A virtual server-side distributed key authentication system and method
By employing a key authentication method that involves collaboration between external terminal devices, client apps, and servers, the synchronization and security issues of wireless communication systems are resolved, enabling secure data transmission and storage.
Patent Information
- Application Number
- CN202211632019.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-19
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2042-12-19
AI Technical Summary
Wireless communication systems are not stable enough in terms of synchronization and security, and existing technologies are unable to effectively solve these problems.
A key-based security authentication method is adopted, which is based on the collaboration of an external terminal device, a client APP, and a server. The client and server generate key parameters and the encryption module calculates and encrypts them. The external terminal device decrypts the data and generates a collaborative key for data encryption.
It improves the security and effectiveness of communication, prevents key tampering and unauthorized login, and ensures the secure transmission and storage of data.
Smart Images

Figure CN115941177B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of device authentication security technology, and in particular to a virtual server-side distributed key authentication system and method. Background Technology
[0002] Wireless communication systems are widely deployed to provide a variety of telecommunications services, such as telephone, video, data, messaging, and broadcasting. Typical wireless communication systems employ multiple access technologies to support communication with multiple users by sharing available system resources (e.g., bandwidth, transmit power). Examples of such multiple access technologies include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single-carrier frequency division multiple access (SC-FDMA) systems, and time division synchronous code division multiple access (TD-SCDMA) systems.
[0003] These multiple access technologies have been applied in various telecommunications standards to provide a universal protocol enabling different wireless devices to communicate at the municipal, national, regional, and even global levels. However, these technologies are not stable enough in terms of synchronization and security. This application proposes a key-based security authentication method based on the collaboration of an external terminal, a client application, and a server, which solves the technical difficulties existing in the prior art. Summary of the Invention
[0004] In view of this, the present invention provides a virtual server-side distributed key authentication system and method, which adopts a key security authentication method based on the collaboration of external terminal devices, client APP and server to improve the security and effectiveness of communication.
[0005] To achieve the above objectives, the present invention adopts the following technical solution:
[0006] A virtual server-side distributed key authentication system includes: a client, a server, a first encryption module, and an external terminal device;
[0007] The client is communicatively connected to the first input terminal of the first encryption module and is used to generate the first key parameters for participating in the collaborative key generation.
[0008] The server is connected to the second input terminal of the first encryption module and is used to generate the second key parameters that participate in the generation of the collaborative key.
[0009] The first encryption module is used to calculate and encrypt the first key parameter and the second key parameter to obtain the first ciphertext;
[0010] The external terminal device is communicatively connected to the first encryption module, and is used to receive and decrypt the first ciphertext, generate the collaborative key, and encrypt the data to obtain encrypted data.
[0011] Optionally, the first encryption module includes a first receiving unit, a first encryption unit, and a sending unit connected in sequence;
[0012] The first receiving unit is configured to receive the first key parameter and the second key parameter;
[0013] The first encryption unit is used to calculate and encrypt the first key parameter and the second key parameter received by the first receiving unit to obtain the first ciphertext;
[0014] The sending unit is used to send the obtained first ciphertext to the external terminal device.
[0015] Optionally, the external terminal device includes: a second receiving unit, a second decryption unit, a collaborative key generation unit, a third key parameter generation unit, and a data encryption unit;
[0016] The second receiving unit is communicatively connected to the input end of the second decryption unit and is used to receive the first ciphertext output by the sending unit;
[0017] The second decryption unit is communicatively connected to the first input terminal of the collaborative key generation unit, and is used to decrypt the first ciphertext to obtain the first key parameter and the second key parameter;
[0018] The third key parameter generation unit is communicatively connected to the second input terminal of the collaborative key generation unit, and is used to generate the third key parameter participating in the collaborative key generation.
[0019] The collaborative key generation unit is communicatively connected to the input end of the data encryption unit and is used to calculate the first key parameter, the second key parameter, and the third key parameter to obtain the collaborative key.
[0020] The data encryption unit is used to encrypt the data using the obtained collaborative key to obtain the encrypted data.
[0021] Optionally, the collaborative key generation unit uses a symmetric encryption algorithm to perform encrypted calculations on the first key parameter, the second key parameter, and the third key parameter.
[0022] Optionally, the symmetric encryption algorithm is one of DES, 3DES, and AES.
[0023] Optionally, the external terminal device is a Magic Box.
[0024] A virtual server-side distributed key authentication method, applied to the aforementioned virtual server-side distributed key authentication system, includes the following steps:
[0025] S1. The client generates a first key parameter for participating in the collaborative key generation and sends the first key parameter to the first encryption module.
[0026] S2. The server generates a second key parameter that participates in the generation of the collaborative key, and sends the second key parameter to the first encryption module;
[0027] S3. The first encryption module calculates and encrypts the received first key parameter and second key parameter to obtain the first ciphertext, and sends the first ciphertext to the external terminal device;
[0028] S4. The external terminal device receives and decrypts the first ciphertext, generates the collaborative key, and encrypts the data to obtain encrypted data.
[0029] Optionally, the specific content of generating the collaborative ciphertext in S4 is as follows: using a symmetric encryption algorithm to perform encryption calculations on the first key parameter, the second key parameter, and the third key parameter to obtain the collaborative key.
[0030] As can be seen from the above technical solution, compared with the prior art, the present invention provides a virtual server-side distributed key authentication system and method: adopting a key security authentication method based on the collaboration of external terminal devices, client APP and server, improving the security and effectiveness of communication; preventing key tampering and unauthorized login, and ensuring the secure transmission and storage of data. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0032] Figure 1 This invention provides a block diagram of a virtual server-side distributed key authentication system.
[0033] Figure 2 The first encryption module structure diagram provided by the present invention;
[0034] Figure 3 This is a structural block diagram of the external terminal device provided by the present invention;
[0035] Figure 4 The present invention provides a flowchart of a virtual server-side distributed key authentication system method. Detailed Implementation
[0036] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0037] Reference Figure 1 As shown, the present invention discloses a virtual server-side distributed key authentication system, comprising: a client, a server, a first encryption module, and an external terminal device;
[0038] The client communicates with the first input terminal of the first encryption module and is used to generate the first key parameters for participating in the collaborative key generation.
[0039] The server connects to the second input of the first encryption module and is used to generate the second key parameters for participating in the generation of the collaborative key.
[0040] The first encryption module is used to calculate and encrypt the first key parameter and the second key parameter to obtain the first ciphertext;
[0041] An external terminal device is connected to the first encryption module to receive and decrypt the first ciphertext, generate a collaborative key, and encrypt the data to obtain encrypted data.
[0042] Further, see Figure 2As shown, the first encryption module includes a first receiving unit, a first encryption unit, and a sending unit connected in sequence;
[0043] The first receiving unit is used to receive the first key parameter and the second key parameter;
[0044] The first encryption unit is used to calculate and encrypt the first key parameter and the second key parameter received by the first receiving unit to obtain the first ciphertext;
[0045] The sending unit is used to send the obtained first ciphertext to an external terminal device.
[0046] Furthermore, see Figure 3 As shown, the external terminal device includes: a second receiving unit, a second decryption unit, a collaborative key generation unit, a third key parameter generation unit, and a data encryption unit;
[0047] The second receiving unit is communicatively connected to the input end of the second decryption unit and is used to receive the first ciphertext output by the sending unit.
[0048] The second decryption unit is communicatively connected to the first input terminal of the collaborative key generation unit, and is used to decrypt the first ciphertext to obtain the first key parameter and the second key parameter;
[0049] The third key parameter generation unit is communicatively connected to the second input terminal of the collaborative key generation unit and is used to generate the third key parameters participating in the collaborative key generation.
[0050] The collaborative key generation unit is connected to the input end of the data encryption unit and is used to calculate the first key parameter, the second key parameter, and the third key parameter to obtain the collaborative key.
[0051] The data encryption unit is used to encrypt data using the obtained collaborative key to obtain encrypted data.
[0052] Furthermore, the collaborative key generation unit uses a symmetric encryption algorithm to perform encrypted calculations on the first key parameter, the second key parameter, and the third key parameter.
[0053] Furthermore, the symmetric encryption algorithm is one of DES, 3DES, or AES.
[0054] Furthermore, the external terminal device is a magic box.
[0055] and Figure 1 Corresponding to the system described above, embodiments of the present invention also provide a virtual server-side distributed key authentication system, applied to... Figure 1 For details on the system, please refer to [link / reference]. Figure 4 :
[0056] S1. The client generates the first key parameter for participating in the collaborative key generation and sends the first key parameter to the first encryption module.
[0057] S2. The server generates a second key parameter for participating in the collaborative key generation and sends the second key parameter to the first encryption module;
[0058] S3. The first encryption module calculates and encrypts the received first key parameter and second key parameter to obtain the first ciphertext, and sends the first ciphertext to the external terminal device;
[0059] S4. The external terminal device receives and decrypts the first ciphertext, generates a collaborative key, and encrypts the data to obtain encrypted data.
[0060] Furthermore, the specific content of generating the collaborative ciphertext in S4 is as follows: using a symmetric encryption algorithm to perform encryption calculations on the first key parameter, the second key parameter, and the third key parameter to obtain the collaborative key.
[0061] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and relevant parts can be referred to the descriptions in the method embodiments. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0062] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A virtual service end distributed key authentication system, characterized in that, The application relates to a virtual service end distributed key authentication system. The client is in communication connection with the first input end of the first encryption module and is used for generating a first key parameter participating in collaborative key generation. The server is in communication connection with the second input end of the first encryption module and is used for generating a second key parameter participating in the collaborative key generation. The first encryption module is used for calculating and encrypting the first key parameter and the second key parameter to obtain a first ciphertext. The external terminal device is in communication connection with the first encryption module, is used for receiving and decrypting the first ciphertext, simultaneously generating the collaborative key, and encrypting data to obtain encrypted data. The first encryption module comprises a first receiving unit, a first encryption unit and a sending unit which are connected in sequence. The first receiving unit is used for receiving the first key parameter and the second key parameter. The first encryption unit is used for calculating and encrypting the first key parameter and the second key parameter received by the first receiving unit to obtain the first ciphertext. The sending unit is used for sending the obtained first ciphertext to the external terminal device. The external terminal device comprises a second receiving unit, a second decryption unit, a collaborative key generation unit, a third key parameter generation unit and a data encryption unit. The second receiving unit is in communication connection with the input end of the second decryption unit and is used for receiving the first ciphertext output by the sending unit. The second decryption unit is in communication connection with the first input end of the collaborative key generation unit and is used for decrypting the first ciphertext into the first key parameter and the second key parameter. The third key parameter generation unit is in communication connection with the second input end of the collaborative key generation unit and is used for generating a third key parameter participating in the collaborative key generation. The collaborative key generation unit is in communication connection with the input end of the data encryption unit and is used for performing encryption calculation on the first key parameter, the second key parameter and the third key parameter by using a symmetric encryption algorithm to obtain the collaborative key. The data encryption unit is used for encrypting the data by using the obtained collaborative key to obtain the encrypted data.
2. The virtual service end distributed key authentication system according to claim 1, wherein the collaborative key generation unit performs encryption calculation on the first key parameter, the second key parameter and the third key parameter by using a symmetric encryption algorithm.
3. The virtual service end distributed key authentication system according to claim 2, wherein the symmetric encryption algorithm is one of DES, 3DES and AES.
4. The virtual service end distributed key authentication system according to claim 1, wherein the external terminal device is a magic box. The virtual service end distributed key authentication system is applied to any one of claims 1-4 and comprises the following steps: S1. The client generates a first key parameter participating in collaborative key generation and sends the first key parameter to the first encryption module. 5. A virtual service end distributed key authentication method, characterized in that, S2. The server generates a second key parameter participating in the collaborative key generation, and sends the second key parameter to the first encryption module; S3. The first encryption module calculates and encrypts the received first key parameter and second key parameter, obtains a first ciphertext, and sends the first ciphertext to an external terminal device; S4. The external terminal device receives and decrypts the first ciphertext, simultaneously generates the collaborative key, and encrypts data to obtain encrypted data; The specific content of generating the collaborative key in S4 is that the first key parameter, the second key parameter and the third key parameter are calculated and encrypted by using a symmetric encryption algorithm to obtain the collaborative key.