A processing method and electronic device

By using a verifiable secret sharing method, authorization and verification information are generated for devices in a device group, solving the problems of low certificate management and authentication efficiency in inter-device interconnection and mutual recognition, and achieving efficient and secure device authentication and communication.

CN115913545BActive Publication Date: 2026-02-27LENOVO (BEIJING) LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211570718.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-08
Publication Date
2026-02-27
Estimated Expiration
2042-12-08

AI Technical Summary

Technical Problem

Existing technologies for interconnection and mutual recognition between devices suffer from problems such as complex certificate management, low authentication efficiency, and heavy computing burden on small IoT devices.

Method used

A verifiable secret sharing method is adopted, and a trusted third-party organization generates authorization and verification information for devices in the device group. Secret recovery processing and authentication are performed between devices, avoiding the use of certificate management and signature verification algorithms.

Benefits of technology

It improves the efficiency of inter-device authentication, reduces the computing burden on devices, saves storage space, and enhances the security of end-to-end device communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913545B_ABST
    Figure CN115913545B_ABST
Patent Text Reader

Abstract

The application discloses a processing method and an electronic device, and the processing method can be applied to the electronic device, and specifically comprises the following steps: obtaining authorization information and first verification information corresponding to the electronic device and other electronic devices respectively; the authorization information corresponding to each device respectively comprises a corresponding secret fragment of each secret value in a plurality of secret values, and the first verification information corresponding to each device respectively is information used for performing trustworthiness verification on the secret value; determining a corresponding number of other electronic devices satisfying a quantity condition from the other electronic devices; performing secret recovery processing according to the authorization information corresponding to the electronic device and the authorization information corresponding to the corresponding number of other electronic devices, and obtaining a secret recovery result; and then performing device authentication on each device participating in the secret recovery processing according to the secret recovery result and at least one piece of information in the first verification information corresponding to each device participating in the secret recovery processing.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of secure communication, and particularly relates to a processing method and an electronic device. BACKGROUND

[0002] In the field of IOT (Internet of Things), before the secure communication between end-to-end devices, the interconnection and mutual authentication between the devices are usually required.

[0003] At present, the interconnection and mutual authentication between the devices generally adopt a PKI (Public Key Infrastructure) mechanism, which realizes the secure authentication of the devices by verifying that the certificate of the device is issued by a legal trusted third party. In the verification process, a signature verification algorithm is used to verify the validity of the signature in the certificate (such as x509 certificate), so as to verify the legality of the device. However, this interconnection and mutual authentication method has a series of problems such as complex certificate management, low authentication efficiency based on the signature verification algorithm, and heavy computing burden for small IoT devices. SUMMARY

[0004] To this end, the present application discloses the following technical solutions:

[0005] A processing method applied to an electronic device of an authenticating party, the method comprising:

[0006] obtaining authorization information and first verification information corresponding to the electronic device and other electronic devices respectively, wherein the authorization information corresponding to each device respectively comprises a corresponding secret fragment of each secret value in a plurality of secret values, and the first verification information corresponding to each device respectively is information used for verifying the credibility of the secret value;

[0007] determining a corresponding number of other electronic devices from the other electronic devices that satisfy a quantity condition;

[0008] performing secret recovery processing according to the authorization information corresponding to the electronic device and the authorization information corresponding to the corresponding number of other electronic devices, to obtain a secret recovery result;

[0009] performing device authentication on each device participating in the secret recovery processing according to at least one of the secret recovery result and the first verification information corresponding to each device participating in the secret recovery processing.

[0010] Optionally, the performing device authentication on each device participating in the secret recovery processing according to at least one of the secret recovery result and the first verification information corresponding to each device participating in the secret recovery processing comprises:

[0011] determining whether the secret recovery result represents a recovered secret value;

[0012] If the secret value is recovered, it is determined whether the recovered secret value is trusted based on the first verification information;

[0013] If the secret value is recovered, it is determined whether the recovered secret value is trusted based on the first verification information;

[0014] If the secret value is not recovered or the recovered secret value is not trusted, it is determined that each device participating in the secret recovery process is not authenticated.

[0015] Optionally, before obtaining the authorization information and the first verification information corresponding to the electronic device and the other electronic devices respectively, the method further comprises:

[0016] sending an authorization request to an authorization party, wherein the authorization request comprises a group identifier of a device group, and the electronic device and the other electronic devices are corresponding devices in the device group;

[0017] obtaining authorization information and first verification information corresponding to the electronic device transmitted by the authorization party, wherein the obtained authorization information is corresponding part of authorization information generated by the authorization party for each device in the device group based on a target secret shard generation rule determined by the authorization party based on the group identifier.

[0018] Optionally, the authorization information corresponding to each device in the device group further comprises an auxiliary shard generated by the authorization party based on an auxiliary random number, and before obtaining the authorization information and the first verification information corresponding to the electronic device and the other electronic devices respectively, the method further comprises:

[0019] obtaining second verification information transmitted by the authorization party;

[0020] based on the auxiliary shard and the second verification information, verifying whether the authorization information obtained by each device in the device group is trusted in cooperation with the other electronic devices in the device group, and if so, triggering the step of obtaining the authorization information and the first verification information corresponding to the electronic device and the other electronic devices respectively.

[0021] A processing method applied to an electronic device of an authorization party, the method comprising:

[0022] obtaining an authorization request sent by an authentication party, wherein the authorization request is used to request authorization for each authentication party electronic device included in a device group of the authentication party;

[0023] determining a target secret shard generation rule;

[0024] generate, based on the target secret shard generation rule, corresponding authorization information and first verification information for credibility verification of the secret value for each of the plurality of authentication-side electronic devices; the authorization information generated for each authentication-side electronic device includes a corresponding secret shard of each secret value in the plurality of trusted secret values;

[0025] send the generated authorization information and the first verification information to the authentication side.

[0026] Optionally, the determining the target secret shard generation rule comprises:

[0027] determining the target secret shard generation rule according to the group identifier of the device group included in the authorization request.

[0028] Optionally, after obtaining the at least one authorization request sent by the authentication side, the method further comprises:

[0029] generating, based on the auxiliary random number, corresponding auxiliary shards for the plurality of authentication-side electronic devices;

[0030] generating second verification information for credibility verification of the authorization information;

[0031] sending the auxiliary shards and the second verification information to the authentication side, so that the authentication side verifies whether the authorization information obtained by each device in the device group is credible based on the auxiliary shards and the second verification information.

[0032] Optionally, the above-mentioned processing method applied to the authorization-side electronic device further comprises:

[0033] generating at least a corresponding relationship information between the group identifier of the device group and the target secret shard generation rule, and storing the generated corresponding relationship information.

[0034] Optionally, the above-mentioned processing method applied to the authorization-side electronic device further comprises one of the following:

[0035] obtaining a quit request sent by a first electronic device for indicating a quit of a first device group, and disclosing the authorization information and the first verification information corresponding to the first electronic device, so that an authentication side corresponding to the first device group performs device authentication in combination with the disclosed information;

[0036] obtaining a join request sent by a second electronic device for indicating a join of a second device group, obtaining a secret shard generation rule matching a group identifier of the second device group from the corresponding relationship information, generating corresponding authorization information and first verification information for the second electronic device according to the obtained secret shard generation rule, and feeding back the generated information to the second electronic device.

[0037] An electronic device, comprising:

[0038] a memory for storing at least a set of computer instructions;

[0039] a controller for implementing the processing method applied to the authenticating-party electronic device as claimed in any one of the above, or the processing method applied to the authorized-party electronic device as claimed in any one of the above, by invoking and executing the set of instructions stored in the memory.

[0040] From the above solutions, the present application discloses a processing method and an electronic device, which can be applied to an electronic device, and specifically includes: obtaining authorization information and first verification information corresponding to the electronic device and other electronic devices respectively; the authorization information corresponding to each device respectively includes a corresponding secret fragment of each secret value in a plurality of secret values, and the first verification information corresponding to each device respectively is information used for verifying the credibility of the secret value; determining a corresponding number of other electronic devices satisfying a quantity condition from the above other electronic devices; performing secret recovery processing according to the authorization information corresponding to the electronic device and the authorization information corresponding to the corresponding number of other electronic devices, to obtain a secret recovery result; and then performing device authentication on each device participating in the secret recovery processing according to the secret recovery result and at least one piece of information in the first verification information corresponding to each device participating in the secret recovery processing. BRIEF DESCRIPTION OF DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.

[0042] Figure 1 is a flowchart of the processing method applied to the authenticating party provided by the present application;

[0043] Figure 2 is another flowchart of the processing method applied to the authenticating party provided by the present application;

[0044] Figure 3 is a flowchart of the processing method applied to the authorized party provided by the present application;

[0045] Figure 4 is an information transmission schematic diagram of the authorization stage in an application example provided by the present application;

[0046] Figure 5 is another flowchart of the processing method applied to the authorized party provided by the present application;

[0047] Figure 6 is another flowchart of the processing method applied to the authorized party provided in the present application;

[0048] Figure 7 is a schematic diagram of the authorization verification between devices in the authentication and authorization phase in an application example provided in the present application;

[0049] Figure 8 is a schematic diagram of the authentication processing between devices in the mutual authentication phase in an application example provided in the present application;

[0050] Figure 9 is a structural diagram of the electronic device provided in the present application. DETAILED DESCRIPTION

[0051] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0052] The present application discloses a processing method and an electronic device, which are used to solve the mutual authentication problem between multiple devices in secure communication based on a verifiable secret sharing method. The processing method can be applied to the IoT field, but is not limited thereto. The processing method of the present application can be applied to any field or scenario involving mutual authentication between multiple devices.

[0053] The disclosed processing method includes a processing method applicable to an authentication party electronic device and a processing method applicable to an authorized party electronic device matched therewith.

[0054] Referring to Figure 1 , a flowchart of the processing method applicable to the authentication party in the present application is provided. The processing method can be specifically applied to any electronic device in multiple electronic devices with mutual authentication requirements, for example, each smart home device in the smart home scenario in the IoT field, or each computer device in a workgroup to be coordinated for a task, etc.

[0055] As shown in Figure 1 , the processing method applicable to the authentication party provided in the present application can include the following processing process:

[0056] Step 101, obtaining authorization information and first verification information corresponding to the electronic device and other electronic devices respectively.

[0057] In this application embodiment, multiple electronic devices that have mutual authentication requirements are referred to as a device group. The devices in the device group often need to perform interconnection and mutual recognition before they can perform data transmission or task collaboration to ensure the communication security between end-to-end devices.

[0058] The electronic devices and other electronic devices mentioned here refer to the corresponding devices within the same device group of the authenticator. Further, in this embodiment, the electronic device specifically refers to the executing device of the method of this application within its device group. For ease of description, this executing device is referred to as the current electronic device, and other electronic devices are devices other than the executing device within the device group. Optionally, devices within the same device group can simultaneously execute the method of this application to achieve mutual authentication. For each device executing the method of this application, it can be considered as the electronic device described in this embodiment (i.e., the current electronic device), and devices within its group other than itself can be considered as other electronic devices.

[0059] In this application, a trusted third-party organization is still required as the authorizing party to issue trusted authorization information to the devices in order to authorize each device in the device group.

[0060] Accordingly, the processing method applied to the certifying party may also include the following steps 11)-12) before step 101:

[0061] 11) Send an authorization request to the licensor; the authorization request includes the group identifier of the device group.

[0062] Optionally, when a group of devices, such as multiple smart home devices connected to the same Wi-Fi network in a household, or various computer devices in the same workgroup, need to perform mutual authentication between devices based on secure communication requirements such as task collaboration or data transmission, they can send an authorization request to the authorized party, i.e., a trusted third-party organization. The authorization request includes the group identifier of the corresponding device group, such as the group number. In addition, it may also include the number of devices contained in the device group, the device identifier of the device to be authorized in the device group (e.g., the universal unique identifier (UUID) of a laptop computer), and other information.

[0063] In one embodiment, each device in the device group can send an authorization request to a trusted third-party organization individually. In this case, the device identifier included in the authorization request is the device identifier of the device that initiated the authorization request. The trusted third-party organization identifies each device as belonging to the same device group by the same group identifier included in the authorization requests initiated by different devices.

[0064] In other embodiments, each device in the device group of the authenticating party device can also agree to uniformly initiate the authorization request for each device in the device group by negotiation, in which case, the device agreed by negotiation can collect the device identifiers of each device in the group, and initiate a unified authorization request to the trusted third-party institution based on the collected device identifiers, and the device identifiers carried in the authorization request include the device identifiers of each device in the device group. However, it is not limited thereto, and in actual application, a configured proxy can also uniformly collect the identifiers of each device in the device group, and initiate a unified authorization request for each device in the group to the trusted third-party institution by the proxy.

[0065] The group identifier corresponding to the device group, such as the group number, can be sent by one or more devices in the device group or a configured proxy to the trusted third-party institution before initiating the authorization request to the trusted third-party institution, and then the trusted third-party institution allocates and feeds back the group identifier to the device group or its proxy by responding to the request.

[0066] In the authenticating party, the electronic device as the execution subject of the method of the present application, i.e. the current electronic device, when sending the authorization request to the trusted third-party institution, can specifically send a unified authorization request for authorizing each device in the device group to which it belongs, or can separately send a request for requesting authorization for its own device with other devices in the group. This is not limited, and can be determined according to actual application.

[0067] 12) obtaining the authorization information corresponding to the electronic device and the first verification information transmitted by the authorized party; the obtained authorization information is the corresponding part of the authorization information generated by the authorized party for each device in the device group based on a target secret fragment generation rule, and the target secret fragment generation rule is determined by the authorized party based on the group identifier.

[0068] The authorized party, i.e. the trusted third-party institution, after receiving the authorization request of the authenticating party, generates corresponding authorization information for each device in the device group by a verifiable secret sharing method, and the authorization information generated for each device includes a corresponding secret fragment of each secret value in a plurality of trusted secret values. For example, the number of devices in the device group is 10, and the authorized party can divide each trusted secret value into 10 secret fragments, and obtain 10 groups of secret fragments, each group of secret fragments including a corresponding secret fragment of each secret value in the trusted secret values a, b and c. Each group of secret fragments corresponds to each device one by one, and is used as authorization information distributed to different devices in the device group.

[0069] In addition, the trusted third-party institution also generates first verification information for verifying the secret value for each device in the device group. The authorization information and the first verification information generated for each device are transmitted to the corresponding device in the authentication device group by a corresponding transmission mode, so that each device of the authentication party performs device authentication based on the received authorization information and the first verification information

[0070] Each device in the authentication device group, such as the current electronic device and each other electronic device, can obtain the authorization information and the first verification information corresponding to each device transmitted by the trusted third-party institution; wherein the authorization information obtained by each device is the corresponding part of the authorization information generated by the authorization party based on the target secret fragment generation rule for each device in the device group.

[0071] In the above example, the 10 devices in the authentication device group can respectively obtain the corresponding one of the 10 groups of secret fragments generated by the trusted third-party institution as the authorization party, and different devices respectively obtain different groups of secret fragments one-to-one.

[0072] The target secret fragment generation rule is determined by the authorization party based on the group identifier in the authorization request. The process of determining the target secret fragment generation rule by the authorization party based on the group identifier in the authorization request and the process of generating authorization information for each device in the device group based on the target secret fragment generation rule will be described in detail in the embodiments below.

[0073] Step 102, determining a corresponding number of other electronic devices from the above other electronic devices that meet the number condition.

[0074] The number condition can be set as: the number of other electronic devices is at least a preset threshold t.

[0075] The value of t can be determined by pre-negotiation of each device in the authentication device group. It should be no less than the minimum number of devices required to achieve secret recovery in the verifiable secret sharing (assuming the minimum number of devices is t0), that is, t≥(t0-1).

[0076] In actual applications, the value of t can be determined in combination with the minimum number of devices (t0) required to achieve secret recovery in a verifiable secret sharing and the security requirement of the secret in the verifiable secret sharing. Different security tolerances of the number of secret fragments (referring to the number of secret fragments of the same secret value used for secret recovery) for secret recovery are different. Under the premise of being able to recover the secret value, the higher the security requirement, the smaller the number of secret fragments required for secret recovery, and the fewer the number of devices required to participate in secret recovery. Therefore, preferably, the preset threshold t is set as t=(t0-1), and the number condition is set as: the number of other devices is set as the threshold t (and t=(t0-1)). This enables subsequent secret recovery based on (t+1) devices, i.e., t0 devices, selected from the current electronic device and the other electronic devices, which correspondingly enables secret recovery and improves the security of the secret in the verifiable secret sharing as much as possible.

[0077] After obtaining the authorization information and the first verification information generated by the authorized party, the current electronic device can randomly determine a corresponding number of other electronic devices that meet the number condition from the device group to which the current electronic device belongs. For example, assuming that the device group contains n devices, the current electronic device can randomly determine t=(t0-1) other devices from the (n-1) other devices of the device group for subsequent device authentication based on secret recovery.

[0078] Step 103: performing secret recovery processing according to the authorization information of the electronic device and the authorization information of the corresponding number of other electronic devices, to obtain a secret recovery result.

[0079] After determining the corresponding number of other electronic devices that meet the number condition, the current electronic device can obtain the authorization information corresponding to each of the corresponding number of other electronic devices, and perform secret recovery processing in combination with the authorization information of the current electronic device and the corresponding number of other electronic devices. Assuming that a group of secret fragments corresponding to t other electronic devices are obtained, the current electronic device can perform secret recovery processing based on (t+1) groups of secret fragments.

[0080] Optionally, the current electronic device can perform secret value recovery through a Lagrange interpolation polynomial in combination with the authorization information of the current electronic device and the corresponding number of other electronic devices, such as a group of secret fragments corresponding to each of the corresponding number of other electronic devices, to obtain a corresponding secret recovery result.

[0081] Step 104: performing device authentication on each device participating in the secret recovery processing according to the secret recovery result and at least one piece of information in the first verification information corresponding to each device participating in the secret recovery processing.

[0082] In this step, the current electronic device can specifically determine whether the secret recovery result represents the recovered secret value, and if the secret value is recovered, further determine whether the recovered secret value is trusted based on the first verification information, that is, use the first verification information to verify the trustworthiness of the recovered secret value, and if the recovered secret value is verified to be trusted, it is determined that each device participating in the secret recovery process (such as the above-mentioned t+1 devices) passes the authentication, which can ensure the security communication between the subsequent devices, and the required data transmission or task coordination and other communication interaction processes can be continued between the authenticated devices; otherwise, if the secret value is not recovered or the recovered secret value is not trusted, it is determined that each device participating in the secret recovery process does not pass the authentication, and in this case, the communication interaction between the devices is rejected to avoid security threats in end-to-end device communication.

[0083] The first verification information sent by each device in the authorized direction authentication device group is the same, specifically the information generated by processing the trusted secret value used to generate the secret shard. For example, assuming that the trusted third-party institution randomly generates random numbers a, b, and c as trusted secret values, where a∈F, b∈F, c=ab, F represents a finite field, the first verification information generated for each device in the device group can be hash(a+b), that is, the hash value obtained by hashing the sum of random numbers a and b according to a predetermined hash algorithm.

[0084] For this example, if the current electronic device selects the authorization information of the other t devices and combines its own authorization information, such as a set of secret shards corresponding to each device, it can perform Lagrange recovery to obtain the recovered secret values a', b', and c', and then further verify whether hash(a'+b')=hash(a+b) is true. If true, it means that the current device and the selected other t devices pass the authentication, otherwise, if the secret value cannot be recovered or the recovered secret value does not satisfy the above formula, it means that the current device and the selected other t devices do not pass the authentication.

[0085] In practical applications, each device in the device group can broadcast its own authorization information and first verification information, and collect the information broadcast by other devices, select the authorization information and first verification information broadcast by other devices that meet the quantity condition (such as t), and combine its own authorization information and first verification information to perform device authentication based on secret recovery and trustworthiness verification.

[0086] Optionally, in an embodiment, after receiving the information broadcasted by the other electronic device, the current electronic device can also first verify whether the number of received broadcast information meets the number condition, such as whether it reaches t, if not, it is directly determined that each device fails to pass the authentication. If yes, it is further verified whether the first verification information of the current device and all other electronic devices are consistent, the purpose is to ensure that the authorization information of the plurality of devices in this time comes from the same batch of authorization of the same trusted third party, assuming that the first verification information of a device is inconsistent with the first verification information of the device outside, the device is refused to participate in the authentication, to prevent wasting computing power, on this basis, the required number (such as t) of broadcast information of other electronic devices can be selected from the broadcast information of each device whose first verification information is consistent with each other, and the authorization information and the first verification information of the current electronic device are combined to perform device authentication based on secret recovery and trustworthiness verification.

[0087] In this process, if an illegal device (i.e. a device that obtains trusted authorization information and first verification information without authorization of the device grouping in this time by the trusted third party) joins, or a device in the device grouping fails to successfully obtain the trusted authorization information generated by the trusted third party for the device grouping due to abnormality or attack, etc., it will be eliminated at the corresponding link of the above processing process (cannot participate in device authentication, and cannot participate in subsequent device communication interaction accordingly), or fails to recover the secret value or the recovered secret value is not trusted, etc., resulting in that the final device authentication based on secret recovery and trustworthiness verification fails, thereby ensuring the security of the end-to-end device communication.

[0088] In summary, the application proposes and realizes a solution for mutual authentication of multiple devices based on a verifiable secret sharing method, which does not need to use a certificate, avoids a series of complex problems such as issuance, management and revocation of the certificate, and does not need to use a signature verification algorithm for device authentication, thereby improving the authentication efficiency of mutual authentication between devices, reducing the computing power burden during device authentication, and saving the occupation of storage space such as device memory.

[0089] In an embodiment, the authorization information corresponding to each device in the device grouping can also include an auxiliary slice generated by the authorization party based on an auxiliary random number.

[0090] Referring to the processing method flowchart shown in Figure 2 The processing method applied to the authentication party provided by the application can further include the following processing before step 101:

[0091] Step 201, obtaining the second verification information transmitted by the authorization party.

[0092] In this embodiment, in addition to generating corresponding authorization information and first verification information for each device in the device group, the trusted third-party organization also generates auxiliary sharding values ​​for each device based on auxiliary random numbers, thereby obtaining auxiliary sharding for each device.

[0093] Optionally, a trusted third-party organization can generate auxiliary random numbers and use the corresponding polynomial to calculate the auxiliary random numbers to obtain the corresponding auxiliary sharding values.

[0094] For example, a trusted third-party organization generates random numbers β∈F and uses the polynomial f β (x)=β t x t +…+β1x+β;f βb (x)=β t ′x t +…+β1′x+βb, calculate the auxiliary slice values ​​[β], [βb].

[0095] In addition, the trusted third-party organization generates second verification information for each device in the device group. For example, the trusted third-party organization selects a random number r∈F and calculates f1(x)=rf. a (x)+f β (x), f2(x)=r1f b (x)-f βb (x)-rf c The obtained {r, f1(x), f2(x)} is used as the second verification information. The generated second verification information is used by the certifying party in combination with auxiliary fragmentation to verify the credibility of the authorization information obtained by each device in the device group.

[0096] Subsequently, a trusted third-party organization can transmit the generated auxiliary fragments and second verification information to each device in the device group. Optionally, the auxiliary fragments can be transmitted together with the secret fragments as authorization information to each device in the device group, while the second verification information is transmitted separately. For example, the authorization information including the secret fragments and auxiliary fragments can be transmitted to each device through a secure channel, or the second verification information can be transmitted to each device through broadcast.

[0097] The transmission method of the first verification information is similar to that of the second verification information, and it can also be transmitted in a broadcast manner, but is not limited to that.

[0098] Step 202: Based on the auxiliary fragmentation and second verification information, collaborate with other electronic devices in the device group to verify whether the authorization information obtained by each device in the device group is trustworthy. If trustworthy, trigger the processing of obtaining the authorization information and first verification information corresponding to the electronic device and other electronic devices in step 101.

[0099] After receiving the information transmitted by the authorized party, such as the authorization information and the first and second verification information, each device in the device group first verifies whether the authorization information obtained by each device in the device group is authentic to determine the legality of the authorization information.

[0100] In this embodiment, the authenticity verification of the authorization information obtained by each device essentially refers to the authenticity verification of the secret fragments contained in the authorization information.

[0101] Specifically, based on the obtained auxiliary fragments and the second verification information, each device in the device group can use a set of authenticity verification processes to cooperatively verify whether the secret fragments obtained by each device are indeed the secret fragments generated by the trusted third-party institution for each device in the device group. If yes, it indicates that the authorization information obtained by each device in the device group is authentic. In this case, the process of obtaining the authorization information and the first verification information corresponding to the electronic device and other electronic devices in step 101 can be triggered to continue the subsequent device authentication process based on secret recovery and verification. If no, it indicates that the authorization information obtained by each device in the device group is not authentic. In this case, the subsequent device authentication process can be rejected.

[0102] By adding the authenticity verification process of the authorization information obtained by each device in the device group to the authentication party, the subsequent device authentication process can be directly rejected in the case where the authorization information is not authentic, further enhancing the security of end-to-end device communication, and also saving the resource consumption of the device to a certain extent.

[0103] Referring to Figure 3 , a processing method flowchart applied to an authorized party is shown, which specifically can include:

[0104] Step 301, obtaining an authorization request sent by an authentication party, the authorization request being used to request to authorize each authentication party electronic device contained in a device group of the authentication party.

[0105] When a group of devices, such as multiple smart home devices connected to the same Wi-Fi in a family, or each computer device in the same workgroup, need to be mutually authenticated before secure communication based on task cooperation or data transmission between each other, an authorization request can be initiated to the authorized party, i.e., a trusted third-party institution. The authorization request includes the group identifier of the corresponding device group, such as the group number. In addition, it can also include the number of devices contained in the device group, the device identifier of the device to be authorized in the device group (such as the universally unique identifier UUID of a notebook computer), and other information.

[0106] The authorization request obtained by the authorization party can be one or more. When there is one, the authorization request is specifically an authorization request for all devices in the device group, which is uniformly initiated by a certain device in the device group (the device agreed by negotiation among all devices in the device group) or a set proxy. The device identifier carried in the authorization request specifically includes the device identifier of each device in the device group. When there are multiple authorization requests, the multiple authorization requests are specifically requests initiated by each device in the device group respectively and individually. The device identifier carried in each authorization request is specifically the device identifier of the electronic device itself that initiates the request. In this case, the authorization party is a trusted third-party institution, which identifies each device as belonging to the same device group through the same group identifier included in the authorization requests of different devices.

[0107] Step 302, determining a target secret shard generation rule.

[0108] After obtaining the authorization request sent by the authentication party, the authorization party can determine the target secret shard generation rule according to the group identifier of the device group included in the authorization request.

[0109] Specifically, the authorization party can determine whether an authorization request containing the group identifier has been obtained in the past, and store the secret shard generation rule corresponding to the group identifier. If yes, the authorization party can directly read the secret shard generation rule corresponding to the group identifier and use the read rule as the target secret shard generation rule. If not, the authorization party can temporarily generate the required target secret shard generation rule.

[0110] Optionally, the target secret shard generation rule includes a plurality of polynomials for generating secret shards. The plurality of polynomials included can generate a secret shard corresponding to a trusted secret value by processing the trusted secret value.

[0111] Step 303, generating corresponding authorization information and first verification information for trusted verification of secret values for a plurality of authentication party electronic devices based on the target secret shard generation rule; the authorization information generated for each authentication party electronic device includes a corresponding secret shard of each secret value in the plurality of trusted secret values.

[0112] As a trusted third-party institution, the authorization party generates authorization information for a plurality of devices through verifiable secret sharing. When generating the authorization information through verifiable secret sharing, the authorization party generates corresponding authorization information for a plurality of devices in the authentication party device group using the determined target secret shard generation rule.

[0113] The number of polynomials included in the target secret shard generation rule is the same as the number of trusted secret values, and is used to obtain a plurality of groups of secret shards corresponding to different trusted secret values by processing the different trusted secret values in a one-to-one manner. Each group of secret shards includes a secret shard value of each secret value. The number of groups of secret shards is the same as the number of devices in the device group. Each device in the device group can obtain a group of secret shards different from each other in a one-to-one manner as its authorization information.

[0114] The following is an example:

[0115] A trusted third-party institution generates random numbers a, b, and c as trusted secret values, where a∈F, b∈F, and c=ab. F represents a finite field. On this basis, the following polynomials are randomly generated:

[0116] f a (x)=α t x t +…+α1x+a; (1)

[0117] f b (x)=α t ′x t +…+α1′x+b; (2)

[0118] f c (x)=α t ″x t +…+α1″x+c。 (3)

[0119] And the generated polynomials are used to calculate the secret shards [a], [b], and [c] of the trusted secret values a, b, and c.

[0120] Specifically, the polynomial (1) can be used to calculate the trusted secret value a to obtain a plurality of secret shards [a] of a. Similarly, the polynomial (2) can be used to calculate the trusted secret value b to obtain a plurality of secret shards [b] of b. And the polynomial (3) can be used to calculate the trusted secret value c to obtain a plurality of secret shards [c] of c. Taking the calculation of the trusted secret value a as an example, each calculated f a (x) value can be used as a secret shard of a. The value of x can be randomly selected, i.e., a random number can be used.

[0121] The trusted third-party institution also generates first verification information for each device in the device group for device authentication processing of the authentication device. For the above example, the trusted third-party institution can specifically use a preset hash algorithm to perform a hash operation on the sum of the trusted secret values a and b, and the obtained hash value hash(a+b) is used as the first verification information.

[0122] Step 304, sending the generated authorization information and the first verification information to the authentication party.

[0123] Afterwards, as the authorized party, the trusted third-party institution can transmit the generated authorization information and the first verification information to each device in the device group through a corresponding transmission mode.

[0124] Preferably, referring to Figure 4 As shown in the information transmission diagram of the authorization phase, the trusted third-party institution can send the authorization information [a], [b], [c] to each device in the device group through a secure channel, and broadcast the first verification information hash(a+b).

[0125] Further, in an embodiment, based on the transmission of the authorization information [a], [b], [c] through the secure channel, the following can be implemented: the authorized party obtains the public key of each device in the device group, encrypts each group of secret fragments in a one-to-one manner using the public key of each device, and assembles the obtained multiple groups of encrypted secret fragments to obtain unified authorization information, and then sends the unified authorization information to each device in the device group. After each device receives the unified authorization information, it decrypts it using its own private key, and a group of secret fragments that are successfully decrypted serve as the authorization information of the device itself.

[0126] After obtaining the corresponding authorization information and the first verification information, each device in the authentication party device group can implement mutual authentication between devices by executing the processing method applied to the authentication party provided in any of the above embodiments.

[0127] The present embodiment authorizes multiple devices based on a verifiable secret sharing method, avoiding a series of complex problems such as issuance, management, and revocation of certificates, and in the device authentication phase based on authorization information, does not need to use a signature verification algorithm for device authentication, thereby improving the authentication efficiency of mutual authentication between devices, reducing the computational burden during device authentication, and saving the occupation of storage space such as device memory.

[0128] In an embodiment, optionally, referring to Figure 5 The processing method applied to the authorized party provided in the present application can further include the following processing after step 301.

[0129] Step 501, generating corresponding auxiliary fragments for multiple authentication party electronic devices based on auxiliary random numbers.

[0130] In the present embodiment, the trusted third-party institution generates corresponding authorization information and first verification information for each device in the device group, and also generates auxiliary fragment values for each device based on auxiliary random numbers, thereby obtaining the auxiliary fragments of each device.

[0131] Optionally, the trusted third party institution can generate an auxiliary random number and calculate the auxiliary random number by using a corresponding polynomial to obtain a corresponding auxiliary shard value.

[0132] For example, the trusted third party institution randomly generates a random number β∈F and calculates an auxiliary shard value [β],[βb] by using polynomials f β (x)=β t x t +…+β1x+β;f βb (x)=β t ′x t +…+β1′x+βb.

[0133] Step 502, generating second verification information for verifying the trustworthiness of the authorization information.

[0134] In addition, the trusted third party institution also generates second verification information for each device in the device group.

[0135] For example, the trusted third party institution selects a random number r∈F and calculates f1(x)=rf a (x)+f β (x), f2(x)=r1f b (x)-f βb (x)-rf c (x), and the obtained {r, f1(x), f2(x)} is used as the second verification information.

[0136] Step 503, sending the auxiliary shard and the second verification information to the authentication party, so that the authentication party verifies whether the authorization information obtained by each device in the device group is trustworthy based on the auxiliary shard and the second verification information.

[0137] Subsequently, as the authorized party, the trusted third party institution can transmit the auxiliary shard and the second verification information to each device in the device group. Figure 4 Optionally, in combination with the description of the auxiliary shard and the second verification information in the above-mentioned step 501, the auxiliary shard can be used as the authorization information together with the secret shard and be transmitted to each device in the device group in the authorization information, and the second verification information can be transmitted separately, for example, the authorization information is transmitted to each device through a secure channel, and the second verification information is transmitted through a broadcast mode.

[0138] Subsequently, each device in the device group can first verify whether the authorization information (i.e., the obtained secret shard) obtained by each device in the device group is trusted based on the auxiliary shard and the second verification information after receiving the information transmitted by the authorized party, such as the authorization information and the first and second verification information, and in the case of being trusted, the subsequent device authentication process based on secret recovery and verification is continued.

[0139] In actual application, as long as the authorization information, the first verification information, the auxiliary shard and the second verification information can be transmitted to each device before the obtained authorization information is verified by each device in the device group, and the generation or transmission order of the authorization information / first verification information and the auxiliary shard / second verification information is not limited, such as not being limited to the execution order shown in the figure. Figure 5

[0140] The embodiment can support the authentication party to verify the trustworthiness of the obtained authorization information by adding the generation and transmission processing of the auxiliary shard and the second verification information at the authorized party, and directly reject the subsequent device authentication process in the case of untrusted authorization information, further enhancing the security of end-to-end device communication, and also saving the resource consumption of the device to a certain extent.

[0141] In an embodiment, optionally, referring to Figure 6 The processing method applied to the authorized party provided by the application can further include the following processing.

[0142] Step 601, at least generate the corresponding relationship information between the group identifier in the authorization request and the target secret shard generation rule, and store the generated corresponding relationship information.

[0143] Optionally, the trusted third-party institution can generate the corresponding relationship between the plurality of polynomials contained in the target secret shard generation rule and the group identifier of this time, such as generating the corresponding relationship between the group number and f a (x), f b (x), f c (x), and store the generated corresponding relationship as the authentication information of this time.

[0144] In the case that the trusted third-party institution further generates the auxiliary shard and the second verification information for the authentication party, the corresponding relationship between the plurality of polynomials contained in the target secret shard generation rule, the polynomials required for generating the auxiliary shard, and the second verification information, such as the corresponding relationship between the group number and f a (x), f b (x), f c (x), f β (x), f βb ​(x), r, f1(x), f2(x), and stores the correspondence as the authentication information of this time.

[0145] The authorized party can store the generated correspondence information by means of a local list, but is not limited thereto. By storing the generated correspondence information locally, the authorized party can support direct reading of the relevant authentication information corresponding to the group identifier, such as the relevant polynomial, for generating the authorization information and verification information when the authorization request for the group identifier is received again subsequently.

[0146] On this basis, the application supports dynamic expansion of the device nodes in the device group, including joining and exiting of the devices, and the authentication party device can dynamically join or exit the devices on demand based on the actual task coordination requirements.

[0147] Correspondingly, further referring to Figure 6 The processing method applied to the authorized party provided by the application can further include a corresponding one of the following processes.

[0148] In step 602, an exit request for indicating exit of the first device group is obtained from the first electronic device, and the authorization information and the first verification information corresponding to the first electronic device are disclosed, so that the authentication party corresponding to the first device group performs device authentication in combination with the disclosed information.

[0149] When the first electronic device in the device group of the authentication party needs to exit the first device group to which it belongs based on the task coordination requirements, an exit request can be sent to the trusted third-party institution as the authorized party. Optionally, the exit request includes the group identifier of the first device group requested to exit and the device identifier of the first electronic device.

[0150] In response to the obtained exit request, the trusted third-party institution records the information of the first electronic device that exits the first device group, and discloses the authorization information and the first verification information corresponding to the first electronic device, such as the secret fragments [a], [b], [c] and hash(a+b) corresponding to the first electronic device.

[0151] In actual applications, the trusted third-party institution can maintain a revocation list, record the device information of the devices that exit each device group through the revocation list, and disclose the secret fragments [a], [b], [c] and hash(a+b) of the exited devices and other information.

[0152] Subsequently, when the device group such as the first device group is authenticated again, each device in the group can first query the revocation list, determine whether there is an exited device according to the information of other devices received by itself, and if there is, the authentication of the exited device is not passed.

[0153] In step 603, the second electronic device sends a joining request for indicating joining the second device group, the corresponding relationship information is obtained from the secret fragment generation rule matched with the group identifier of the second device group, the corresponding authorization information of the second electronic device is generated according to the obtained secret fragment generation rule, the first verification information is generated, and the generated information is fed back to the second electronic device.

[0154] When a device needs to join the second device group based on the task cooperation requirement, a joining request can be sent to the trusted third party institution as the authorized party. Optionally, the joining request includes the group identifier of the second device group requested to join and the device identifier of the second electronic device.

[0155] In response to the obtained joining request, the trusted third party institution queries the authentication information corresponding to the group identifier from the stored corresponding relationship information between the device identifier and the secret fragment generation rule and other authentication information thereof, such as the f a (x),f b (x),f c (x),f β (x),f βb (x),r,f1(x),f2(x) and other information, and directly generates and transmits the authorization information, the first verification information, the second verification information and other information of the second electronic device matched with the second device group according to the queried related information.

[0156] Subsequently, the second electronic device can join the second device group for task cooperation through mutual authentication between the devices in the second device group based on the obtained authorization information and related verification information.

[0157] If the corresponding relationship information stored in the trusted third party institution does not include the related authentication information corresponding to the group identifier of the second device group, the trusted third party institution can generate the corresponding secret fragment generation rule and other information for the group identifier, so as to generate the required authorization information and related verification information for the second electronic device.

[0158] The embodiment stores the authentication information of each device group in the authorized party, supports the dynamic expansion of the device nodes in the device group based on the stored authentication information, further improves the flexibility of the end-to-end device communication application, and can better meet the task cooperation requirement between multiple devices.

[0159] An application example of the method of the present application is provided below.

[0160] In this example, based on the verifiable secret sharing method, the process of mutual authentication between multiple devices is mainly divided into three stages, namely the authorization stage, the authentication authorization stage and the mutual authentication stage between multiple devices, as follows:

[0161] (I) Authorization stage

[0162] The trusted third-party institution as the authorized party will issue authorization information to each device in the authentication party device group (assuming the total number is n) after receiving the authorization request of the authentication party; the authorization request includes the group identifier, for example, in the case of smart home, the devices in the same family will have a group number; or multiple electronic devices of the same user have the same group number.

[0163] Then, the trusted third-party institution realizes the authorization processing of the authorization stage through the following exemplary processing flow:

[0164] 11) The trusted third-party institution records the group number of this application and generates random numbers a, b, and c as trusted secret values, where a∈F, b∈F, and c=ab;

[0165] 12) The trusted third-party institution generates authorization information for multiple devices through verifiable secret sharing, that is, randomly generates polynomials f a (x)=α t x t +…+α1x+α,f b (x)=α t ′x t +…+α1′x+b,f c (x)=α t ″x t +…+α1″x+c, and calculates secret fragments [a], [b], and [c] based on the polynomials;

[0166] 13) The trusted third-party institution randomly generates an auxiliary random number β∈F, and calculates auxiliary fragments [β] and [βb] based on the polynomials f β (x)=β t x t +…+β1x+β,f βb (x)=β t ′x t +…+β1′x+βb;

[0167] 14) The trusted third-party institution selects a random number r∈F, and calculates f1(x)=rf a (x)+f β (x), f2(x)=r1f b (x)-f βb (x)-rf c (x);

[0168] 15) The trusted third party institution stores the current authentication information locally through a list, including the current group number, and f a (x), f b (x), f c (x), f β (x), f βb (x), r, f1(x), f2(x), that is, the corresponding relationship between the current group number and the related authentication information of each polynomial is constructed and stored. Then the authorization information [a], [b], [c], [β], [βb] is sent to each device through a secure channel, and the second verification information {r, f1(x), f2(x)} is broadcast.

[0169] 15) To ensure mutual authentication during multi-device authentication, the trusted third party institution calculates hash(a+b) as the serial number of the current authorization, that is, as the first verification information, and broadcasts it to each device. For details, see Figure 4 .

[0170] (II) Authorization phase

[0171] After receiving the authorization information, each device in the device group first verifies whether the authorization information obtained by each device in the device group is trustworthy to determine the legality of the authorization information.

[0172] For details, see Figure 7 , an example implementation process is provided as follows:

[0173] 21) Each device calculates and verifies f1(i) = r[a] + [β] to determine whether f1(i) = r[a] + [β] is true. If true, success_1 is broadcast; otherwise, if not true, fail_1 is broadcast.

[0174] Where i is an integer, which can be a corresponding value between [0, n-1].

[0175] 22) Each device detects the number of received success_1. If it reaches a preset number such as t+1, it continues to calculate r1 = f1(0) = ra+β; otherwise, it ends and does not execute the subsequent process.

[0176] Where the preset number can be the minimum number of devices required to participate in device authentication.

[0177] 23) Each device verifies whether f2(i) = r1[b]-[βb]-r[c] is true, that is, whether f2(i) = r1[b]-[βb]-r[c] is true. If true, success_2 is broadcast; otherwise, if not true, fail_2 is broadcast.

[0178] 24) Each device checks the number of success_2 received. If the number reaches the preset number (e.g., t+1), it continues to verify whether f2(0)==0 is true. If true, it broadcasts success_3; if false, it broadcasts failure_3; if the number does not reach the preset number (e.g., t+1), it ends and does not execute the subsequent process.

[0179] 25) Each device checks the number of received success_3 messages. If the number reaches the preset number (e.g., t+1), it indicates that the authorization information of each device has been verified and is trustworthy. Otherwise, it indicates that the device is untrustworthy.

[0180] In this stage, the certifier, through the above verification process, essentially verifies whether the secret fragments obtained by each device are indeed generated by a trusted third-party organization for each device in this device group. If so, it means that the authorization information obtained by each device in the device group is trustworthy, and the next stage of the device certification process will continue. If not, it means that the authorization information obtained by each device in the device group is untrustworthy, and the subsequent device certification process will be rejected accordingly.

[0181] (III) Multi-device mutual recognition stage

[0182] After the above two stages of processing, combined with [see also...] Figure 8 Each device broadcasts its own authorization information [a], [b], [c] and first verification information hash(a+b), and receives information broadcast by other devices.

[0183] After receiving information broadcast by other devices, each device performs inter-device authentication, such as... Figure 8 As shown, an exemplary implementation process is as follows:

[0184] 31) First, check if the number of broadcast messages received from other devices meets the above quantity condition, such as at least t. If yes, continue the subsequent process; otherwise, end.

[0185] 32) Verify whether the first verification information of all devices is consistent. The purpose is to ensure that the authorization information of multiple devices comes from the same batch of authorizations from the same trusted third party. If the first verification information of a certain device is inconsistent with that of other devices, the authentication of that device will be rejected to prevent waste of computing power.

[0186] 33) When the first authentication information of each device is verified to be consistent, randomly select the information sent by the other t devices, combine the authorization information of the current electronic device itself, and perform secret recovery based on the Lagrange interpolation polynomial; if the secret values a', b', c' can be recovered, and the verification hash(a'+b')≠hash(a+b) is true, output result 1, which indicates that the authorization information of the t+1 devices is indeed the trusted authorization information issued by the trusted third party, and the authentication is passed; otherwise, if the Lagrange recovery cannot be performed, or hash(a'+b')≠hash(a+b), the output result is 0, indicating that each device fails to pass the authentication.

[0187] In actual application, the authentication process of this stage can be performed by only one device in the device group, and the t+1 devices including the one device are authenticated, if the output result of the one device is 1, indicating that the corresponding t+1 devices pass the authentication, and the output is 0, indicating that the authentication is failed.

[0188] But not limited to this, in other embodiments, the t+1 devices to be involved in device authentication can also be determined by negotiation of each device in the device group, and each device in the t+1 devices performs secret recovery and verification based on the secret fragments provided by the t+1 devices, and only when the authentication results of all devices indicate that the t+1 devices pass the authentication, it is determined that the t+1 devices pass the authentication, otherwise, it is determined that the authentication is failed. This implementation mode can further avoid the problem of low reliability of the final authentication result caused by the untrusted device performing the authentication process in the previous implementation mode, and further improves the security of end-to-end device communication.

[0189] In addition, a dynamic expansion phase of the device node can also be included.

[0190] The dynamic expansion of the device node includes device exit and joining, as follows:

[0191] a. Device exit

[0192] For device exit, the trusted third party maintains a revocation list for recording the device information of the devices that exit in each group, and the trusted third party discloses the fragment information [a], [b], [c] and the first authentication information hash(a+b) of the exited devices; when the authentication is performed again, the devices in the group will first query the revocation list to determine whether a device has exited according to the information received from other devices, and if the device has exited, the authentication of the device is failed.

[0193] b. Device joining

[0194] When a new device is added, it sends an authorization request to a trusted third-party organization, including group identifiers such as the group number to be added. The trusted third-party organization queries its local list; if the group number already exists, it authorizes the new device using the polynomial corresponding to the number. If the group number does not exist, a new authorization request is initiated, and the trusted third-party organization temporarily generates the corresponding polynomial and other information, and authorizes the device based on the generated polynomial and other information.

[0195] This application also discloses an electronic device, which may be, but is not limited to, a device in a variety of general or special computing device environments or configurations, such as: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor devices, etc.

[0196] The composition and structure of electronic devices, such as Figure 9 As shown, it includes at least:

[0197] Memory 10 is used to store the computer instruction set;

[0198] Computer instruction sets can be implemented in the form of computer programs.

[0199] The processor 20 is configured to implement, by executing a set of computer instructions, the processing method disclosed in any of the above method embodiments, for use by an authenticator or for an licensor.

[0200] The processor 20 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices.

[0201] Electronic devices have a display device and / or have a display interface and can connect to an external display device.

[0202] Optionally, the electronic device may also include a camera assembly, and / or be connected to an external camera assembly.

[0203] In addition to these components, electronic devices may also include communication interfaces, communication buses, and other parts. Memory, processor, and communication interface communicate with each other through the communication bus.

[0204] The communication interface is used for communication between the electronic device and other devices. The communication bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc., which can be divided into an address bus, a data bus, a control bus, etc.

[0205] It should be noted that each of the embodiments in the present specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be mutually referred to.

[0206] For the convenience of description, the above system or device is described as various modules or units respectively described in terms of functions. Of course, in the implementation of the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0207] From the above description of the embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus the necessary general hardware platform. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments of the present application.

[0208] Finally, it should be noted that in this paper, relationship terms such as first, second, third and fourth are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.

[0209] The above merely describes the preferred embodiments of the present application, and it should be pointed out that, for those skilled in the art, some improvements and refinements can be made without departing from the principles of the present application, and these improvements and refinements should also be considered as the protection scope of the present application.

Claims

1. A processing method applied to an electronic device of an authenticator, the method comprising: Obtain the authorization information and first verification information corresponding to the electronic device and other electronic devices respectively; The authorization information corresponding to each device includes the corresponding secret fragment of each secret value among multiple secret values, and the first verification information corresponding to each device is the information used to verify the credibility of the secret value; Determine the corresponding number of other electronic devices that meet the quantity conditions from the other electronic devices; Based on the authorization information corresponding to the electronic device and the authorization information corresponding to the corresponding number of other electronic devices, a secret recovery process is performed to obtain a secret recovery result. Based on the secret recovery result and at least one of the first verification information corresponding to each device participating in the secret recovery process, device authentication is performed on each device participating in the secret recovery process.

2. The method according to claim 1, wherein the step of authenticating each device participating in the secret recovery process based on at least one of the secret recovery result and the first verification information corresponding to each device participating in the secret recovery process includes: Determine whether the secret recovery result indicates that the secret value has been recovered; If the secret value is recovered, its reliability is determined based on the first verification information; If trusted, then verify that each device involved in the secret recovery process has been authenticated; If the secret value is not recovered or the recovered secret value is unreliable, it is determined that the devices involved in the secret recovery process have not passed authentication.

3. The method according to claim 1, further comprising, before obtaining the authorization information and first verification information corresponding to the electronic device and other electronic devices respectively: Send an authorization request to the authorizing party; The authorization request includes a group identifier for the device group, and the electronic device and the other electronic devices are the corresponding devices in the device group; The authorization information and first verification information corresponding to the electronic device transmitted by the authorizing party are obtained; the obtained authorization information is the corresponding part of the authorization information generated by the authorizing party for each device in the device group based on the target secret fragmentation generation rule, and the target secret fragmentation generation rule is determined by the authorizing party based on the group identifier.

4. The method according to claim 3, wherein the authorization information corresponding to each device in the device group further includes: The authorizing party generates auxiliary fragments based on auxiliary random numbers; Before obtaining the authorization information and verification information corresponding to the electronic device and other electronic devices respectively, the process also includes: Obtain the second verification information transmitted by the authorizing party; Based on the auxiliary fragmentation and the second verification information, the system collaborates with other electronic devices in the device group to verify whether the authorization information obtained by each device in the device group is credible. If credible, the system triggers the step of obtaining the authorization information and the first verification information corresponding to the electronic device and other electronic devices respectively.

5. A processing method applied to an electronic device of an licensor, the method comprising: Receive an authorization request sent by the authenticator, the authorization request being used to request authorization for each authenticator electronic device included in the authenticator's device group; Determine the rules for generating target secret fragments; Based on the target secret fragmentation generation rule, corresponding authorization information and first verification information for verifying the trustworthiness of the secret value are generated for multiple authenticator electronic devices respectively. The authorization information generated for each certifying party's electronic device includes a corresponding secret fragment for each of the multiple trusted secret values; The generated authorization information and the first verification information are sent to the authenticator, so that any authenticator electronic device can obtain the authorization information and the first verification information corresponding to the authenticator electronic device and other authenticator electronic devices respectively; a corresponding number of other authenticator electronic devices that meet the quantity conditions are determined from the other authenticator electronic devices; based on the authorization information corresponding to the authenticator electronic device and the authorization information corresponding to the corresponding number of other authenticator electronic devices, secret recovery processing is performed to obtain secret recovery results; based on the secret recovery results and at least one of the first verification information corresponding to each authenticator electronic device participating in the secret recovery processing, device authentication is performed on each authenticator electronic device participating in the secret recovery processing.

6. The method according to claim 5, wherein determining the target secret fragment generation rule includes: The target secret fragment generation rule is determined based on the group identifier of the device group contained in the authorization request.

7. The method of claim 5, further comprising, after receiving at least one authorization request sent by the authenticator: Based on auxiliary random numbers, corresponding auxiliary fragments are generated for the multiple authenticator electronic devices respectively; Generate second verification information for verifying the credibility of the authorization information; The auxiliary fragment and the second verification information are sent to the authenticator so that the authenticator can verify whether the authorization information obtained by each device in the device group is credible based on the auxiliary fragment and the second verification information.

8. The method according to claim 6, further comprising: At least the correspondence information between the group identifier of the device group and the target secret fragment generation rule is generated and stored.

9. The method of claim 8, further comprising one of the following: Obtain an exit request sent by the first electronic device to indicate exiting the first device group, and disclose the authorization information and first verification information corresponding to the first electronic device so that the authenticator corresponding to the first device group can perform device authentication in combination with the disclosed information; The system receives a join request from a second electronic device indicating that it is to join a second device group. It then obtains a secret fragmentation generation rule that matches the group identifier of the second device group from the correspondence information. Based on the obtained secret fragmentation generation rule, it generates corresponding authorization information for the second electronic device and generates first verification information. Finally, it feeds back the generated information to the second electronic device.

10. An electronic device, comprising: Memory, used to store at least one set of computer instructions; A controller is configured to implement the processing method as described in any one of claims 1-4, or the processing method as described in any one of claims 5-9, by invoking and executing the instruction set stored in the memory.

Citation Information

Patent Citations

  • Threshold key verification method and related equipment

    CN113746623A