, in response to the verification passed instruction sent by the authentication server, generates a fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first numerical value, and the second numerical value; the authentication server, in response to the verification confirmation instruction sent by the target client, generates a sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first numerical value, and the second numerical value.
[0042] Optionally, the generating module is specifically further configured to calculate a first parameter according to the first hash digest, the third hash digest, and the fifth hash digest by using a first preset formula; the first preset formula is:
[0043] t = Hash(HD P1 ||HD P2 ||HD P3 );
[0044] wherein, the above t is the first parameter; the above Hash is a hash function; the above HD P1 is the first hash digest; the above HD P2 is the third hash digest; the above HD P3 is the fifth hash digest; calculate a second parameter according to the first prime number and the second prime number by using a second preset formula; the second preset formula is:
[0045] M = m 1 ×m 2 ;
[0046] wherein, the above M is the second parameter; the above m 1 is the first prime number; the above m 2 is the second prime number; calculate a third parameter according to the second parameter, the first prime number, and the second prime number by using a third preset formula; the third preset formula is:
[0047]
[0048] wherein, the above M i is the third parameter, the above m iis the first prime number or the second prime number; according to the third parameter, the first prime number, and the second prime number, using the fourth preset formula, the fourth parameter is calculated; the fourth preset formula is:
[0049] y i = M i -1 (mod(m i ))(i = 1, 2);
[0050] wherein, the above y i is the fourth parameter; the above mod is a remainder function; according to the second parameter, the third parameter, the fourth parameter, the first value, and the second value, using the fifth preset formula, the fifth parameter is calculated; the fifth preset formula is:
[0051] x = (a 1 y 1 M 1 + a 2 y 2 M 2 )(mod(M));
[0052] wherein, the above x is the fifth parameter; the above a 1 is the first value; the above y 1 is the fourth parameter when i = 1; the above M 1 is the third parameter when i = 1; the above a 2 is the second value; the above y 2 is the fourth parameter when i = 2; the above M 2 is the third parameter when i = 2; according to the fifth parameter, the second public key, the third public key, and the fourth private key, using the sixth preset formula, the fifth shared communication key is calculated; the sixth preset formula is:
[0053] shareKey client = e(Fx + tR);
[0054] wherein, the above shareKey client is the fifth shared communication key; the above e is the fourth private key; the above F is the second public key; the above R is the third public key.
[0055] Optionally, the generation module is specifically further configured to calculate the first parameter according to the first hash digest, the third hash digest, and the fifth hash digest, using the first preset formula; calculate the second parameter according to the first prime number and the second prime number, using the second preset formula; calculate the third parameter according to the second parameter, the first prime number, and the second prime number, using the third preset formula; calculate the fourth parameter according to the third parameter, the first prime number, and the second prime number, using the fourth preset formula; the fourth preset formula is:
[0056] yi = M i -1 (mod(m i )) (i = 1, 2);
[0057] According to the second parameter, the third parameter, the fourth parameter, the first value, and the second value, use the fifth preset formula to calculate the fifth parameter; according to the fifth parameter, the second private key, the third private key, and the fourth public key, use the sixth preset formula to calculate the fifth shared communication key; the sixth preset formula is:
[0058] shareKey broker = E(fx + tr);
[0059] Among them, the above shareKey broker is the sixth shared communication key; the above E is the fourth public key; the above f is the second private key; the above t is the third private key.
[0060] According to the third aspect of the present application, a communication system is provided, including the communication method described in the first aspect.
[0061] Optionally, the communication system further includes:
[0062] The first client is used to publish messages. The first client is communicatively connected to the authentication server and communicatively connected to the proxy server;
[0063] The second client is used to receive messages of the subscribed topics. The second client is communicatively connected to the proxy server; the proxy server; the authentication server.
[0064] According to the fourth aspect of the present application, a storage medium is provided. At least one executable instruction is stored in the storage medium. When the executable instruction is executed by a processor, the steps of the communication method described in any one of the first aspects are implemented.
[0065] With the above technical solution, a communication method, device, communication system and storage medium provided by the present application. Specifically, by designing a lightweight key negotiation algorithm, the client and the authentication server generate a symmetric shared communication key based on the lightweight key negotiation algorithm, and establish a secure communication channel for the client and the server in the MQTT protocol. On the one hand, during the communication process, both the key and the message are encrypted by the shared communication key. An attacker can only obtain the encrypted message and the session key, and cannot obtain the plaintext of the message, so it is impossible to eavesdrop on and leak the corresponding message, thus solving the security problem when the message is stored and processed in plaintext at the proxy end and improving the key security. On the other hand, there is no need to add an additional handshake process to negotiate the key like the SSL / TLS solution, which solves the overhead problem that may be caused by the additional network round-trip in the SSL / TLS solution, and avoids burdening the client in the communication, reducing the computing overhead and storage overhead of the MQTT client, improving the portability of Internet of Things communication, and thus achieving a better trade-off between the performance index and data security of the MQTT protocol.
[0066] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically given below. Brief Description of the Drawings
[0067] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present application. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0068] Figure 1 It shows a schematic flowchart of a communication method provided by an embodiment of the present application;
[0069] Figure 2 It shows a schematic structural diagram of a communication device provided by an embodiment of the present application;
[0070] Figure 3 It shows a schematic structural diagram of an authentication server provided by an embodiment of the present application;
[0071] Figure 4 It shows a schematic structural diagram of a communication system provided by an embodiment of the present application. Detailed Embodiments
[0072] Exemplary embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be fully conveyed to those skilled in the art.
[0073] An embodiment of the present application provides a communication method. As Figure 1 shown, the method includes:
[0074] 101. In response to a communication request, obtain the topic included in the communication request and the payload to be published on the topic.
[0075] In this step, in response to the communication request, obtain the topic published by the publisher in the communication request and the payload to be published on the topic. It should be noted that the payload is the specific content of the message to be published.
[0076] 102. The first client encrypts the payload and the device identifier of the first client using the first session key to generate a first ciphertext.
[0077] In this step, the first client is the publisher side that publishes the message. When each publisher side publishes a message, it randomly generates a first session key according to the topic. Subsequently, the generated first session key is used to encrypt the payload and the device identifier of the publisher side to generate a first ciphertext.
[0078] In the above manner, the first client uses the session key generated by itself according to the topic to encrypt the transmitted message and the identity identifier, improving the security of the client's control over the session key.
[0079] 103. The first client encrypts the device identifier and the first session key using the first shared communication key to generate an encrypted device identifier and a second session key, and sends the second session key to the authentication server.
[0080] In this step, the first client uses the first shared communication key to encrypt its device identifier to generate an encrypted device identifier. At the same time, the first client uses the first shared communication key to encrypt the first session key to generate an encrypted second session key. Subsequently, the encrypted second session key is sent to the authentication server for the authentication server to store the first session key in the database.
[0081] Optionally, after receiving the second session key, the authentication server unlocks the second session key using the second shared communication key symmetric to the first shared communication key to decrypt the first session key and stores the first session key in the database.
[0082] It should be noted that the shared communication key belongs to the symmetric key, which is generated by the client and the authentication server respectively using the key negotiation algorithm. The client uses the shared communication key to encrypt and decrypt data for secure transmission with the proxy server and the authentication server. Specifically, the first shared communication key is the shared communication key generated by the first client, and the second shared communication key that can decrypt it is the shared communication key generated by the authentication server.
[0083] 104. The first client generates a message packet based on the first ciphertext, the topic, and the encrypted device identifier, and sends it to the proxy server.
[0084] In this step, the first client encapsulates the encrypted first ciphertext, the topic, and the encrypted device identifier into a message packet and sends it to the proxy server.
[0085] In the above way, on the one hand, the message is in an encrypted state before transmission, making it difficult for attackers to obtain the original message, thus improving the security of data transmission; on the other hand, there is no need to add an additional handshake process similar to the SSL / TLS scheme to negotiate the subsequent symmetric key, avoiding burdening the client during data transmission.
[0086] 105. The proxy server determines the topic and the second client corresponding to the topic based on the message packet, and sends the topic, the second client, and the encrypted device identifier to the authentication server.
[0087] In this step, after receiving the message packet sent by the first client, the proxy server analyzes the message packet to determine the topic to which the message sent by the first client belongs. Then, it queries the second client corresponding to this topic, that is, the subscriber side. After determining the subscriber, the proxy server sends the topic, the second client, and the encrypted device identifier of the first client to the authentication server.
[0088] 106. The authentication server generates a third ciphertext based on the second shared communication key, the topic, the encrypted device identifier, and the first public key, and sends it to the proxy server.
[0089] 107. The proxy server encrypts the first ciphertext and the third ciphertext using the third shared communication key to generate a fourth ciphertext, and sends it to the second client.
[0090] In steps 106 and 107, after receiving the message sent by the proxy server, the authentication server decrypts the encrypted device identifier using the second shared communication key to obtain the device identifier of the first client. Then, the proxy server uses the topic and the device identifier of the first client to query the stored first session key of the first client in the database.
[0091] Further, the proxy server encrypts the first session key and the device identifier using the first public key to generate a third ciphertext, and sends the third ciphertext and the third shared communication key to the proxy server.
[0092] Further, the proxy server encrypts the first ciphertext and the third ciphertext using the third shared communication key sent by the authentication server to obtain a fourth ciphertext. The proxy server sends the fourth ciphertext to the second client.
[0093] It should be noted that the first public key is the subscription public key in the subscription public-private key pair corresponding to the second client. Specifically, after receiving the topic and the subscriber side, the authentication server generates a subscription public-private key pair for the topic and the subscriber side. Among them, the generation of the subscription public-private key pair adopts a conventional key algorithm in the art, and the present application does not make specific limitations here. The third shared communication key is the shared communication key generated by the authentication server for the second client.
[0094] 108. The second client decrypts the fourth ciphertext using the fourth shared communication key to obtain the first ciphertext and the third ciphertext.
[0095] In this step, after receiving the ciphertext sent by the proxy server, the second client decrypts the fourth ciphertext sent by the proxy server using the fourth shared communication key symmetric to the third shared communication key to obtain the third ciphertext and the first ciphertext containing the payload.
[0096] Through the above method, when the proxy server forwards the data published by the publisher, it can use the shared communication key of the subscriber side to perform secondary encryption on it, solving the problem that the message is stored and processed in plain text on the proxy server, and improving the security of communication.
[0097] 109. The second client decrypts the third ciphertext using the first private key to obtain the first session key and the device identifier.
[0098] In this step, after the second client decrypts to obtain the third ciphertext, it decrypts the third ciphertext using the first private key to obtain the first session key and the device identifier of the first client.
[0099] It should be noted that the first private key is the subscription private key of the subscription public-private key generated by the authentication server for the topic and the subscriber side, and this subscription private key is used to decrypt the message encrypted by the subscription public key.
[0100] 110. The second client decrypts the first ciphertext using the first session key to obtain the payload and the device identifier.
[0101] In this step, the second client decrypts the first ciphertext using the first session key to obtain the payload published by the publisher and the device identifier of the first client.
[0102] In the above manner, the subscriber receives the doubly encrypted ciphertext, and the original message is obtained by decrypting it twice, ensuring the integrity of the entire publish-forward process. Further, before the subscriber decrypts the message, the message and the key are always in an encrypted state. On the premise that the subscriber's session key is not leaked, it is difficult for an attacker to obtain the original text of the message, ensuring the security of the overall communication.
[0103] 111. The second client compares the device identifier decrypted using the first private key with the device identifier decrypted using the first session key.
[0104] 112. If the device identifier decrypted using the first subscription private key is the same as the device identifier decrypted using the first session key, the payload is retained.
[0105] In steps 111 and 112, the device identifier decrypted from the third ciphertext is the device identifier sent by the authentication server to the subscriber side through the proxy server, while the device identifier in the first ciphertext is the device identifier in the publisher-side message packet. To prevent an attacker from tampering with the data during data transmission, the second client compares whether the device identifier decrypted using the first private key is the same as the device identifier in the publisher-side message packet. If they are the same, it indicates that the data is intact and not tampered with during data transmission, and the payload is retained at this time; if they are different, it indicates that the data has been maliciously tampered with during data transmission, and the payload is rejected at this time.
[0106] In the above manner, by comparing the device identifiers in the different ciphertexts received by the subscriber, the verification of the security of data transmission is realized, ensuring that the data finally saved by the subscriber is correct data, and effectively improving the security of data transmission.
[0107] The communication method provided by the embodiment of the present application designs a lightweight key negotiation algorithm, enabling the client and the authentication server to generate a symmetric shared communication key based on the lightweight key negotiation algorithm, and establishing a secure communication channel for the client and the server in the MQTT protocol. On the one hand, during the communication process, both the key and the message are encrypted using the shared communication key. An attacker can only obtain the encrypted message and session key, and cannot obtain the plaintext of the message, so they cannot eavesdrop on or leak the corresponding message, thus solving the security problem when the message is stored and processed in plaintext at the proxy end and improving the key security. On the other hand, there is no need to add an extra handshake process to negotiate the key like the SSL / TLS solution, solving the overhead problem that the SSL / TLS solution may cause due to additional network round-trips, and avoiding burdening the client in the communication, reducing the computing and storage overhead of the MQTT client, improving the portability of IoT communication, and thus achieving a better trade-off between performance indicators and data security for the MQTT protocol.
[0108] Further, as a refinement and extension of the specific implementation manner of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, the embodiment of the present application provides another communication method, which includes:
[0109] 201. In response to a client registration request, obtain the registration information of the target client included in the client registration request, where the target client includes a first client and a second client.
[0110] In this step, when each client registers, it sends a registration request to the authentication center. The authentication center responds to the registration request and obtains the registration information of the target client in the request, facilitating the authentication center to compare the registration information with the registration information of the registered clients stored in the database to authenticate the target client and determine whether the target client is legal.
[0111] It should be noted that the target client can be any client to be registered, and the target client includes a first client of the publisher and a second client of the subscriber.
[0112] Optionally, the registration information includes device information such as the device identifier of the target client and the timestamp when the registration is initiated.
[0113] 202. The authentication server determines whether the target client is registered according to the registration information and the client information in the authentication server.
[0114] In this step, the authentication server compares the registration information of the target client with the registered client information in the database of the authentication server to determine whether the target client has been registered, and further determine the legitimacy of the target client. Specifically, when the registration information of the target client is not included in the client information in the database, it indicates that the target client has not been registered, and the target client is determined to be a trusted and legitimate client; when the registration information of the target client is already included in the client information in the database, it indicates that the target client has been registered, and the target client may be a client maliciously registered by an attacker, and the target client is determined to be an untrusted client.
[0115] In the above manner, the authentication server uses the registered client information stored in the database to authenticate the target client, screens out untrusted clients, to ensure the security of the proxy server, and further ensure the security of subsequent data transmission.
[0116] 203. In the case where the target client has not been registered, the authentication server generates an identity identifier for the target client based on the client device identifier, the first timestamp, and the preset parameter information, to register the target client.
[0117] In this step, after determining that the target client has not been registered, the authentication center will generate a unique identity identifier for the target client based on the target client device identifier, the first timestamp at the time of initiating registration, and the parameter information of the proxy server.
[0118] Optionally, after the authentication center generates the identity identifier of the target client, it stores the generated identity identifier in the database. By using the identity identifier in the database, it ensures that each client identity can only be used once, to screen out untrusted clients, and effectively improve the security of the connection between the proxy server and the client.
[0119] It should be noted that the parameter information of the proxy server refers to the various parameter indicators of the proxy server during its current operation, as well as the IP address information of the proxy server.
[0120] 204. The authentication server sends the first prime number, the second prime number, and the identity identifier corresponding to the target client to the target client.
[0121] In this step, after the authentication server completes the registration of the target client, the authentication server generates the first prime number and the second prime number corresponding to the target client. Subsequently, it sends the first prime number, the second prime number, and the identity identifier of the target client to the target client.
[0122] It should be noted that the first prime number and the second prime number of each client are different. After the target client is registered, two non-repeating prime numbers are randomly selected from all unused prime numbers as the first prime number and the second prime number of the target client.
[0123] In a specific embodiment, after the authentication server completes the registration of the target client, the authentication server generates two prime numbers m 1 、m 2 for the target client, and then returns m 1 、m 2 of the target client and the identity identifier ClientToken to the target client.
[0124] 205. The target client generates a first hash value and a first hash digest according to the identity identifier, device identifier, and first timestamp.
[0125] In this step, the target client uses a hash function to calculate the identity identifier, the device identifier of the target client, and the first timestamp to obtain the first hash value. Subsequently, the first hash value, device identifier, and first timestamp are calculated to obtain the first hash digest.
[0126] In the above manner, the hash operation is performed on the data sent by the target client and the proxy client with the identity identifier of the client and the timestamp to obtain the hash value. Since the identity identifier is issued by the authentication server, the attacker cannot obtain the identity identifier and modify the hash value, effectively ensuring the integrity of the data.
[0127] 206. The target client sends the device identifier, first timestamp, first hash value, and first hash digest to the authentication server.
[0128] 207. The authentication server generates a second hash digest according to the first hash value, device identifier, and first timestamp.
[0129] In steps 206 and 207, the target client sends the device identifier, first timestamp, and the generated first hash value and first hash digest to the authentication server. Further, after the authentication server receives this information sent by the target client, it finds the stored identity identifier of the target client in the database through the device identifier of the target client. Subsequently, the first hash value, device identifier, and first timestamp are subjected to a hash operation to obtain the second hash digest.
[0130] 208. When the first hash digest is the same as the second hash digest, the authentication server generates a second hash value according to the device identifier and the first timestamp.
[0131] In this step, the generated first hash digest is compared with the second hash digest. If the first hash digest is different from the second hash digest, it indicates that an attacker has maliciously tampered with the target client data. Then a warning is issued and the subsequent requests from the client are ignored. Further, if the first hash digest is the same as the second hash digest, it indicates that the current data is secure. At this time, the authentication server queries the stored identity identifier corresponding to the device identifier in the database according to the device identifier of the target client. Then, a hash operation is performed on the device identifier, the stored identity identifier, and the first timestamp to obtain a second hash value.
[0132] In the above manner, based on the comparison result of the first hash digest and the second hash digest, it is determined whether the data is complete, so as to verify the security of the data before the target client sends the data to the authentication server, effectively resist replay attacks and man-in-the-middle attacks, prevent attackers from maliciously tampering with the data of the target client, and effectively improve the security of data transmission.
[0133] In a specific embodiment, the target client uses a hash function to calculate the identity identifier ClientToken, the device identifier ClientID, and the first timestamp STAMP P1 , to obtain a first hash value Q Client , and calculate a first hash digest HD P1 . Thereafter, the target client sends the relevant necessary ClientID, the first timestamp STAMP P1 , Q Client , and HD P1 to the authentication server. After receiving this information, the authentication server queries the ClientToken of the target client through ClientID, and then calculates ClientToken, ClientID, and STAMP P1 in the same way to obtain the second hash value Q of the data Client1 , and compares it with the data Q Client sent by the target client to verify the integrity of the data.
[0134] 209. When the first hash value and the second hash value are the same, the authentication server generates a second public-private key pair, a third public-private key pair, and a first numerical value, where the second public-private key pair includes a second public key and a second private key, and the third public-private key pair includes a third public key and a third private key.
[0135] In this step, after generating the second hash value, the authentication server compares the first hash value with the second hash value. If the first hash value and the second hash value are the same, it indicates that the data of the current client is secure data. At this time, the authentication server randomly generates a second public-private key pair and a third public-private key pair. Meanwhile, a first numerical value is randomly selected between 0 and the first prime number.
[0136] It should be noted that the authentication server generates a second public-private key pair and a third public-private key pair by using a conventional key generation algorithm in the art. Among them, the second public-private key pair includes a second public key and a second private key, and the third public-private key pair includes a third public key and a third private key.
[0137] In the above manner, after data verification is first performed using the hash digest, data verification is then performed using the hash value. Since the hash digest is relatively concise, when it is verified according to the hash digest that the data has been tampered with, subsequent operations do not need to be performed, effectively saving the time for data verification and improving the efficiency of data security verification. Further, after data security verification is performed using the hash digest, the complete hash value is further used to verify the client to improve the security of the connection between the server and the client.
[0138] 210. The authentication server generates a third hash digest according to the third public key, the identity identifier, and the second timestamp.
[0139] In this step, the authentication server performs a hash operation on the third public key, the identity identifier of the target client, and the second timestamp to generate a third hash digest. It should be noted that the second timestamp is the timestamp corresponding to the current time.
[0140] 211. The authentication server sends the second public key, the third public key, the first value, the second timestamp, and the third hash digest to the target client.
[0141] In this step, the authentication server sends the generated second public key, third public key, first value, second timestamp, and third hash digest to the target client.
[0142] 212. The target client generates a fourth hash digest according to the second public key, the second timestamp, and the identity identifier.
[0143] In this step, after receiving the second public key, the third public key, the first value, the second timestamp, and the third hash digest, the target client performs a hash operation on the second public key, the second timestamp, and its own identity identifier to obtain a fourth hash digest.
[0144] In a specific embodiment, after the integrity verification of the data is completed, the authentication server generates two pairs of public-private keys, namely the second public-private key pair (F, f) and the third public-private key pair (R, r). At the same time, a first value a will be randomly selected between (0, m 1 ) 1 . Thereafter, a hash calculation is performed on the second public key R of the second pair of public-private key pairs, ClientToken, and the second timestamp STAMP P2 to obtain a third hash digest HD P2After completion, the authentication server returns the second public key F, the third public key R, and the private key of the two pairs to the target client. 1 、STAMP P2 and HD P2 After the target client receives it, the received R and STAMP are calculated using the hash function. P2 And its own ClientToken, get the corresponding fourth hash digest HD P21 , and with HD P2 Compare and verify the integrity of the data.
[0145] 213. When the third hash digest is the same as the fourth hash digest, the target client generates a fourth public-private key pair, where the fourth public-private key pair includes a fourth public key and a fourth private key.
[0146] In this step, after the target client generates the fourth hash digest, it compares the received third hash digest with the fourth hash digest. After determining that the third hash digest is the same as the fourth hash digest, the target client randomly generates a fourth public-private key pair, specifically, the fourth public-private key pair includes a fourth public key and a fourth private key.
[0147] Optionally, after determining that the third hash digest is the same as the fourth hash digest, the target client randomly selects a second value between 0 and a second prime number, and determines a third timestamp according to the current time.
[0148] 214. The target client generates a fifth hash digest according to the fourth public key, the identity identifier and the third timestamp.
[0149] In this step, the target client performs a hash operation on the generated fourth public key, its own identity identifier and the third timestamp to generate a fifth hash digest.
[0150] 215. The target client sends the fourth public key, the fifth hash digest, the second value, and the third timestamp to the authentication server.
[0151] 216. The authentication server generates a sixth hash digest according to the fourth public key, the identity identifier and the third timestamp.
[0152] In step 215 and step 216, the target client sends the generated fourth public key, fifth hash digest, second value and third timestamp to the authentication server. The authentication server performs a hash operation on the received fourth public key, identity and third timestamp to obtain a sixth hash digest.
[0153] In a specific embodiment, after the target client completes data verification, the target client randomly generates a fourth public-private key pair (E, e) and randomly selects a value between 0 and m. 2 The second value a2 After that, use the hash function to calculate the fourth public key E, the third timestamp STAMP P3 and ClientToken, and generate the fifth hash digest HD P3 Then the target client sends E, a 2 , STAMP P3 and HD P3 to the authentication server. The authentication server uses the hash function to calculate the received E, ClientToken, and STAMP P3 to obtain the sixth hash digest HD P31 , and compare it with HD P3 for data verification.
[0154] 217. When the fifth hash digest is the same as the sixth hash digest, in response to the verification passed instruction sent by the authentication server, the target client generates the fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first value, and the second value.
[0155] In this step, compare the fifth hash digest generated by the target client with the sixth hash digest generated by the authentication server. When the fifth hash digest is the same as the sixth hash digest, the authentication server sends a verification passed instruction to the target client. After receiving the verification passed instruction, the client uses the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first value, and the second value to calculate the fifth shared communication key exclusive to the target client.
[0156] Through the above method, after ensuring the integrity and security of the data of the client and the authentication server in terms of time, the target client calculates the shared communication key, which is convenient for encrypting and communicating data using the shared communication key in the subsequent communication process.
[0157] In the embodiment of the present application, optionally, in step 217, that is, generating the fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first value, and the second value, specifically includes: calculating a first parameter according to the first hash digest, the third hash digest, and the fifth hash digest using a first preset formula;
[0158] The first preset formula is:
[0159] t = Hash(HD P1 ||HD P2 ||HD P3);
[0160] Among them, the above t is the first parameter; the above Hash is a hash function; the above HD P1 is the first hash digest; the above HD P2 is the third hash digest; the above HD P3 is the fifth hash digest;
[0161] Calculate the second parameter according to the first prime number and the second prime number using the second preset formula;
[0162] The second preset formula is:
[0163] M = m 1 × m 2 ;
[0164] Among them, the above M is the second parameter; the above m 1 is the first prime number; the above m 2 is the second prime number;
[0165] Calculate the third parameter according to the second parameter, the first prime number and the second prime number using the third preset formula;
[0166] The third preset formula is:
[0167]
[0168] Among them, the above M i is the third parameter, the above m i is the first prime number or the second prime number;
[0169] Calculate the fourth parameter according to the third parameter, the first prime number and the second prime number using the fourth preset formula;
[0170] The fourth preset formula is:
[0171] y i = M i -1 (mod(m i ))(i = 1, 2);
[0172] Among them, the above y i is the fourth parameter; the above mod is a remainder function;
[0173] Calculate the fifth parameter according to the second parameter, the third parameter, the fourth parameter, the first value and the second value using the fifth preset formula;
[0174] The fifth preset formula is:
[0175] x = (a 1 y 1 M 1 + a2 y 2 M 2 )(mod(M));
[0176] Wherein, the above x is the fifth parameter; the above a 1 is the first value; the above y 1 is the fourth parameter when i = 1; the above M 1 is the third parameter when i = 1; the above a 2 is the second value; the above y 2 is the fourth parameter when i = 2; the above M 2 is the third parameter when i = 2;
[0177] According to the fifth parameter, the second public key, the third public key and the fourth private key, use the sixth preset formula to calculate the fifth shared communication key;
[0178] The sixth preset formula is:
[0179] shareKey client = e(Fx + tR);
[0180] Wherein, the above shareKey client is the fifth shared communication key; the above e is the fourth private key; the above F is the second public key; the above R is the third public key.
[0181] In this embodiment, first perform a hashing operation on the first hash digest HD P1 , the third hash digest HD P2 and the fifth hash digest HD P3 to obtain the first parameter t. Then, multiply the first prime number m 1 and the second prime number m 2 to obtain the second parameter M, and use M divided by m 1 to obtain the third parameter M 1 when i = 1, and use M divided by m 2 to obtain the third parameter M 2 when i = 2. Then, use the fourth preset formula to calculate the fourth parameters y 1 and y 2 respectively, and use the fifth preset formula to calculate the fifth parameter x. Finally, use the sixth preset formula to calculate the fifth shared communication key shareKey client exclusive to the target client.
[0182] It can be understood that the fifth shared communication key includes the first shared communication key and the third shared communication key.
[0183] 218. The authentication server, in response to the verification confirmation instruction sent by the target client, generates a sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first value, and the second value.
[0184] In this step, while generating the fifth shared communication key, the target client sends a verification confirmation instruction that has been verified and passed to the authentication server. After receiving the confirmation instruction from the target client, the authentication server generates a sixth shared communication key according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first value, and the second value. It should be noted that the sixth shared communication key corresponds to the fifth shared communication key of the target client and is used to decrypt the data encrypted with the fifth shared communication key.
[0185] Optionally, the authentication server encrypts the verification passed instruction with the fourth public key and sends it to the target client. The target client receives the encrypted instruction and decrypts it with the fourth private key to obtain the verification passed instruction. Subsequently, the target client encrypts the verification confirmation instruction with the second public key and sends the encrypted verification confirmation instruction to the authentication server to inform the authentication server that the verification passed instruction has been obtained. The authentication server decrypts it with the second private key to obtain the decrypted verification confirmation instruction. By encrypting and decrypting the transmitted verification passed instruction and verification confirmation instruction, the security of data transmission is effectively improved.
[0186] In the embodiment of the present application, optionally, in step 218, that is, generating a sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first value, and the second value, specifically includes: calculating a first parameter according to the first hash digest, the third hash digest, and the fifth hash digest using a first preset formula; calculating a second parameter according to the first prime number and the second prime number using a second preset formula; calculating a third parameter according to the second parameter, the first prime number, and the second prime number using a third preset formula; calculating a fourth parameter according to the third parameter, the first prime number, and the second prime number using a fourth preset formula;
[0187] The fourth preset formula is:
[0188] y i =M i -1 (mod(m i ))(i = 1, 2);
[0189] Calculate a fifth parameter according to a second parameter, a third parameter, a fourth parameter, a first value, and a second value by using a fifth preset formula; calculate a fifth shared communication key according to the fifth parameter, a second private key, a third private key, and a fourth public key by using a sixth preset formula.
[0190] The sixth preset formula is:
[0191] shareKey broker = E(fx + tr);
[0192] Wherein, the above-mentioned shareKey broker is the sixth shared communication key; the above-mentioned E is the fourth public key; the above-mentioned f is the second private key; the above-mentioned t is the third private key.
[0193] In this embodiment, first perform a hashing operation on the first hash digest HD P1 , the third hash digest HD P2 , and the fifth hash digest HD P3 to obtain a first parameter t. Subsequently, multiply the first prime number m 1 and the second prime number m 2 to obtain a second parameter M, and use M divided by m 1 to obtain the third parameter M 1 when i = 1, and use M divided by m 2 to obtain the third parameter M 2 when i = 2. Subsequently, use the fourth preset formula to calculate the fourth parameters y 1 and y 2 , and use the fifth preset formula to calculate the fifth parameter x. Finally, use the sixth preset formula to calculate the sixth shared communication key shareKey broker of the authentication server.
[0194] It can be understood that the sixth shared communication key includes the second shared communication key and the fourth shared communication key.
[0195] Through the above method, after the target client registers and verifies with the authentication server, the target client and the authentication server use the key negotiation algorithm and the lightweight key negotiation method of the remaining theory to generate a secure shared communication key, improving the security of subsequent data transmission and storage.
[0196] 219. In response to a communication request, obtain the topic included in the communication request and the payload to be published on the topic.
[0197] In this step, in response to the communication request, obtain the topic published by the publisher in the communication request, and the payload to be published on the topic. It should be noted that the payload is the specific content of the message to be published.
[0198] Optionally, when the first client / second client needs to connect to the proxy server, it needs to authenticate with the authentication server first. The authentication server compares the connection information such as the device identifier sent by the first client / second client with the registered information in the database to verify the identity of the first client / second client, so as to determine whether the first client / second client is an unregistered client or an untrusted client, in order to ensure the security of subsequent data transmission.
[0199] In a specific embodiment, after the publisher client and the subscriber client register with and are verified by the authentication server, the publisher pub, the subscriber sub, and the authentication server use a lightweight key negotiation method to negotiate keys, and obtain the first shared communication key shareKey of the publisher pub. pub and the third shared communication key shareKey of the subscriber sub sub as well as the second shared communication key shareKey of the authentication server side pbroker and the fourth shared communication key shareKey sbroker . In response to the publish request of the publisher pub, the topic and payload in the request are obtained.
[0200] 220. The first client uses the first session key to encrypt the payload and the device identifier of the first client, and generates a first ciphertext.
[0201] In this step, the first client is the publisher side that publishes the message. When each publisher side publishes a message, it randomly generates a first session key according to the topic. Then, it uses the generated first session key to encrypt the payload and the device identifier of the publisher side, and generates a first ciphertext. 221. The first client uses the first shared communication key to encrypt the device identifier and the first session key, generates an encrypted device identifier and a second session key, and sends the second session key to the authentication server.
[0202] In this step, the first client uses the first shared communication key to encrypt its device identifier to generate an encrypted device identifier. At the same time, the first client uses the first shared communication key to encrypt the first session key to generate an encrypted second session key. Then, it sends the encrypted second session key to the authentication server for the authentication server to store the first session key in the database.
[0203] 222. The first client generates a message packet according to the first ciphertext, the topic, and the encrypted device identifier, and sends it to the proxy server.
[0204] In this step, the first client encapsulates the encrypted first ciphertext, the topic, and the encrypted device identifier into a message packet and sends it to the proxy server.
[0205] In a specific embodiment, the publisher pub randomly generates a first session key encKey according to the topic T1 , and uses encKey T1 to encrypt the payload pt of the message to be published on the topic T1 and the device identifier ClientID to generate the ciphertext first ciphertext ct T1 , and uses the first shared communication key shareKey pub to encrypt the first session key encKey T1 to generate the encrypted second session key pEncKey T1 , uses the first shared communication key shareKey pub to encrypt the device identifier ClientID to generate the encrypted device identifier ctclientID. Further, the publisher pub encapsulates the encrypted ciphertext first ciphertext ct T1 , the topic T1, and ctclientID into a message packet PUBLISH and sends it to the proxy server, and then sends the encrypted second session key pEncKey T1 to the authentication server.
[0206] 223. The proxy server determines the topic and the second client corresponding to the topic according to the message packet, and sends the topic, the second client, and the encrypted device identifier to the authentication server.
[0207] In this step, after receiving the message packet sent by the first client, the proxy server analyzes the message packet to determine the topic to which the message sent by the first client belongs. Thereafter, it queries the second client corresponding to the topic, that is, the subscriber side. After determining the subscriber, the proxy server sends the topic, the second client, and the encrypted device identifier of the first client to the authentication server.
[0208] 224. The authentication server generates a third ciphertext according to the second shared communication key, the topic, the encrypted device identifier, and the first public key, and sends it to the proxy server.
[0209] 225. The proxy server encrypts the first ciphertext and the third ciphertext using the third shared communication key to generate a fourth ciphertext, and sends it to the second client.
[0210] In steps 224 and 225, after the authentication server receives the message sent by the proxy server, it decrypts the encrypted device identifier using the second shared communication key to obtain the device identifier of the first client. Subsequently, the proxy server queries the stored first session key of the first client in the database using the topic and the device identifier of the first client. Further, the proxy server encrypts the first session key and the device identifier using the first public key to generate a third ciphertext, and sends the third ciphertext and the third shared communication key to the proxy server. Further, the proxy server encrypts the first ciphertext and the third ciphertext using the third shared communication key sent by the authentication server to obtain a fourth ciphertext. The proxy server sends the fourth ciphertext to the second client.
[0211] In an embodiment of the present application, optionally, in step 224, that is, the authentication server generates a third ciphertext according to the second shared communication key, the topic, the encrypted device identifier, and the first public key, and sends it to the proxy server, specifically including: the authentication server decrypts the encrypted device identifier using the second shared communication key to obtain the device identifier of the first client; the authentication server determines the first session key using the topic and the device identifier; the authentication server generates a first public-private key pair according to the topic and the second client, where the first public-private key pair includes a first public key and a first private key; the authentication server encrypts the first private key using the third shared communication key and sends the encrypted first private key to the second client; the authentication server encrypts the first session key and the device identifier using the first public key to generate a third ciphertext; the authentication server sends the third ciphertext to the proxy server.
[0212] In a specific embodiment, after the proxy server receives the PUBLISH sent by the publisher pub, it analyzes from the message header that the message sent by the publisher pub belongs to the topic T1, and then queries the subscriber sub of the topic T1. The proxy server sends the topic T1, the subscriber sub, and the encrypted device identifier ctclientID to the authentication server. After receiving the encrypted second session key pEncKeyT1 transmitted by the publisher, the authentication server uses the second shared communication key shareKey pbroker to decrypt the first session key encKeyT1 and store it. Further, after the authentication server receives the message sent by the proxy server, it uses the second shared communication key shareKey pbroker to decrypt ctclientID to obtain ClientID, and then finds the first session key encKeyT1 using the topic T1 and ClientID. Then, the authentication server generates a first public-private key pair for the topic T1 and the subscriber sub, that is, a subscription public-private key pair (Y, y). The authentication server encrypts the first session key encKeyT1 and the device identifier ClientID using the first public key Y to generate the encrypted third ciphertext ctkeyT1ID After that, the encrypted third ciphertext ctkey T1ID and the third shared communication key shareKey sbroker are sent to the proxy server. The first private key y is encrypted using the third shared communication key shareKey sbroker to obtain the encrypted first private key and sent to the subscriber sub. Further, the proxy server uses the third preset communication key shareKey sbroker to encrypt the first ciphertext ct containing the payload published by the publisher pub that needs to be forwarded to the subscriber sub before T1 and the encrypted third ciphertext ctkey T1ID to obtain the fourth ciphertext. The proxy server sends the fourth ciphertext to the subscriber sub.
[0213] 226. The second client uses the fourth shared communication key to decrypt the fourth ciphertext to obtain the first ciphertext and the third ciphertext.
[0214] In this step, after receiving the ciphertext sent by the proxy server, the second client uses the fourth shared communication key symmetric to the third shared communication key to decrypt the fourth ciphertext sent by the proxy server to obtain the third ciphertext and the first ciphertext containing the payload.
[0215] 227. The second client uses the first private key to decrypt the third ciphertext to obtain the first session key and the device identifier.
[0216] In this step, after decrypting to obtain the third ciphertext, the second client uses the first private key to decrypt the third ciphertext to obtain the first session key and the device identifier of the first client.
[0217] 228. The second client uses the first session key to decrypt the first ciphertext to obtain the payload and the identity identifier.
[0218] In this step, the second client uses the first session key to decrypt the first ciphertext to obtain the payload published by the publisher and the device identifier of the first client.
[0219] 229. The second client compares the device identifier decrypted using the first private key with the device identifier decrypted using the first session key.
[0220] 230. If the device identifier decrypted using the first subscription private key is the same as the device identifier decrypted using the first session key, the payload is retained.
[0221] In steps 229 and 230, the device identifier obtained by decrypting the third ciphertext is the device identifier sent by the authentication server to the subscriber side through the proxy server, while the device identifier in the first ciphertext is the device identifier in the publisher side message. To prevent attackers from tampering with data during data transmission, the second client compares whether the device identifier obtained by decrypting with the first private key is the same as the device identifier in the publisher side message. If they are the same, it indicates that the data is intact and not tampered with during data transmission, and the payload is retained at this time; if they are different, it indicates that the data is maliciously tampered with during data transmission, and the payload is rejected at this time.
[0222] Further, as Figure 1 a specific implementation of the Figure 2As shown in the figure, an embodiment of the present application provides a communication device 200, which is applicable to a communication system. The communication system includes a first client, a second client, a proxy server, and an authentication server. The device includes: an obtaining module 201, configured to obtain a subject included in the communication request and a payload to be published on the subject in response to the communication request; a generating module 202, configured to encrypt the payload and the device identifier of the first client by using the first session key by the first client to generate a first ciphertext; the generating module 202 is further configured to encrypt the device identifier and the first session key by using the first shared communication key by the first client to generate an encrypted device identifier and a second session key, and send the second session key to the authentication server; the generating module 202 is further configured to generate a message packet according to the first ciphertext, the subject, and the encrypted device identifier by the first client, and send it to the proxy server; a determining module 203, configured to determine the subject and the second client corresponding to the subject according to the message packet by the proxy server, and send the subject, the second client, and the encrypted device identifier to the authentication server; the generating module 202 is further configured to generate a third ciphertext according to the second shared communication key, the subject, the encrypted device identifier, and the first public key by the authentication server, and send it to the proxy server; the generating module 202 is further configured to encrypt the first ciphertext and the third ciphertext by using the third shared communication key by the proxy server to generate a fourth ciphertext, and send it to the second client; the generating module 202 is further configured to decrypt the fourth ciphertext by using the fourth shared communication key by the second client to obtain the first ciphertext and the third ciphertext; the generating module 202 is further configured to decrypt the third ciphertext by using the first private key by the second client to obtain the first session key and the device identifier; the generating module 202 is further configured to decrypt the first ciphertext by using the first session key by the second client to obtain the payload and the device identifier; a comparing module 204, configured to compare the device identifier decrypted by using the first private key by the second client with the device identifier decrypted by using the first session key; a storing module 205, configured to retain the payload if the device identifier decrypted by using the first subscription private key is the same as the device identifier decrypted by using the first session key.
[0223] Optionally, the generating module 202 is specifically configured to: decrypt the encrypted device identifier by using the second shared communication key by the authentication server to obtain the device identifier of the first client; determine the first session key by using the subject and the device identifier by the authentication server; generate a first public-private key pair according to the subject and the second client by the authentication server, where the first public-private key pair includes a first public key and a first private key; encrypt the first private key by using the third shared communication key by the authentication server, and send the encrypted first private key to the second client; encrypt the first session key and the device identifier by using the first public key by the authentication server to generate a third ciphertext; send the third ciphertext to the proxy server.
[0224] Optionally, the obtaining module 201 is further configured to obtain the registration information of the target client included in the client registration request in response to the client registration request, where the target client is the first client or the second client.
[0225] Optionally, the apparatus further includes: a determining module 206, configured to determine whether the target client is registered by the authentication server according to the registration information and the client information in the authentication server.
[0226] Optionally, the generating module 202 is further configured to, when the target client is not registered, generate an identity identifier of the target client by the authentication server according to the client device identifier, the first timestamp, and the preset parameter information, so as to register the target client.
[0227] Optionally, the apparatus further includes: a sending module 207, configured to send the first prime number, the second prime number, and the identity identifier corresponding to the target client by the authentication server to the target client.
[0228] Optionally, the generating module 202 is further configured to generate a first hash value and a first hash digest by the target client according to the identity identifier, the device identifier, and the first timestamp.
[0229] Optionally, the sending module 207 is further configured to send the device identifier, the first timestamp, the first hash value, and the first hash digest by the target client to the authentication server.
[0230] Optionally, the generating module 202 is further configured to, when the first hash digest is the same as the second hash digest, generate a second hash value by the authentication server according to the device identifier and the first timestamp; when the first hash value is the same as the second hash value, generate a second public-private key pair, a third public-private key pair, and a first numerical value by the authentication server, where the second public-private key pair includes a second public key and a second private key, and the third public-private key pair includes a third public key and a third private key; generate a third hash digest by the authentication server according to the third public key, the identity identifier, and the second timestamp.
[0231] Optionally, the sending module 207 is further configured to send the second public key, the third public key, the first numerical value, the second timestamp, and the third hash digest by the authentication server to the target client.
[0232] Optionally, the generating module 202 is further configured to generate a fourth hash digest by the target client according to the second public key, the second timestamp, and the identity identifier; when the third hash digest is the same as the fourth hash digest, generate a fourth public-private key pair by the target client, where the fourth public-private key pair includes a fourth public key and a fourth private key; generate a fifth hash digest by the target client according to the fourth public key, the identity identifier, and the third timestamp.
[0233] Optionally, the sending module 207 is further configured to enable the target client to send the fourth public key, the fifth hash digest, the second numerical value, and the third timestamp to the authentication server.
[0234] Optionally, the generating module 202 is further configured to enable the authentication server to generate a sixth hash digest based on the fourth public key, the identity identifier, and the third timestamp; in the case where the fifth hash digest is the same as the sixth hash digest, the target client, in response to the verification passed instruction sent by the authentication server, generates a fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first numerical value, and the second numerical value; the authentication server, in response to the verification confirmation instruction sent by the target client, generates a sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first numerical value, and the second numerical value.
[0235] Optionally, the generating module 202 is specifically further configured to calculate a first parameter according to the first hash digest, the third hash digest, and the fifth hash digest by using a first preset formula; the first preset formula is:
[0236] t = Hash(HD P1 ||HD P2 ||HD P3 );
[0237] wherein, the above t is the first parameter; the above Hash is a hash function; the above HD P1 is the first hash digest; the above HD P2 is the third hash digest; the above HD P3 is the fifth hash digest; calculate a second parameter according to the first prime number and the second prime number by using a second preset formula; the second preset formula is:
[0238] M = m 1 ×m 2 ;
[0239] wherein, the above M is the second parameter; the above m 1 is the first prime number; the above m 2 is the second prime number; calculate a third parameter according to the second parameter, the first prime number, and the second prime number by using a third preset formula; the third preset formula is:
[0240]
[0241] wherein, the above M i is the third parameter, and the above m iis the first prime number or the second prime number; according to the third parameter, the first prime number and the second prime number, using the fourth preset formula, the fourth parameter is calculated; the fourth preset formula is:
[0242] y i = M i -1 (mod(m i ))(i = 1, 2);
[0243] wherein, the above y i is the fourth parameter; the above mod is the remainder function; according to the second parameter, the third parameter, the fourth parameter, the first value and the second value, using the fifth preset formula, the fifth parameter is calculated; the fifth preset formula is:
[0244] x = (a 1 y 1 M 1 + a 2 y 2 M 2 )(mod(M));
[0245] wherein, the above x is the fifth parameter; the above a 1 is the first value; the above y 1 is the fourth parameter when i = 1; the above M 1 is the third parameter when i = 1; the above a 2 is the second value; the above y 2 is the fourth parameter when i = 2; the above M 2 is the third parameter when i = 2; according to the fifth parameter, the second public key, the third public key and the fourth private key, using the sixth preset formula, the fifth shared communication key is calculated; the sixth preset formula is:
[0246] shareKey client = e(Fx + tR);
[0247] wherein, the above shareKey client is the fifth shared communication key; the above e is the fourth private key; the above F is the second public key; the above R is the third public key.
[0248] Optionally, the generating module 202 is further specifically configured to calculate the first parameter according to the first hash digest, the third hash digest and the fifth hash digest by using the first preset formula; calculate the second parameter according to the first prime number and the second prime number by using the second preset formula; calculate the third parameter according to the second parameter, the first prime number and the second prime number by using the third preset formula; calculate the fourth parameter according to the third parameter, the first prime number and the second prime number by using the fourth preset formula; the fourth preset formula is:
[0249] yi = M i -1 (mod(m i ))(i = 1, 2);
[0250] According to the second parameter, the third parameter, the fourth parameter, the first value, and the second value, use the fifth preset formula to calculate the fifth parameter; according to the fifth parameter, the second private key, the third private key, and the fourth public key, use the sixth preset formula to calculate the fifth shared communication key; the sixth preset formula is:
[0251] shareKey broker = E(fx + tr);
[0252] Wherein, the above shareKey broker is the sixth shared communication key; the above E is the fourth public key; the above f is the second private key; the above t is the third private key.
[0253] According to an embodiment of the present invention, a communication system is provided, including the above communication method.
[0254] In an embodiment of the present application, optionally, the communication system further includes: a first client for publishing messages, the first client is communicatively connected to an authentication server and communicatively connected to a proxy server; a second client for receiving messages of a subscribed topic, the second client is communicatively connected to the proxy server; a proxy server; an authentication server.
[0255] In this embodiment, the communication system includes a first client, a second client, a proxy server, and an authentication server. It should be noted that the first client is the client for publishing messages; the second client is the client for receiving messages on the subscribed topic; the proxy server is the server with the function of message storage and processing; the authentication server is a trusted third party institution with the function of message security authentication.
[0256] Specifically, the first client is the client for publishing messages, registers with the authentication server, and conducts lightweight key negotiation with it to obtain a secure shared communication key. The publisher randomly generates a session key for the topic to encrypt the original data and transmits it to the proxy server, and uses the shared communication key to encrypt the session key and transmit it to the authentication server. Since the message is already in an encrypted state before transmission, it is difficult for an attacker to obtain the original message on the premise that the session key is not leaked.
[0257] Furthermore, the second client is the client that receives messages on the subscribed topics. The subscriber receives the subscription private key sent by the authentication server and the encrypted data sent by the proxy server. The subscriber decrypts the data sent by the proxy server using its own shared communication key to obtain the encrypted session key and the session key-encrypted data. Then, the received private key sent by the authentication server is used to decrypt and obtain the session key, and further obtain the original text sent by the publisher. Similar to the publisher, since the message is already in an encrypted state before transmission, it is difficult for an attacker to obtain the original text of the message on the premise that the session key is not leaked.
[0258] Furthermore, the authentication server is used for the registration, identity authentication, key calculation and generation, and related information storage of the client (publisher / subscriber). The authentication server receives the encrypted session key transmitted by the publisher and decrypts and stores it using the publisher's shared communication key. After that, the authentication server generates subscription public and private keys at the topic granularity based on the topics sent by the proxy server and the subscribers subscribing to the topics, and sends the subscription private key to the subscriber using the subscriber's shared communication key. Then, the session key is encrypted with the subscription public key, and it and the subscriber's shared communication key are sent to the proxy server side. Specifically, as Figure 3 shown, the authentication server mainly includes a registration management center, an identity authentication center, a key negotiation and generation center, and a database. The publisher / subscriber device registers with the authentication server through the client, and the identity authentication center authenticates the client to determine whether the client is legal. When it is determined that the client has not been registered, the registration management center registers it, generates an identity identifier and stores it in the database. Furthermore, after successful registration, the key negotiation and generation center of the authentication server generates a shared communication key for each device to ensure the secure transmission and storage processing of data. By transferring the key generation operation from the client to the authentication server, the computational amount and key storage amount of the client are reduced.
[0259] Furthermore, the proxy server is used to forward message data to the subscriber and perform storage processing on the data transmitted by the publisher. After receiving the data, the proxy server verifies the security of the data. After passing the verification, it parses out the topic and the subscriber subscribing to the topic and sends them to the authentication server. When the proxy server forwards a message to the subscriber, it encrypts the data using the subscriber's shared communication key sent by the authentication server and forwards it to the subscriber together with the session key encrypted with the subscription public key.
[0260] Optionally, as Figure 4As shown, the communication process between the first client and the proxy server is unidirectional, i.e., from the first client to the proxy server. Since the session key is randomly generated by the first client, an attacker cannot steal the encryption key. During the transmission process, both the key and the message are encrypted. The attacker can only obtain the encrypted message and the message key, and cannot get the plaintext of the message, so they cannot eavesdrop on or leak the corresponding message. This ensures the security of data during transmission.
[0261] Furthermore, as Figure 4 shown, the communication between the proxy server and the authentication server is bidirectional. The main process between them is the request and response process of the process key. Since there are no hardware limitations of the client in the Internet of Things environment, such as memory and computing power limitations, between the proxy server and the authentication server, the communication between them can be completely solved by the existing solution, i.e., the SSL / TLS protocol solution. Since the SSL / TLS protocol solution is used, the corresponding attack means will not take effect. In addition, even if the proxy server is invaded, since the data transmitted during the entire communication process is encrypted, the attacker can only obtain the shared communication key returned by the authentication server and the encrypted session key of the subscriber side. For the shared communication key, it is impossible to separately deduce the encryption key of the publisher side or the subscriber side through the shared communication key. Therefore, the attacker cannot decrypt the original message through the shared communication key. For the encrypted session key of the subscriber side, decrypting it requires first obtaining the shared communication key generated by the subscriber side, but the shared communication key of the subscriber side is unique to it. This ensures the security of data in terms of storage and processing.
[0262] Furthermore, as Figure 4 shown, the communication between the proxy server and the second client is also unidirectional. The proxy server forwards and pushes the message ciphertext and the encrypted session key to the corresponding second client. During the transmission process, both the session key and the corresponding message ciphertext are in an encrypted state. The attacker cannot separately deduce the corresponding plaintext from the ciphertext, but can only indirectly obtain the plaintext content by cracking the encryption key. The session key is encrypted by the relevant shared communication key, and only the second client can calculate and deduce the corresponding shared communication key. Therefore, the attacker cannot obtain the original plaintext message content, which ensures the security of data during transmission.
[0263] According to an embodiment of the present invention, a storage medium is provided. The storage medium stores at least one executable instruction, and the computer executable instruction can execute the communication method in any of the above method embodiments.
[0264] Through the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented through hardware or by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various implementation scenarios of this application.
[0265] Those skilled in the art can understand that the drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the drawings are not necessarily essential for implementing this application.
[0266] Those skilled in the art can understand that the modules in the devices in the implementation scenarios can be distributed in the devices in the implementation scenarios according to the description of the implementation scenarios, or can be correspondingly changed to be located in one or more devices different from this implementation scenario. The modules in the above implementation scenarios can be combined into one module, or can be further split into multiple sub-modules.
[0267] The above serial numbers of this application are only for description and do not represent the advantages or disadvantages of the implementation scenarios.
[0268] The above discloses only several specific implementation scenarios of this application. However, this application is not limited thereto, and any changes that can be thought of by those skilled in the art should fall within the protection scope of this application.
Claims
1. A communication method, characterized in that, it is applicable to a communication system, wherein the communication system includes a first client, a second client, a proxy server, and an authentication server, and the method includes: In response to a communication request, obtaining the subject included in the communication request and the payload to be published on the subject; The first client encrypts the payload and the device identifier of the first client using a first session key to generate a first ciphertext; The first client encrypts the device identifier and the first session key using a first shared communication key to generate an encrypted device identifier and a second session key, and sends the second session key to the authentication server; The first client generates a message packet based on the first ciphertext, the subject, and the encrypted device identifier, and sends it to the proxy server; The proxy server determines the subject and the second client corresponding to the subject based on the message packet, and sends the subject, the second client, and the encrypted device identifier to the authentication server; The authentication server generates a third ciphertext based on a second shared communication key, the subject, the encrypted device identifier, and a first public key, and sends it to the proxy server; The proxy server encrypts the first ciphertext and the third ciphertext using a third shared communication key to generate a fourth ciphertext, and sends it to the second client; The second client decrypts the fourth ciphertext using a fourth shared communication key to obtain the first ciphertext and the third ciphertext; The second client decrypts the third ciphertext using a first private key to obtain the first session key and the device identifier; The second client decrypts the first ciphertext using the first session key to obtain the payload and the device identifier; The second client compares the device identifier decrypted using the first private key with the device identifier decrypted using the first session key; If the device identifier decrypted using the first subscription private key is the same as the device identifier decrypted using the first session key, the payload is retained.
2. The communication method according to claim 1, characterized in that, the step in which the authentication server generates a third ciphertext based on a second shared communication key, the subject, the encrypted device identifier, and a first public key, and sends it to the proxy server specifically includes: The authentication server decrypts the encrypted device identifier using the second shared communication key to obtain the device identifier of the first client; The authentication server determines the first session key using the subject and the device identifier; The authentication server generates a first public-private key pair based on the subject and the second client, where the first public-private key pair includes a first public key and a first private key; The authentication server encrypts the first private key using the third shared communication key and sends the encrypted first private key to the second client; The authentication server encrypts the first session key and the device identifier by using the first public key to generate the third ciphertext; The authentication server sends the third ciphertext to the proxy server.
3. The communication method according to claim 1, wherein, Before obtaining the subject included in the communication request and the payload to be published on the subject in response to the communication request, the method further includes: In response to a client registration request, obtaining the registration information of a target client included in the client registration request, where the target client is a first client or a second client; The authentication server determines whether the target client is registered according to the registration information and the client information in the authentication server; In the case where the target client is not registered, the authentication server generates an identity identifier of the target client according to the client device identifier, the first timestamp, and preset parameter information to register the target client.
4. The communication method according to claim 3, wherein, After the authentication server generates the identity identifier of the target client according to the client device identifier, the first timestamp, and preset parameter information to register the target client, the method further includes: The authentication server sends the first prime number, the second prime number, and the identity identifier corresponding to the target client to the target client; The target client generates a first hash value and a first hash digest according to the identity identifier, the device identifier, and the first timestamp; The target client sends the device identifier, the first timestamp, the first hash value, and the first hash digest to the authentication server; The authentication server generates a second hash digest according to the first hash value, the device identifier, and the first timestamp; In the case where the first hash digest is the same as the second hash digest, the authentication server generates a second hash value according to the device identifier and the first timestamp; In the case where the first hash value is the same as the second hash value, the authentication server generates a second public-private key pair, a third public-private key pair, and a first numerical value, where the second public-private key pair includes a second public key and a second private key, and the third public-private key pair includes a third public key and a third private key; The authentication server generates a third hash digest according to the third public key, the identity identifier, and the second timestamp; The authentication server sends the second public key, the third public key, the first numerical value, the second timestamp, and the third hash digest to the target client; The target client generates a fourth hash digest according to the second public key, the second timestamp, and the identity identifier; In the case where the third hash digest is the same as the fourth hash digest, the target client generates a fourth public-private key pair, where the fourth public-private key pair includes a fourth public key and a fourth private key; After determining that the third hash digest is the same as the fourth hash digest, the target client randomly selects a second value between 0 and the second prime number, and determines a third timestamp according to the current time; The target client generates a fifth hash digest according to the fourth public key, the identity identifier, and the third timestamp; The target client sends the fourth public key, the fifth hash digest, the second value, and the third timestamp to the authentication server; The authentication server generates a sixth hash digest according to the fourth public key, the identity identifier, and the third timestamp; When the fifth hash digest is the same as the sixth hash digest, the target client, in response to the verification passed instruction sent by the authentication server, generates a fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first value, and the second value; The authentication server, in response to the verification confirmation instruction sent by the target client, generates a sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first value, and the second value.
5. The communication method according to claim 4, wherein, The step of generating a fifth shared communication key corresponding to the target client according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second public key, the third public key, the fourth private key, the first value, and the second value specifically includes: Calculating a first parameter according to the first hash digest, the third hash digest, and the fifth hash digest by using a first preset formula; The first preset formula is: t = Hash(HD P1 || HD P2 || HD P3 ); Wherein, the above-mentioned t is the first parameter; the above-mentioned Hash is a hash function; the above-mentioned HD P1 is the first hash digest; the above-mentioned HD P2 is the third hash digest; the above-mentioned HD P3 is the fifth hash digest; Calculating a second parameter according to the first prime number and the second prime number by using a second preset formula; The second preset formula is: M = m 1 × m 2 ; Among them, the above M is the second parameter; the above m 1 is the first prime number; the above m 2 is the second prime number; Calculating a third parameter according to the second parameter, the first prime number, and the second prime number by using a third preset formula; The third preset formula is: ; Among them, the above-mentioned M i is the third parameter, and the above-mentioned m i is the first prime number or the second prime number; Calculating a fourth parameter according to the third parameter, the first prime number, and the second prime number by using a fourth preset formula; The fourth preset formula is: y i =M i -1 (mod (m i )) (i = 1, 2); wherein, the above-mentioned y i is the fourth parameter; the above-mentioned mod is the remainder function; Calculating a fifth parameter according to the second parameter, the third parameter, the fourth parameter, the first value, and the second value by using a fifth preset formula; The fifth preset formula is: x = (a 1 y 1 M 1 + a 2 y 2 M 2 )(mod(M)); Among them, the above-mentioned x is the fifth parameter; the above-mentioned a 1 is the first numerical value; the above-mentioned y 1 is the fourth parameter when i = 1; the above-mentioned M 1 is the third parameter when i = 1; the above-mentioned a 2 is the second numerical value; the above-mentioned y 2 is the fourth parameter when i = 2; the above-mentioned M 2 is the third parameter when i = 2; Calculating the fifth shared communication key according to the fifth parameter, the second public key, the third public key, and the fourth private key by using a sixth preset formula; The sixth preset formula is: shareKey client =e(Fx + tR); Among them, the above-mentioned shareKey client is the fifth shared communication key; the above-mentioned e is the fourth private key; the above-mentioned F is the second public key; the above-mentioned R is the third public key.
6. The communication method according to claim 5, wherein, The step of generating a sixth shared communication key corresponding to the authentication server according to the first hash digest, the third hash digest, the fifth hash digest, the first prime number, the second prime number, the second private key, the third private key, the fourth public key, the first value, and the second value specifically includes: Calculate a first parameter according to the first hash digest, the third hash digest, and the fifth hash digest by using the first preset formula; Calculate a second parameter according to the first prime number and the second prime number by using the second preset formula; Calculate a third parameter according to the second parameter, the first prime number, and the second prime number by using the third preset formula; Calculate a fourth parameter according to the third parameter, the first prime number, and the second prime number by using the fourth preset formula; The fourth preset formula is: y i =M i -1 (mod (m i )) (i = 1, 2); Calculate a fifth parameter according to the second parameter, the third parameter, the fourth parameter, the first value, and the second value by using the fifth preset formula; Calculate the fifth shared communication key according to the fifth parameter, the second private key, the third private key, and the fourth public key by using the sixth preset formula; The sixth preset formula is: shareKey broker =E(fx + tr); Among them, the above-mentioned shareKey broker is the sixth shared communication key; the above-mentioned E is the fourth public key; the above-mentioned f is the second private key; the above-mentioned t is the third private key.
7. A communication device characterized in that it is applicable to a communication system, where the communication system includes a first client, a second client, a proxy server, and an authentication server, and the device includes: an obtaining module, configured to obtain a topic included in the communication request and a payload to be published on the topic in response to the communication request; a generating module, configured to encrypt the payload and the device identifier of the first client by using a first session key by the first client to generate a first ciphertext; The generating module is further configured to encrypt the device identifier and the first session key by using a first shared communication key by the first client to generate an encrypted device identifier and a second session key, and send the second session key to the authentication server; The generating module is further configured to generate a message packet according to the first ciphertext, the topic, and the encrypted device identifier by the first client, and send it to the proxy server; a determining module, configured to determine the topic and the second client corresponding to the topic according to the message packet by the proxy server, and send the topic, the second client, and the encrypted device identifier to the authentication server; The generating module is further configured to generate a third ciphertext according to a second shared communication key, the topic, the encrypted device identifier, and a first public key by the authentication server, and send it to the proxy server; The generating module is further configured to encrypt the first ciphertext and the third ciphertext by using a third shared communication key by the proxy server to generate a fourth ciphertext, and send it to the second client; The generating module is further configured to decrypt the fourth ciphertext by using a fourth shared communication key by the second client to obtain the first ciphertext and the third ciphertext; The generating module is further configured to decrypt the third ciphertext by using a first private key by the second client to obtain the first session key and the device identifier; The generating module is further configured to decrypt the first ciphertext by using the first session key by the second client to obtain the payload and the device identifier; A comparison module, configured to compare the device identifier obtained by decrypting using the first private key by the second client with the device identifier obtained by decrypting using the first session key; A storage module, configured to retain the payload if the device identifier obtained by decrypting using the first subscription private key is the same as the device identifier obtained by decrypting using the first session key.
8. A communication system comprising: The communication method according to any one of claims 1-6.
9. The communication system according to claim 8, wherein, it further comprises: A first client, configured to publish a message, the first client is communicatively connected to an authentication server, and the first client is communicatively connected to a proxy server; The second client, configured to receive messages of a subscribed topic, the second client is communicatively connected to the proxy server; The proxy server; The authentication server.
10. A storage medium, in which at least one executable instruction is stored, and the executable instruction causes a processor to perform operations corresponding to the communication method according to any one of claims 1-6.
Citation Information
Patent Citations
Electronic document safe sharing system and method thereof
CN101989984A
Secret key negotiation method and device
CN106603485A