A kind of association control method and related device

By receiving association requests in nodes, verifying identity authentication information and updating counters, the problem of nodes being associated with illegal attackers is solved, and higher data security and system stability are achieved.

CN116235467BActive Publication Date: 2025-05-16HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080104749.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-07-30
Publication Date
2025-05-16
Estimated Expiration
2040-07-30

AI Technical Summary

Technical Problem

The prior art is difficult to effectively prevent nodes from establishing associations with illegal attackers, resulting in threats to communication security.

Method used

By receiving the association request from the second node, after confirming that its identity is trustworthy, use the shared key to verify the identity authentication information, and update the counter when the verification fails to prevent illegal association.

Benefits of technology

Effectively prevent nodes from establishing associations with illegal attackers, improve data security, and avoid the risk of nodes crashing due to processing large numbers of requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116235467B_ABST
    Figure CN116235467B_ABST
Patent Text Reader

Abstract

A method and device for association, applied to short-distance communication. The method comprises: determining that the identity of a second node is credible (S303), sending a first authentication request to the second node (S304), wherein the first authentication request includes first identity authentication information generated according to a shared key; receiving a first authentication response from the second node, wherein the first authentication response includes second identity authentication information; verifying the second identity authentication information according to the shared key (S307); if the verification fails, updating a first authentication failure counter (S308). The method can prevent a node from establishing association with an illegal attacker and protect the data security of the node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, in particular to the field of short-distance communication technology, such as cockpit communication, and specifically to an association control method and related device for communication security management. Background Art

[0002] In today's rapidly developing information technology, mobile terminals, whether mobile phones, tablets or other portable smart terminals, are important personal smart tools that we cannot do without. While enjoying the convenience brought by information technology, we are also facing the threat of security vulnerabilities and privacy leaks. Take smart cars as an example. With the widespread application of vehicle communications, vehicle communications have also brought a series of security risks to cars. For example, through existing short-range communication technologies (such as wireless fidelity Wi-Fi, Bluetooth, etc.), hackers may invade the vehicle information system, obtain vehicle information, and even remotely control the car, which poses a high threat to user privacy and vehicle safety. Millions of cars around the world are affected. For another example, Denial of Service (DoS) is the most common and most vulnerable attack behavior in the vehicle communication process. The attacker will deliberately attack the defects of the network protocol implementation or directly use brutal means to cruelly exhaust the resources of the attacked object (such as the control center in the vehicle), so that the attacked object cannot provide normal services, stops responding, or even crashes. Among them, the Auth Flood attack is a type of DOS attack. The attacker will send a large number of request frames to the associated nodes. When the node receives a large number of request frames, which exceeds the processing capacity it can bear, it will cause the node to be paralyzed and unable to continue to provide normal services, thereby affecting the communication between other nodes and the node. Therefore, in order to ensure the security of communication, the association control of nodes is crucial.

[0003] In the prior art, restrictions can be imposed on nodes requesting association through whitelist or blacklist technology. Specifically, if the identifier of node A is in the whitelist of node B, node B will receive the association request from node A and then associate. Correspondingly, if the identifier of node C is in the blacklist of node B, node B may not receive the association request from node C, or may refuse to associate. For example, during Bluetooth communication, a Bluetooth device can establish an association with a specific Bluetooth device (i.e., the Bluetooth device listed in the whitelist) by establishing a whitelist. However, whitelists or blacklists are usually filtered by identifiers (such as device addresses). An attacker can modify his or her identifier to a trusted identifier, so that the node cannot identify illegal attackers, resulting in the node being associated with the attacker, threatening the node's data security.

[0004] Therefore, how to prevent nodes from establishing associations with illegal attackers is a hot issue that technicians in this field are currently studying. Summary of the invention

[0005] The embodiment of the present application discloses an association control method and related devices, which can prevent nodes from establishing associations with illegal attackers and protect the data security of nodes.

[0006] In a first aspect, an embodiment of the present application provides an association control method, the method comprising:

[0007] receiving a first association request from a second node;

[0008] Determining that the identity of the second node is credible, sending a first authentication request to the second node, wherein the first authentication request includes first identity authentication information, and the first identity authentication information is generated according to a shared key between the first node and the second node; wherein the shared key can be regarded as a first secret value shared between the first node and the second node;

[0009] receiving a first authentication response from the second node, wherein the first authentication response includes second identity authentication information;

[0010] verifying the second identity authentication information according to the shared key;

[0011] If the verification of the second identity authentication information fails, a first authentication failure counter is updated, where the first authentication failure counter represents the number of verification failures for the second node.

[0012] In the embodiment of the present application, after confirming that the identity of the second node is credible, it is also necessary to verify the identity of the second node based on the shared key of the first node and the second node. In this way, even if the attacker modifies the identity identifier and bypasses the step of "confirming that the identity is credible", it is still impossible to pass the identity verification of the first node because it is difficult to forge the identity verification information, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node.

[0013] Furthermore, if the verification fails, the number of verification failures will be updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, so that nodes that fail multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, their association requests (such as sending authentication requests) can no longer be processed, thereby preventing the node from crashing due to processing a large number of requests and ensuring that the services provided by the node are normal.

[0014] In a possible implementation manner of the first aspect, determining that the identity of the second node is credible includes:

[0015] Determining that the identifier of the second node is in the first whitelist;

[0016] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0017] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0018] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0019] In the above method, the nodes that request association can be controlled by blacklist or whitelist, so that the identity authentication of the untrusted second node is not required. On the one hand, it can prevent the crash due to processing a large number of requests and ensure the normal operation of the service. On the other hand, since no association is established with nodes that have not been authenticated, the node is prevented from establishing association with illegal attackers, thereby improving the data security of the node.

[0020] In yet another possible implementation of the first aspect, determining that the identity of the second node is credible includes:

[0021] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0022] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0023] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0024] In another possible implementation of the first aspect, the first authentication response further includes second integrity verification data, and the second integrity verification data is used to verify the message integrity of the first authentication response; and the method further includes:

[0025] Determine that the message integrity check of the first authentication response passes.

[0026] It can be seen that after confirming that the identity of the second node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication response from being tampered with by an attacker, thereby avoiding affecting the verification of the identity authentication information of the second node and ensuring the stable operation of the services provided by the node.

[0027] In yet another possible implementation manner of the first aspect, before receiving the first association request from the second node, the step further includes:

[0028] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0029] In the above method, when the number of associated nodes is less than or equal to a preset first association threshold, the association request from the second node can be received. The first association threshold can limit the amount of services that the node can provide. When the first association threshold is exceeded, the node can no longer receive or process association requests to avoid affecting the communication of other nodes associated with the node, thereby ensuring the stable operation of the services provided by the node.

[0030] In another possible implementation of the first aspect, the method further includes:

[0031] If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

[0032] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to indicate that the first node establishes an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0033] In another possible implementation of the first aspect, the method further includes:

[0034] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0035] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of verification failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node, thereby ensuring the stable operation of the services provided by the node.

[0036] In another possible implementation of the first aspect, if verification of the second identity information according to the shared key fails, after updating the first authentication failure counter, the method further includes:

[0037] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0038] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for many times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the node from establishing association with illegal attackers and improving the data security of the node.

[0039] In another possible implementation of the first aspect, the validity period of the first blacklist is a predefined or configured first duration.

[0040] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0041] In another possible implementation of the first aspect, the method further includes:

[0042] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0043] The above implementations illustrate factors related to the validity period of the first blacklist. On the one hand, the validity period of the first blacklist may be related to the number of times a second node joins the first blacklist. The more times a second node joins the first blacklist, the longer it stays in the first blacklist. Further, optionally, when the number of times it is added to the first blacklist exceeds a certain threshold, it may be permanently added to the first blacklist.

[0044] On the other hand, the validity period of the first blacklist may be related to the device type to which the second node belongs. Specifically, the second node may pre-acquire the device type of the second node and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the first node may also pre-define the blacklist validity period corresponding to the second node, which will not be repeated here. In another possible implementation of the first aspect, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0045] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication will not be performed, so as to avoid wasting node resources and affecting the normal association of other nodes.

[0046] In a second aspect, the embodiment of the present application further provides an association method, including:

[0047] Determining that the identity of the first node is credible, and sending a first association request to the first node;

[0048] Receiving a first authentication request from the first node, wherein the first authentication request includes first identity authentication information;

[0049] Verifying the first identity authentication information according to a shared key between the second node and the first node; wherein the shared key is a secret value shared between the first node and the second node;

[0050] If the verification of the first identity authentication information is successful, a first authentication response is sent to the first node, wherein the first authentication response includes second identity authentication information; wherein the second identity authentication information is generated according to the shared key.

[0051] In the embodiment of the present application, after confirming that the identity of the first node is credible, a first association request is sent to the first node. Then, based on the first identity authentication information in the first authentication request, the identity authentication information of the first node is verified by a shared key. After the verification is passed, the second identity authentication information is sent to the first node, and the second identity authentication information can be used by the first node to verify the identity of the second node. It can be seen that after confirming that the identity is credible, the identity authentication of both parties must be passed before the association can be performed, so that it is difficult for an attacker to bypass the identity authentication of the second node by modifying the identity such as the identification, thereby avoiding the second node from establishing an association with an illegal attacker and improving the data security of the node.

[0052] In a possible implementation manner of the second aspect, determining that the identity of the first node is credible includes:

[0053] Determining that the identifier of the first node is in a second whitelist;

[0054] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0055] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0056] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0057] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the nodes can be controlled not to send an association request to an untrusted first node, thereby avoiding the nodes from establishing association with illegal attackers and improving the data security of the nodes.

[0058] In yet another possible implementation of the second aspect, determining that the identity of the first node is credible includes:

[0059] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0060] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0061] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0062] In yet another possible implementation of the second aspect, the first authentication request further includes first integrity verification data, and the first integrity verification data is used to verify the message integrity of the first authentication request;

[0063] The method further comprises:

[0064] Determine that a message integrity check of the first authentication request passes.

[0065] It can be seen that after confirming that the identity of the first node is credible, in addition to identity authentication, it is also necessary to perform integrity verification on the message carrying the identity authentication information to prevent the content in the first authentication request from being tampered with by an attacker, thereby avoiding affecting the verification of the identity authentication information of the first node and ensuring the stable operation of the services provided by the node.

[0066] In yet another possible implementation manner of the second aspect, before determining that the identity of the first node is credible and sending the first association request to the first node, the process further includes:

[0067] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0068] In the above method, an association request can be sent to the first node only when the number of associated nodes is less than or equal to a preset second association threshold. The second threshold can limit the number of nodes that a node can associate with. When the second association threshold is exceeded, the node can no longer associate with other nodes, thereby avoiding affecting the communication of other nodes associated with the node and ensuring the stable operation of the service provided by the node.

[0069] In another possible implementation manner of the second aspect, the method further includes:

[0070] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0071] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the second node, the second node receives a first association response from the first node, and the association response is used to indicate that the first node establishes an association with the second node. Further, the first response message can inform the second node that the association has been successful and subsequent communication can be carried out.

[0072] In another possible implementation manner of the second aspect, the method further includes:

[0073] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0074] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the node.

[0075] In another possible implementation manner of the second aspect, the method further includes:

[0076] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0077] It can be seen that if the identity authentication information of the first node fails to be verified, the number of failed verifications of the first node is updated, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the first node's control over its association by modifying the identity such as the identifier, thereby preventing the node from establishing association with an illegal attacker and improving the data security of the node.

[0078] In another possible implementation of the second aspect, if the verification of the first identity authentication information fails, after updating the second authentication failure counter, the method further includes:

[0079] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0080] Adding the identifier of the first node to the second blacklist.

[0081] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification for multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node.

[0082] In yet another possible implementation of the second aspect, the validity period of the second blacklist is a predefined or configured second duration.

[0083] It can be seen that there is a predefined or configured second time period in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second time period can be 10 days, and when the identifier of a first node is added to the blacklist for 10 days, it can be removed from the blacklist.

[0084] In another possible implementation of the second aspect, if the verification of the first identity authentication information fails, after updating the second authentication failure counter, the method further includes:

[0085] determining that the value of the second authentication failure counter is less than a second threshold,

[0086] A second association request is sent to the first node.

[0087] It is understandable that during the authentication process, the authentication information verification may fail due to the loss or transmission error of certain parameters during the transmission process. Therefore, if the number of authentication failures for the first node has not exceeded the preset second threshold, an association request may be resent to the first node to request association with the node, thereby improving the robustness of the system and ensuring the stable operation of the services provided by the node.

[0088] In another possible implementation of the second aspect, if the verification of the first identity authentication information fails, after updating the second authentication failure counter, the method further includes:

[0089] Determining that the value of the second authentication failure counter is less than a second threshold;

[0090] Obtaining third confirmation indication information;

[0091] A second association request is sent to the first node.

[0092] It can be seen that before resending the second association request, confirmation indication information needs to be obtained. The third confirmation indication information can be indication information obtained according to the confirmation operation input by the user, and the confirmation operation can be a confirmation of the output prompt information. For example, a prompt information can be output to remind the user that the verification failed and the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0093] In another possible implementation manner of the second aspect, the method further includes:

[0094] If the time that the identifier of the first node is added to the second blacklist exceeds a second duration, the identifier of the first node is removed from the second blacklist, and the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist and the type of the first node.

[0095] The above implementations illustrate factors related to the validity period of the second blacklist. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a first node is added to the second blacklist, the longer it will stay in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a certain threshold, it may be permanently added to the second blacklist.

[0096] On the other hand, the validity period of the second blacklist may be related to the device type to which the first node belongs. Specifically, the first node may pre-acquire the device type of the first node and determine different validity periods of the second blacklist according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The validity period of the blacklist for high-risk devices is longer than that for low-risk devices. In addition, the second node can also pre-define the validity period of the blacklist corresponding to the first node, which will not be repeated here.

[0097] In yet another possible implementation of the second aspect, if the identity of the first node is not trustworthy, the step of sending the first association request to the first node is not performed.

[0098] It can be seen that if the identity of the first node is not credible, no identity authentication request will be sent to the first node to avoid wasting node resources.

[0099] In a third aspect, an embodiment of the present application further provides an association control device, including:

[0100] A communication unit, configured to receive a first association request from a second node;

[0101] a processing unit, configured to determine that the identity of the second node is credible, and send a first authentication request to the second node through the communication unit, wherein the first authentication request includes first identity authentication information, and the first identity authentication information is generated according to a shared key between the first node and the second node;

[0102] The communication unit is further configured to receive a first authentication response from the second node, wherein the first authentication response includes second identity authentication information;

[0103] The processing unit is further configured to verify the second identity authentication information according to the shared key;

[0104] The processing unit is further configured to update a first authentication failure counter if the authentication of the second identity authentication information fails, wherein the first authentication failure counter represents the number of authentication failures for the second node.

[0105] In the embodiment of the present application, after confirming that the identity of the second node is credible, the above-mentioned device verifies the identity of the second node according to the shared key with the second node. In this way, even if the attacker modifies the identity identifier and bypasses the step of the above-mentioned device determining that the identity is credible, it is still impossible to pass the above-mentioned device's identity verification because it is difficult to forge identity verification information, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0106] Furthermore, if the verification fails, the above device will update the number of verification failures, which can be used to subsequently determine whether the identity of the second node is credible, so that nodes that have failed multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, the above device can no longer process their association requests (such as sending authentication requests), thereby preventing the above device from crashing due to processing a large number of requests and ensuring normal service.

[0107] In a possible implementation manner of the third aspect, the processing unit is specifically configured to:

[0108] Determining that the identifier of the second node is in the first whitelist;

[0109] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0110] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0111] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0112] The above device controls the nodes that request association according to the blacklist or whitelist, so that there is no need to authenticate the untrusted second node. On the one hand, it can prevent the crash due to processing a large number of requests and ensure the normal operation of the service. On the other hand, since no association is established with nodes that have not been authenticated, the above device is prevented from establishing association with illegal attackers, thereby improving the data security of the above device.

[0113] In yet another possible implementation of the third aspect, the processing unit 702 is specifically configured to:

[0114] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0115] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0116] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0117] In yet another possible implementation of the third aspect, the first authentication response further includes second integrity verification data, where the second integrity verification data is used to verify the message integrity of the first authentication response;

[0118] The processing unit is specifically used for:

[0119] Determine that the message integrity check of the first authentication response passes.

[0120] It can be seen that after confirming that the identity of the second node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication response from being tampered with by an attacker, thereby avoiding affecting the verification of the identity authentication information of the second node and ensuring the stable operation of the services provided by the above-mentioned device.

[0121] In yet another possible implementation manner of the third aspect, the processing unit is further configured to:

[0122] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0123] It can be seen that the first association threshold is preset in the above device, and the association request from the second node can be received only when the number of associated nodes is less than or equal to the preset first association threshold. The first threshold can limit the bearing capacity of the service that the above device can provide. When the first association threshold is exceeded, the above device can no longer receive or process the association request, so as to avoid affecting the communication of other nodes associated with the above device, thereby ensuring the stable operation of the service provided by the above device.

[0124] In yet another possible implementation manner of the third aspect, the communication unit is further configured to:

[0125] If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

[0126] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to instruct the above device to establish an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0127] In yet another possible implementation manner of the third aspect, the processing unit is further configured to:

[0128] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0129] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of authentication failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node and ensure the stable operation of the services provided by the above device.

[0130] In yet another possible implementation manner of the third aspect, the processing unit is further configured to:

[0131] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0132] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for multiple times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0133] In yet another possible implementation of the third aspect, the validity period of the first blacklist is a predefined or configured first duration.

[0134] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0135] In yet another possible implementation manner of the third aspect, the processing unit is further configured to:

[0136] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0137] The above implementations illustrate factors related to the validity period of the first blacklist. On the one hand, the validity period of the first blacklist may be related to the number of times a second node joins the first blacklist. The more times a second node joins the first blacklist, the longer it stays in the first blacklist. Further, optionally, when the number of times it is added to the first blacklist exceeds a certain threshold, it may be permanently added to the first blacklist.

[0138] On the other hand, the validity period of the first blacklist may be related to the device type to which the second node belongs. Specifically, the second node may pre-acquire the device type of the second node and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the first node can also pre-define the blacklist validity period corresponding to the second node, which will not be repeated here. This application does not specifically limit the number of device types and can be designed according to specific scenarios.

[0139] In yet another possible implementation of the third aspect, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0140] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication steps will not be performed, so as to avoid wasting the resources of the above device and affecting the normal association of other nodes.

[0141] In a fourth aspect, an embodiment of the present application further provides an association device, including:

[0142] A processing unit determines that the identity of the first node is credible, and sends a first association request to the first node through a communication unit;

[0143] The communication unit is further configured to receive a first authentication request from the first node, wherein the first authentication request includes first identity authentication information;

[0144] The processing unit is further used to verify the first identity authentication information according to the shared key between the second node and the first node;

[0145] The communication unit is further configured to send a first authentication response to the first node if the verification of the first identity authentication information is successful, wherein the first authentication response includes second identity authentication information; wherein the second identity authentication information is generated based on the shared key.

[0146] In the embodiment of the present application, after confirming that the identity of the first node is credible, the above-mentioned device sends a first association request to the first node. Then, based on the first identity authentication information in the first authentication request, the identity authentication information of the first node is verified by a shared key. After the verification is passed, the second identity authentication information is sent to the first node, and the second identity authentication information can be used by the first node to verify the identity of the above-mentioned device. It can be seen that after confirming that the identity is credible, the identity authentication of both parties must be passed before the association can be carried out, so that it is difficult for an attacker to bypass the second node's identity authentication by modifying the identity such as the identification, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0147] In a possible implementation manner of the fourth aspect, the processing unit is specifically configured to:

[0148] Determining that the identifier of the first node is in a second whitelist;

[0149] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0150] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0151] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0152] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the above device can be controlled not to send an association request to an untrusted first node, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0153] In yet another possible implementation manner of the fourth aspect, the processing unit is specifically configured to:

[0154] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0155] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0156] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0157] In yet another possible implementation of the fourth aspect, the first authentication request further includes first integrity verification data, and the first integrity verification data is used to verify the message integrity of the first authentication request;

[0158] The processing unit is further used for:

[0159] Determine that a message integrity check of the first authentication request passes.

[0160] It can be seen that after confirming that the identity of the first node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication request from being tampered with by an attacker, thereby affecting the verification of the identity authentication information of the first node, thereby ensuring the stable operation of the services provided by the above-mentioned device.

[0161] In yet another possible implementation manner of the fourth aspect, the processing unit is further configured to:

[0162] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0163] It can be seen that the above device is preset with a second association threshold, and the association request can be sent to the first node only when the number of associated nodes is less than or equal to the preset second association threshold. The second threshold can limit the number of nodes that the above device can associate with, and when the second association threshold is exceeded, the above device can no longer associate with other nodes, so as to avoid affecting the communication of other nodes associated with the device, thereby ensuring the stable operation of the service provided by the above device.

[0164] In yet another possible implementation manner of the fourth aspect, the communication unit is further configured to:

[0165] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0166] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the second node, the above-mentioned device can receive a first association response from the first node, and the association response is used to indicate that the above-mentioned device has established an association with the second node. Further, the first response message can inform the above-mentioned device that the association has been successful and subsequent communication can be carried out.

[0167] In yet another possible implementation manner of the fourth aspect, the processing unit is further configured to:

[0168] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0169] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the above device.

[0170] In yet another possible implementation manner of the fourth aspect, the processing unit is further configured to:

[0171] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0172] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of times the identity of the first node has failed to be verified, and the number of times the identity of the node has failed can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the first node's association control over it by modifying the identity such as the identifier, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0173] In yet another possible implementation manner of the fourth aspect, the processing unit is further configured to:

[0174] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0175] Adding the identifier of the first node to the second blacklist.

[0176] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification for multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0177] In another possible implementation of the fourth aspect, the validity period of the second blacklist is a predefined or configured second duration.

[0178] It can be seen that there is a predefined or configured second duration in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second duration of the blacklist can be 10 days, and the identifier of a first node can be removed from the blacklist after being added to the blacklist for 10 days.

[0179] In yet another possible implementation of the fourth aspect, the processing unit is further configured to determine that the value of the second authentication failure counter is less than a second threshold;

[0180] The communication unit is further configured to send a second association request to the first node.

[0181] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of failed verifications of the first node, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the first node's association control over it by modifying the identity such as the identifier, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the node.

[0182] In yet another possible implementation of the fourth aspect, the processor is further configured to:

[0183] Determining that the value of the second authentication failure counter is less than a second threshold;

[0184] Obtaining third confirmation indication information;

[0185] A second association request is sent to the first node.

[0186] It can be seen that before resending the second association request, confirmation indication information needs to be obtained. The third confirmation indication information can be indication information obtained according to the confirmation operation input by the user, and the confirmation operation can be a confirmation of the output prompt information. For example, a prompt information can be output to remind the user that the verification failed and the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0187] In yet another possible implementation of the fourth aspect, the processor is further configured to:

[0188] If the time that the identifier of the first node is added to the second blacklist exceeds a second duration, the identifier of the first node is removed from the second blacklist, and the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist and the type of the first node.

[0189] The above implementations illustrate factors related to the validity period of the second blacklist. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a first node is added to the second blacklist, the longer it will stay in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a certain threshold, it may be permanently added to the second blacklist.

[0190] On the other hand, the validity period of the second blacklist may be related to the device type to which the first node belongs. Specifically, the first node may pre-acquire the device type of the first node and determine different validity periods of the second blacklist according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The validity period of the blacklist for high-risk devices is longer than that for low-risk devices. In addition, the second node can also pre-define the validity period of the blacklist corresponding to the first node, which will not be repeated here.

[0191] In yet another possible implementation of the fourth aspect, if the identity of the first node is not trustworthy, the step of sending the first association request to the first node is not performed.

[0192] It can be seen that if the identity of the first node is not credible, no identity authentication request will be sent to the first node to avoid wasting node resources.

[0193] In the fifth aspect, an embodiment of the present application also provides a communication device, which includes at least one processor and a communication interface, and the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the first aspect or any possible implementation method of the first aspect.

[0194] In a possible implementation manner of the fifth aspect, the at least one processor is configured to call a computer program stored in at least one memory to perform the following operations:

[0195] receiving a first association request from a second node via a communication interface;

[0196] Determining that the identity of the second node is credible, sending a first authentication request to the second node through a communication interface, wherein the first authentication request includes first identity authentication information, and the first identity authentication information is generated according to a shared key between the first node and the second node; wherein the shared key can be regarded as a first secret value shared between the first node and the second node;

[0197] receiving, through the communication interface, a first authentication response from the second node, wherein the first authentication response includes second identity authentication information;

[0198] verifying the second identity authentication information according to the shared key;

[0199] If the verification of the second identity authentication information fails, a first authentication failure counter is updated, where the first authentication failure counter represents the number of verification failures for the second node.

[0200] In the embodiment of the present application, after confirming that the identity of the second node is credible, the above-mentioned device verifies the identity of the second node according to the shared key with the second node. In this way, even if the attacker modifies the identity identifier and bypasses the step of the above-mentioned device determining that the identity is credible, it is still impossible to pass the above-mentioned device's identity verification because it is difficult to forge identity verification information, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the above-mentioned device.

[0201] Furthermore, if the verification fails, the above device will update the number of verification failures, which can be used to subsequently determine whether the identity of the second node is credible, so that nodes that have failed multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, the above device can no longer process their association requests (such as sending authentication requests), thereby preventing the above device from crashing due to processing a large number of requests and ensuring normal service.

[0202] In yet another possible implementation of the fifth aspect, the processor is specifically configured to:

[0203] Determining that the identifier of the second node is in the first whitelist;

[0204] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0205] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0206] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0207] The above device controls the nodes that request association according to the blacklist or whitelist, so that there is no need to authenticate the untrusted second node. On the one hand, it can prevent the crash due to processing a large number of requests and ensure the normal operation of the service. On the other hand, since no association is established with nodes that have not been authenticated, the above device is prevented from establishing association with illegal attackers, thereby improving the data security of the above device.

[0208] In yet another possible implementation of the fifth aspect, the processor is specifically configured to:

[0209] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0210] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0211] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0212] In yet another possible implementation of the fifth aspect, the first authentication response further includes second integrity verification data, where the second integrity verification data is used to verify the message integrity of the first authentication response;

[0213] The processor is further configured to determine whether a message integrity check of the first authentication response passes.

[0214] It can be seen that after confirming that the identity of the second node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication response from being tampered with by an attacker, thereby avoiding affecting the verification of the identity authentication information of the second node and ensuring the stable operation of the services provided by the above-mentioned device.

[0215] In yet another possible implementation of the fifth aspect, the processor is further configured to:

[0216] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0217] It can be seen that the first association threshold is preset in the above device, and the association request from the second node can be received only when the number of associated nodes is less than or equal to the preset first association threshold. The first threshold can limit the amount of service that can be provided by the node, and when the first association threshold is exceeded, the above device can no longer receive or process the association request, so as to avoid affecting the communication of other nodes associated with the above device, thereby ensuring the stable operation of the service provided by the above device.

[0218] In yet another possible implementation of the fifth aspect, the processor is further configured to:

[0219] If the verification of the second identity authentication information is successful, a first association response is sent to the second node through the communication interface, where the first association response is used to instruct the first node to establish an association with the second node.

[0220] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to instruct the above device to establish an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0221] In yet another possible implementation of the fifth aspect, the processor is further configured to:

[0222] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0223] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of authentication failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node, thereby ensuring the stable operation of the services provided by the above device.

[0224] In yet another possible implementation of the fifth aspect, the processor is further configured to:

[0225] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0226] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for multiple times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the above-mentioned device from establishing association with illegal attackers and improving the data security of the above-mentioned device.

[0227] In another possible implementation of the fifth aspect, the validity period of the first blacklist is a predefined or configured first duration.

[0228] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0229] In yet another possible implementation of the fifth aspect, the processor is further configured to:

[0230] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0231] The above implementations illustrate factors related to the validity period of the blacklist. On the one hand, the validity period of the blacklist may be related to the number of times the second node is added to the blacklist. The more times a second node is added to the blacklist, the longer it will be in the blacklist. Further, optionally, when the number of times it is added to the blacklist exceeds a certain threshold, it may be permanently added to the blacklist.

[0232] On the other hand, the validity period of the blacklist may be related to the device type to which the second node belongs. Specifically, the second node may pre-acquire the device type of the second node and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The blacklist validity period of a high-risk device is longer than that of a low-risk device. In addition, the above-mentioned device can also pre-define the blacklist validity period corresponding to the second node, which will not be repeated here.

[0233] In another possible implementation of the fifth aspect, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0234] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication steps will not be performed, so as to avoid wasting the resources of the above device and affecting the normal association of other nodes.

[0235] In the sixth aspect, an embodiment of the present application also provides a communication device, which includes at least one processor and a communication interface, and the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the first aspect or any possible implementation method of the first aspect.

[0236] In a possible implementation manner of the sixth aspect, the at least one processor is configured to call a computer program stored in at least one memory to perform the following operations:

[0237] Determining that the identity of the first node is credible, and sending a first association request to the first node;

[0238] Receiving a first authentication request from the first node, wherein the first authentication request includes first identity authentication information;

[0239] Verifying the first identity authentication information according to a shared key between the second node and the first node; wherein the shared key is a secret value shared between the first node and the second node;

[0240] If the verification of the first identity authentication information is successful, a first authentication response is sent to the first node, wherein the first authentication response includes second identity authentication information; wherein the second identity authentication information is generated according to the shared key.

[0241] In the embodiment of the present application, after confirming that the identity of the first node is credible, the above-mentioned device sends a first association request to the first node. Then, based on the first identity authentication information in the first authentication request, the identity authentication information of the first node is verified by a shared key. After the verification is passed, the second identity authentication information is sent to the first node, and the second identity authentication information can be used by the first node to verify the identity of the above-mentioned device. It can be seen that after confirming that the identity is credible, the identity authentication of both parties must be passed before association can be performed, so that it is difficult for an attacker to bypass the identity authentication of the above-mentioned device by modifying the identity such as the identification, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker, and improving the data security of the above-mentioned device.

[0242] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0243] Determining that the identifier of the first node is in a second whitelist;

[0244] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0245] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0246] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0247] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the above device can be controlled not to send an association request to an untrusted first node, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0248] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0249] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0250] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0251] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0252] In yet another possible implementation of the sixth aspect, the first authentication request further includes first integrity verification data, and the first integrity verification data is used to verify the message integrity of the first authentication request;

[0253] The processor is further configured to determine whether a message integrity check of the first authentication request passes.

[0254] It can be seen that after confirming that the identity of the first node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication request from being tampered with by an attacker, thereby affecting the verification of the identity authentication information of the first node, thereby ensuring the stable operation of the services provided by the above-mentioned device.

[0255] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0256] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0257] It can be seen that the above device is preset with a second association threshold, and the association request can be sent to the first node only when the number of associated nodes is less than or equal to the preset second association threshold. The second threshold can limit the number of nodes that the above device can associate with, and when the second association threshold is exceeded, the above device can no longer associate with other nodes, so as to avoid affecting the communication of other nodes associated with the above device, thereby ensuring the stable operation of the service provided by the above device.

[0258] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0259] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0260] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the above-mentioned device, the above-mentioned device receives a first association response from the first node, and the association response is used to indicate that the first node establishes an association with the second node. Further, the first response message can inform the above-mentioned device that the association has been successful and subsequent communication can be carried out.

[0261] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0262] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0263] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the above device.

[0264] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0265] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0266] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of times the identity of the first node has failed to be verified, and the number of times the identity of the node has failed can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the association control of the above device by modifying the identity such as the identifier, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0267] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0268] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0269] Adding the identifier of the first node to the second blacklist.

[0270] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the above-mentioned device.

[0271] In another possible implementation of the sixth aspect, the validity period of the second blacklist is a predefined or configured second duration.

[0272] It can be seen that there is a predefined or configured second duration in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second duration of the blacklist can be 10 days, and the identifier of a first node can be removed from the blacklist after being added to the blacklist for 10 days.

[0273] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0274] determining that the value of the second authentication failure counter is less than a second threshold,

[0275] A second association request is sent to the first node.

[0276] It is understandable that during the authentication process, the authentication information verification may fail due to the loss or transmission error of certain parameters during the transmission process. Therefore, if the number of authentication failures for the first node has not exceeded the preset second threshold, an association request may be resent to the first node to request association with the first node, thereby improving the robustness of the system and ensuring the stable operation of the services provided by the above-mentioned device.

[0277] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0278] Determining that the value of the second authentication failure counter is less than a second threshold;

[0279] Obtaining third confirmation indication information;

[0280] A second association request is sent to the first node.

[0281] It can be seen that before resending the second association request, confirmation indication information needs to be obtained. The third confirmation indication information can be indication information obtained according to the confirmation operation input by the user, and the confirmation operation can be a confirmation of the output prompt information. For example, a prompt information can be output to remind the user that the verification failed and the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0282] In yet another possible implementation of the sixth aspect, the processor is further configured to:

[0283] If the time that the identifier of the first node is added to the second blacklist exceeds a second duration, the identifier of the first node is removed from the second blacklist, and the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist and the type of the first node.

[0284] The above implementations illustrate factors related to the validity period of the second blacklist. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a first node is added to the second blacklist, the longer it will stay in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a certain threshold, it may be permanently added to the second blacklist.

[0285] On the other hand, the validity period of the second blacklist may be related to the device type to which the first node belongs. Specifically, the first node may pre-acquire the device type of the first node and determine different validity periods of the second blacklist according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The validity period of the blacklist for high-risk devices is longer than that for low-risk devices. In addition, the above-mentioned device can also pre-define the validity period of the blacklist corresponding to the first node, which will not be repeated here.

[0286] In another possible implementation of the sixth aspect, if the identity of the first node is not trustworthy, the step of sending the first association request to the first node is not performed.

[0287] It can be seen that if the identity of the first node is not credible, no identity authentication request will be sent to the first node to avoid wasting node resources.

[0288] In a seventh aspect, an embodiment of the present application further provides an association control method, the method comprising:

[0289] receiving a first association request from a second node;

[0290] Determining that the identity of the second node is credible, sending a first authentication request to the second node, where the first authentication request includes first integrity verification data;

[0291] receiving a first authentication response from the second node, wherein the first authentication response includes second integrity verification data;

[0292] verifying the message integrity of the first authentication response according to the second integrity verification data;

[0293] If the verification of the message integrity of the first authentication response fails, a first authentication failure counter is updated, where the first authentication failure counter represents the number of authentication failures for the second node.

[0294] In the embodiment of the present application, after confirming that the identity of the second node is credible, the authentication response message from the second node needs to be verified for message integrity before association. If the message integrity verification fails, the number of verification failures is updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, thereby preventing attackers from tampering with data in the authentication process (such as identity authentication information), thereby avoiding the node from establishing association with illegal attackers, and improving the data security of the node.

[0295] In a possible implementation manner of the seventh aspect, determining that the identity of the second node is credible includes:

[0296] Determining that the identifier of the second node is in the first whitelist;

[0297] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0298] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0299] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0300] In the above method, the node requesting association can be controlled according to the blacklist or whitelist, thereby eliminating the need to authenticate the identity of the untrusted second node, thereby avoiding the node from establishing association with an illegal attacker and improving the data security of the node.

[0301] In a possible implementation manner of the seventh aspect, determining that the identity of the second node is credible includes:

[0302] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0303] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0304] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0305] In yet another possible implementation manner of the seventh aspect, before the receiving the first association request from the second node, the step further includes:

[0306] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0307] It can be seen that a first association threshold is preset in the node, and the association request from the second node can be received only when the number of associated nodes is less than or equal to the preset first association threshold. The first threshold can limit the amount of services that the node can provide. When the first association threshold is exceeded, the node can no longer receive or process association requests, avoiding affecting the communication of other nodes associated with the node, and ensuring the stable operation of the services provided by the node.

[0308] In yet another possible implementation of the seventh aspect, the first authentication response further includes second identity authentication information, and the method further includes:

[0309] If the integrity of the first authentication response is verified, verifying the second identity authentication information according to the shared key between the second node and the second node;

[0310] If the verification of the second identity authentication information fails, a first authentication failure counter is updated, where the first authentication failure counter represents the number of verification failures for the second node.

[0311] It can be seen that after confirming that the identity of the second node is credible, if the integrity verification passes, the identity of the second node is verified based on the shared key with the second node. If the verification fails, the number of verification failures is updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, so that nodes that fail multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, their association requests can no longer be processed (such as sending authentication requests), thereby preventing the node from crashing due to processing a large number of requests and ensuring the normal operation of the service.

[0312] In yet another possible implementation manner of the seventh aspect, the method further includes:

[0313] If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

[0314] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to indicate that the first node establishes an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0315] In yet another possible implementation manner of the seventh aspect, the method further includes:

[0316] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0317] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of verification failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node, thereby ensuring the stable operation of the services provided by the node.

[0318] In yet another possible implementation manner of the seventh aspect, the method further includes:

[0319] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0320] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for many times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the node from establishing association with illegal attackers and improving the data security of the node.

[0321] In another possible implementation of the seventh aspect, the validity period of the first blacklist is a predefined or configured first duration.

[0322] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0323] In yet another possible implementation manner of the seventh aspect, the method further includes:

[0324] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0325] The above implementations illustrate factors related to the validity period of the first blacklist. On the one hand, the validity period of the first blacklist may be related to the number of times a second node joins the first blacklist. The more times a second node joins the first blacklist, the longer it will stay in the first blacklist. Further, optionally, when the number of times it is added to the blacklist exceeds a certain threshold, it may be permanently added to the blacklist.

[0326] On the other hand, the validity period of the first blacklist may be related to the device type to which the second node belongs. Specifically, the second node may pre-acquire the device type of the second node and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the first node can also pre-define the blacklist validity period corresponding to the second node, which will not be repeated here. In another possible implementation of the seventh aspect, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0327] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication steps will not be performed, so as to avoid wasting node resources and affecting the normal association of other nodes.

[0328] In an eighth aspect, an embodiment of the present application further provides an association method, including:

[0329] Determining that the identity of the first node is credible, and sending a first association request to the first node;

[0330] Receiving a first authentication request from the first node, wherein the first authentication request includes first integrity verification data;

[0331] verifying the message integrity of the first authentication request according to the first integrity verification data;

[0332] If the verification of the message integrity of the first authentication request passes, a first authentication response is sent to the first node, where the first authentication response includes second integrity verification data.

[0333] In an embodiment of the present application, after confirming that the identity of the second node is credible, the first node needs to be authenticated before communication (for example, through identity verification information, etc.). In order to prevent attackers from tampering with data in the authentication process, the first authentication request needs to be verified for message integrity. If the message integrity verification is passed, association with the first node is allowed, thereby preventing attackers from tampering with the message content, thereby avoiding the node from establishing association with illegal attackers, and improving the data security of the node.

[0334] In a possible implementation manner of the eighth aspect, determining that the identity of the first node is credible includes:

[0335] Determining that the identifier of the first node is in a second whitelist;

[0336] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0337] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0338] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0339] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the nodes can be controlled not to send an association request to an untrusted first node, thereby avoiding the nodes from establishing association with illegal attackers and improving the data security of the nodes.

[0340] In a possible implementation manner of the eighth aspect, determining that the identity of the first node is credible includes:

[0341] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0342] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0343] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0344] In yet another possible implementation manner of the eighth aspect, before determining that the identity of the first node is credible and sending the first association request to the first node, further comprising:

[0345] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0346] It can be seen that the node is preset with a second association threshold, and only when the number of associated nodes is less than or equal to the preset second association threshold can an association request be sent to the first node. The second threshold can limit the number of nodes that the node can associate with, and when the second association threshold is exceeded, the node can no longer associate with other nodes, so as to avoid affecting the communication of other nodes associated with the node, thereby ensuring the stable operation of the services provided by the node.

[0347] In yet another possible implementation manner of the eighth aspect, the method further includes:

[0348] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0349] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the second node, the second node receives a first association response from the first node, and the association response is used to indicate that the first node establishes an association with the second node. Further, the first response message can inform the second node that the association has been successful and subsequent communication can be carried out.

[0350] In yet another possible implementation manner of the eighth aspect, the method further includes:

[0351] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0352] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the node.

[0353] In yet another possible implementation manner of the eighth aspect, the method further includes:

[0354] If the verification of the message integrity of the first authentication response fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of authentication failures for the first node.

[0355] Generally speaking, if the message integrity verification of the first authentication response fails, it means that the first authentication response message is no longer complete or has been modified by an attacker. Therefore, the number of failed verifications of the identity of the first node is updated. The number of failed verifications can be used to subsequently determine whether the identity of the first node is credible.

[0356] In yet another possible implementation manner of the eighth aspect, the first authentication request message further includes first identity authentication information, and if verification of message integrity of the first authentication response is passed, sending the first authentication response to the first node includes:

[0357] If the message integrity verification of the first authentication response passes, verifying the first identity authentication information according to the shared key between the first node and the first node;

[0358] If the verification of the first identity authentication information is successful, the first authentication response is sent to the first node.

[0359] It can be seen that after confirming that the identity of the first node is credible, if the integrity verification passes, the identity of the first node is verified based on the shared key with the first node. This makes it difficult for attackers to bypass the association control by modifying the identity such as the identifier, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node.

[0360] In yet another possible implementation manner of the eighth aspect, the method further includes:

[0361] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0362] It can be seen that if the identity authentication information of the first node fails to be verified, the number of failed verifications of the first node is updated, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible, so that nodes that have failed verifications multiple times can no longer be determined to be credible. For nodes that are not confirmed to be credible, association requests can no longer be sent to them, thereby ensuring that the services provided by the nodes are normal.

[0363] In yet another possible implementation manner of the eighth aspect, the method further includes:

[0364] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0365] Adding the identifier of the first node to the second blacklist.

[0366] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification for multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node.

[0367] In another possible implementation of the eighth aspect, the validity period of the second blacklist is a predefined or configured second duration.

[0368] It can be seen that there is a predefined or configured second duration in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second duration of the blacklist can be 10 days, and the identifier of a first node can be removed from the blacklist after being added to the blacklist for 10 days.

[0369] In yet another possible implementation of the eighth aspect, if the verification of the first identity authentication information fails, after updating the second authentication failure counter, the method further includes:

[0370] determining that the value of the second authentication failure counter is less than a second threshold,

[0371] A second association request is sent to the first node.

[0372] It is understandable that during the authentication process, the authentication information verification may fail due to the loss or transmission error of certain parameters during the transmission process. Therefore, if the number of authentication failures for the first node has not exceeded the preset second threshold, an association request may be resent to the first node to request association with the node, thereby improving the robustness of the system and ensuring the stable operation of the services provided by the node.

[0373] In yet another possible implementation of the eighth aspect, if the verification of the first identity authentication information fails, after updating the second authentication failure counter, the method further includes:

[0374] Determining that the value of the second authentication failure counter is less than a second threshold;

[0375] Obtaining third confirmation indication information;

[0376] A second association request is sent to the first node.

[0377] It can be seen that before resending the second association request, confirmation indication information needs to be obtained. The third confirmation indication information can be indication information obtained according to the confirmation operation input by the user, and the confirmation operation can be a confirmation of the output prompt information. For example, a prompt information can be output to remind the user that the verification failed and the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0378] In yet another possible implementation manner of the eighth aspect, the method further includes:

[0379] If the time that the identifier of the first node is added to the second blacklist exceeds a second duration, the identifier of the first node is removed from the second blacklist, and the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist and the type of the first node.

[0380] The above implementations illustrate factors related to the validity period of the second blacklist. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a first node is added to the second blacklist, the longer it will stay in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a certain threshold, it may be permanently added to the second blacklist.

[0381] On the other hand, the validity period of the second blacklist may be related to the device type to which the first node belongs. Specifically, the first node may pre-acquire the device type of the first node and determine different second blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the second node can also pre-define the blacklist validity period corresponding to the first node, which will not be repeated here. In another possible implementation of the eighth aspect, if the identity of the first node is not trustworthy, the step of sending the first association request to the first node is not performed.

[0382] It can be seen that if the identity of the first node is not credible, no identity authentication request will be sent to the first node to avoid wasting node resources.

[0383] In a ninth aspect, an embodiment of the present application further provides an association control device, including:

[0384] A communication unit, configured to receive a first association request from a second node;

[0385] a processing unit, configured to determine that the identity of the second node is credible, and send a first authentication request to the second node through the communication unit, wherein the first authentication request includes first integrity verification data;

[0386] The communication unit is further configured to receive a first authentication response from the second node, wherein the first authentication response includes second integrity check data;

[0387] The processing unit is further configured to verify the message integrity of the first authentication response according to the second integrity verification data;

[0388] The processing unit is further configured to update a first authentication failure counter if verification of the message integrity of the first authentication response fails, wherein the first authentication failure counter represents the number of authentication failures for the second node.

[0389] In the embodiment of the present application, after confirming that the identity of the second node is credible, the above-mentioned device also needs to perform message integrity verification on the message from the second node before association. If the message integrity verification fails, the number of verification failures is updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, thereby preventing attackers from tampering with data in the authentication process (such as identity authentication information), thereby avoiding the above-mentioned device from establishing association with illegal attackers, and improving the data security of the above-mentioned device.

[0390] In a possible implementation manner of the ninth aspect, the processing unit is specifically configured to:

[0391] Determining that the identifier of the second node is in the first whitelist;

[0392] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0393] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0394] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0395] The above device controls the node requesting association according to the blacklist or whitelist, thereby eliminating the need to authenticate the identity of the untrustworthy second node, avoiding the node from establishing association with an illegal attacker, and improving the data security of the node.

[0396] In a possible implementation manner of the ninth aspect, the processing unit is specifically configured to:

[0397] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0398] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0399] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0400] In yet another possible implementation manner of the ninth aspect, the processing unit is further configured to:

[0401] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0402] It can be seen that the first association threshold is preset in the above device, and the association request from the second node can be received only when the number of associated nodes is less than or equal to the preset first association threshold. The first threshold can limit the bearing capacity of the service that the above device can provide. When the first association threshold is exceeded, the above device can no longer receive or process the association request, so as to avoid affecting the communication of other nodes associated with the above device, thereby ensuring the stable operation of the service provided by the above device.

[0403] In yet another possible implementation manner of the ninth aspect, the processing unit is further configured to:

[0404] If the integrity of the first authentication response is verified, verifying the second identity authentication information according to the shared key between the second node and the second node;

[0405] If the verification of the second identity authentication information fails, a first authentication failure counter is updated, where the first authentication failure counter represents the number of verification failures for the second node.

[0406] It can be seen that after the above device confirms that the identity of the second node is credible, if the integrity verification passes, the identity of the second node is verified according to the shared key with the second node. If the verification fails, the number of verification failures is updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, so that nodes that fail to pass verification multiple times can no longer be determined as credible. For nodes that are not confirmed as credible, their association requests can no longer be processed (such as sending authentication requests), thereby preventing the node from crashing due to processing a large number of requests and ensuring the normal operation of the service.

[0407] In yet another possible implementation manner of the ninth aspect, the communication unit is further configured to:

[0408] If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

[0409] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to instruct the above device to establish an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0410] In yet another possible implementation manner of the ninth aspect, the processing unit is further configured to:

[0411] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0412] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of authentication failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node and ensure the stable operation of the services provided by the above device.

[0413] In yet another possible implementation manner of the ninth aspect, the processing unit is further configured to:

[0414] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0415] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for multiple times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0416] In another possible implementation of the ninth aspect, the validity period of the first blacklist is a predefined or configured first duration.

[0417] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0418] In yet another possible implementation manner of the ninth aspect, the processing unit is further configured to:

[0419] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0420] The above implementations illustrate factors related to the validity period of the first blacklist. On the one hand, the validity period of the first blacklist may be related to the number of times a second node joins the first blacklist. The more times a second node joins the first blacklist, the longer it stays in the first blacklist. Further, optionally, when the number of times it is added to the first blacklist exceeds a certain threshold, it may be permanently added to the first blacklist.

[0421] On the other hand, the validity period of the first blacklist may be related to the device type to which the second node belongs. Specifically, the second node may obtain the device type of the second node in advance and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The validity period of the blacklist for high-risk devices is longer than that for low-risk devices. In addition, the first node can also pre-define the validity period of the blacklist corresponding to the second node, which will not be repeated here.

[0422] In another possible implementation of the ninth aspect, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0423] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication steps will not be performed, so as to avoid wasting the resources of the above device and affecting the normal association of other nodes.

[0424] In a tenth aspect, an embodiment of the present application further provides an association device, including:

[0425] A processing unit, configured to determine that the identity of the first node is credible, and send a first association request to the first node through a communication unit;

[0426] The communication unit is further configured to receive a first authentication request from the first node, wherein the first authentication request includes first identity authentication information and first integrity check data;

[0427] The processing unit is further configured to verify the message integrity of the first authentication request according to the first integrity verification data;

[0428] The communication unit is further configured to send a first authentication response to the first node if the verification of the message integrity of the first authentication request is passed, wherein the first authentication response includes second integrity verification data.

[0429] In an embodiment of the present application, after confirming that the identity of the second node is credible, the above-mentioned device also needs to authenticate the first node before communicating (for example, through identity verification information, etc.). In order to prevent attackers from tampering with data in the authentication process, it is necessary to first perform message integrity verification on the first authentication request. If the message integrity verification passes, it is allowed to associate with the first node, thereby preventing attackers from tampering with the message content, thereby avoiding the node from establishing an association with an illegal attacker, and improving the data security of the node.

[0430] In a possible implementation manner of the tenth aspect, the processing unit is specifically configured to:

[0431] Determining that the identifier of the first node is in a second whitelist;

[0432] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0433] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0434] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0435] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the above device can be controlled not to send an association request to an untrusted first node, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0436] In a possible implementation manner of the tenth aspect, the processing unit is specifically configured to:

[0437] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0438] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0439] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0440] In yet another possible implementation manner of the tenth aspect, the processing unit is further configured to:

[0441] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0442] It can be seen that the above device is preset with a second association threshold, and the association request can be sent to the first node only when the number of associated nodes is less than or equal to the preset second association threshold. The second threshold can limit the number of nodes that the above device can associate with, and when the second association threshold is exceeded, the above device can no longer associate with other nodes, so as to avoid affecting the communication of other nodes associated with the device, thereby ensuring the stable operation of the service provided by the above device.

[0443] In yet another possible implementation manner of the tenth aspect, the communication unit is further configured to:

[0444] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0445] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the second node, the above-mentioned device can receive a first association response from the first node, and the association response is used to indicate that the above-mentioned device has established an association with the second node. Further, the first response message can inform the above-mentioned device that the association has been successful and subsequent communication can be carried out.

[0446] In yet another possible implementation manner of the tenth aspect, the processing unit is further configured to:

[0447] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0448] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the above device.

[0449] In yet another possible implementation manner of the tenth aspect, the processing unit is further configured to:

[0450] If the verification of the message integrity of the first authentication response fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of authentication failures for the first node.

[0451] Generally speaking, if the message integrity verification of the first authentication response fails, it means that the first authentication response message is no longer complete or has been modified by an attacker. Therefore, the number of verification failures for the first node is updated, and the number of verification failures can be used to subsequently determine whether the identity of the first node is credible.

[0452] In another possible implementation of the tenth aspect, the first authentication request message further includes first identity authentication information, and the processing unit is further configured to verify the first identity authentication information according to a shared key between the first node and the first authentication response if the message integrity verification of the first authentication response passes;

[0453] The communication unit is further configured to send the first authentication response to the first node if the verification of the first identity authentication information is successful.

[0454] It can be seen that after confirming that the identity of the first node is credible, if the integrity verification passes, the identity of the first node is verified based on the shared key with the first node. This makes it difficult for an attacker to bypass the association control of the above device by modifying the identity such as the identifier, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node.

[0455] In yet another possible implementation manner of the tenth aspect, the processing unit is further configured to:

[0456] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0457] It can be seen that if the identity authentication information of the first node fails to be verified, the above-mentioned device updates the number of times the identity of the first node has failed to be verified, and the number of times the identity of the first node has failed can be used to subsequently determine whether the identity of the node is credible, so that the node that has failed multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, association requests can no longer be sent to them, thereby ensuring that the services provided by the nodes are carried out normally. In another possible implementation of the tenth aspect, the processing unit is also used to:

[0458] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0459] Adding the identifier of the first node to the second blacklist.

[0460] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification for multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0461] In another possible implementation of the tenth aspect, the validity period of the second blacklist is a predefined or configured second duration.

[0462] It can be seen that there is a predefined or configured second duration in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second duration of the blacklist can be 10 days, and the identifier of a first node can be removed from the blacklist after being added to the blacklist for 10 days.

[0463] In yet another possible implementation of the tenth aspect, the processing unit is further configured to determine that the value of the second authentication failure counter is less than a second threshold;

[0464] The communication unit is further configured to send a second association request to the first node.

[0465] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of failed verifications of the first node, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the first node's association control over it by modifying the identity such as the identifier, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the node.

[0466] In yet another possible implementation manner of the tenth aspect, the processing unit is further configured to:

[0467] Determining that the value of the second authentication failure counter is less than a second threshold;

[0468] Obtaining third confirmation indication information;

[0469] A second association request is sent to the first node.

[0470] It can be seen that before resending the second association request, confirmation indication information needs to be obtained. The third confirmation indication information can be indication information obtained according to the confirmation operation input by the user, and the confirmation operation can be a confirmation of the output prompt information. For example, a prompt information can be output to remind the user that the verification failed and the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0471] In yet another possible implementation manner of the tenth aspect, the processing unit is further configured to:

[0472] If the time that the first node's identifier is added to the second blacklist exceeds a second duration, the first node's identifier is removed from the second blacklist. The second duration is related to the number of times the first node's identifier is added to the second blacklist and the type of the first node.

[0473] The above implementations illustrate factors related to the validity period of the second blacklist. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a first node is added to the second blacklist, the longer it will stay in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a certain threshold, it may be permanently added to the second blacklist.

[0474] On the other hand, the validity period of the second blacklist may be related to the device type to which the first node belongs. Specifically, the first node may pre-acquire the device type of the first node and determine different second blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the second node can also pre-define the blacklist validity period corresponding to the first node, which will not be repeated here. In another possible implementation of the tenth aspect, if the identity of the first node is not trustworthy, the step of sending the first association request to the first node is not performed.

[0475] It can be seen that if the identity of the first node is not credible, no identity authentication request will be sent to the first node to avoid wasting node resources.

[0476] In the eleventh aspect, an embodiment of the present application also provides a communication device, which includes at least one processor and a communication interface, and the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the seventh aspect or any possible implementation method of the seventh aspect.

[0477] In the twelfth aspect, an embodiment of the present application also provides a communication device, which includes at least one processor and a communication interface, and the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the eighth aspect or any possible implementation method of the eighth aspect.

[0478] In the thirteenth aspect, an embodiment of the present application also provides a communication system, which includes a first node and a second node, wherein the first node is the device described in the third aspect or any possible implementation of the third aspect, or the fifth aspect or any possible implementation of the fifth aspect, and the second node is the device described in the fourth aspect or any possible implementation of the fourth aspect, or the sixth aspect or any possible implementation of the sixth aspect.

[0479] In the fourteenth aspect, an embodiment of the present application also provides a communication system, which includes a first node and a second node, wherein the first node is the ninth aspect or any possible implementation of the ninth aspect, or the device described in the eleventh aspect, and the second node is the tenth aspect or any possible implementation of the tenth aspect, or the device described in the twelfth aspect.

[0480] In the fifteenth aspect, an embodiment of the present application discloses a computer-readable storage medium, in which a computer program is stored. When the computer program runs on one or more processors, the method described in the first aspect or any possible implementation of the first aspect is executed, or the method described in the second aspect or any possible implementation of the second aspect is executed, or the method described in the seventh aspect or any possible implementation of the seventh aspect is executed, or the method described in the eighth aspect or any possible implementation of the eighth aspect is executed.

[0481] In the sixteenth aspect, an embodiment of the present application discloses a chip system, which includes at least one processor, a memory and an interface circuit, wherein the interface circuit is used to provide information input / output for the at least one processor, and the memory stores a computer program. When the computer program runs on one or more processors, it executes the method described in the first aspect or any possible implementation of the first aspect, or executes the method described in the second aspect or any possible implementation of the second aspect, or executes the method described in the seventh aspect or any possible implementation of the seventh aspect, or executes the method described in the eighth aspect or any possible implementation of the eighth aspect.

[0482] In the seventeenth aspect, an embodiment of the present application discloses a vehicle, wherein the vehicle includes a first node (e.g., a car cockpit domain controller CDC), wherein the first node is the device described in the third aspect or any possible implementation of the third aspect, or the fifth aspect or any possible implementation of the fifth aspect. Further, the vehicle also includes a second node (e.g., at least one of the modules such as a camera, a screen, a microphone, an audio system, a radar, an electronic key, a keyless entry or a start system controller), and the second node is the device described in the fourth aspect or any possible implementation of the fourth aspect, or the sixth aspect or any possible implementation of the sixth aspect.

[0483] In the eighteenth aspect, an embodiment of the present application discloses a vehicle, wherein the vehicle includes a first node (e.g., a car cockpit domain controller CDC), wherein the first node is the ninth aspect or any possible implementation of the ninth aspect, or the device described in the eleventh aspect. Further, the vehicle also includes a second node (e.g., at least one of a camera, a screen, a microphone, an audio system controller, a radar, an electronic key, a keyless entry or start system controller, etc.), wherein the second node is the tenth aspect or any possible implementation of the tenth aspect, or the device described in the twelfth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0484] The following is an introduction to the drawings used in the embodiments of the present application.

[0485] Figure 1 It is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application;

[0486] Figure 2 This is a schematic diagram of a usage scenario of an association control method provided in an embodiment of the present application;

[0487] Figure 3 It is a flowchart of an association control method provided in an embodiment of the present application;

[0488] Figure 4 This is a schematic diagram of a blacklist and a whitelist provided in an embodiment of the present application;

[0489] Figure 5 It is a flowchart of another association control method provided in an embodiment of the present application;

[0490] Figure 6 It is a flowchart of another association control method provided in an embodiment of the present application;

[0491] Figure 7 is a structural schematic diagram of another association control device provided in an embodiment of the present application;

[0492] Figure 8 It is a structural schematic diagram of another association device provided in an embodiment of the present application;

[0493] Fig. 9 is a structural diagram of a communication device provided in an embodiment of the present application;

[0494] Fig.10 is a structural diagram of another communication device provided in an embodiment of the present application;

[0495] Fig.11 is a structural schematic diagram of another association control device provided in an embodiment of the present application;

[0496] Fig.12 It is a structural schematic diagram of another association device provided in an embodiment of the present application;

[0497] Fig.13 is a structural diagram of another communication device provided in an embodiment of the present application;

[0498] Fig.14 It is a structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0499] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. It should be noted that in the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs, and the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0500] The following is a brief introduction to the relevant technologies and professional terms involved in this application to facilitate understanding.

[0501] 1. Node

[0502] A node is an electronic device that has the ability to send and receive data. For example, a node can be a car cockpit domain device, or a module in a car cockpit device (such as a cockpit domain controller (CDC), camera, screen, microphone, audio, electronic key, keyless entry or start system controller, etc.). In the specific implementation process, a node can be a data transfer device, such as a router, a repeater, a bridge or a switch, or a terminal device, such as various types of user equipment (UE), mobile phones, tablet computers (pad), desktop computers, headphones, speakers, etc. It can also include machine intelligence devices such as self-driving equipment, transportation safety equipment, virtual reality (VR) terminal equipment, augmented reality (AR) terminal equipment, machine type communication (MTC) equipment, industrial control equipment, remote medical equipment, smart grid equipment, smart city equipment, and wearable devices (such as smart watches, smart bracelets, pedometers, etc.), etc. In some technical scenarios, the name of a device with similar data transceiver capabilities may not be called a node, but for the convenience of description, electronic devices with data transceiver capabilities are collectively referred to as nodes in the embodiments of the present application.

[0503] 2. Shared key (SK)

[0504] During the communication process, data is transmitted between communication nodes. If the data needs to be kept confidential, it needs to be encrypted with a key. The shared key is the same secret value stored in the nodes of both communicating parties. The shared key can be pre-defined or pre-configured in the nodes of both parties, or generated by both parties through the same key acquisition method, or sent by a trusted device (such as KDC) to the first node and the second node respectively.

[0505] For example, the vehicle's cockpit domain controller (CDC) and the on-board radar device are two nodes that can communicate. When deploying the CDC and the on-board radar, the automobile factory staff has pre-configured the shared key between the CDC and the on-board radar. Through this shared key, the security of communication between the vehicle's CDC and the roof radar can be guaranteed.

[0506] For another example, the cockpit domain controller (CDC) of the vehicle and the owner's mobile phone are two nodes that can communicate. When the owner needs to associate with the vehicle's CDC through the mobile phone, the shared key can be obtained through the key acquisition method, such as exchanging key negotiation algorithm parameters between the mobile phone and the vehicle's CDC to generate a key through the key negotiation algorithm. The shared key can be used to verify the identities of both nodes when the mobile phone requests to associate with the vehicle's CDC again.

[0507] 3. Key Derivation

[0508] Key derivation is the process of deriving one or more secret values ​​from a secret value, and the algorithm used to derive a key is called a key derivation function (KDF), also known as a key derivation algorithm. For example, the new secret value DK derived from the secret value Key can be expressed as: DK = KDF (Key).

[0509] Commonly used key derivation algorithms include password-based key derivation function (PBKDF), scrypt algorithm, etc., among which PBKDF algorithm includes first-generation PBKDF1 and second-generation PBKDF2. Optionally, some KDF algorithms use hash algorithms to hash the input secret value during the key derivation process, so the KDF function can also receive an algorithm identifier as input to indicate which hash algorithm to use.

[0510] It should also be noted that the "authentication", "verification" and "verification" mentioned in the embodiments of the present application can represent the meaning of checking whether it is correct or reasonable. The "association" mentioned in the embodiments of the present application indicates the process of establishing a connection between the first node and the second node. In some specific technical scenarios, "association" can also be described as "access".

[0511] The system architecture and business scenarios of the embodiments of the present application are described below. It should be noted that the system architecture and business scenarios described in this application are intended to more clearly illustrate the technical solutions of the present application and do not constitute a limitation on the technical solutions provided by the present application. It is known to those skilled in the art that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by the present application are also applicable to similar technical problems.

[0512] See also Figure 1 , Figure 1 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application, including a first node 101 and a second node 102. The first node 101 can be requested to associate by the second node 202. After the association is successful, the first node 101 can communicate with the second node 102 through a data link. Optionally, the data link for the first node 101 to communicate with the second node 102 may include various types of connection media, such as wireless links, specifically wireless fidelity technology (Wi-Fi), Bluetooth, Zigbee, and other wireless links (such as general wireless short-range transmission technology), etc., and wired links, such as optical fiber links, etc.

[0513] Optionally, the first node 101 may be an initiator of communication, which may be referred to as a master node or an access point (AP), and correspondingly, the second node 102 is a receiver of communication, which may be referred to as a slave node.

[0514] The first node 101 and the second node 102 may be devices of the same type or devices of different types. Figure 2 , Figure 2 1 is a schematic diagram of a use scenario of an association control method provided in an embodiment of the present application. The cockpit domain controller (CDC) 201 is the control center in the smart cockpit device and can be regarded as the first node 101. The smart phone 202 is a device that can have data transmission and reception capabilities and can be regarded as the second node 102. Among them, CDC201 can be associated with other Bluetooth devices via Bluetooth, and the smart phone 202 supports the Bluetooth function, so it can request to associate with the CDC201.

[0515] In the existing communication process, nodes are easily attacked by attackers. For example, an attacker can forge the identity of the second node and request to associate with the first node. If the attacker successfully associates, the data security of the first node will be threatened. Especially in the vehicle communication process, if CDC201 receives the attacker's association, it is easy to cause vehicle data leakage or even attack by the attacker, endangering driving safety. For another example, the attacker sends a large number of request frames to the node. When the node receives a large number of request frames that exceed the processing capacity it can bear, it will cause the node to be paralyzed and unable to continue to provide normal services, thereby affecting the communication between other nodes and the node. In order to solve this problem, the embodiment of the present application provides the following association control method.

[0516] See also Figure 3 , Figure 3 is a flow chart of an association control method provided in an embodiment of the present application. The association control method can be based on Figure 1 The communication system shown in the figure is implemented, and the method at least includes the following steps:

[0517] Step S301: The second node determines that the identity of the first node is credible.

[0518] Specifically, the second node can determine that the identity of the first node is credible by at least the following three methods:

[0519] Method 1: Determine that the identity of the first node is trustworthy through a blacklist and / or a whitelist.

[0520] See also Figure 4 , Figure 4 It is a schematic diagram of a blacklist and a whitelist provided in an embodiment of the present application, wherein the identifiers of multiple nodes are stored in the blacklist 401 and the whitelist 402, wherein the identifier of the node can be the node's identification (ID), media access control (MAC) address, domain name, domain address or other custom identifier, for example, the identifier "00-00-00-AA-AA-AA" in the blacklist 401 is the identifier of a certain node. Optionally, the blacklist may also include one or more of the joining time, expiration time, number of times the node's identifier is added to the blacklist, etc., and correspondingly, the whitelist may also include one or more of the joining time, expiration time, key configuration type, etc. of the node's identifier. For the convenience of description, in each embodiment of the present application, the blacklist in the second node is referred to as the second blacklist, and the whitelist in the second node is referred to as the second self-list. It can be understood that the node's identifier cannot be in both the second whitelist and the second blacklist at the same time.

[0521] The second node can determine whether the identity of the first node is credible by determining whether the identifier of the first node is in the second whitelist or the second blacklist. There are two specific implementation methods:

[0522] Implementation method 1: The second node determines that the identifier of the first node is in the second whitelist, which indicates that the identity of the first node is credible.

[0523] Implementation method 2: The second node determines that the identifier of the first node is not in the second blacklist, which indicates that the identity of the first node is credible.

[0524] Optionally, the second node can obtain the identifier of the first node by obtaining the input information, or obtain the identifier of the first node by receiving the message broadcast by the first node. For example, the first node can broadcast a message, and the broadcast message may include the identifier of the first node. After the second node receives the broadcast message, it can confirm whether the identity of the first node is credible based on the identifier of the first node, the second blacklist or the second whitelist. Optionally, the second node stores a correspondence between the identifiers of one or more other nodes and the key configuration type, and the key configuration type can be a pre-configured type and a password generation type. Among them, the pre-configured type indicates that the shared key between the first node and the second node is pre-configured or pre-defined. For example, when assembling a vehicle, the OEM staff pre-configures the shared key between the CDC and the microphone. The password generation type, which can also be called a "password access type", indicates that the shared key between the first node and the second node is a shared key generated according to the password when the association is established by password access. Furthermore, nodes with different key configuration types can have different ways of determining the identity to be credible, which specifically include the following two situations:

[0525] Implementation method three: For the first node whose key configuration type is pre-configured, if it is confirmed that the identifier of the first node is in the second whitelist, it indicates that the identity of the node is credible. Optionally, if the identifier of the first node is in the second blacklist, the identity of the first node is not credible. For example, referring to Table 1, Table 1 is a possible correspondence between node identifiers and key configuration types provided in an embodiment of the present application. If node A1 identified as "66-66-66-FF-FF-FF" requests association, since the key configuration type of node A1 is a pre-configured type, and referring to whitelist 402, it can be known that the identifier of node A1 is in whitelist 402, it can be confirmed that the identity of node A1 is credible.

[0526] Logo Key configuration type Shared Secret 66-66-66-FF-FF-FF Pre-configuration PSK1 00-00-00-AA-AA-AA Password Generation PSK2 44-44-44-EE-EE-EE Password Generation PSK3 77-77-77-GG-GG-GG Password Generation PSK4

[0527] Implementation method 4: For the first node whose key configuration type is password generated, if it is confirmed that the identifier of the first node is not in the second blacklist, it indicates that the identity of the first node is credible. For example, referring to Table 1, if the node A2 with the identifier "77-77-77-GG-GG-GG" requests association, since the key configuration type of node A2 is password generated, and referring to Figure 4 It can be seen that the identifier of the node A2 is not in the blacklist 401, so it can be confirmed that the identity of the node A2 is credible.

[0528] Method 2: Determine that the identity of the first node is credible by obtaining the second confirmation indication information.

[0529] The second node obtains second confirmation indication information, which indicates that the identity of the first node is credible. The second confirmation indication information is indication information obtained according to a confirmation operation input by the user, and the confirmation operation may be a confirmation of the output prompt information, for example:

[0530] Implementation method 5: The second node outputs the second prompt information to remind the user that it is necessary to request to associate with the first node. After receiving the user's confirmation operation and obtaining the second confirmation indication information, it can be determined that the identity of the first node is credible. Further, if the second node receives the user's rejection operation after outputting the second prompt information, it can be determined that the identity of the first node is not credible.

[0531] Method three: Determine that the identity of the first node is credible through a blacklist and / or a whitelist and confirmation indication information.

[0532] When the blacklist and the whitelist cannot confirm whether the identity of the first node is credible, the second node can determine whether the identity of the first node is credible through the confirmation indication information. Specifically, when the identifier of the first node is not in the second blacklist, or when the identifier of the first node is neither in the second blacklist nor in the second whitelist, obtain the second confirmation indication information, which indicates that the identity of the first node is credible. Optionally, in the specific implementation process, different key configuration types can also have different processing, for example:

[0533] Implementation method six: For a first node whose key configuration type is password generation, if the identifier of the first node is not in the second blacklist and is not in the second whitelist, obtain second confirmation indication information, which indicates that the identity of the first node is credible. Optionally, if the second confirmation indication information is not obtained, it can be confirmed that the identity of the second node is not credible.

[0534] Optionally, the second node may be predefined or configured with a second association threshold, which is used to characterize the number of currently associated nodes. The second node may confirm the number of associated nodes of the second node before or after confirming that the identity of the first node is credible, or may confirm the number of associated nodes of the second node periodically or non-periodically. That is, the method includes the following steps: confirming whether the number of nodes currently associated with the second node is less than or equal to (or less than) the second association threshold or determining whether the number of nodes currently associated with the second node is greater than (or greater than or equal to) the second association threshold. If the number of currently associated nodes is greater than (or greater than or equal to) the second association threshold, the second node may not send an association request to the first node or may subsequently cancel the association with the first node to avoid affecting the communication between the second node and other nodes, thereby ensuring the stable operation of the services provided by the second node.

[0535] Step S302: the second node sends a first association request to the first node.

[0536] Specifically, the second node may send the first association request message to the first node via a wireless link (eg, Wi-Fi, Bluetooth, Zigbee, or one of other short-range wireless links, etc.) or a wired link (eg, optical fiber).

[0537] Correspondingly, the first node receives a first association request from the second node. Optionally, the first node may predefine or configure a first association threshold, which is used to characterize the number of nodes currently associated. The first node may confirm the number of nodes currently associated with the first node before or after receiving the first association request message from the second node, or periodically or non-periodically, that is, the method may include the following steps: determining whether the number of nodes currently associated with the first node is less than or equal to (or less than) the first association threshold or determining whether the number of nodes currently associated with the first node is greater than (or greater than or equal to) the first association threshold. The first association threshold can limit the amount of service that the first node can provide. When the number of nodes associated with the first node is greater than (or greater than or equal to) the first association threshold, the first node may no longer receive or process the association request, and therefore will not receive or process the above-mentioned first association request, thereby avoiding affecting the communication between the first node and other associated nodes, and ensuring the stable operation of the service provided by the first node.

[0538] Optionally, the first association request message may include at least one of the identity of the second node or a freshness parameter obtained (or generated) by the second node, etc. The freshness parameter may include at least one of a random number (number once, NONCE), a counter (counter), a sequence number (number), etc. For the convenience of description, the freshness parameter in the first association request message is referred to as the first freshness parameter.

[0539] Step S303: The first node determines that the identity of the second node is credible.

[0540] Specifically, the first node can determine that the identity of the second node is credible in at least the following three ways:

[0541] Method 1: Determine the trustworthiness of the second node through a blacklist and / or a whitelist.

[0542] For the convenience of description, in each embodiment of the present application, the blacklist in the first node is referred to as the first blacklist, and the whitelist in the first node is referred to as the first whitelist. It is understandable that in the first node, the identifier of a node cannot be in both the first whitelist and the first blacklist at the same time.

[0543] The first node can determine whether the identity of the second node is credible by determining whether the identifier of the second node is in the first whitelist or the first blacklist. Specifically, there are two cases:

[0544] Case 1: The first node determines that the identifier of the second node is in the first whitelist, which indicates that the identity of the second node is credible.

[0545] Case 2: The first node determines that the identifier of the second node is not in the first blacklist, which indicates that the identity of the second node is credible. Optionally, if the identifier of the second node is in the first blacklist, which indicates that the identity of the second node is not credible, the first node may discard the first association request or ignore the request and not proceed to the following steps.

[0546] Optionally, the first association request message includes the identity of the second node, and the first node may obtain the identity of the second node by receiving the first association request message.

[0547] Optionally, the first node stores a correspondence between the identifiers of one or more other nodes and the key configuration type, and the key configuration type can be a pre-configuration type and a password generation type. Among them, the pre-configuration type indicates that the shared key between the first node and the second node is pre-configured or pre-defined. For example, when assembling the vehicle, the OEM staff pre-configures the shared key between the CDC and the microphone. The password generation type indicates that the shared key between the first node and the second node is associated by password access, and then the shared key is generated based on the password. Furthermore, nodes with different key configuration types can have different ways of determining identity trustworthiness. There can be the following two cases in specific implementation:

[0548] Case 3: For a second node whose key configuration type is pre-configured, if it is confirmed that the identifier of the second node is in the first whitelist, it indicates that the identity of the second node is credible.

[0549] Case 4: For the second node whose key configuration type is password generated, if it is confirmed that the identifier of the second node is not in the first blacklist, it indicates that the identity of the node is credible. Optionally, if the identifier of the node is in the first blacklist, the identity of the second node is not credible, and the first node can discard the first association request or ignore the request and not proceed to the subsequent steps.

[0550] Method 2: Determine that the identity of the second node is credible by obtaining the first confirmation indication information.

[0551] The first node obtains first confirmation indication information, which indicates that the identity of the second node is credible. Specifically, the first confirmation indication information is indication information obtained according to a confirmation operation input by a user, and the confirmation operation may be a confirmation of the output prompt information. For example:

[0552] Case 5: The first node outputs the first prompt information to remind the user that it is necessary to associate with the second node. After receiving the user's confirmation operation and obtaining the first confirmation indication information, it can be determined that the identity of the two nodes is credible. Further, if the first node receives the user's rejection operation after outputting the first prompt information, it can be confirmed that the identity of the second node is not credible, and the first node can discard the first association request or ignore the request and not proceed to the subsequent steps.

[0553] Method three: Determine that the identity of the second node is credible through the blacklist and / or whitelist and confirmation indication information.

[0554] When the blacklist and the whitelist cannot confirm whether the identity of the second node is credible, the first node can determine whether the identity of the second node is credible through the confirmation indication information. Specifically, when the identifier of the second node is not in the first blacklist, or when the identifier of the second node is neither in the first blacklist nor in the first whitelist, the first confirmation indication information is obtained, and the first confirmation indication information indicates that the identity of the second node is credible. Optionally, in the specific implementation process, different key configuration types can also be processed differently, for example:

[0555] Case 6: For a second node whose key configuration type is password generated, if the identifier of the second node is not in the first blacklist and is not in the first whitelist, obtain first confirmation indication information, which indicates that the identity of the second node is credible. Optionally, if the first confirmation indication information is not obtained, it can be confirmed that the identity of the second node is not credible, and the first node can discard the first association request or ignore the request and not proceed to the subsequent steps.

[0556] Step S304: the first node sends a first authentication request to the second node.

[0557] Specifically, the first authentication request may include first identity authentication information. The first identity authentication information is generated by the first node according to a shared key between the first node and the second node. The shared key may be a pre-shared key PSK between the first node and the second node.

[0558] For example, the first node may generate the first identity authentication information AUTHa according to the pre-shared key PSK through KDF, for example: AUTHa=KDF(PSK).

[0559] Optionally, when the first association request includes the first freshness parameter, the first identity authentication information may be generated by the first node according to the shared key and the first freshness parameter. For example, the first node generates the first identity authentication information AUTHa through KDF according to the pre-shared key PSK and the first freshness parameter NONCEe, for example: AUTHa=KDF(PSK, NONCEe).

[0560] Optionally, in actual processing, the parameters used by the first node to generate the first identity authentication information may also include other information. For example, the generated first identity authentication information AUTHa may satisfy: AUTHa=KDF(PSK, first association request).

[0561] Optionally, the first authentication request also includes a second freshness parameter, which may be at least one of a random number obtained (or generated) by the second node, a random number (number once, NONCE), a counter, a serial number, etc. Further optionally, when the first authentication request includes the second freshness parameter, the first identity authentication information AUTHa generated by the first node may also satisfy: AUTHa = KDF (PSK, NONCEa, first association request), where NONCEa is the second freshness parameter in the first authentication request.

[0562] Optionally, the first authentication request may also include first integrity verification data, etc. The first integrity verification data is verification data generated according to the symmetric key and integrity protection algorithm, and is used by the second node to verify the message integrity of the first authentication request. In a specific implementation, the verification data may also be referred to as a message authentication code (MAC).

[0563] Step S305: The second node verifies the first identity authentication information according to the shared key between the second node and the first node.

[0564] Specifically, since the first identity authentication information is generated by the first node according to the shared key between the first node and the second node, the second node also has the shared key and can verify whether the first identity authentication information is correct according to the shared key.

[0565] In an optional solution, according to the protocol, the first node uses the same parameters to generate the first identity authentication information as the first node, and the second node should also use the same parameters to generate the verification information. If the verification information is the same as the first identity authentication information, the verification is considered to be successful. For example, the first identity authentication information is generated by KDF, so the second node can generate the verification information through KDF, also known as the verification value check1. The second node verifies whether the first identity authentication information is correct through the verification information. The following is an example:

[0566] For example, if the first identity authentication information AUTHa is KDF (PSK, NONCEe), the second node obtains the check value check1 = KDF (PSK, NONCEe) through KDF based on PSK and the first freshness parameter NONCEe. If the check value check1 is the same as AUTHa, the verification is successful.

[0567] Optionally, before or after verifying the first identity authentication information according to the shared key between the second node and the first node, the second node verifies the message integrity of the first authentication request to prevent the content in the first authentication request from being tampered with by an attacker. For example, the first authentication request includes first integrity verification data, and the second node can verify the message integrity of the first authentication request according to the first integrity verification data.

[0568] Optionally, if the message integrity check of the first authentication request fails, the second node may update the number of integrity check failures for the first node, and the number of integrity check failures may be used to subsequently determine whether the identity of the first node is credible. Further optionally, the second node may update the number of integrity check failures for the first node in the following two situations:

[0569] Case 1: The second node uses the second authentication failure counter to represent the number of authentication failures for the first node. The authentication for the first node may include message integrity check and identity authentication. Therefore, if the message integrity check of the first authentication request fails or the identity authentication of the second node fails, the second node may add 1 to the second authentication failure counter, which may be used to subsequently confirm whether the identity of the first node is credible.

[0570] Case 2: The second node uses a second integrity check counter to represent the number of times the integrity check on the first node fails. If the message integrity check on the first authentication request fails, the second node can add 1 to the second integrity check counter. The second integrity check counter can be used to subsequently confirm whether the identity of the first node is credible.

[0571] Step S306: If the second node succeeds in verifying the first identity authentication information, it sends a first authentication response to the first node.

[0572] Specifically, the first authentication response may include second identity authentication information. The second identity authentication information is generated by the second node according to a shared key between the second node and the second node. The shared key may be a pre-shared key PSK between the first node and the second node.

[0573] For example, the second node may generate the second identity authentication information AUTHe according to the pre-shared key PSK through KDF, for example: AUTHe=KDF(PSK).

[0574] Optionally, when the second freshness parameter is included in the first authentication request, the second identity authentication information may be generated by the second node according to the shared key and the second freshness parameter. For example, the second node generates the second identity authentication information AUTHe through KDF according to the pre-shared key PSK and the second freshness parameter NONCEa, for example: AUTHe = KDF (PSK, NONCEa).

[0575] Optionally, in actual processing, the parameters for generating the second identity authentication information by the second node may further include other information. For example, the generated second identity authentication information AUTHe may satisfy: AUTHe=KDF(PSK, first authentication request).

[0576] Optionally, when the first association request may also include the first freshness parameter, the second identity authentication information AUTHe generated by the second node may also satisfy: AUTHe=KDF(PSK, NONCEe, first authentication request), wherein NONCEe is the first freshness parameter in the first association request.

[0577] Optionally, the first association request may also include second integrity verification data, etc. The second integrity verification data is verification data generated according to the symmetric key and integrity protection algorithm, and is used by the first node to verify the message integrity of the first association request. In a specific implementation, the verification data may also be referred to as a message authentication code (MAC).

[0578] Step S307: The first node verifies the second identity authentication information according to the shared key.

[0579] Specifically, since the second identity authentication information is generated based on a shared key between the first node and the second node, the first node also has the shared key and can verify whether the second identity authentication information is correct based on the shared key.

[0580] In an optional solution, according to the protocol, the first node should also use the same parameters to generate the verification information as the second node uses to generate the second identity authentication information. If the verification information is the same as the first identity authentication information, the verification is considered to be successful. For example, the second identity authentication information is generated by KDF, so the first node can generate verification information through KDF, also known as the verification value check2, and then verify whether the second identity authentication information is correct through the verification information. The following is an example:

[0581] For example, if the second identity authentication information AUTHe is KDF (PSK, NONCEa), the first node obtains the check value check2 = KDF (PSK, NONCEa) through KDF according to PSK and the second freshness parameter NONCEa. If the check value check2 is the same as AUTHe, the verification is successful; if the check value check2 is different from AUTHe, the verification fails.

[0582] Optionally, before or after verifying the second identity authentication information according to the shared key, the first node verifies the message integrity of the first authentication response to prevent the content in the first authentication response from being tampered with by an attacker. Specifically, the first authentication response includes second integrity verification data, and the first node can verify the message integrity of the first authentication response according to the second integrity verification data.

[0583] Optionally, if the message integrity check of the first authentication response fails, the first node may update the number of integrity check failures for the second node, and the number of integrity check failures may be used to subsequently determine whether the identity of the second node is credible. Further optionally, the first node may update the number of integrity check failures for the second node in the following two situations:

[0584] Case 1: The first node uses the first authentication failure counter to represent the number of authentication failures for the second node. The authentication for the second node includes message integrity check and identity authentication. Therefore, if the message integrity check of the first authentication response fails or the identity authentication of the second node fails, the first node can add 1 to the first authentication failure counter, and the first authentication failure counter can be used to subsequently confirm whether the identity of the second node is credible.

[0585] Case 2: The first node uses the first integrity check counter to represent the number of times the integrity check on the second node fails. If the message integrity check on the first authentication response fails, the first node can add 1 to the first integrity check counter. The first integrity check counter can be used to subsequently confirm whether the identity of the second node is credible.

[0586] Step S308: If the first node fails to verify the second identity authentication information, the first authentication failure counter is updated.

[0587] Specifically, the first authentication failure counter represents the number of authentication failures for the second node. For example, if the authentication of the second identity authentication information fails, the first authentication failure counter can be increased by 1, and the number of authentication failures can be used to subsequently determine whether the identity of the second node is credible.

[0588] Optionally, the association control method described in the embodiment of the present application may also include: Figure 5 Step S501 shown, step S501 is specifically as follows:

[0589] Step S501: If the value of the first authentication failure counter exceeds a first threshold, the first node adds the identifier of the second node to a first blacklist.

[0590] Specifically, the first authentication failure counter is used to characterize the number of verification failures for the second node, and the number exceeding the first threshold value may be greater than or equal to the first threshold value. If the value of the first authentication failure counter exceeds the first threshold value, it indicates that the second node has failed verification multiple times, so the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the first blacklist. After being added to the first blacklist, the identity of the second node will not be determined as credible, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node. It is understandable that since the identifier of the node cannot be in both the first blacklist and the first whitelist, when the identifier of the second node is added to the first blacklist, if the identifier of the second node is in the first whitelist, the identifier of the first node needs to be removed from the first whitelist.

[0591] Optionally, the validity period of the first blacklist is a predefined or configured first duration. For example, the first duration of the first blacklist may be 20 days, and the identifier of the second node may be removed from the blacklist 20 days after being added to the first blacklist.

[0592] Optionally, if the time for the second node's identifier to be added to the first blacklist exceeds the first duration, the second node's identifier is removed from the first blacklist, and the first duration is related to the number of times the second node's identifier is added to the first blacklist and the device type of the second node. Specifically, on the one hand, the validity period of the first blacklist may be related to the number of times the second node is added to the first blacklist. The more times a second node is added to the first blacklist, the longer it will be in the first blacklist. Further, optionally, when the number of times it is added to the first blacklist exceeds a set value (for example, more than 10 times), it can be permanently added to the first blacklist and cannot be removed. On the other hand, the validity period of the first blacklist may be related to the device type to which the second node belongs. Specifically, the second node can obtain the device type of the second node in advance and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the first node may also predefine a blacklist validity period corresponding to the second node, which will not be described in detail here.

[0593] It should be noted that the present application does not limit the number of specific device types, and multiple types of devices can be defined and corresponding blacklists and blacklist validity periods can be set according to actual needs. Specifically, the first blacklist can also include multiple groups of blacklists, each of which is used for more specific and detailed device management.

[0594] Optionally, the association control method described in the embodiment of the present application may also include: Figure 5 Step S502 is shown, and the specific details of step S502 are as follows:

[0595] Step S502: If the verification of the second identity authentication information is successful, the first node sends a first association response to the second node.

[0596] Specifically, after confirming that the identity of the second node is credible, if the identity authentication is passed, the first node can send a first association response to the second node, and the first association response is used to indicate that the first node has established an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0597] Optionally, the association control method described in the embodiment of the present application may also include: Figure 5 Step S503 or step 503-step 504 shown, step 503-step 504 are specifically as follows:

[0598] Step S503: If the verification of the first identity authentication information fails, the second node updates the second authentication failure counter.

[0599] Specifically, the second authentication failure counter represents the number of authentication failures for the first node. If the authentication information of the first node fails, the second authentication failure counter can be increased by 1, and the second authentication failure counter can be used to subsequently determine whether the identity of the first node is credible.

[0600] Step S504: If the value of the second authentication failure counter exceeds the second threshold, the second node adds the identifier of the first node to the second blacklist.

[0601] Specifically, if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification multiple times, so the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the second blacklist. After being added to the second blacklist, the identity of the first node will not be determined as credible, thereby avoiding the second node from establishing an association with an illegal attacker and improving the data security of the second node. It is understandable that since the identifier of the first node cannot be in both the second blacklist and the second whitelist, after adding the identifier of the first node to the second blacklist, if the identifier of the first node is in the second whitelist, the identifier of the first node needs to be removed from the second whitelist.

[0602] Optionally, the validity period of the second blacklist is a predefined or configured second duration. The second duration can be regarded as the validity period of the blacklist. For example, the second duration of the second blacklist can be 10 days. When the identifier of a first node is added to the second blacklist for 10 days, it can be removed from the second blacklist.

[0603] Optionally, the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist and the type of the first node. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a node is added to the second blacklist, the longer it will be in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a set value (for example, more than 15 times), it can be permanently added to the second blacklist and cannot be removed. On the other hand, the validity period of the second blacklist may be related to the type of device to which the first node belongs. Specifically, the first node can obtain the device type of the first node in advance and determine different second blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the second node can also predefine the blacklist validity period corresponding to the first node, which will not be repeated here.

[0604] Optionally, if the second node determines that the value of the second authentication failure counter is less than a second threshold, a second association request may be sent to the first node. Specifically, during the identity authentication information verification process, the identity authentication information verification may fail due to the loss or transmission error of certain parameters during the transmission process. Therefore, if the number of failed verifications of the first node has not exceeded the preset second threshold, an association request may be resent to the first node to request association with the first node, thereby improving the robustness of the system and ensuring the stable operation of the services provided by the node.

[0605] Optionally, before the second node sends the second association request, a third confirmation indication information may be obtained, and the third confirmation indication information may be indication information obtained according to a confirmation operation input by the user, and the confirmation operation may be a confirmation of the output prompt information. For example, the second node may output a prompt information to remind the user that the verification has failed and that the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0606] exist Figure 3 or and Figure 5In the embodiment shown, after confirming that the identity of the second node is credible, the identity of the second node is verified based on the shared key with the second node. In this way, even if the attacker modifies the identity identifier and bypasses the step of "confirming that the identity is credible", it is still impossible to pass the identity verification of the first node because it is difficult to forge the identity verification information, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node.

[0607] Furthermore, if the verification fails, the number of verification failures will be updated, and the number of verification failures can be used to determine whether the identity of the second node is credible in the future, so that the node that fails multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, their association requests (such as sending authentication requests) can no longer be processed, thereby preventing the node from crashing due to processing a large number of requests and ensuring the normal operation of the service.

[0608] See also Figure 6 , Figure 6 is a flow chart of the association control method provided in the embodiment of the present application. The method can be based on Figure 1 The method is implemented by the architecture shown in the figure, and includes but is not limited to the following steps:

[0609] Step S601: The second node determines that the identity of the first node is credible.

[0610] For details, please refer to the relevant description of step S301.

[0611] Step S602: The second node sends a first association request to the first node.

[0612] For details, please refer to the relevant description of step S302.

[0613] Step S603: The first node determines that the identity of the second node is credible.

[0614] For details, please refer to the relevant description of step S303.

[0615] Step S604: the first node sends a first authentication request to the second node.

[0616] Specifically, the first authentication request includes first integrity verification data, etc. The first integrity verification data is verification data generated according to a key and an integrity protection algorithm, and is used by the second node to verify the message integrity of the first authentication request. In a specific implementation, the verification data may also be referred to as a message authentication code (MAC).

[0617] For example, the first integrity check data MAC1 can be obtained according to a Cipher-based Message Authentication Code (CMAC) algorithm by sharing the key K1 and part or all of the data data1 in the first authentication request except MAC1, for example: MAC1=CMAC(K1, data1).

[0618] Optionally, the first authentication request may include first identity authentication information. The first identity authentication information is generated by the first node based on a shared key between the first node and the second node. The shared key may be a pre-shared key between the first node and the second node. For example, the first node may generate the first identity authentication information AUTHa through KDF based on the pre-shared key PSK, that is, AUTHa=KDF(PSK).

[0619] Optionally, when the first freshness parameter is included in the first association request, the first identity authentication information may be generated by the first node based on the shared key and the first freshness parameter. For example, the first node generates the first identity authentication information AUTHa through KDF based on the pre-shared key PSK and the first freshness parameter NONCEe, for example, AUTHa=KDF(PSK, NONCEe). Further optionally, in actual processing, the parameters for generating the first identity authentication information by the first node may also include other information, for example, the generated first identity authentication information AUTHa may satisfy: AUTHa=KDF(PSK, first association request). Further optionally, when the second freshness parameter is included in the first authentication request, the first identity authentication information AUTHa generated by the first node may also satisfy: AUTHa=KDF(PSK, NONCEa, first association request), where NONCEa is the second freshness parameter in the first authentication request.

[0620] Step S605: The second node verifies the message integrity of the first authentication request.

[0621] Specifically, the first authentication request includes first integrity verification data, and the second node can verify the message integrity of the first authentication request according to the first integrity verification data to prevent the content in the first authentication request from being tampered with by an attacker.

[0622] In a possible solution, the first node generates the first integrity check data in the same way as the second node generates the check value. If the generated check value is the same as the first integrity check data, the message integrity passes. For example, the first integrity check data MAC1 is obtained by the first node according to the CMAC algorithm, using the shared key K1 and part or all of the data data1 in the first authentication request except MAC1. Then the second node generates the check value check3 in the same way: check3 = CMAC (K1, data1). If check3 is the same as MAC1, it means that the data data1 in the first authentication request has not been tampered with, and the integrity verification of the first authentication request passes.

[0623] Optional, Figure 6 The illustrated association control method further includes step S606, which is specifically as follows:

[0624] Step S606: If the message integrity check of the first authentication request fails, the second node updates the second authentication failure counter.

[0625] Specifically, the second node can use a second authentication failure counter to represent the number of verification failures for the first node. Therefore, if the message integrity check for the first authentication request fails, the second node can add 1 to the value of the second authentication failure counter. The second authentication failure counter can be used to subsequently confirm whether the identity of the first node is credible.

[0626] Optional, Figure 6 The illustrated association control method further includes step S607, which is as follows:

[0627] Step S607: If the value of the second authentication failure counter exceeds the second threshold, the second node adds the identifier of the first node to the second blacklist.

[0628] Specifically, the second authentication failure counter represents the number of authentication failures for the first node, and the number exceeding the second threshold may be greater than or equal to the second threshold. If the number of message integrity authentication failures for the first authentication request exceeds the second threshold, it may indicate that the message from the first node may have been tampered with by an attacker for multiple times or is originally erroneous data, so the identifier of the first node is added to the second blacklist, which avoids the second node from establishing an association with an illegal attacker and improves the data security of the second node.

[0629] Optionally, if the second node determines that the value of the second authentication failure counter is less than or equal to the second threshold, a second association request may be sent to the first node. Further optionally, before the second node sends the second association request, a third confirmation indication information may be obtained, and the third confirmation indication information may be indication information obtained according to a confirmation operation input by the user, and the confirmation operation may be a confirmation of the output prompt information. For example, the second node may output a prompt message to remind the user that the verification has failed and that the association request needs to be re-initiated. After receiving the user confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0630] Optional, Figure 6 The illustrated association control method further includes step S608, which is as follows:

[0631] Step S608: The second node verifies the first identity authentication information according to the shared key between the second node and the first node.

[0632] For details, please refer to the relevant description of step S305.

[0633] Optional, Figure 6 The illustrated association control method further includes step S609, which is as follows:

[0634] Step S609: If the verification of the first identity authentication information fails, the second node updates the second authentication failure counter.

[0635] Specifically, the second authentication failure counter represents the number of authentication failures for the first node. If the authentication information of the first node fails, the value of the second authentication failure counter can be increased by 1, and the second authentication failure counter can be used to subsequently determine whether the identity of the first node is credible.

[0636] Optional, Figure 6 The illustrated association control method further includes step S610, which is as follows:

[0637] Step S610: If the value of the second authentication failure counter exceeds the second threshold, the second node adds the identifier of the first node to the second blacklist.

[0638] Specifically, the second authentication failure counter represents the number of verification failures for the first node, and the number exceeding the second threshold may be greater than or equal to the second threshold. If the value of the second authentication failure counter exceeds the second threshold, it indicates that the first node has failed verification multiple times, so the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the second blacklist. After being added to the second blacklist, the identity of the first node will not be determined to be credible, thereby avoiding the second node from establishing an association with an illegal attacker and improving the data security of the node.

[0639] Optionally, if the second node determines that the value of the second authentication failure counter is less than the second threshold, a second association request may be sent to the first node. Further optionally, before the second node sends the second association request, a third confirmation indication information may be obtained, and the third confirmation indication information may be indication information obtained according to a confirmation operation input by the user, and the confirmation operation may be a confirmation of the output prompt information. For example, the second node may output a third prompt information to remind the user that the identity authentication of the first node has failed and that the association request needs to be re-initiated. After receiving the user confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0640] Optionally, in the specific implementation process, the second node may first perform the operation of step S608 or step S608-step S610 and then perform the operation of step S605 or step S605-step S607. That is, the second node may first verify the first identity authentication information according to the shared key and then verify the message integrity of the first authentication request.

[0641] Step S611: The second node sends a first authentication response to the first node.

[0642] Specifically, the first authentication response may also include second integrity verification data, etc. The second integrity verification data is verification data generated according to the symmetric key and integrity protection algorithm, and is used by the first node to verify the message integrity of the first association request. In a specific implementation, the verification data may also be referred to as a message authentication code (MAC). For example, the second integrity verification data MAC2 may be obtained according to the CMAC algorithm by sharing the key K1 and part or all of the data data2 in the first authentication response except MAC2, for example: MAC2 = CMAC (K1, data2).

[0643] Optionally, if the message integrity check of the first authentication request passes, the second node sends a first authentication response to the first node. Further optionally, if the message integrity check of the first authentication request passes and the second node verifies the first identity authentication information, the first authentication response is sent to the first node.

[0644] Optionally, the first authentication response may also include second identity authentication information. The second identity authentication information is generated by the second node based on a shared key between the second node and the first node. The shared key may be a pre-shared key PSK between the first node and the second node. For example, the second node may generate the second identity authentication information AUTHe through KDF based on the pre-shared key PSK, for example: AUTHe=KDF(PSK).

[0645] Optionally, in the case where the second freshness parameter is included in the first authentication request, the second identity authentication information may be generated by the second node based on the shared key and the second freshness parameter. For example, the second node generates the second identity authentication information AUTHe through KDF based on the pre-shared key PSK and the second freshness parameter NONCEa, for example: AUTHe = KDF (PSK, NONCEa). Further optionally, in actual processing, the parameters for generating the second identity authentication information by the second node may also include other information, for example, the generated second identity authentication information AUTHe may satisfy: AUTHe = KDF (PSK, first authentication request). Further optionally, in the case where the first freshness parameter may also be included in the first association request, the second identity authentication information AUTHe generated by the second node may also satisfy: AUTHe = KDF (PSK, NONCEe, first authentication request), where NONCEe is the first freshness parameter in the first association request.

[0646] Step S612: The first node verifies the message integrity of the first authentication response.

[0647] Specifically, the first authentication response includes second integrity verification data, and the first node can verify the message integrity of the first authentication response according to the second integrity verification data to prevent the content in the first authentication response from being tampered with by an attacker.

[0648] In a possible solution, the second node generates the second integrity check data in the same way as the first node generates the check value. If the generated check value is the same as the second integrity check data, the message integrity passes. For example, the second integrity check data MAC2 is obtained by the second node according to the CMAC algorithm, using the shared key K1 and part or all of the data data2 in the first authentication response except MAC2. Then the second node generates the check value check4 in the same way: check4 = CMAC (K1, data2). If check4 is the same as MAC2, it means that the data data2 in the first authentication response has not been tampered with, and the integrity verification of the first authentication response passes.

[0649] S613: If the message integrity check of the first authentication response fails, the first node updates the first authentication failure counter.

[0650] Specifically, the first node can use a first authentication failure counter to represent the number of verification failures for the second node. Therefore, if the message integrity check of the first authentication response fails, the first node can add 1 to the value of the first authentication failure counter. The first authentication failure counter can be used to subsequently confirm whether the identity of the second node is credible.

[0651] Optional, Figure 6 The illustrated association control method further includes step S614, which is as follows:

[0652] Step S614: If the value of the first authentication failure counter exceeds the first threshold, the first node adds the identifier of the second node to the first blacklist.

[0653] Specifically, the first authentication failure counter represents the number of verification failures for the second node, and exceeding the first threshold value may be greater than or equal to the first threshold value. If the value of the first authentication failure counter exceeds the first threshold value, it can be explained that the message from the second node may have been tampered with by the attacker for many times or is originally wrong data, so the identifier of the second node is added to the first blacklist, avoiding association with illegal attackers and improving the data security of the node.

[0654] Optional, Figure 6 The illustrated association control method further includes step S615, which is specifically as follows:

[0655] Step S615: The first node verifies the second identity authentication information according to the shared key.

[0656] For details, please refer to the relevant description of step S307.

[0657] Optional, Figure 6The shown association control method further includes step S616 or step S616-step S617, and step S616-step S617 are specifically as follows:

[0658] Step S616: If the message integrity check of the first authentication response fails, the first node updates the first authentication failure counter.

[0659] For details, please refer to the relevant description of step S308.

[0660] Step S617: If the value of the first authentication failure counter exceeds the first threshold, the first node adds the identifier of the second node to the first blacklist.

[0661] For details, please refer to the relevant description of step S501.

[0662] Optionally, in the specific implementation process, the first node may also first perform the operation of step S615 or step S615-step S617 and then perform the operation of step S612 or step S612-step S613. In other words, the first node may first verify the second identity authentication information according to the shared key and then verify the message integrity of the first authentication response.

[0663] Optional, Figure 6 The illustrated association control method further includes step S618, which is as follows:

[0664] Step S618: The first node sends a first association response to the second node.

[0665] Specifically, the first association response is used to instruct the first node to establish an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be performed.

[0666] Optionally, if the message integrity check of the first authentication response passes, the first node sends the first association response to the second node. Further optionally, if the message integrity check of the first authentication response passes and the first node verifies the second identity authentication information, the first node sends the first association response to the second node.

[0667] exist Figure 6 In the embodiment shown, after confirming that the identity of the second node is credible, the authentication response message from the second node needs to be verified for message integrity before association is performed. If the message integrity verification fails, the number of verification failures is updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, thereby preventing attackers from tampering with data during the authentication process, thereby avoiding the node from establishing association with illegal attackers, and improving the data security of the node.

[0668] The method of the embodiment of the present application is described in detail above, and the device of the embodiment of the present application is provided below.

[0669] See also Figure 7 , Figure 7 : is a structural diagram of an association control device 70 provided in an embodiment of the present application. The device 70 may be a node or a device in a node, such as a chip or an integrated circuit. The device 70 may include a communication unit 701 and a processing unit 702. The description of each unit is as follows:

[0670] The communication unit 701 is configured to receive a first association request from a second node;

[0671] The processing unit 702 is configured to determine that the identity of the second node is credible, and send a first authentication request to the second node through the communication unit 701, where the first authentication request includes first identity authentication information, where the first identity authentication information is generated according to a shared key between the first node and the second node;

[0672] The communication unit 701 is further configured to receive a first authentication response from the second node, wherein the first authentication response includes second identity authentication information;

[0673] The processing unit 702 is further configured to verify the second identity authentication information according to the shared key;

[0674] The processing unit 702 is further configured to update a first authentication failure counter if the authentication of the second identity authentication information fails, wherein the first authentication failure counter represents the number of authentication failures for the second node.

[0675] In the embodiment of the present application, after confirming that the identity of the second node is credible, the above-mentioned device 70 verifies the identity of the second node according to the shared key with the second node. In this way, even if the attacker modifies the identity identifier and bypasses the step of the above-mentioned device 70 determining that the identity is credible, it is still impossible to pass the above-mentioned device's identity verification because it is difficult to forge identity verification information, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0676] Furthermore, if the verification fails, the device 70 will update the number of verification failures, which can be used to subsequently determine whether the identity of the second node is credible, so that nodes that have failed multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, the device 70 can no longer process their association requests (such as sending authentication requests), thereby preventing the device 70 from crashing due to processing a large number of requests and ensuring normal service.

[0677] It should be noted here that the division of the above-mentioned multiple units is only a logical division based on function, and does not serve as a limitation on the specific structure of the device 70. In a specific implementation, some of the functional modules may be subdivided into more small functional modules, and some functional modules may be combined into one functional module, but no matter whether these functional modules are subdivided or combined, the general process executed by the device 70 in the process of association control is the same. For example, the above-mentioned communication unit 701 can also be transformed into a receiving unit and a sending unit, and the receiving unit is used to implement the function of receiving messages in the communication unit 701, and the sending unit is used to implement the function of sending messages in the communication unit 701. Usually, each unit corresponds to its own program code (or program instruction), and when the program code corresponding to each of these units runs on the processor, the unit executes the corresponding process to implement the corresponding function.

[0678] In a possible implementation manner, the processing unit 702 is specifically configured to:

[0679] Determining that the identifier of the second node is in the first whitelist;

[0680] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0681] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0682] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0683] The device 70 controls the nodes that request association according to the blacklist or whitelist, so that there is no need to authenticate the untrusted second node. On the one hand, it can prevent the crash due to processing a large number of requests and ensure the normal operation of the service. On the other hand, since no association is established with nodes that have not been authenticated, the device 70 is prevented from establishing association with illegal attackers, thereby improving the data security of the device 70.

[0684] In a possible implementation manner, the processing unit is specifically configured to:

[0685] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0686] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0687] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0688] In yet another possible implementation, the first authentication response further includes second integrity verification data, and the second integrity verification data is used to verify the message integrity of the first authentication response;

[0689] The processing unit 702 is specifically configured to:

[0690] Determine that the message integrity check of the first authentication response passes.

[0691] It can be seen that after confirming that the identity of the second node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication response from being tampered with by an attacker, thereby avoiding affecting the verification of the identity authentication information of the second node and ensuring the stable operation of the services provided by the above-mentioned device.

[0692] In yet another possible implementation, the processing unit 702 is further configured to:

[0693] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0694] It can be seen that the first association threshold is preset in the above device, and the association request from the second node can be received only when the number of associated nodes is less than or equal to the preset first association threshold. The first threshold can limit the bearing capacity of the service that the above device can provide. When the first association threshold is exceeded, the above device can no longer receive or process the association request, so as to avoid affecting the communication of other nodes associated with the above device, thereby ensuring the stable operation of the service provided by the above device.

[0695] In yet another possible implementation, the communication unit 701 is further configured to:

[0696] If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

[0697] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to instruct the above device to establish an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0698] In yet another possible implementation, the processing unit 702 is further configured to:

[0699] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0700] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of authentication failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node and ensure the stable operation of the services provided by the above device.

[0701] In yet another possible implementation, the processing unit 702 is further configured to:

[0702] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0703] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for multiple times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0704] In another possible implementation, the validity period of the first blacklist is a predefined or configured first duration.

[0705] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0706] In yet another possible implementation, the processing unit 702 is further configured to:

[0707] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0708] The above implementations illustrate factors related to the validity period of the first blacklist. On the one hand, the validity period of the first blacklist may be related to the number of times a second node joins the first blacklist. The more times a second node joins the first blacklist, the longer it stays in the first blacklist. Further, optionally, when the number of times it is added to the first blacklist exceeds a certain threshold, it may be permanently added to the first blacklist.

[0709] On the other hand, the validity period of the first blacklist may be related to the device type to which the second node belongs. Specifically, the second node may pre-acquire the device type of the second node and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the first node can also pre-define the blacklist validity period corresponding to the second node, which will not be repeated here. This application does not specifically limit the number of device types and can be designed according to specific scenarios.

[0710] In yet another possible implementation, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0711] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication steps will not be performed, so as to avoid wasting the resources of the above device and affecting the normal association of other nodes.

[0712] It should be noted that the implementation of each unit can also refer to Figure 3 or Figure 5 The device 70 can be Figure 3 or Figure 5 The first node in the embodiment shown.

[0713] See also Figure 8 , Figure 8 80 is a schematic diagram of the structure of an association device 80 provided in an embodiment of the present application. The device 80 may be a node or a device in a node, such as a chip or an integrated circuit. The device 80 may include a processing unit 801 and a communication unit 802. The description of each unit is as follows:

[0714] The processing unit 801 determines that the identity of the first node is credible, and sends a first association request to the first node through the communication unit 802;

[0715] The communication unit 802 is further configured to receive a first authentication request from the first node, wherein the first authentication request includes first identity authentication information;

[0716] The processing unit 801 is further configured to verify the first identity authentication information according to a shared key between the second node and the first node;

[0717] The communication unit 802 is further configured to send a first authentication response to the first node if the verification of the first identity authentication information is successful, wherein the first authentication response includes second identity authentication information; wherein the second identity authentication information is generated based on the shared key.

[0718] In the embodiment of the present application, after confirming that the identity of the first node is credible, the above-mentioned device sends a first association request to the first node. Then, based on the first identity authentication information in the first authentication request, the identity authentication information of the first node is verified by a shared key. After the verification is passed, the second identity authentication information is sent to the first node, and the second identity authentication information can be used by the first node to verify the identity of the above-mentioned device. It can be seen that after confirming that the identity is credible, the identity authentication of both parties must be passed before the association can be carried out, so that it is difficult for an attacker to bypass the second node's identity authentication by modifying the identity such as the identification, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0719] It should be noted here that the division of the above-mentioned multiple units is only a logical division based on function, and does not serve as a limitation on the specific structure of the device 80. In a specific implementation, some of the functional modules may be subdivided into more small functional modules, and some functional modules may be combined into one functional module, but no matter whether these functional modules are subdivided or combined, the general process executed by the device 80 in the process of association control is the same. For example, the above-mentioned communication unit 802 can also be transformed into a receiving unit and a sending unit, and the receiving unit is used to implement the function of receiving messages in the communication unit 802, and the sending unit is used to implement the function of sending messages in the communication unit 802. Usually, each unit corresponds to its own program code (or program instruction), and when the program code corresponding to each of these units runs on the processor, the unit executes the corresponding process to implement the corresponding function.

[0720] In a possible implementation manner, the processing unit 801 is specifically configured to:

[0721] Determining that the identifier of the first node is in a second whitelist;

[0722] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0723] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0724] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0725] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the above device can be controlled not to send an association request to an untrusted first node, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0726] In yet another possible implementation, the processing unit 801 is specifically configured to:

[0727] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0728] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0729] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0730] In yet another possible implementation, the first authentication request further includes first integrity verification data, and the first integrity verification data is used to verify the message integrity of the first authentication request;

[0731] The processing unit 801 is further configured to:

[0732] Determine that a message integrity check of the first authentication request passes.

[0733] It can be seen that after confirming that the identity of the first node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication request from being tampered with by an attacker, thereby affecting the verification of the identity authentication information of the first node, thereby ensuring the stable operation of the services provided by the above-mentioned device.

[0734] In yet another possible implementation, the processing unit 801 is further configured to:

[0735] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0736] It can be seen that the above device is preset with a second association threshold, and the association request can be sent to the first node only when the number of associated nodes is less than or equal to the preset second association threshold. The second threshold can limit the number of nodes that the above device can associate with, and when the second association threshold is exceeded, the above device can no longer associate with other nodes, so as to avoid affecting the communication of other nodes associated with the device, thereby ensuring the stable operation of the service provided by the above device.

[0737] In yet another possible implementation, the communication unit 802 is further configured to:

[0738] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0739] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the second node, the above-mentioned device can receive a first association response from the first node, and the association response is used to indicate that the above-mentioned device has established an association with the second node. Further, the first response message can inform the above-mentioned device that the association has been successful and subsequent communication can be carried out.

[0740] In yet another possible implementation, the processing unit 801 is further configured to:

[0741] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0742] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the above device.

[0743] In yet another possible implementation, the processing unit 801 is further configured to:

[0744] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0745] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of times the identity of the first node has failed to be verified, and the number of times the identity of the node has failed can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the first node's association control over it by modifying the identity such as the identifier, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0746] In yet another possible implementation, the processing unit 801 is further configured to:

[0747] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0748] Adding the identifier of the first node to the second blacklist.

[0749] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification for multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0750] In yet another possible implementation, the validity period of the second blacklist is a predefined or configured second duration.

[0751] It can be seen that there is a predefined or configured second duration in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second duration of the blacklist can be 10 days, and the identifier of a first node can be removed from the blacklist after being added to the blacklist for 10 days.

[0752] In yet another possible implementation, the processing unit 801 is further configured to determine that the value of the second authentication failure counter is less than a second threshold;

[0753] The communication unit 802 is further configured to send a second association request to the first node.

[0754] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of failed verifications of the first node, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the first node's association control over it by modifying the identity such as the identifier, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the node.

[0755] In yet another possible implementation, the processor is further configured to:

[0756] Determining that the value of the second authentication failure counter is less than a second threshold;

[0757] Obtaining third confirmation indication information;

[0758] A second association request is sent to the first node.

[0759] It can be seen that before resending the second association request, confirmation indication information needs to be obtained. The third confirmation indication information can be indication information obtained according to the confirmation operation input by the user, and the confirmation operation can be a confirmation of the output prompt information. For example, a prompt information can be output to remind the user that the verification failed and the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0760] In yet another possible implementation, the processor is further configured to:

[0761] If the time that the identifier of the first node is added to the second blacklist exceeds a second duration, the identifier of the first node is removed from the second blacklist, and the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist and the type of the first node.

[0762] The above implementations illustrate factors related to the validity period of the second blacklist. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a first node is added to the second blacklist, the longer it will stay in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a certain threshold, it may be permanently added to the second blacklist.

[0763] On the other hand, the validity period of the second blacklist may be related to the device type to which the first node belongs. Specifically, the first node may pre-acquire the device type of the first node and determine different second blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the second node can also pre-define the blacklist validity period corresponding to the first node, which will not be repeated here. In another possible implementation, if the identity of the first node is not trustworthy, the step of sending the first association request to the first node is not executed.

[0764] It can be seen that if the identity of the first node is not credible, no identity authentication request will be sent to the first node to avoid wasting node resources.

[0765] It should be noted that the implementation of each unit can also refer to Figure 3 or Figure 5 The device 80 can be Figure 3 or Figure 5 The second node in the embodiment shown.

[0766] See also Fig. 9 , Fig. 9 1 is a schematic diagram of the structure of a communication device 90 provided in an embodiment of the present application. The communication device 90 may be a node or a device in a node, such as a chip or an integrated circuit. The device 90 may include at least one memory 901 and at least one processor 902. Optionally, a bus 903 may also be included. Further optionally, a communication interface 904 may also be included, wherein the memory 901, the processor 902 and the communication interface 904 are connected via a bus 903.

[0767] The memory 901 is used to provide a storage space, in which data such as an operating system and a computer program can be stored. The memory 901 can be a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or a portable read-only memory (CD-ROM), etc., or a combination of multiple thereof.

[0768] The processor 902 is a module that performs arithmetic operations and / or logical operations, and may specifically be a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), or a combination of one or more of the processing modules.

[0769] The communication interface 904 is used to receive data sent externally and / or send data externally, and may be a wired link interface such as an Ethernet cable, or a wireless link (Wi-Fi, Bluetooth, general wireless transmission, etc.) interface. Optionally, the communication interface 1104 may also include a transmitter (such as a radio frequency transmitter, an antenna, etc.) coupled to the interface, or a receiver, etc.

[0770] The processor 902 in the device 90 is used to read the computer program stored in the memory 901 to execute the aforementioned association control method, for example Figure 3 or Figure 5 The described associated control method.

[0771] For example, the processor 902 in the device 90 is used to read the computer program stored in the memory 901 to perform the following operations:

[0772] receiving a first association request from a second node via the communication interface 904;

[0773] Determine that the identity of the second node is credible, and send a first authentication request to the second node through the communication interface 904, where the first authentication request includes first identity authentication information, and the first identity authentication information is generated according to a shared key between the first node and the second node; wherein the shared key can be regarded as a first secret value shared between the first node and the second node;

[0774] receiving, through the communication interface 904, a first authentication response from the second node, wherein the first authentication response includes second identity authentication information;

[0775] Verifying the second identity authentication information according to the shared key;

[0776] If the verification of the second identity authentication information fails, a first authentication failure counter is updated, where the first authentication failure counter represents the number of verification failures for the second node.

[0777] In the embodiment of the present application, after confirming that the identity of the second node is credible, the device 90 verifies the identity of the second node according to the shared key with the second node. In this way, even if the attacker modifies the identity identifier and bypasses the step of the device 90 determining that the identity is credible, it is still impossible to pass the identity verification of the device 90 because it is difficult to forge the identity verification information, thereby avoiding the device 90 from establishing an association with an illegal attacker and improving the data security of the device 90.

[0778] Furthermore, if the verification fails, the device 90 will update the number of verification failures, which can be used to subsequently determine whether the identity of the second node is credible, so that nodes that fail multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, the device 90 can no longer process their association requests (such as sending authentication requests), thereby preventing the device 90 from crashing due to processing a large number of requests and ensuring normal service.

[0779] In yet another possible implementation, the processor 902 is specifically configured to:

[0780] Determining that the identifier of the second node is in the first whitelist;

[0781] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0782] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0783] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0784] The device 90 controls the nodes that request association according to the blacklist or whitelist, so that there is no need to authenticate the untrusted second node. On the one hand, it can prevent the crash due to processing a large number of requests and ensure the normal operation of the service. On the other hand, since no association is established with nodes that have not been authenticated, the device 90 is prevented from establishing association with illegal attackers, thereby improving the data security of the device 90.

[0785] In yet another possible implementation, the processor 902 is specifically configured to:

[0786] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0787] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0788] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0789] In yet another possible implementation, the first authentication response further includes second integrity verification data, and the second integrity verification data is used to verify the message integrity of the first authentication response;

[0790] The processor 902 is further configured to determine whether a message integrity check of the first authentication response passes.

[0791] It can be seen that after confirming that the identity of the second node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication response from being tampered with by an attacker, thereby avoiding affecting the verification of the identity authentication information of the second node and ensuring the stable operation of the services provided by the above-mentioned device 90.

[0792] In yet another possible implementation, the processor 902 is further configured to:

[0793] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0794] It can be seen that the first association threshold is preset in the above-mentioned device 90. When the number of associated nodes is less than or equal to the preset first association threshold, the association request from the second node can be received. The first threshold can limit the bearing capacity of the service that the node can provide. When the first association threshold is exceeded, the above-mentioned device 90 can no longer receive or process the association request, so as to avoid affecting the communication of other nodes associated with the above-mentioned device 90, and ensure the stable operation of the service provided by the above-mentioned device 90.

[0795] In yet another possible implementation, the processor 902 is further configured to:

[0796] If the verification of the second identity authentication information is successful, a first association response is sent to the second node through the communication interface 904, where the first association response is used to instruct the first node to establish an association with the second node.

[0797] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to instruct the above-mentioned device 90 to establish an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0798] In yet another possible implementation, the processor 902 is further configured to:

[0799] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0800] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of verification failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node, thereby ensuring the stable operation of the services provided by the above-mentioned device 90.

[0801] In yet another possible implementation, the processor 902 is further configured to:

[0802] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0803] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for multiple times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the above-mentioned device 90 from establishing an association with an illegal attacker, and improving the data security of the above-mentioned device 90.

[0804] In another possible implementation, the validity period of the first blacklist is a predefined or configured first duration.

[0805] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0806] In yet another possible implementation, the processor 902 is further configured to:

[0807] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0808] The above implementations illustrate factors related to the validity period of the blacklist. On the one hand, the validity period of the blacklist may be related to the number of times the second node is added to the blacklist. The more times a second node is added to the blacklist, the longer it will be in the blacklist. Further, optionally, when the number of times it is added to the blacklist exceeds a certain threshold, it may be permanently added to the blacklist.

[0809] On the other hand, the validity period of the blacklist may be related to the device type to which the second node belongs. Specifically, the second node may pre-acquire the device type of the second node and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The validity period of the blacklist for high-risk devices is longer than that for low-risk devices. In addition, the above-mentioned device 90 can also pre-define the validity period of the blacklist corresponding to the second node, which will not be repeated here.

[0810] In yet another possible implementation, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0811] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication steps will not be performed, so as to avoid wasting resources of the above-mentioned device 90 and affecting the normal association of other nodes.

[0812] It should be noted that the specific implementation of each unit can also refer to Figure 3 or Figure 5 The communication device 90 can be Figure 3 or Figure 5 The first node in the embodiment shown.

[0813] See also Fig.10 , Fig.10 1 is a schematic diagram of the structure of a communication device 100 provided in an embodiment of the present application. The communication device 100 may be a node or a device in a node, such as a chip or an integrated circuit. The device 100 may include at least one memory 1001 and at least one processor 1002. Optionally, a bus 1003 may also be included. Further optionally, a communication interface 1004 may also be included, wherein the memory 1001, the processor 1002 and the communication interface 1004 are connected via the bus 1003.

[0814] The memory 1001 is used to provide a storage space, and the storage space can store data such as an operating system and a computer program, etc. The memory 1001 can be one or a combination of RAM, ROM, EPROM, CD-ROM, etc.

[0815] The processor 1002 is a module that performs arithmetic operations and / or logical operations, and may specifically be one or a combination of multiple processing modules such as a CPU, a GPU, an MPU, an ASIC, an FPGA, and a CPLD.

[0816] The communication interface 1004 is used to receive data sent externally and / or send data to the outside, and may be a wired link interface such as an Ethernet cable, or a wireless link (Wi-Fi, Bluetooth, etc.) interface. Optionally, the communication interface 1104 may also include a transmitter (such as a radio frequency transmitter, an antenna, etc.) coupled to the interface, or a receiver, etc.

[0817] The processor 1002 in the device 100 is used to read the computer program stored in the memory 1001 to execute the aforementioned association control method, for example Figure 3 or Figure 5 The described associated control method.

[0818] For example, the processor 1002 in the device 100 is used to read the computer program stored in the memory 1001, and to perform the following operations:

[0819] Determining that the identity of the first node is credible, and sending a first association request to the first node;

[0820] Receiving a first authentication request from the first node, wherein the first authentication request includes first identity authentication information;

[0821] Verifying the first identity authentication information according to a shared key between the second node and the first node; wherein the shared key is a secret value shared between the first node and the second node;

[0822] If the verification of the first identity authentication information is successful, a first authentication response is sent to the first node, wherein the first authentication response includes second identity authentication information; wherein the second identity authentication information is generated according to the shared key.

[0823] In the embodiment of the present application, after confirming that the identity of the first node is credible, the above-mentioned device 100 sends a first association request to the first node. Then, according to the first identity authentication information in the first authentication request, the identity authentication information of the first node is verified by a shared key, and after the verification is passed, the second identity authentication information is sent to the first node, and the second identity authentication information can be used by the first node to verify the identity of the above-mentioned device 100. It can be seen that after confirming that the identity is credible, the identity authentication of both parties must be passed before association can be performed, so that it is difficult for an attacker to bypass the identity authentication of the above-mentioned device 100 by modifying the identity such as the identification, thereby avoiding the above-mentioned device 100 from establishing an association with an illegal attacker, and improving the data security of the above-mentioned device 100.

[0824] In yet another possible implementation, the processor 1002 is further configured to:

[0825] Determining that the identifier of the first node is in a second whitelist;

[0826] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0827] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0828] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0829] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the above device 100 can be controlled not to send an association request to an untrusted first node, thereby avoiding the above device 100 from establishing an association with an illegal attacker and improving the data security of the above device 100.

[0830] In yet another possible implementation, the processor 1002 is further configured to:

[0831] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0832] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0833] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0834] In yet another possible implementation, the first authentication request further includes first integrity verification data, and the first integrity verification data is used to verify the message integrity of the first authentication request;

[0835] The processor is further configured to determine whether a message integrity check of the first authentication request passes.

[0836] It can be seen that after confirming that the identity of the first node is credible, in addition to identity authentication, it is also necessary to perform an integrity check on the message carrying the identity authentication information to prevent the content in the first authentication request from being tampered with by an attacker, thereby affecting the verification of the identity authentication information of the first node, thereby ensuring the stable operation of the services provided by the above-mentioned device 100.

[0837] In yet another possible implementation, the processor 1002 is further configured to:

[0838] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0839] It can be seen that the second association threshold is preset in the above-mentioned device 100. When the number of associated nodes is less than or equal to the preset second association threshold, the association request can be sent to the first node. The second threshold can limit the number of nodes that the above-mentioned device 100 can associate with. When the second association threshold is exceeded, the above-mentioned device 100 can no longer associate with other nodes, so as to avoid affecting the communication of other nodes associated with the above-mentioned device 100, thereby ensuring the stable operation of the service provided by the above-mentioned device 100.

[0840] In yet another possible implementation, the processor 1002 is further configured to:

[0841] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0842] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the above-mentioned device 100, the above-mentioned device 100 receives a first association response from the first node, and the association response is used to indicate that the first node establishes an association with the second node. Further, the first response message can inform the above-mentioned device 100 that the association has been successful and subsequent communication can be carried out.

[0843] In yet another possible implementation, the processor 1002 is further configured to:

[0844] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0845] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the above-mentioned device 100.

[0846] In yet another possible implementation, the processor 1002 is further configured to:

[0847] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0848] It can be seen that if the identity authentication information of the first node fails to be verified, the device 100 updates the number of failed verifications of the first node, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the association control of the device 100 by modifying the identity such as the identifier, thereby avoiding the device 100 from establishing an association with an illegal attacker, and improving the data security of the device 100.

[0849] In yet another possible implementation, the processor 1002 is further configured to:

[0850] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0851] Adding the identifier of the first node to the second blacklist.

[0852] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the above-mentioned device 100 from establishing an association with an illegal attacker, and improving the data security of the above-mentioned device 100.

[0853] In yet another possible implementation, the validity period of the second blacklist is a predefined or configured second duration.

[0854] It can be seen that there is a predefined or configured second duration in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second duration of the blacklist can be 10 days, and the identifier of a first node can be removed from the blacklist after being added to the blacklist for 10 days.

[0855] In yet another possible implementation, the processor 1002 is further configured to:

[0856] determining that the value of the second authentication failure counter is less than a second threshold,

[0857] A second association request is sent to the first node.

[0858] It is understandable that, during the authentication process, the authentication information may fail due to the loss or transmission error of certain parameters during the transmission process. Therefore, if the number of authentication failures for the first node has not exceeded the preset second threshold, an association request may be resent to the first node to request association with the first node, thereby improving the robustness of the system and ensuring the stable operation of the service provided by the above-mentioned device 100. In another possible implementation, the processor 1002 is further used to:

[0859] Determining that the value of the second authentication failure counter is less than a second threshold;

[0860] Obtaining third confirmation indication information;

[0861] A second association request is sent to the first node.

[0862] It can be seen that before resending the second association request, confirmation indication information needs to be obtained. The third confirmation indication information can be indication information obtained according to the confirmation operation input by the user, and the confirmation operation can be a confirmation of the output prompt information. For example, a prompt information can be output to remind the user that the verification failed and the association request needs to be re-initiated. After receiving the user's confirmation operation and obtaining the third confirmation indication information, the second association request is sent to the first node. In this way, the user verifies the identity of the first node that needs to be re-associated, which can avoid associating with an untrusted node and ensure the security of communication.

[0863] In yet another possible implementation, the processor 1002 is further configured to:

[0864] If the time that the identifier of the first node is added to the second blacklist exceeds a second duration, the identifier of the first node is removed from the second blacklist, and the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist and the type of the first node.

[0865] The above implementations illustrate factors related to the validity period of the second blacklist. On the one hand, the validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. The more times a first node is added to the second blacklist, the longer it will stay in the second blacklist. Further, optionally, when the number of times it is added to the second blacklist exceeds a certain threshold, it may be permanently added to the second blacklist.

[0866] On the other hand, the validity period of the second blacklist may be related to the device type to which the first node belongs. Specifically, the first node may pre-acquire the device type of the first node and determine different validity periods of the second blacklist according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the first node belongs to a smart cockpit controller CDC, a virtual reality device AR, etc., it can be considered a low-risk device. If the first node belongs to a server, a computer, etc., it can be considered a high-risk device. The validity period of the blacklist for high-risk devices is longer than that for low-risk devices. In addition, the above-mentioned device 100 can also pre-define the validity period of the blacklist corresponding to the first node, which will not be repeated here.

[0867] In yet another possible implementation, if the identity of the first node is not trustworthy, the step of sending the first association request to the first node is not performed.

[0868] It can be seen that if the identity of the first node is not credible, no identity authentication request will be sent to the first node to avoid wasting node resources.

[0869] It should be noted that the specific implementation of each module can also refer to Figure 3 or Figure 5 The communication device 100 may be Figure 3 or Figure 5 The second node in the embodiment shown.

[0870] See also Fig.11 , Fig.11 1 is a schematic diagram of the structure of an association control device 110 provided in an embodiment of the present application. The device 110 may be a node or a device in a node, such as a chip or an integrated circuit. The device 110 may include a communication unit 1101 and a processing unit 1102. The description of each unit is as follows:

[0871] The communication unit 1101 is configured to receive a first association request from a second node;

[0872] The processing unit 1102 is configured to determine that the identity of the second node is credible, and send a first authentication request to the second node through the communication unit 1101, where the first authentication request includes first integrity check data;

[0873] The communication unit 1101 is further configured to receive a first authentication response from the second node, wherein the first authentication response includes second integrity check data;

[0874] The processing unit 1102 is further configured to verify the message integrity of the first authentication response according to the second integrity verification data;

[0875] The processing unit 1102 is further configured to update a first authentication failure counter if verification of the message integrity of the first authentication response fails, wherein the first authentication failure counter represents the number of authentication failures for the second node.

[0876] In the embodiment of the present application, after confirming that the identity of the second node is credible, the above-mentioned device also needs to perform message integrity verification on the authentication response message from the second node before association. If the message integrity verification fails, the number of verification failures is updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, thereby preventing attackers from tampering with data in the authentication process (such as identity authentication information), thereby avoiding the above-mentioned device from establishing association with illegal attackers, and improving the data security of the above-mentioned device.

[0877] In a possible implementation manner, the processing unit 1102 is specifically configured to:

[0878] Determining that the identifier of the second node is in the first whitelist;

[0879] Alternatively, determining that the identifier of the second node is not in the first blacklist;

[0880] Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist;

[0881] Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist.

[0882] The above device controls the node requesting association according to the blacklist or whitelist, thereby eliminating the need to authenticate the identity of the untrustworthy second node, avoiding the node from establishing association with an illegal attacker, and improving the data security of the node.

[0883] In a possible implementation manner, the processing unit 1102 is specifically configured to:

[0884] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the second node is in the first whitelist;

[0885] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the second node is in the first whitelist;

[0886] If the identifier of the second node is not in the first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not in the first whitelist, obtain first confirmation indication information, and the first confirmation indication information indicates that the identity of the second node is credible.

[0887] In yet another possible implementation, the processing unit 1102 is further configured to:

[0888] It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

[0889] It can be seen that the first association threshold is preset in the above device, and the association request from the second node can be received only when the number of associated nodes is less than or equal to the preset first association threshold. The first threshold can limit the bearing capacity of the service that the above device can provide. When the first association threshold is exceeded, the above device can no longer receive or process the association request, so as to avoid affecting the communication of other nodes associated with the above device, thereby ensuring the stable operation of the service provided by the above device.

[0890] In yet another possible implementation, the processing unit 1102 is further configured to:

[0891] If the integrity of the first authentication response is verified, verifying the second identity authentication information according to the shared key between the second node and the second node;

[0892] If the verification of the second identity authentication information fails, a first authentication failure counter is updated, where the first authentication failure counter represents the number of verification failures for the second node.

[0893] It can be seen that after the above device confirms that the identity of the second node is credible, if the integrity verification passes, the identity of the second node is verified according to the shared key with the second node. If the verification fails, the number of verification failures is updated, and the number of verification failures can be used to subsequently determine whether the identity of the second node is credible, so that nodes that fail to pass verification multiple times can no longer be determined as credible. For nodes that are not confirmed as credible, their association requests can no longer be processed (such as sending authentication requests), thereby preventing the node from crashing due to processing a large number of requests and ensuring the normal operation of the service.

[0894] In yet another possible implementation, the communication unit 1101 is further configured to:

[0895] If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

[0896] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, a first association response can be sent to the second node, and the association response is used to instruct the above device to establish an association with the second node. Further, the first response message can be used to inform the second node that the association has been successful and communication can be carried out.

[0897] In yet another possible implementation, the processing unit 1102 is further configured to:

[0898] If the verification of the second identity authentication information is successful, the first authentication failure counter is reset.

[0899] It can be seen that after confirming that the identity of the second node is credible, if the identity authentication is passed, the number of authentication failures for the second node needs to be reset to avoid affecting the subsequent determination of the identity of the second node and ensure the stable operation of the services provided by the above device.

[0900] In yet another possible implementation, the processing unit 1102 is further configured to:

[0901] Determine that the value of the first authentication failure counter is greater than or equal to a first threshold, and add the identifier of the second node to the first blacklist.

[0902] It can be seen that if the number of verification failures for the second node exceeds the preset first threshold, it indicates that the second node has failed verification for multiple times, and the second node may be an attacker who frequently sends association requests, so the identifier of the second node is added to the blacklist. After being added to the blacklist, the identity of the second node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0903] In another possible implementation, the validity period of the first blacklist is a predefined or configured first duration.

[0904] It can be seen that the first blacklist has a predefined or configured first duration, which can be regarded as the validity period of the blacklist. For example, the first duration of the blacklist can be one week, and the identifier of a second node can be removed from the blacklist after being added to the blacklist for one week.

[0905] In yet another possible implementation, the processing unit 1102 is further configured to:

[0906] If the time that the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist, and the first duration is related to at least one of the number of times the identifier of the second node is added to the first blacklist and the type of the second node.

[0907] The above-mentioned implementation method illustrates factors related to the validity period of the first blacklist. On the one hand, the validity period of the first blacklist may be related to the number of times a second node joins the first blacklist. The more times a second node joins the first blacklist, the longer it stays in the first blacklist. Further, optionally, when the number of times it is added to the first blacklist exceeds a certain threshold, it may be permanently added to the first blacklist.

[0908] On the other hand, the validity period of the first blacklist may be related to the device type to which the second node belongs. Specifically, the second node may obtain the device type of the second node in advance, and determine different blacklist validity periods according to different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, a speaker, etc., it can be considered a low-risk device. If the second node belongs to a mobile phone, a computer, etc., it can be considered a high-risk device. The blacklist validity period of high-risk devices is longer than that of low-risk devices. In addition, the first node can also pre-define the blacklist validity period corresponding to the second node, which will not be repeated here. In another possible implementation, if the identity of the second node is not trustworthy, the step of sending the first authentication request to the second node is not performed.

[0909] It can be seen that if the identity of the second node is not credible, the subsequent identity authentication steps will not be performed, so as to avoid wasting the resources of the above device and affecting the normal association of other nodes.

[0910] It should be noted here that the division of the above-mentioned multiple units is only a logical division based on function, and does not serve as a limitation on the specific structure of the device 110. In a specific implementation, some of the functional modules may be subdivided into more small functional modules, and some functional modules may be combined into one functional module, but no matter whether these functional modules are subdivided or combined, the general process executed by the device 110 in the process of association control is the same. For example, the above-mentioned communication unit can also be transformed into a receiving unit and a sending unit, and the receiving unit is used to implement the function of receiving messages in the communication unit, and the sending unit is used to implement the function of sending messages in the communication unit. Usually, each unit corresponds to its own program code (or program instruction), and when the program code corresponding to each of these units runs on the processor, the unit executes the corresponding process to implement the corresponding function.

[0911] It should be noted that the implementation of each unit can also refer to Figure 6 The device 110 can be Figure 6 The first node in the embodiment shown.

[0912] See also Fig.12 , Fig.121 is a schematic diagram of the structure of an association control device 120 provided in an embodiment of the present application. The device 120 may be a node or a device in a node, such as a chip or an integrated circuit. The device 120 may include a processing unit 1201 and a communication unit 1202. The description of each unit is as follows:

[0913] The processing unit 1201 is configured to determine that the identity of the first node is credible, and send a first association request to the first node through the communication unit 1202;

[0914] The communication unit 1202 is further configured to receive a first authentication request from the first node, wherein the first authentication request includes first identity authentication information and first integrity check data;

[0915] The processing unit 1201 is further configured to verify the message integrity of the first authentication request according to the first integrity verification data;

[0916] The communication unit 1202 is further configured to send a first authentication response to the first node if the message integrity verification of the first authentication request passes, wherein the first authentication response includes second integrity verification data.

[0917] In an embodiment of the present application, after confirming that the identity of the second node is credible, the above-mentioned device also needs to authenticate the first node before communicating (for example, through identity verification information, etc.). In order to prevent attackers from tampering with data in the authentication process, it is necessary to first perform message integrity verification on the first authentication request. If the message integrity verification passes, it is allowed to associate with the first node, thereby preventing attackers from tampering with the message content, thereby avoiding the node from establishing an association with an illegal attacker, and improving the data security of the node.

[0918] In a possible implementation manner, the processing unit 1201 is specifically configured to:

[0919] Determining that the identifier of the first node is in a second whitelist;

[0920] Alternatively, determining that the identifier of the first node is not in the second blacklist;

[0921] Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist;

[0922] Alternatively, second confirmation indication information is obtained, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist.

[0923] In the above method, the associated nodes can be controlled by a blacklist or a whitelist, and the above device can be controlled not to send an association request to an untrusted first node, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the above device.

[0924] In yet another possible implementation, the processing unit 1201 is specifically configured to:

[0925] If the type of the shared key between the first node and the second node is a pre-configured type, determining that the identifier of the first node is in the second whitelist;

[0926] If the type of the shared key between the first node and the second node is a password generation type, determining that the identifier of the first node is in the second whitelist;

[0927] If the identifier of the first node is not in the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not in the second whitelist, obtain second confirmation indication information, and the second confirmation indication information indicates that the identity of the second node is credible.

[0928] In yet another possible implementation, the processing unit 1201 is further configured to:

[0929] It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

[0930] It can be seen that the above device is preset with a second association threshold, and the association request can be sent to the first node only when the number of associated nodes is less than or equal to the preset second association threshold. The second threshold can limit the number of nodes that the above device can associate with, and when the second association threshold is exceeded, the above device can no longer associate with other nodes, so as to avoid affecting the communication of other nodes associated with the device, thereby ensuring the stable operation of the service provided by the above device.

[0931] In yet another possible implementation, the communication unit 1202 is further configured to:

[0932] A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

[0933] It can be seen that after confirming that the identity of the first node is credible, if the first node passes the identity authentication of the second node, the above-mentioned device can receive a first association response from the first node, and the association response is used to indicate that the above-mentioned device has established an association with the second node. Further, the first response message can inform the above-mentioned device that the association has been successful and subsequent communication can be carried out.

[0934] In yet another possible implementation, the processing unit 1201 is further configured to:

[0935] A second authentication failure counter is reset, where the second authentication failure counter represents the number of authentication failures for the first node.

[0936] It can be seen that after confirming that the identity of the first node is credible, if the identity authentication is passed, the number of verification failures for the first node needs to be reset to avoid affecting the subsequent determination of the identity of the first node, thereby ensuring the stable operation of the services provided by the above device.

[0937] In yet another possible implementation, the processing unit 1201 is further configured to:

[0938] If the verification of the message integrity of the first authentication response fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of authentication failures for the first node.

[0939] Generally speaking, if the message integrity verification of the first authentication response fails, it means that the first authentication response message is no longer complete or has been modified by an attacker. Therefore, the number of verification failures for the first node is updated, and the number of verification failures can be used to subsequently determine whether the identity of the first node is credible.

[0940] In another possible implementation, the first authentication request message also includes first identity authentication information, and the processing unit 1201 is further configured to verify the first identity authentication information according to a shared key between the first node and the first authentication response message if the message integrity verification of the first authentication response passes;

[0941] The communication unit 1202 is further configured to send the first authentication response to the first node if the verification of the first identity authentication information is successful.

[0942] It can be seen that after confirming that the identity of the first node is credible, if the integrity verification passes, the identity of the first node is verified based on the shared key with the first node. This makes it difficult for an attacker to bypass the association control of the above device by modifying the identity such as the identifier, thereby avoiding the node from establishing an association with an illegal attacker and improving the data security of the node.

[0943] In yet another possible implementation, the processing unit 1201 is further configured to:

[0944] If the verification of the first identity authentication information fails, a second authentication failure counter is updated, where the second authentication failure counter represents the number of verification failures for the first node.

[0945] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of failed verifications of the first node, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible, so that nodes that fail to pass multiple verifications can no longer be determined to be credible. For nodes that are not confirmed to be credible, association requests can no longer be sent to them, thereby ensuring that the services provided by the nodes are carried out normally. In another possible implementation, the processing unit 1201 is also used to:

[0946] determining that the value of the second authentication failure counter is greater than or equal to a second threshold,

[0947] Adding the identifier of the first node to the second blacklist.

[0948] It can be seen that if the number of verification failures for the first node exceeds the preset second threshold, it indicates that the first node has failed verification for multiple times, and the first node may be an attacker who frequently sends authentication requests, so the identifier of the first node is added to the blacklist. After being added to the blacklist, the identity of the first node will not be determined as credible, thereby avoiding the above-mentioned device from establishing an association with an illegal attacker and improving the data security of the node.

[0949] In yet another possible implementation, the validity period of the second blacklist is a predefined or configured second duration.

[0950] It can be seen that there is a predefined or configured second duration in the second blacklist, which can be regarded as the validity period of the blacklist. For example, the second duration of the blacklist can be 10 days, and the identifier of a first node can be removed from the blacklist after being added to the blacklist for 10 days.

[0951] In yet another possible implementation, the processing unit 1201 is further configured to determine that the value of the second authentication failure counter is less than a second threshold;

[0952] The communication unit is further configured to send a second association request to the first node.

[0953] It can be seen that if the identity authentication information of the first node fails to be verified, the above device updates the number of failed verifications of the first node, and the number of failed verifications can be used to subsequently determine whether the identity of the node is credible. This makes it difficult for an attacker to bypass the first node's association control over it by modifying the identity such as the identifier, thereby avoiding the above device from establishing an association with an illegal attacker and improving the data security of the node.

[0954] In yet another possible implementation, the processing unit ...

Claims

1. A method for association control, characterized in that: include: receiving a first association request from a second node; Determining that the identity of the second node is credible, sending a first authentication request to the second node, where the first authentication request includes first identity authentication information, where the first identity authentication information is generated according to a shared key between the first node and the second node; receiving a first authentication response from the second node, wherein the first authentication response includes second identity authentication information; Verifying the second identity authentication information according to the shared key; If the verification of the second identity authentication information fails, updating a first authentication failure counter, where the first authentication failure counter represents the number of verification failures for the second node; When the value of the first authentication failure counter is greater than or equal to a first threshold, the identifier of the second node is added to a first blacklist.

2. The method according to claim 1, characterized in that The determining that the identity of the second node is credible includes: Determining that the identifier of the second node is in the first whitelist; Alternatively, determining that the identifier of the second node is not in the first blacklist; Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist; Alternatively, obtaining first confirmation indication information, wherein the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist; Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible.

3. The method according to claim 1, characterized in that The first authentication response also includes second integrity verification data, and the second integrity verification data is used to verify the message integrity of the first authentication response; the method also includes: Determine that the message integrity check of the first authentication response passes.

4. The method according to claim 1, characterized in that The first authentication response also includes second integrity verification data, and the second integrity verification data is used to verify the message integrity of the first authentication response; the method also includes: If the verification of the message integrity of the first authentication response fails, the first authentication failure counter is updated.

5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

6. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

7. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: When the message integrity check of the first authentication response passes and the verification of the second identity authentication information passes, the first authentication failure counter is reset.

8. The method according to any one of claims 1 to 4, characterized in that: The validity period of the first blacklist is a predefined or configured first duration.

9. A method of association, characterized in that: include: Determining that the identity of the first node is credible, and sending a first association request to the first node; Receiving a first authentication request from the first node, wherein the first authentication request includes first identity authentication information; Verifying the first identity authentication information according to a shared key between the second node and the first node; If the verification of the first identity authentication information is successful, a first authentication response is sent to the first node, wherein the first authentication response includes second identity authentication information; wherein the second identity authentication information is generated according to the shared key; If the verification of the first identity authentication information fails, updating a second authentication failure counter, where the second authentication failure counter represents the number of verification failures for the first node; When the value of the second authentication failure counter is greater than or equal to a second threshold, the identifier of the first node is added to a second blacklist.

10. The method according to claim 9, characterized in that The determining that the identity of the first node is credible includes: Determining that the identifier of the first node is in a second whitelist; Alternatively, determining that the identifier of the first node is not in the second blacklist; Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist; Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist; Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible.

11. The method according to claim 9, characterized in that The first authentication request also includes first integrity verification data, and the first integrity verification data is used to verify the message integrity of the first authentication request; the method also includes: Determine that a message integrity check of the first authentication request passes.

12. The method according to any one of claims 9 to 11, characterized in that: Before determining that the identity of the first node is credible and sending the first association request to the first node, the method further includes: It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

13. The method according to any one of claims 9 to 11, characterized in that: The method further comprises: A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

14. The method according to any one of claims 9 to 11, characterized in that: The method further comprises: When the verification of the first identity authentication information is successful, the second authentication failure counter is reset.

15. The method according to any one of claims 9 to 11, characterized in that: The validity period of the second blacklist is a predefined or configured second time period.

16. The method according to any one of claims 9 to 11, characterized in that: If the verification of the first identity authentication information fails, after updating the second authentication failure counter, the method further includes: When the value of the second authentication failure counter is less than a second threshold, a second association request is sent to the first node.

17. An association control device, characterized in that: include: A communication unit, configured to receive a first association request from a second node; a processing unit, configured to determine that the identity of the second node is credible, and send a first authentication request to the second node through the communication unit, wherein the first authentication request includes first identity authentication information, and the first identity authentication information is generated according to a shared key between the first node and the second node; The communication unit is further configured to receive a first authentication response from the second node, wherein the first authentication response includes second identity authentication information; The processing unit is further used for: Verifying the second identity authentication information according to the shared key; If the verification of the second identity authentication information fails, updating a first authentication failure counter, where the first authentication failure counter represents the number of verification failures for the second node; When the value of the first authentication failure counter is greater than or equal to a first threshold, the identifier of the second node is added to a first blacklist.

18. The device according to claim 17, characterized in that The processing unit is specifically used for: Determining that the identifier of the second node is in the first whitelist; Alternatively, determining that the identifier of the second node is not in the first blacklist; Alternatively, obtaining first confirmation indication information, where the first confirmation indication information indicates that the identity of the second node is credible, wherein the identifier of the second node is not in the first blacklist; Alternatively, obtaining first confirmation indication information, wherein the first confirmation indication information indicates that the identity of the second node is credible; wherein the identifier of the second node is not in the first blacklist and is not in the first whitelist; Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible.

19. The device according to claim 17, characterized in that The first authentication response also includes second integrity verification data, where the second integrity verification data is used to verify the message integrity of the first authentication response; The processing unit is specifically used for: Determine that the message integrity check of the first authentication response passes.

20. The device according to claim 17, characterized in that The first authentication response also includes second integrity verification data, and the second integrity verification data is used to verify the message integrity of the first authentication response; the processing unit is further used to: If the verification of the message integrity of the first authentication response fails, the first authentication failure counter is updated.

21. The device according to any one of claims 17 to 20, characterized in that The processing unit is further used for: It is determined that a first association quantity is less than or equal to a preset first association threshold, wherein the first association quantity represents the number of currently associated nodes.

22. The device according to any one of claims 17 to 20, characterized in that The communication unit is further used for: If the verification of the second identity authentication information is successful, a first association response is sent to the second node, where the first association response is used to instruct the first node to establish an association with the second node.

23. The device according to any one of claims 17 to 20, characterized in that The processing unit is further configured to: reset the first authentication failure counter if the verification of the second identity authentication information is successful.

24. The device according to any one of claims 17 to 20, characterized in that The validity period of the first blacklist is a predefined or configured first duration.

25. An association control device, characterized in that: include: A processing unit determines that the identity of the first node is credible, and sends a first association request to the first node through a communication unit; The communication unit is further configured to receive a first authentication request from the first node, wherein the first authentication request includes first identity authentication information; The processing unit is further used to verify the first identity authentication information according to the shared key between the second node and the first node; The communication unit is further configured to send a first authentication response to the first node if the verification of the first identity authentication information is successful, wherein the first authentication response includes second identity authentication information; wherein the second identity authentication information is generated according to the shared key; The processing unit is also used for: If the verification of the first identity authentication information fails, updating a second authentication failure counter, where the second authentication failure counter represents the number of verification failures for the first node; When the value of the second authentication failure counter is greater than or equal to a second threshold, the identifier of the first node is added to a second blacklist.

26. The device according to claim 25, characterized in that The processing unit is specifically used for: Determining that the identifier of the first node is in a second whitelist; Alternatively, determining that the identifier of the first node is not in the second blacklist; Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible, wherein the identifier of the first node is not in the second blacklist; Alternatively, obtaining second confirmation indication information, where the second confirmation indication information indicates that the identity of the first node is credible; wherein the identifier of the first node is not in the second blacklist and is not in the second whitelist; Alternatively, first confirmation indication information is obtained, where the first confirmation indication information indicates that the identity of the second node is credible.

27. The device according to claim 25, characterized in that The first authentication request also includes first integrity verification data, where the first integrity verification data is used to verify the message integrity of the first authentication request; The processing unit is further used for: Determine that a message integrity check of the first authentication request passes.

28. The device according to any one of claims 25 to 27, characterized in that The processing unit is further used for: It is determined that a second association quantity is less than or equal to a preset second association threshold, wherein the second association quantity represents the number of currently associated nodes.

29. The device according to any one of claims 25 to 27, characterized in that The communication unit is further used for: A first association response is received from the first node, where the first association response is used to instruct the first node to establish an association with the second node.

30. The device according to any one of claims 25 to 27, characterized in that The processing unit is further used for: When the verification of the first identity authentication information is successful, the second authentication failure counter is reset.

31. The device according to any one of claims 25 to 27, characterized in that The validity period of the second blacklist is a predefined or configured second time period.

32. The device according to any one of claims 25 to 27, characterized in that When the value of the second authentication failure counter is less than a second threshold, The communication unit is further configured to send a second association request to the first node.

33. An association control method, characterized in that: include: receiving a first association request from a second node; Determining that the identity of the second node is credible, sending a first authentication request to the second node, where the first authentication request includes first integrity verification data; receiving a first authentication response from the second node, wherein the first authentication response includes second integrity verification data; verifying the message integrity of the first authentication response according to the second integrity verification data; If the verification of the message integrity of the first authentication response fails, updating a first authentication failure counter, where the first authentication failure counter represents the number of authentication failures for the second node; When the value of the first authentication failure counter is greater than or equal to a first threshold, the identifier of the second node is added to a first blacklist.

34. A method of association, characterized in that: include: Determining that the identity of the first node is credible, and sending a first association request to the first node; Receiving a first authentication request from the first node, wherein the first authentication request includes first integrity verification data; verifying the message integrity of the first authentication request according to the first integrity verification data; If the message integrity verification of the first authentication request passes, sending a first authentication response to the first node; If the verification of the message integrity of the first authentication request fails, updating a second authentication failure counter, where the second authentication failure counter represents the number of authentication failures for the first node; When the value of the second authentication failure counter is greater than or equal to a second threshold, the identifier of the first node is added to a second blacklist.

35. An association control device, characterized in that: include: A communication unit, configured to receive a first association request from a second node; A processing unit, configured to determine that the identity of the second node is credible, and send a first authentication request to the second node through the communication unit, wherein the first authentication request includes first integrity verification data; The communication unit is further configured to receive a first authentication response from the second node, wherein the first authentication response includes second integrity check data; The processing unit is further configured to verify the message integrity of the first authentication response according to the second integrity verification data; The processing unit is further used for: If the verification of the message integrity of the first authentication response fails, updating a first authentication failure counter, where the first authentication failure counter represents the number of authentication failures for the second node; When the value of the first authentication failure counter is greater than or equal to a first threshold, the identifier of the second node is added to a first blacklist.

36. A correlation device, characterized in that: include: A processing unit, configured to determine that the identity of the first node is credible, and send a first association request to the first node through a communication unit; The communication unit is further configured to receive a first authentication request from the first node, wherein the first authentication request includes first integrity check data; The processing unit is further configured to verify the message integrity of the first authentication request according to the first integrity verification data; The communication unit is further configured to send a first authentication response to the first node if the message integrity verification of the first authentication request passes; The processing unit is further used for: If the verification of the message integrity of the first authentication request fails, updating a second authentication failure counter, where the second authentication failure counter represents the number of authentication failures for the first node; When the value of the second authentication failure counter is greater than or equal to a second threshold, the identifier of the first node is added to a second blacklist.

37. A communication device, characterized in that: The device includes at least one processor and a communication interface, and the at least one processor is used to call a computer program stored in at least one memory, so that the device implements the method according to any one of claims 1-8, or implements the method according to any one of claims 9-16.

38. A communication device, characterized in that: The device includes at least one processor and a communication interface, and the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method as claimed in claim 33 or 34.

39. A communication system, characterized in that: include: A first node, wherein the first node comprises the apparatus according to any one of claims 17 to 24; A second node, wherein the second node comprises the apparatus according to any one of claims 25-32.

40. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program runs on one or more processors, it executes the method according to any one of claims 1-8 and 33, or implements the method according to any one of claims 9-16 and 34.

41. A vehicle, characterized in that: include: A first device for executing the method according to any one of claims 1-8 and 33, and / or a second device for executing the method according to any one of claims 9-16 and 34.

Citation Information

Patent Citations

  • A response request method and device

    CN101193068A

  • Information sharing method, terminal device, storage medium and computer program product

    CN110611905A