Encryption method, device and electronic device

By adopting ECC-based lightweight encryption method and improved XTEA algorithm in distributed systems, the temporary encryption key is generated using ECDH key exchange, which solves the problem of vulnerability to devices in distributed systems, and realizes the security of data transmission and the reliability of authentication.

CN116208411BActive Publication Date: 2025-07-22ZHONGNENG POWER TECH DEV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310181006.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-17
Publication Date
2025-07-22
Estimated Expiration
2043-02-17

AI Technical Summary

Technical Problem

In distributed systems, electronic devices are vulnerable to network attacks, traditional cryptographic algorithms and protocol deployments have great limitations, and the device's computing and storage power are limited, making it difficult to ensure data transmission security.

Method used

Using a lightweight encryption method based on the elliptic curve key system (ECC), temporary public and private key pairs are generated through electronic devices and central devices, temporary encryption keys are generated using ECDH key exchange algorithm, data encryption is combined with the improved XTEA algorithm, and data transmission security is ensured through a two-way authentication protocol.

Benefits of technology

The security of data transmission in distributed systems is realized, prevents playback attacks, identity authentication problems and man-in-the-middle attacks, adapts to device resource limitations, and ensures the security of data transmission and the reliability of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116208411B_ABST
    Figure CN116208411B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an encryption method, apparatus, and electronic device. The method is applied to an electronic device of an encryption system, and the encryption system further includes a central device. The method includes: obtaining a temporary encryption key, where the temporary encryption key is determined based on a first temporary private key generated by the electronic device and a second temporary public key sent by the central device; obtaining first encrypted data based on the temporary encryption key; and sending the first encrypted data to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data. By using the temporary encryption key to obtain the first encrypted data, the present application can ensure the confidentiality of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular, to an encryption method, device and electronic device. Background Art

[0002] In the information age, the rapid development of information technologies such as cloud computing, the Internet of Things, big data, and 5G communication networks has made data a truly new production factor, and data sharing and circulation are imperative. Therefore, how to transmit data safely and effectively is a technical problem that needs to be solved urgently. Summary of the invention

[0003] The purpose of the present disclosure is to provide an encryption method, an apparatus and an electronic device, by which the security of data transmission can be ensured.

[0004] In order to achieve the above-mentioned object, a first aspect of the present disclosure provides an encryption method, which is applied to an electronic device of an encryption system, wherein the encryption system also includes a central device, and the method includes:

[0005] Acquire a temporary encryption key, where the temporary encryption key is determined based on a first temporary private key generated by the electronic device and a second temporary public key sent by the central device;

[0006] obtaining first encrypted data based on the temporary encryption key;

[0007] The first encrypted data is sent to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

[0008] Optionally, obtaining the first encrypted data based on the temporary encryption key includes:

[0009] Obtaining a hash value of first data, where the first data is determined by a hash value of a first message and an electronic device, and the first message is obtained based on basic information of the electronic device and a central device;

[0010] determining a signature of the first fixed private key based on the hash value of the first data and the first fixed private key;

[0011] The signature of the first fixed private key and the first message are encrypted using a temporary encryption key to obtain first encrypted data.

[0012] Optionally, determining the signature of the first fixed private key based on the hash value of the first data and the first fixed private key includes:

[0013] Get the first random number;

[0014] determining a signature of the first fixed private key based on the first random number, the hash value of the first data, and the first fixed private key;

[0015] Encrypt the signature of the first fixed private key and the first message with the temporary encryption key to obtain the first encrypted data, including:

[0016] Obtain the first point value corresponding to the first random number;

[0017] Encrypt the first point value, the signature of the first fixed private key and the first message with the temporary encryption key to obtain the first encrypted data.

[0018] Optionally, the method further includes:

[0019] Perform KECCAK operation on the basic information of the electronic device twice continuously to obtain the first candidate information;

[0020] Perform base64 encoding on the first n bytes of the first candidate information to obtain the hash value of the electronic device.

[0021] Optionally, obtaining the first encrypted data based on the temporary encryption key includes:

[0022] Use the extended micro-encryption algorithm and the temporary encryption key to complete encryption through iteration to obtain the first encrypted data.

[0023] Optionally, the method further includes:

[0024] Receive the second encrypted data from the central device;

[0025] Decrypt the second encrypted data with the temporary encryption key to obtain the first decryption result;

[0026] Authenticate the central device based on the decryption result.

[0027] Optionally, the method further includes:

[0028] After successfully authenticating the central device, obtain the transmission symmetric key;

[0029] Encrypt the data to be transmitted with the transmission symmetric key to obtain the target data;

[0030] Send the target data to the central device.

[0031] The second aspect of the present disclosure provides an encryption method applied to the central device of an encryption system, and the encryption system further includes an electronic device. The method includes:

[0032] Generate a second temporary public key and send the second temporary public key to the electronic device to instruct the electronic device to obtain a temporary encryption key based on the first temporary private key and the second temporary public key it generates. The second temporary public key is determined based on the second temporary private key generated by the central device;

[0033] Receive the first encrypted data sent by the electronic device, where the first encrypted data is obtained by the electronic device based on a temporary encryption key;

[0034] Authenticate the electronic device based on the first encrypted data.

[0035] Optionally, authenticating the electronic device based on the first encrypted data includes:

[0036] Decrypt the first encrypted data using the temporary encryption key to obtain a second decryption result;

[0037] Authenticate the electronic device based on the second decryption result.

[0038] Optionally, the method further includes:

[0039] Obtain second encrypted data based on the temporary encryption key;

[0040] Send the second encrypted data to the electronic device to instruct the electronic device to authenticate the central device.

[0041] Optionally, obtaining the second encrypted data based on the temporary encryption key includes:

[0042] Obtain the hash value of second data, where the second data is determined by a second message and the hash value of the central device, and the second message is obtained according to the basic information of the electronic device and the central device;

[0043] Determine the signature of the second fixed private key based on the hash value of the second data and the second fixed private key;

[0044] Encrypt the signature of the second fixed private key and the second message using the temporary encryption key to obtain the second encrypted data.

[0045] Optionally, the method further includes:

[0046] Obtain the basic information of the central device;

[0047] Perform two consecutive KECCAK operations on the basic information of the central device to obtain a second candidate information;

[0048] Perform base64 encoding on the first n bytes of the second candidate information to obtain the hash value of the central device.

[0049] A third aspect of the present disclosure provides an encryption device, the device includes:

[0050] A key acquisition module configured to acquire a temporary encryption key, where the temporary encryption key is determined based on a first temporary private key generated by the electronic device and a second temporary public key generated by the central device;

[0051] A data acquisition module, configured to acquire first encrypted data based on a temporary encryption key;

[0052] A sending module, configured to send the first encrypted data to a central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

[0053] A fourth aspect of the present disclosure provides an encryption device, the device includes:

[0054] A public key generation module, configured to generate a second temporary public key and send the second temporary public key to the electronic device to instruct the electronic device to acquire a temporary encryption key based on the first temporary private key generated by it and the second temporary public key, and the second temporary public key is determined based on the second temporary private key generated by the central device;

[0055] A data receiving module, configured to receive the first encrypted data sent by the electronic device, and the first encrypted data is acquired by the electronic device based on the temporary encryption key;

[0056] An authentication module, configured to authenticate the electronic device based on the first encrypted data.

[0057] According to a fifth aspect of the embodiments of the present disclosure, an electronic device is provided, including:

[0058] A memory, on which a computer program is stored;

[0059] A processor, configured to execute the computer program in the memory to implement the steps of the encryption method provided in the first aspect.

[0060] According to a sixth aspect of the embodiments of the present disclosure, a central device is provided, including:

[0061] A memory, on which a computer program is stored;

[0062] A processor, configured to execute the computer program in the memory to implement the steps of the encryption method provided in the second aspect.

[0063] According to a seventh aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored, and when the program instructions are executed by a processor, the steps of the encryption methods provided in the first aspect and the second aspect of the present disclosure are implemented.

[0064] In the above technical solution, through the above technical solution, a temporary encryption key is acquired, where the temporary encryption key is determined based on the first temporary private key generated by the electronic device and the second temporary public key sent by the central device. On this basis, the first encrypted data is acquired based on the temporary encryption key, and the first encrypted data is sent to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data, so as to ensure the security of data transmission.

[0065] Other features and advantages of the present disclosure will be described in detail in the following detailed implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] The accompanying drawings are used to provide a further understanding of the present disclosure, and constitute a part of the specification. Together with the following detailed implementation, they are used to explain the present disclosure, but do not constitute a limitation to the present disclosure. In the accompanying drawings:

[0067] Figure 1 is a flowchart of an encryption method shown according to an exemplary embodiment.

[0068] Figure 2 is an exemplary diagram of an encryption framework in an encryption method shown according to an exemplary embodiment.

[0069] Figure 3 is a flowchart of an encryption method shown according to another exemplary embodiment.

[0070] Figure 4 is a flowchart of an encryption method shown according to an exemplary embodiment.

[0071] Figure 5 is an exemplary flowchart of an encryption method shown according to an exemplary embodiment.

[0072] Figure 6 is a block diagram of an encryption device shown according to an exemplary embodiment.

[0073] Figure 7 is a block diagram of an encryption device shown according to an exemplary embodiment.

[0074] Figure 8 is a block diagram of an electronic device shown according to an exemplary embodiment.

[0075] Figure 9 is a block diagram of a central device shown according to an exemplary embodiment. DETAILED IMPLEMENTATION

[0076] The following details the specific implementation of the present disclosure in conjunction with the accompanying drawings. It should be understood that the specific implementation described herein is only for explaining and understanding the present disclosure, and is not used to limit the present disclosure.

[0077] It should be understood that the various steps described in the method embodiments of the present disclosure may be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard. The term "including" and its variants used herein are open-ended, that is, "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0078] It should be noted that the concepts such as "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units. It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0079] With the promulgation and implementation of a series of laws and standards on network security, cryptographic security, and data security, the security issues of digitalization, informatization, etc. have been highly valued by people. Industrial informatization systems and Internet of Things systems both belong to distributed systems. At present, the devices accessing the distributed systems are geographically dispersed, and the number of devices is large, the access environment is complex, and the access methods are diverse, which in turn leads to the distributed systems being easily vulnerable to illegal intrusion and attack.

[0080] Industrial monitoring systems mainly rely on internal local area networks. With the development of device informatization and intelligence, industrial monitoring systems inevitably need to exchange information with external networks. However, in the external environment, especially the Internet environment, network attack technologies pose a great threat to traditional industrial monitoring systems. At present, the electronic devices in distributed systems are extremely vulnerable to the influence of their deployment scenarios, and the computing power, storage capacity, and power of each electronic device are limited. As a result, the deployment of traditional cryptographic algorithms, cryptographic protocols, etc. also has great limitations.

[0081] In view of this, the present disclosure provides an encryption method, device, and electronic device to solve the above technical problems.

[0082] Figure 1 is a flowchart of an encryption method shown according to an exemplary embodiment, which is applied to an electronic device, such as Figure 1 shown, and includes the following steps.

[0083] In step S110, a temporary encryption key is obtained.

[0084] In the embodiments of the present disclosure, the temporary encryption key may be determined based on a first temporary private key generated by an electronic device and a second temporary public key sent by a central device, where the second temporary public key may be generated by the central device and sent to the electronic device. Specifically, the second temporary public key may be obtained by the central device when generating a second temporary private key and calculating in combination with the second temporary private key and a base point.

[0085] Here, the electronic device may also be referred to as the device side, and the central device may also be referred to as the system server side, the system service side, or the system service, etc.

[0086] In some embodiments, the electronic device may generate a first temporary private key after power-on. Similarly, the central device may generate a second temporary private key after power-on. The electronic device and the central device may generate their respective private keys separately, and there is no sequence relationship between the two.

[0087] Optionally, the electronic device may also generate a first temporary public key while generating the first temporary private key. In addition, the central device may also generate a second temporary public key while generating the second temporary private key. Here, the electronic device and the central device may use the same set of elliptic curve parameters.

[0088] In a specific embodiment, after the electronic device and the central device initialize the elliptic system, they may generate their respective public-private key pairs according to the public-private key pair generation algorithm. The first temporary private key and the first temporary public key generated by the electronic device may be k1 and Q1 respectively, and the second temporary private key and the second temporary public key generated by the central device may be k2 and Q2 respectively.

[0089] The electronic device and the central device may generate their respective public-private keys using the Elliptic Curve Cryptography (ECC), so that higher security can be achieved with relatively small overhead.

[0090] As an example, the embodiments of the present disclosure may use a 192-bit ECC curve to generate public and private keys. The ECC curve parameters here may be: prime number p = BDB6F4FE 3E8B1D9E 0DA8C0D4 6F4C318C EFE4AFE3B6B8551F; coefficient a = BB8E5E8F BC115E13 9FE6A814 FE48AAA6 F0ADA1AA5DF91985; coefficient b = 1854BEBD C31B21B7 AEFC80AB 0ECD10D5 B1B3308E 6DBF11C1; base point G(x,y), whose order is denoted as n; coordinate x: 4AD5F704 8DE709AD 51236DE6 5E4D4B48 2C836DC6E4106640; coordinate y: 02BB3A02D4AAADAC AE24817A 4CA3A1B0 14B52704 32DB27D2; order n: BDB6F4FE 3E8B1D9E 0DA8C0D40FC96219 5DFAE76F 56564677. Public and private keys can be generated through these parameters.

[0091] In summary, the elliptic curves used in the embodiments of the present disclosure can all adopt F P -192 elliptic curves, so as to achieve the overall lightweight design.

[0092] It should be noted that the first temporary private key and the second temporary private key in the embodiments of the present disclosure may be random integers generated by the electronic device and the central device respectively. As an example, the first temporary private key k1 and the second temporary private key k2 ∈ [1, n - 2]. On this basis, taking G as the base point, Q(x q , y q ) = [k]G can be obtained through calculation. In other words, the first temporary public key Q1 = [k1]G; the second temporary public key Q2 = [k2]G.

[0093] In a specific implementation, after the electronic device randomly generates a private key k1 (the first temporary private key) and calculates to obtain the first temporary public key Q1 (Q1 = k1 * G), it can send the base point G and the first temporary public key Q1 to the central device to instruct the central device to calculate the temporary encryption key s. In this process, the central device can also randomly generate a private key k2 (the second temporary private key) and calculate to obtain the second temporary public key Q2 (Q2 = k2 * G). When the central device obtains the temporary encryption key s, it can multiply the first temporary public key Q1 by the second temporary private key k2, that is, the temporary encryption key s = Q1 * k2 = (k1 * G) * k2 = k1 * k2 * G.

[0094] On this basis, the electronic device can receive a second temporary public key Q2 and encrypted data C from the central device, where the encrypted data C can be the data obtained by the central device encrypting Q1. Then, the electronic device can obtain a temporary encryption key s based on the second temporary public key, and the temporary encryption key s = Q2 * k1 = (k2 * G) * k1 = k1 * k2 * G. Here, the temporary encryption key can also be referred to as a symmetric key.

[0095] Optionally, the electronic device can use the temporary encryption key s to decrypt the encrypted data C to obtain Q1'. If it is determined that Q1' is equal to the first temporary public key Q1, it means that the common key is reached. If it fails, the key exchange can be restarted.

[0096] The above entire process can be implemented through the ECDH (Elliptic Curve Diffie–Hellman key Exchange) key exchange algorithm.

[0097] In step S120, the first encrypted data is obtained based on the temporary encryption key.

[0098] As an optional method, after the electronic device obtains the temporary encryption key, it can obtain the first encrypted data based on the temporary encryption key. Specifically, the electronic device can use the improved Extended Tiny Encryption Algorithm (XTEA) to complete the encryption of the data to obtain the first encrypted data. In other words, the electronic device can use the Extended Tiny Encryption Algorithm and the temporary encryption key to complete the encryption through iteration to obtain the first encrypted data.

[0099] To better illustrate the process of obtaining the first encrypted data, the embodiments of the present disclosure give a Figure 2 framework example diagram as shown. Here, the encryption framework can be a Feistel block encryption framework, and the encryption is completed through iteration, and then the first encrypted data can be obtained. When encrypting, the embodiments of the present disclosure can first convert the plaintext to be encrypted into a byte string, and then group the converted plaintext in units of 64 bits. The groups less than 64 bits can be padded with 0s.

[0100] Here, encryption and decryption can be to take the plaintext in groups of 8 bytes (64 bits), and four bytes are respectively passed in from both sides of each group. The four bytes on both sides can be Figure 2 v(i) and v(i + 1) in. On this basis, the electronic device can group the temporary encryption key in units of 32 bits to form Figure 2 the key data key[6] in. Here, the temporary encryption key can be 192 bits.

[0101] As shown Figure 2 in the figure, v(i) can first perform two shift operations, and then perform an exclusive OR operation after the shift. Then, the result of the exclusive OR operation is added to v(i) to obtain the sum value. On this basis, sum = sum + Δ, where DeltaΔ can be a constant, which can be obtained by taking the integer part of and the hexadecimal value is 0X890FDAA2.

[0102] The electronic device can select a key from key[6] and add it to Δ, and then perform an exclusive OR operation with the temporary encryption key to obtain O1, where key = Key[sum&5]. Then, the electronic device can add the result of sum + Δ to v(i+1) to obtain S1 and enter the lower half operation.

[0103] In the lower half operation, the electronic device can first perform two shift operations on the result O1 added to v(i+1), and then perform an exclusive OR on the result obtained by the shift. On this basis, the result of the exclusive OR operation is added to v(i+1) to obtain S2.

[0104] The electronic device can select a key from Key[6] and add it to Δ, and then perform an exclusive OR operation on S1 to obtain O2. Where Key = Key[(sum>>11)&5]. On this basis, S2 is added to v(i) and this round of iteration ends, entering the next round of iteration.

[0105] In some embodiments, the number of iteration rounds can be selected according to the computing power and speed of the electronic device, etc. For example, the number of iteration rounds can be selected as 16 rounds, 32 rounds, 64 rounds, etc. After the iteration is completed, the final v(i) and v(i+1) output can be the encrypted data, and multiple such v(i) and v(i+1) can form the first encrypted data.

[0106] The embodiments of the present disclosure expand the key selection of the XTEA algorithm and change the Delta constant used in the traditional TEA algorithm, further enhancing the strength of the XTEA algorithm.

[0107] In step S130, the first encrypted data is sent to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

[0108] As an optional method, after performing the encryption operation using the temporary encryption key and obtaining the first encrypted data, the electronic device can send the first encrypted data to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

[0109] In the embodiments of the present disclosure, the first encrypted data can be sent to the central device through the first authentication request. After the central device determines that the authentication of the electronic device is qualified, it can send a second authentication request to the electronic device, that is, the electronic device can also receive the second authentication request containing the second encrypted data from the central device.

[0110] Here, after receiving the second authentication request sent by the central device, the electronic device can authenticate the central device based on the second encrypted data. After confirming that the central device authentication is qualified, the authentication of both the electronic device and the central device ends.

[0111] It should be noted that the encryption method in the embodiments of the present disclosure can be a lightweight encryption method applicable to distributed systems, that is, the application scenario of the embodiments of the present disclosure can be a distributed system scenario.

[0112] In the embodiments of the present application, the electronic device first obtains a temporary encryption key. Among them, the temporary encryption key is determined based on the first temporary private key generated by the electronic device and the second temporary public key sent by the central device. On this basis, the first encrypted data is obtained based on the temporary encryption key, and the first encrypted data is sent to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data, so as to ensure the security of data transmission. In addition, the embodiments of the present disclosure can solve problems such as replay attacks, identity authentication of distributed devices, authentication of system services, and man-in-the-middle attacks on system services through a two-way authentication protocol.

[0113] Figure 3 It is a flowchart of an encryption method shown according to another exemplary embodiment, applied to an electronic device, as Figure 3 shown, including the following steps.

[0114] In step S210, obtain a temporary encryption key.

[0115] Among them, the specific implementation of step S210 has been described in detail in the above embodiments and will not be elaborated here.

[0116] In step S220, obtain the hash value of the first data.

[0117] In the embodiments of the present disclosure, the first data can be determined by the first message and the hash value of the electronic device, where the first message can be obtained according to the basic information of the electronic device and the central device.

[0118] In some embodiments, the basic information of the electronic device may include at least one of the device ID (Identity), the CPU serial number SN (Serial Numbe), and the MAC (Media Access Control Address) address. Among them, the device ID may be the unique identifier UUID (Universally Unique Identifier) of the electronic device, and this device ID may be referred to as the first device identifier, which may be 128 bits.

[0119] In some other embodiments, the basic information of the central device may include at least one of the device ID, the service address or IP address (Internet Protocol Address) of the central device (system service), and the version of the central device (system service). Among them, the device ID may be the unique identifier UUID of the central device (system service), and this device ID may be referred to as the second device identifier, which may be 128 bits.

[0120] In the embodiments of the present disclosure, the first message may also be referred to as the authentication message header. In a specific embodiment, the first message H1 may be obtained by splicing the device identifiers of the electronic device and the central device.

[0121] Optionally, the first message H1 may also be obtained by splicing the first device identifier ID of the electronic device A , the second device identifier ID of the central device B , the sequence number Index1 of the authentication message, and the time Time1 when the authentication message is sent. Specifically, the first message H1 may be equal to <ID A ||ID B ||Index1||Time1>.

[0122] Here, Index may be the sequence number of the authentication message. Each time an authentication message is sent, both the electronic device and the central device can record the sequence number, and this sequence number is monotonically increasing; Time may be the sending time of the authentication message. The electronic device can keep the time consistent by synchronizing the clock with the central device regularly. If the sending time of the authentication message deviates too much from the current time, it is determined that the message has expired, and at this time, re-authentication is required.

[0123] In the embodiments of the present disclosure, the hash value of the electronic device may correspond to the device identifier of the electronic device, and the hash value of the electronic device may be generated from the basic information of the electronic device. Specifically, in the embodiments of the present disclosure, the basic information of the electronic device may be subjected to two consecutive KECCAK operations to obtain the first candidate information. On this basis, the first n bytes of the first candidate information are base64 encoded to obtain the hash value of the electronic device.

[0124] The parameters involved in the KECCAK operation include r, c, b, and n r and so on, where r is the bit rate, which is the length of each input block; c is the capacity, and its length is twice the output length; b is the vector length, b = r + c, and the value of b depends on the exponent l, b = 25×2 l , l ≥ 2; n r is the number of rounds of iteration n r = 12 + 2×l.

[0125] As a specific implementation, there are three selectable parameters for KECCAK, which can be selected according to the specific application situation. Among them, the first one is KECCAK-f

[200] , r = 40, c = 160, n r = 18; the second one is KECCAK-f

[400] , r = 144, c = 256, n r = 20; the third one is KECCAK-f

[800] , r = 512, c = 288, n r = 22.

[0126] The Hash algorithm in the embodiments of the present disclosure adopts KECCAK-f[b], and by adapting different parameters (200, 400, 800), the Hash algorithm can be adapted to different hardware resources, thereby solving the problem of insufficient distributed device resources.

[0127] As can be known from the above introduction, the basic information of the electronic device may include at least one of the device ID, CPU serial number SN, MAC address, etc. As an example, the basic information of the electronic device is subjected to two consecutive KECCAK operations to obtain the first candidate information result A , and its calculation formula is as follows:

[0128] result A = KECCAK(KECCAK(ID A ||SN||MAC));

[0129] where ID AIt can be the device identifier of an electronic device; SN can be the CPU serial number SN of the electronic device; MAC can be the MAC address of the electronic device.

[0130] Based on this, the embodiment of the present disclosure can take the first n bytes of the first candidate information result A as the checksum checksum1. For example, the electronic device can take the first 4 bytes of the first candidate information result A as the checksum checksum1. Finally, perform base64 encoding on the checksum checksum1 to obtain the Hash pointer Hash A of the electronic device, that is, Hash A = base64(result A ||checksum1).

[0131] In the embodiment of the present disclosure, the Hash pointer of the electronic device corresponds to the electronic device one by one, and not only contains the ID information of the electronic device, but also contains the key hardware information of the electronic device. The hash values Hash A of all electronic devices can be saved in the database of the central device, so that it can prevent the connection of fake devices and also prevent hardware tampering of the electronic device.

[0132] In some embodiments, the hash value h of the first data can be equal to Hash(H1||Hash A ), where H1 can be the first message and Hash A can be the hash value of the electronic device.

[0133] In step S230, determine the signature of the first fixed private key based on the hash value of the first data and the first fixed private key.

[0134] In some embodiments, after obtaining the hash value of the first data, the electronic device can determine the signature of the first fixed private key based on the hash value of the first data and the first fixed private key. In this process, the electronic device can also obtain a first random number, and on this basis, determine the signature of the first fixed private key based on the first random number, the hash value of the first data, and the first fixed private key.

[0135] As an example, the first random number obtained by the electronic device is r, the hash value of the first data is h, and the first fixed private key of the electronic device is k a , and at this time, the signature S A of the first fixed private key = (h + k a x) / r. In this process, the electronic device can also obtain the first point value corresponding to the first random number, and the first point value can be equal to the first random number multiplied by the base point, that is, the first point value = rG(x, y).

[0136] In step S240, the signature of the first fixed private key and the first message are encrypted by the temporary encryption key to obtain the first encrypted data.

[0137] In some embodiments, after obtaining the signature of the first fixed private key, the electronic device may encrypt the signature of the first fixed private key and the first message by the temporary encryption key to obtain the first encrypted data. Optionally, the electronic device may also encrypt the first point value, the signature of the first fixed private key, and the first message by the temporary encryption key to obtain the first encrypted data.

[0138] Here, the temporary encryption key may be the shared password P owned by the electronic device and the central device ab , and the electronic device and the central device may use this temporary encryption key to perform encrypted communication using the improved XTEA.

[0139] As a specific embodiment, the electronic device may encrypt the first message H1, the first point value rG(x, y), and the signature S of the first fixed private key A by the temporary encryption key P ab to perform improved XTEA encryption. The specific encryption process may refer to Figure 2 , and the finally obtained first encrypted data C1 = E(H1||rG||S A , P ab ).

[0140] In step S250, the first encrypted data is sent to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

[0141] In some embodiments, after the electronic device sends the first encrypted data to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data, the electronic device may also receive the second encrypted data from the central device.

[0142] On this basis, the second encrypted data is decrypted using the temporary encryption key to obtain the first decryption result, and finally the central device is authenticated based on the decryption result. Among them, the process of obtaining the second encrypted data is similar to the process of obtaining the first encrypted data.

[0143] In other embodiments, when the authentication between the electronic device and the central device is successful, the present disclosure embodiment may obtain a new transmission symmetric key. In other words, the electronic device and the central device may generate a transmission symmetric key T according to the ECDH key exchange algorithm ab . On this basis, the electronic device and the central device may perform data transmission using the improved XTEA encryption algorithm.

[0144] In the embodiments of the present disclosure, according to the requirements of the central device and the resource situation of the electronic device, the data connection can be terminated after the data transmission ends, and both the electronic device and the central device can release resources. Optionally, the embodiments of the present disclosure can also adopt a long connection, that is, after the data transmission ends, the heartbeat message is used to maintain the effectiveness of the data transmission channel, but the transmission symmetric key T needs to be updated regularly during the long connection process. ab . In other words, the transmission symmetric key T ab should not be updated more than once every 12 hours.

[0145] It should be noted that the hash value Hash of the electronic device can be stored in the electronic device in the embodiments of the present disclosure. A , and this hash value can correspond to the device ID of the electronic device. It can be a Hash value generated from the device ID and the basic information of the device, which is equivalent to the password of device A.

[0146] Optionally, the electronic device can also store the device identifier, hash value Hash, etc. of the central device. B Among them, the hash value of the central device can correspond to the unique identifier UUID of the central device. In addition, the hash value of the central device can be a Hash value generated from data such as the device ID and the basic information of the central device.

[0147] It should be noted that the above information stored in the electronic device can be solidified into the hardware when the electronic device leaves the factory.

[0148] In the embodiments of the present application, the electronic device first obtains a temporary encryption key. Among them, the temporary encryption key is determined based on the first temporary public key sent by the electronic device and the second temporary private key generated by the central device. On this basis, the first encrypted data is obtained based on the temporary encryption key, and the first encrypted data is sent to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data, so as to ensure the security of data transmission. In addition, in the embodiments of the present disclosure, the Hash pointer of the central device is written into the electronic device. In the mutual authentication, the electronic device can prevent man-in-the-middle attacks by confirming the Hash pointer of the central device. And based on the ECDH elliptic curve key exchange and the improved XTEA algorithm, the present disclosure can solve the problem of lightweight symmetric encryption transmission of data.

[0149] Figure 4 is a flowchart of an encryption method shown according to an exemplary embodiment. This method is applied to the central device, as Figure 4 shown, and includes the following steps.

[0150] In step S310, a second temporary public key is generated and sent to the electronic device to instruct the electronic device to obtain a temporary encryption key based on the first temporary private key and the second temporary public key it generates.

[0151] In the embodiments of the present disclosure, the second temporary public key is generated through a second temporary private key, and the generation process of the second temporary private key is similar to that of the first temporary private key, so details are not described herein again.

[0152] In step S320, the first encrypted data sent by the electronic device is received.

[0153] In some embodiments, the central device may receive the first encrypted data sent by the electronic device, where the first encrypted data may be obtained by the electronic device based on the temporary encryption key.

[0154] In step S330, the electronic device is authenticated based on the first encrypted data.

[0155] In some embodiments, after the central device receives the first encrypted data sent by the electronic device, it may authenticate the electronic device based on the first encrypted data. Specifically, the central device may use the temporary encryption key to decrypt the first encrypted data to obtain a second decryption result. On this basis, the central device may authenticate the electronic device based on the second decryption result.

[0156] As a specific embodiment, after receiving the first encrypted data, the central device may use the temporary encryption key P ab to decrypt the first encrypted data C1 to obtain a second decryption result. The specific decryption process may be the reverse of the encryption process, that is, Figure 2 reversing the process can achieve the decryption of the first encrypted data. Among them, the second decryption result may be H1||rG||S A , where H1 may be the first message in the above embodiments; rG is the first point value; S A is the signature of the first fixed private key.

[0157] As known from the above introduction, the first message H1 may be obtained by concatenating the first device identifier ID of the electronic device A , the second device identifier ID of the central device B , the sequence number Index1 of the authentication message, and the time Time1 when the authentication message is sent. Therefore, after obtaining the second result, the central device may obtain the device identifier of the electronic device based on the second decryption result.

[0158] In an embodiment of the present disclosure, the central device may store a device ID-Hash pointer database HashDB, in which the device identifiers and hash values of the electronic devices may be stored in a one-to-one correspondence manner.

[0159] As an alternative, after obtaining the device identifier of the electronic device, the central device may look up the hash value Hash of the electronic device corresponding to the device identifier from the database HashDB. A On this basis, if it is determined that the device identifier of the electronic device exists in the database HashDB, it is determined that the authentication is successful. Optionally, if it is determined that the device identifier of the electronic device does not exist in the database HashDB, it is determined that the authentication fails.

[0160] In addition, as introduced above, it is known that the first message further includes the second device identifier ID of the central device. B The central device may determine whether the first encrypted data is sent to itself based on the second device identifier ID. B If the second device identifier ID sent by the electronic device B matches the device identifier of the central device, it means that the first encrypted data is sent to the central device and the authentication is successful; otherwise, it means that the first encrypted data is not sent to the central device and the authentication fails.

[0161] As another alternative, as introduced above, it is known that the first message H1 may further include the sequence number Index1 of the authentication message and the time Time1 when the authentication message is sent. Therefore, after the central device obtains the second decryption result, it may also determine whether the sequence number Index1 of the authentication message in the second decryption result is monotonically increasing. If it is determined that the sequence number Index1 of the authentication message in the second decryption result is monotonically increasing, it is determined that the authentication is successful; otherwise, it is determined that the authentication fails.

[0162] Optionally, the central device may also determine whether the time Time1 when the authentication message is sent in the second decryption result is within a reasonable range. If it is determined that the time Time1 when the authentication message is sent is within a reasonable range, it is determined that the authentication has not expired, that is, the authentication is successful; otherwise, it is determined that the authentication has expired, that is, the authentication fails.

[0163] As another alternative, through the second decryption result, the embodiment of the present disclosure may obtain the first message H1 and the first device identifier of the electronic device, and through looking up the database HashDB, the hash value Hash of the electronic device may be obtained. A Then, the central device may obtain the message hash h, where h = Hash(H1||Hash A ).

[0164] On this basis, the central device can use the public key Q of the electronic device a to calculate the authentication value, which can be equal to hG / s + xQ a / s, and then compare this authentication value with rG. If the authentication value is equal to rG, it is determined that the signature verification is successful. Among them, hG / s + xQ a / s = hG / s + x(k a G) / s = (h + xk a )G / s = r(h + xk a )G / (h + k a x) = rG. In this way, the central device can complete the authentication of the electronic device.

[0165] In some embodiments, the central device can also obtain the second encrypted data based on the temporary encryption key, and then send the second encrypted data to the electronic device to instruct the electronic device to authenticate the central device.

[0166] Here, when obtaining the second encrypted data based on the temporary encryption key, the central device can obtain the hash value of the second data. Among them, the second data can be determined by the second message and the hash value of the central device. The second message can be obtained according to the basic information of the electronic device and the central device. The process of obtaining the second message is similar to the process of obtaining the first message, and will not be elaborated here.

[0167] On this basis, the central device can determine the signature of the second fixed private key based on the hash value of the second data and the second fixed private key, and encrypt the signature of the second fixed private key and the second message through the temporary encryption key to obtain the second encrypted data.

[0168] In some embodiments, the central device can obtain its basic information and perform two consecutive KECCAK operations on this basic information to obtain the second candidate information result B , and the second candidate information can be equal to KECCAK(KECCAK(M B ||r B ))). Here, M B can be the basic information of the central device, and r B can be a random number generated by the central device.

[0169] On this basis, the embodiment of the present disclosure can take the first n bytes of the second candidate information result B as the checksum checksum2. As an example, the central device can take the second candidate information result BThe first 4 bytes are used as the checksum checksum2. Finally, by performing base64 encoding on the checksum checksum2, the Hash pointer Hash of the central device can be obtained. B , that is, Hash B = base64(result B ||checksum2).

[0170] In the embodiments of the present disclosure, the Hash pointer of the central device corresponds one-to-one with the central device, contains the basic information of the central device, and can prevent man-in-the-middle attacks by confirming the hash value of the central device during mutual authentication.

[0171] In the embodiments of the present disclosure, the central device may store the device identifier of the central device and the hash value Hash of the central device B , where the hash value of the central device may be determined by the device identifier of the central device and basic information, etc. Here, the basic information may include the service address or IP address of the central device, the version of the central device, etc., and these information may all be persistent information in the central device.

[0172] In the embodiments of the present application, the central device can generate a second temporary public key and send it to the electronic device, which can instruct the electronic device to obtain a temporary encryption key based on the first temporary private key and the second temporary public key generated by it. On this basis, the central device can receive the first encrypted data sent by the electronic device, and then authenticate the electronic device based on the first encrypted data. Through mutual authentication, the security of data transmission can be guaranteed to a certain extent. In addition, in the embodiments of the present disclosure, by establishing a device ID-Hash pointer database HashDB, not only can the connection of fake devices be prevented, but also the hardware tampering of devices can be prevented.

[0173] An encryption method is applied to encryption. The encryption system may include the electronic device and the central device in the above embodiments. To better illustrate the encryption process, the embodiments of the present disclosure give an example diagram as Figure 5 shown. Figure 5 In [the figure], A and B may be the electronic device and the central device respectively. When encrypting, A and B may generate their respective public and private keys. Then, A and B may negotiate a temporary encryption key P ab through the generated public and private keys and based on ECDH. Then, A and B may perform mutual authentication, that is, mutual authentication is achieved through the first encrypted data and the second encrypted data.

[0174] On this basis, A and B may negotiate a temporary encryption key T ab through ECDH. If it is determined that the key T ab has expired, then a new temporary encryption key T is negotiated again based on ECDH.ab If the determined key T ab has not expired, then A and B perform data transmission according to the transmission key T ab through an improved XTEA encryption algorithm. If it is determined that the data transmission ends, then end the data transmission; otherwise, negotiate a new transmission key T according to ECDH ab .

[0175] Figure 6 is a block diagram of an encryption device shown according to an exemplary embodiment. As Figure 6 shown, the encryption device 400 may include a key acquisition module 410, a data acquisition module 420, and a sending module 430.

[0176] The key acquisition module 410 is configured to acquire a temporary encryption key, and the temporary encryption key is determined based on a first temporary private key generated by the electronic device and a second temporary public key sent by the central device;

[0177] The data acquisition module 420 is configured to acquire first encrypted data based on the temporary encryption key;

[0178] The sending module 430 is configured to send the first encrypted data to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

[0179] In some embodiments, the data acquisition module 420 may include:

[0180] A first hash value acquisition sub-module, configured to acquire a hash value of first data, where the first data is determined by a first message and a hash value of the electronic device, and the first message is acquired according to basic information of the electronic device and the central device;

[0181] A first signature determination sub-module, configured to determine a signature of the first fixed private key based on the hash value of the first data and the first fixed private key;

[0182] A first encryption sub-module, configured to encrypt the signature of the first fixed private key and the first message through the temporary encryption key to obtain the first encrypted data.

[0183] In some embodiments, the first signature determination sub-module is configured to acquire a first random number, and determine a signature of the first fixed private key based on the first random number, the hash value of the first data, and the first fixed private key. The encryption sub-module is configured to acquire a first point value corresponding to the first random number, and encrypt the first point value, the signature of the first fixed private key, and the first message through the temporary encryption key to obtain the first encrypted data.

[0184] In some embodiments, the encryption device 400 may further include:

[0185] A first candidate information acquisition module, configured to perform two consecutive KECCAK operations on the basic information of the electronic device to obtain first candidate information;

[0186] A first encoding module, configured to perform base64 encoding on the first n bytes of the first candidate information to obtain the hash value of the electronic device.

[0187] In some embodiments, the data acquisition module 420 is further configured to complete encryption by iteration using an extended micro-encryption algorithm and the temporary encryption key to obtain the first encrypted data.

[0188] In some embodiments, the encryption device 400 may further include:

[0189] A second encrypted data receiving module, configured to receive second encrypted data from the central device;

[0190] A first decryption module, configured to decrypt the second encrypted data using the temporary encryption key to obtain a first decryption result;

[0191] A first authentication module, configured to authenticate the central device based on the decryption result.

[0192] In some embodiments, the encryption device 400 may further include:

[0193] A transmission key acquisition module, configured to acquire a transmission symmetric key after successfully authenticating the central device;

[0194] A transmission encryption module, configured to encrypt the data to be transmitted using the transmission symmetric key to obtain target data;

[0195] A target data sending module, configured to send the target data to the central device.

[0196] In the embodiments of the present disclosure, the electronic device first obtains a temporary encryption key, where the temporary encryption key is determined based on a first temporary private key generated by the electronic device and a second temporary public key sent by the central device. On this basis, the first encrypted data is obtained based on the temporary encryption key, and the first encrypted data is sent to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data, so as to ensure the security of data transmission.

[0197] Figure 7 is a block diagram of an encryption device shown according to an exemplary embodiment, as Figure 7As shown, the encryption device 500 may include a public key generation module 510, a data receiving module 520, and an authentication module 530.

[0198] The public key generation module 510 is configured to generate a second temporary public key and send the second temporary public key to the electronic device to instruct the electronic device to obtain a temporary encryption key based on the first temporary private key generated by it and the second temporary public key, where the second temporary public key is determined based on the second temporary private key generated by the central device;

[0199] The data receiving module 520 is configured to receive the first encrypted data sent by the electronic device, where the first encrypted data is obtained by the electronic device based on the temporary encryption key;

[0200] The authentication module 530 is configured to authenticate the electronic device based on the first encrypted data.

[0201] In some embodiments, the authentication module 530 may include:

[0202] A second decryption sub-module, configured to decrypt the first encrypted data using the temporary encryption key to obtain a second decryption result;

[0203] A second authentication sub-module, configured to authenticate the electronic device based on the second decryption result.

[0204] In some embodiments, the encryption device 500 may further include:

[0205] A second encrypted data acquisition module, configured to obtain second encrypted data based on the temporary encryption key;

[0206] A second encrypted data sending module, configured to send the second encrypted data to the electronic device to instruct the electronic device to authenticate the central device.

[0207] In some embodiments, the second encrypted data acquisition module may include:

[0208] A second hash value acquisition sub-module, configured to acquire the hash value of second data, where the second data is determined by a second message and the hash value of the central device, and the second message is obtained according to the basic information of the electronic device and the central device;

[0209] A second signature determination sub-module, configured to determine the signature of the second fixed private key based on the hash value of the second data and the second fixed private key;

[0210] A second encryption sub-module, configured to encrypt the signature of the second fixed private key and the second message through the temporary encryption key to obtain the second encrypted data.

[0211] In some embodiments, the encryption device 500 may further include:

[0212] A basic information acquisition module, configured to acquire the basic information of the central device;

[0213] A second candidate information acquisition module, configured to perform two consecutive KECCAK operations on the basic information of the central device to obtain second candidate information;

[0214] A second encoding module, configured to perform base64 encoding on the first n bytes of the second candidate information to obtain the hash value of the central device.

[0215] In the embodiments of the present application, the central device can generate a second temporary public key and send the second temporary public key to the electronic device, which can instruct the electronic device to obtain a temporary encryption key based on the first temporary private key and the second temporary public key generated by it. On this basis, the central device can receive the first encrypted data sent by the electronic device, and then authenticate the electronic device based on the first encrypted data. Through mutual authentication, the security of data transmission can be ensured to a certain extent.

[0216] Regarding the device in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.

[0217] The present disclosure also provides a computer-readable storage medium, on which computer program instructions are stored, and when the program instructions are executed by a processor, the steps of the encryption method provided by the present disclosure are implemented.

[0218] The present disclosure also provides an encryption system, which may include an electronic device and a central device. Among them, the electronic device is used to execute the steps of the encryption method related to the electronic device described above; the central device is used to execute the steps of the encryption method related to the central device described above.

[0219] Figure 8 It is a block diagram of an electronic device 700 shown according to some embodiments. For example, the electronic device 700 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, a smart car, etc.

[0220] Referring to Figure 8 , the electronic device 700 may include one or more of the following components: a first processing component 702, a first memory 704, a first power supply component 706, a multimedia component 708, an audio component 710, a first input / output interface 712, a sensor component 714, and a communication component 716.

[0221] The first processing component 702 generally controls the overall operation of the electronic device 700, such as operations associated with display, telephone calls, data communication, camera operations, and recording operations. The first processing component 702 may include one or more first processors 720 to execute instructions to complete all or part of the steps of the above encryption method. In addition, the first processing component 702 may include one or more modules to facilitate the interaction between the first processing component 702 and other components. For example, the first processing component 702 may include a multimedia module to facilitate the interaction between the multimedia component 708 and the first processing component 702.

[0222] The first memory 704 is configured to store various types of data to support the operation of the electronic device 700. Examples of such data include instructions for any application or method operating on the electronic device 700, contact data, phone book data, messages, pictures, videos, and the like. The first memory 704 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0223] The first power component 706 provides power to various components of the electronic device 700. The first power component 706 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device 700.

[0224] The multimedia component 708 includes a screen that provides an output interface between the electronic device 700 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe actions but also detect the duration and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 708 includes a front camera and / or a rear camera. When the electronic device 700 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera may receive external multimedia data. Each of the front camera and the rear camera may be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0225] The audio component 710 is configured to output and / or input audio signals. For example, the audio component 710 includes a microphone (MIC) that is configured to receive external audio signals when the electronic device 700 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signal can be further stored in the first memory 704 or sent via the communication component 716. In some embodiments, the audio component 710 further includes a speaker for outputting audio signals.

[0226] The first input / output interface 712 provides an interface between the first processing component 702 and a peripheral interface module, and the peripheral interface module can be a keyboard, a click wheel, buttons, etc. These buttons can include but are not limited to: a home button, a volume button, a power button, and a lock button.

[0227] The sensor component 714 includes one or more sensors for providing an assessment of various aspects of the status of the electronic device 700. For example, the sensor component 714 can detect the on / off state of the electronic device 700, the relative positioning of components, such as the display and keypad of the electronic device 700. The sensor component 714 can also detect a change in the position of the electronic device 700 or a component of the electronic device 700, the presence or absence of user contact with the electronic device 700, the orientation or acceleration / deceleration of the electronic device 700, and the temperature change of the electronic device 700. The sensor component 714 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 714 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 714 can further include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0228] The communication component 716 is configured to facilitate communication between the electronic device 700 and other devices in a wired or wireless manner. The electronic device 700 can access a wireless network based on a communication standard, such as WiFi, 2G, or 3G, or a combination thereof. In an exemplary embodiment, the communication component 716 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 716 further includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0229] In an exemplary embodiment, the electronic device 700 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above encryption method.

[0230] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a first memory 704 including instructions, and the above instructions can be executed by a first processor 720 of the electronic device 700 to complete the above encryption method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0231] In addition to being an independent electronic device, the above device may also be a part of an independent electronic device. For example, in one embodiment, the device may be an integrated circuit (IC) or a chip. The integrated circuit may be a single IC or a collection of multiple ICs; the chip may include, but is not limited to, the following types: GPU (Graphics Processing Unit, graphics processor), CPU (Central Processing Unit, central processor), FPGA (Field Programmable Gate Array, programmable logic array), DSP (Digital Signal Processor, digital signal processor), ASIC (Application Specific Integrated Circuit, application specific integrated circuit), SOC (System on Chip, SoC, system-on-chip or system-level chip), etc. The above integrated circuit or chip may be used to execute executable instructions (or code) to implement the above encryption method. The executable instructions may be stored in the integrated circuit or chip, or obtained from other devices or equipment. For example, the integrated circuit or chip includes a processor, a memory, and an interface for communicating with other devices. The executable instructions may be stored in the memory, and when the executable instructions are executed by the processor, the above encryption method is implemented; or, the integrated circuit or chip may receive the executable instructions through the interface and transmit them to the processor for execution to implement the above encryption method.

[0232] In another exemplary embodiment, a computer program product is also provided. The computer program product includes a computer program executable by a programmable device. The computer program has a code portion for performing the above-described encryption method when executed by the programmable device.

[0233] Figure 9 FIG. 4 is a block diagram of a central device according to an exemplary embodiment. The central device may be a network-side device. For example, the central device 800 may be provided as a server, and the server here may be a location server. Referring to Figure 9 FIG. 4, the central device 800 includes a second processing component 822, which further includes one or more processors, and memory resources represented by a second memory 832 for storing instructions executable by the second processing component 822, such as application programs. The application programs stored in the second memory 832 may include one or more modules each corresponding to a set of instructions. In addition, the second processing component 822 is configured to execute instructions to perform the encryption method.

[0234] The central device 800 may further include a second power component 826 configured to perform power management of the central device 800, a wired or wireless network interface 850 configured to connect the central device 800 to a network, and a second input / output interface 858. The central device 800 may operate based on an operating system stored in the memory 832, such as Windows Server TM , Mac OS X TM , Unix TM , Linux TM , FreeBSD TM or the like.

[0235] Those skilled in the art will readily conceive of other embodiments of the present disclosure after considering the specification and practicing the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed by the present disclosure. The specification and embodiments are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0236] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. An encryption method, characterized in that, The method is applied to an electronic device of an encryption system, and the encryption system further includes a central device, including: Obtain a temporary encryption key, which is determined based on a first temporary private key generated by the electronic device and a second public key sent by the central device; Obtain first encrypted data based on the temporary encryption key; The obtaining the first encrypted data based on the temporary encryption key includes: Obtain a hash value of first data, where the first data is determined by a first message and a hash value of the electronic device, and the first message is obtained according to basic information of the electronic device and the central device; Determine a signature of the first fixed private key based on the hash value of the first data and the first fixed private key; Encrypt the signature of the first fixed private key and the first message with the temporary encryption key to obtain the first encrypted data; Send the first encrypted data to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

2. The method according to claim 1, wherein The determining the signature of the first fixed private key based on the hash value of the first data and the first fixed private key includes: Obtain a first random number; Determine the signature of the first fixed private key based on the first random number, the hash value of the first data, and the first fixed private key; The encrypting the signature of the first fixed private key and the first message with the temporary encryption key to obtain the first encrypted data includes: Obtain a first point value corresponding to the first random number; Encrypt the first point value, the signature of the first fixed private key, and the first message with the temporary encryption key to obtain the first encrypted data.

3. The method according to claim 1, characterized in that, The method further includes: Perform KECCAK operation on the basic information of the electronic device twice continuously to obtain first candidate information; Perform base64 encoding on the first n bytes of the first candidate information to obtain the hash value of the electronic device.

4. The method according to claim 1, wherein The obtaining the first encrypted data based on the temporary encryption key includes: Use an extended micro-encryption algorithm and the temporary encryption key to complete encryption through iteration to obtain the first encrypted data.

5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: Receive second encrypted data from the central device; Decrypt the second encrypted data with the temporary encryption key to obtain a first decryption result; Authenticate the central device based on the decryption result.

6. The method according to claim 5, characterized in that The method further includes: After successfully authenticating the central device, obtain a transmission symmetric key; Encrypt data to be transmitted with the transmission symmetric key to obtain target data; Send the target data to the central device.

7. An encryption method, characterized in that, The method is applied to a central device of an encryption system, and the encryption system further includes an electronic device, including: Generate a second temporary public key and send the second temporary public key to the electronic device to instruct the electronic device to obtain a temporary encryption key based on a first temporary private key generated by it and the second temporary public key, where the second temporary public key is determined based on a second temporary private key generated by the central device; Receive the first encrypted data sent by the electronic device, where the first encrypted data is obtained by the electronic device based on the temporary encryption key; Authenticate the electronic device based on the first encrypted data; Obtain second encrypted data based on the temporary encryption key; The obtaining the second encrypted data based on the temporary encryption key includes: Obtain the hash value of second data, where the second data is determined by a second message and the hash value of the central device, and the second message is obtained according to the basic information of the electronic device and the central device; Determine the signature of the second fixed private key based on the hash value of the second data and the second fixed private key; Encrypt the signature of the second fixed private key and the second message with the temporary encryption key to obtain the second encrypted data; Send the second encrypted data to the electronic device to instruct the electronic device to authenticate the central device.

8. The method according to claim 7, characterized in that The authenticating the electronic device based on the first encrypted data includes: Decrypt the first encrypted data with the temporary encryption key to obtain a second decryption result; Authenticate the electronic device based on the second decryption result.

9. The method according to claim 7, wherein The method further includes: Obtain the basic information of the central device; Perform two consecutive KECCAK operations on the basic information of the central device to obtain a second candidate information; Perform base64 encoding on the first n bytes of the second candidate information to obtain the hash value of the central device.

10. An encryption device, characterized in that, The apparatus is applied to an electronic device of an encryption system, and the encryption system further includes a central device, and includes: A key acquisition module configured to acquire a temporary encryption key, where the temporary encryption key is determined based on a first temporary private key generated by the electronic device and a second public key sent by the central device; A data acquisition module configured to obtain first encrypted data based on the temporary encryption key; obtain the hash value of first data, where the first data is determined by a first message and the hash value of the electronic device, and the first message is obtained according to the basic information of the electronic device and the central device; determine the signature of the first fixed private key based on the hash value of the first data and the first fixed private key; encrypt the signature of the first fixed private key and the first message with the temporary encryption key to obtain the first encrypted data; A sending module configured to send the first encrypted data to the central device to instruct the central device to authenticate the electronic device based on the first encrypted data.

11. An encryption device, characterized in that, The apparatus is applied to a central device of an encryption system, and the encryption system further includes an electronic device, and includes: A public key generation module configured to generate a second temporary public key and send the second temporary public key to the electronic device to instruct the electronic device to obtain a temporary encryption key based on a first temporary private key generated by it and the second temporary public key, where the second temporary public key is determined based on a second temporary private key generated by the central device; A data receiving module configured to receive the first encrypted data sent by the electronic device, where the first encrypted data is obtained by the electronic device based on the temporary encryption key; An authentication module, configured to authenticate the electronic device based on the first encrypted data; A second encrypted data acquisition module, configured to acquire second encrypted data based on the temporary encryption key; the acquiring of the second encrypted data based on the temporary encryption key includes: acquiring a hash value of second data, the second data being determined by a second message and a hash value of the central device, the second message being acquired according to the basic information of the electronic device and the central device; determining a signature of the second fixed private key based on the hash value of the second data and the second fixed private key; encrypting the signature of the second fixed private key and the second message with the temporary encryption key to obtain the second encrypted data; A second encrypted data sending module, configured to send the second encrypted data to the electronic device to instruct the electronic device to authenticate the central device.

12. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Communication authentication method and system, electronic equipment, server and storage medium

    CN111935166A

  • Identity verification method and device, computer equipment and storage medium

    CN112422587A