Key aggregation transmission method, device and medium
By using blockchain technology and key aggregation transmission methods, the network congestion and interruption problems caused by key requests in IoT networks are solved, achieving efficient and secure key distribution, reducing network communication overhead, and ensuring key security and the rational use of network resources.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-02-07
- Publication Date
- 2026-04-24
AI Technical Summary
In scenarios such as IoT with a massive number of network devices, existing technologies can cause network congestion and service interruptions due to excessive network resource consumption when faced with a large number of key requests.
By introducing blockchain technology and adopting a key aggregation transmission method, the blockchain sends aggregation instructions to the gateway device. The gateway device generates and transmits the aggregated key to the key-consuming device. The aggregated key contains key fragments from multiple key-consuming devices, realizing centralized processing and distribution of keys, reducing point-to-point parallel distribution, and lowering network resource consumption.
Without affecting transmission efficiency, it improves key provision efficiency, ensures the rational use of network resources, avoids network congestion and business interruption, and enhances the security of key transmission.
Smart Images

Figure CN116388969B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network technology, and in particular to a key aggregation and transmission method.
[0002] Blockchain, gateway devices, key-consuming devices, and computer-readable storage media. Background Technology
[0003] In scenarios with massive numbers of network devices, such as IoT devices, traditional networks distribute device keys point-to-point, using a one-time pad cryptographic mechanism to ensure key security. However, given the characteristic of massive IoT devices consuming a large number of keys instantaneously during business operations, when a large number of IoT devices concurrently request keys within the network domain, network congestion can easily occur due to bandwidth limitations, leading to business interruptions. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a key aggregation and transmission method, a blockchain, a gateway device, a key consumption device, and a computer-readable storage medium, so as to solve the problem of excessive network resource consumption and business interruption caused by a large number of key requests in the prior art.
[0005] In a first aspect, the present invention provides a key aggregation and transmission method applied to blockchain, the method comprising:
[0006] The blockchain sends an aggregation command to the gateway device, instructing it to provide the required keys for several key-consuming devices in an aggregated form.
[0007] This enables the gateway device to generate an aggregation key based on the aggregation instruction, and transmit the aggregation key to several key-consuming devices. The aggregation key includes key fragments for each of the key-consuming devices.
[0008] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0009] Secondly, the present invention provides a key aggregation transmission method applied to a gateway device, the method comprising:
[0010] The gateway device generates an aggregation key based on the aggregation command. The aggregation key includes key fragments from several key-consuming devices.
[0011] The aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys of several key-consuming devices in an aggregated form.
[0012] The gateway device transmits the aggregated key to several key-consuming devices.
[0013] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0014] Thirdly, the present invention provides a key aggregation and transmission method applied to a key consumption device, the method comprising:
[0015] The key-consuming device consumes its own key fragments from the aggregated key to obtain its own required key.
[0016] The aggregated key is generated by the gateway device according to the aggregation instruction and transmitted to several key-consuming devices. The aggregated key includes key fragments from each of the key-consuming devices.
[0017] In this process, the aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys for each key-consuming device in an aggregated form.
[0018] Fourthly, the present invention provides a blockchain, comprising:
[0019] The instruction module is used to enable the blockchain to send aggregation instructions to the gateway device. The aggregation instructions instruct the delivery of the required keys to several key-consuming devices in an aggregated form.
[0020] This enables the gateway device to generate an aggregation key based on the aggregation instruction, and transmit the aggregation key to several key-consuming devices. The aggregation key includes key fragments for each of the key-consuming devices.
[0021] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0022] Fifthly, the present invention provides a gateway device, comprising:
[0023] The aggregation module enables gateway devices to generate an aggregation key based on aggregation instructions. The aggregation key includes key fragments from several key-consuming devices.
[0024] The aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys of several key-consuming devices in an aggregated form.
[0025] The transmission module, connected to the aggregation module, enables the gateway device to transmit the aggregated key to several key-consuming devices.
[0026] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0027] Sixthly, the present invention provides a key consumption device, comprising:
[0028] The consumption module enables the key consumption device to consume its own key fragments from the aggregated key to obtain its required key.
[0029] The aggregated key is generated by the gateway device according to the aggregation instruction and transmitted to several key-consuming devices. The aggregated key includes key fragments from each of the key-consuming devices.
[0030] In this process, the aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys for each key-consuming device in an aggregated form.
[0031] In a seventh aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, it implements the key aggregation transmission method as described above.
[0032] This invention provides a key aggregation and transmission method, a blockchain, a gateway device, key consuming devices, and a computer-readable storage medium. The blockchain sends aggregation instructions to the gateway device, instructing the gateway device to provide an aggregated key to several key consuming devices. Each key consuming device then obtains its required key through the aggregated key. This breaks the one-time pad cryptographic mechanism, improving key provision efficiency. Furthermore, the blockchain manages the participation of multiple devices in the key aggregation and transmission process, ensuring key security. It can guarantee the rational use of network resources when facing a large number of key requests, avoiding network congestion and service interruptions. Attached Figure Description
[0033] Figure 1 This is a flowchart of a key aggregation and transmission method applied to blockchain according to an embodiment of the present invention;
[0034] Figure 2 This is a flowchart of a key aggregation transmission method applied to a key aggregation transmission system according to an embodiment of the present invention;
[0035] Figure 3 This is an interactive diagram of a key aggregation transmission method applied to a key aggregation transmission system according to an embodiment of the present invention;
[0036] Figure 4 This is a flowchart of another key aggregation transmission method applied to a key aggregation transmission system in an embodiment of the present invention;
[0037] Figure 5 This is a schematic diagram of the structure of a key segment in an embodiment of the present invention;
[0038] Figure 6 This is a schematic diagram of the structure of an aggregation key in an embodiment of the present invention;
[0039] Figure 7This is a flowchart of a key aggregation and transmission method applied to a gateway device according to an embodiment of the present invention;
[0040] Figure 8 This is a flowchart of a key aggregation and transmission method applied to a key consumption device according to an embodiment of the present invention;
[0041] Figure 9 This is a schematic diagram of a blockchain structure according to an embodiment of the present invention;
[0042] Figure 10 This is a schematic diagram of the structure of a gateway device according to an embodiment of the present invention;
[0043] Figure 11 This is a schematic diagram of a key consumption device in an embodiment of the present invention. Detailed Implementation
[0044] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0045] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.
[0046] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.
[0047] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.
[0048] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.
[0049] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.
[0050] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0051] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.
[0052] To facilitate understanding of this invention, we will first introduce a scenario with a massive demand for keys and the application prospects of this invention in this scenario.
[0053] In IoT (Internet of Things) scenarios with massive numbers of networked devices, a network domain contains a vast number of small IoT devices connected to a control center. Depending on the needs of different business scenarios, these numerous IoT devices continuously acquire signatures / keys from the network to carry the required business data. However, when a large number of connected devices simultaneously request signatures / keys within a network domain, network bandwidth limitations can easily lead to network congestion, preventing network devices from providing services normally and causing business interruptions.
[0054] One-Time Pad (OTP) cryptography is currently recognized as the most secure cryptographic algorithm. This algorithm requires that the key be used only once; that is, each encryption and decryption operation uses a randomly generated one-time key, and subsequent operations use a different randomly generated key. Based on the guarantee of one-time use and randomness, the OTP mechanism is considered the most secure in cryptographic theory.
[0055] Blockchain technology is a new type of underlying IT (information technology) technology that combines data storage, peer-to-peer transmission, consensus mechanisms, encryption algorithms, and smart contracts. Unlike traditional centralized data structures, data on the blockchain is shared among multiple parties involved in on-chain business through consensus algorithms, and data operations become write-only and query-only. This gives on-chain data characteristics such as decentralization, openness, independence, security, and anonymity. These characteristics ensure the security, stability, immutability, transparency, and traceability of data on the blockchain. The consensus algorithm and immutability of blockchain eliminate the need for trust mechanisms between related institutions on the chain. By introducing smart contracts, blockchain can also achieve de-humanized operation, minimizing the possibility of human intervention.
[0056] Current key generation and distribution mechanisms can easily lead to network congestion and service interruptions in scenarios with massive numbers of network devices, such as IoT. Therefore, an effective mechanism is needed to prevent service interruptions caused by excessive network resource consumption due to a large number of key requests.
[0057] Meanwhile, the current massive number of connected devices, such as IoT devices, lacks an effective and unified identity management mechanism in the network domain. If a traditional tree-structured CA (digital certificate) architecture is adopted, the sheer number of IoT devices and the different standards used by manufacturers make building a tree-structured CA verification architecture complex. This requires corresponding identity management mechanisms for different manufacturers, and in actual business operations, tree-structured CAs lack effective means to handle single points of failure, leading to service interruptions due to the inability to verify identities. Therefore, effective methods are needed to mitigate the risks of single points of failure and malicious behavior from the centralized root CA node in traditional tree-structured CA structures.
[0058] To effectively address the shortcomings of the aforementioned solutions, this invention proposes a key aggregation transmission method, as well as the structural composition of a key aggregation transmission system and the equipment comprising the key aggregation transmission system, including:
[0059] By introducing blockchain technology, distributed and unified management of network domain devices such as IoT key-consuming devices and gateway devices can be achieved. Thanks to the distributed architecture of blockchain, the problem of single point of failure in traditional tree-structured CAs can be effectively solved, and the risk of the entire network becoming untrustworthy due to malicious actions by centralized root CA nodes can be eliminated. By utilizing the de-manualization and automation characteristics of blockchain, the automatic generation and verification of identity credentials can be realized, preventing the risk of information leakage caused by the leakage of identity credentials.
[0060] The adopted key aggregation and distribution mechanism introduces a first gateway device for key security processing and a second gateway device for key aggregation and distribution in the key aggregation and distribution process. Key requests are centrally processed and aggregated for distribution. The gateway device can send the required key to a large number of network devices requesting the key in only one network communication, without the need for parallel distribution of a large number of keys point-to-point. This reduces the occupation of network resources, greatly reduces the risk of network congestion, and prevents business interruption.
[0061] In the generation of identity credentials, the smart contracts of the blockchain and the local computing power of the gateway device are used to generate the same identity credentials on the blockchain and locally, which effectively prevents the risk of identity credentials being leaked due to information transmission. In the entire process of key transmission, by introducing a large number of verification methods, randomization processes and mechanisms, malicious nodes are prevented from stealing keys during key aggregation, which largely ensures the security of key transmission in IoT and other network scenarios.
[0062] During the process of parsing the aggregated key by the key-consuming device, the aggregated key is transmitted serially, and the routing table does not fully disclose the key-consuming device. Therefore, only by possessing all the credentials and information related to the key in the blockchain, gateway device, and key-consuming device can the key be cracked and obtained. Thus, this invention reduces network communication overhead and increases the security of key transmission without affecting transmission efficiency.
[0063] The present invention will now be described in more detail with reference to the accompanying drawings and embodiments.
[0064] Example 1:
[0065] like Figure 1 As shown, Embodiment 1 of the present invention provides a key aggregation and transmission method applied to blockchain, the method comprising:
[0066] S11. The blockchain sends an aggregation command to the gateway device, instructing that several key-consuming devices provide their required keys in an aggregated form.
[0067] This enables the gateway device to generate an aggregation key based on the aggregation instruction, and transmit the aggregation key to several key-consuming devices. The aggregation key includes key fragments for each of the key-consuming devices.
[0068] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0069] Specifically, in this embodiment, as shown in... Figure 1 The method shown corresponds to the key aggregation transmission method applied to the key aggregation transmission system, such as... Figure 2 As shown, it includes:
[0070] S1. The blockchain sends an aggregation instruction to the gateway device, which instructs to provide several key-consuming devices' required keys in an aggregated form.
[0071] S2. The gateway device generates an aggregation key according to the aggregation instruction and transmits the aggregation key to several key consuming devices. The aggregation key includes the key fragments of each of the key consuming devices.
[0072] S3. Several key-consuming devices consume their respective key fragments in the aggregated key to obtain their respective required keys.
[0073] Specifically, in this embodiment, as Figure 1 The method shown can be applied to, for example Figure 3 The blockchain shown is located in a key aggregation and transmission system and participates in, for example, Figure 3The interaction flow shown includes gateway devices and key-consuming devices in the system. Gateway devices may include multiple gateway devices, and key-consuming devices include at least several key-consuming devices (key-consuming devices - 1st hop, 2nd hop... nth hop). In the example... Figure 3 The interactive flow shown includes four stages in the key aggregation transmission method applied to the key aggregation transmission system: I. Device on-chain registration stage, II. Gateway device key generation stage, III. Aggregated key generation stage, and IV. Aggregated key transmission stage. Stages III and IV are the core parts of this invention, implemented as several ( Figure 3 The diagram shows n key-consuming devices providing their respective required keys, which are provided in the form of aggregated keys. The aggregated keys are generated by the gateway device according to the instructions of the blockchain. The blockchain controls the gateway device to participate in providing keys to the key-consuming devices in the form of aggregated keys, thereby improving the efficiency of key provision and ensuring key security.
[0074] To achieve such Figure 3 The functions of stages I, II, III, and IV shown in the diagram, and the functions implemented by each component of the key aggregation transmission system are as follows:
[0075] Blockchain is used to manage the overall key aggregation and transmission process, including functions such as registering network domains, gateway devices, and key-consuming devices; generating identity credentials for gateway devices; generating one-time random keys for gateway devices; authenticating gateway devices and key-consuming devices; generating routing tables for aggregated key transmission; and verifying the accuracy of key fragments in aggregated keys.
[0076] The gateway device is mainly responsible for generating the aggregated key and sending the aggregated key to the key consuming device;
[0077] A key-consuming device is used to send a key request so that the gateway device can generate an aggregate key under the guidance of the blockchain according to the key request, and receive and parse the aggregate key to obtain the key it needs. The key-consuming device can be an IoT device or any network terminal device that requires a key in IoT or other network scenarios.
[0078] For ease of explanation later, the symbols used and their meanings are explained in Table 1 below:
[0079] Table 1. Explanation of Symbols and Their Meanings
[0080]
[0081] Optionally, such as Figure 1 In the key aggregation transmission method shown, before the blockchain sends the aggregation instruction to the gateway device, the method further includes:
[0082] The blockchain receives the second registration information.
[0083] Specifically, the second registration information is sent to the blockchain by each gateway device within the preset network domain based on its own second self-information and the first registration information.
[0084] The first registration information is sent by each key-consuming device in the preset network domain to each gateway device according to its own first self-information;
[0085] The blockchain completes the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
[0086] Optionally, such as Figure 1 In the key aggregation and transmission method shown, the blockchain completes the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information, specifically including:
[0087] The blockchain obtains the second self-information of each gateway device from the second registration information and the key consumption device identifier (DID) of each key consumption device registered with each gateway device.
[0088] Among them, DID is generated by each gateway device obtaining its own information from the first registration information and registering each key-consuming device based on its own information.
[0089] The blockchain generates a network domain identifier (NID) for a preset network domain, and generates a gateway device identifier (GID) for each gateway device by registering each gateway device based on its second self-information.
[0090] The blockchain sets up its own private storage space for each gateway device, and stores the unique identifier UID of each key-consuming device registered by each gateway device in the private storage space. The UID includes NID, GID and DID in sequence.
[0091] The blockchain sends an NID and a GID to each gateway device.
[0092] This allows each gateway device to store the UID of each key-consuming device that it has registered.
[0093] Specifically, in this embodiment, for all key-consuming devices and all gateway devices within a network domain that require keys, the first step is to register them on the blockchain by collecting device information to obtain an identifier for the subsequent key aggregation and transmission process, corresponding to, for example... Figure 3The step I of the key aggregation transmission method applied to the key aggregation transmission system, as shown, specifically includes:
[0094] Ⅰ1. All key-consuming devices within the network domain register with all gateway devices; during registration, each key-consuming device collects its own hardware information, adds a verification random number segment, packages it into a dev.hard data packet, and sends it to each gateway device. Under initialization conditions, R... V =0, dev.hard={[Hardware information related to the key-consuming device][Verification random number R]} V Specifically, this may include information such as the type of key-consuming device, device model, chip information, hardware architecture version, memory information, storage information, network chip information, motherboard information, and device management information used to identify the key-consuming device model, hardware information, and configuration. Key-consuming devices within the network domain can register with all gateway devices within the domain to ensure randomness and redundancy.
[0095] Ⅰ2. Each gateway device generates a unique key-consuming device identifier (DID) for each key-consuming device based on the hardware information in dev.hard. It is worth noting that, for the sake of device security in the subsequent key aggregation process, the DID of the same key-consuming device registered by different gateways can be randomized.
[0096] Ⅰ3. Each gateway device sends its own hardware information, initial state information, and the DID of each key-consuming device obtained during its registration to the blockchain for registration. The hardware information of each gateway device is packaged and stored in the `gateway.hard` data packet, the content of which is similar to `dev.hard`, but excluding the verification random number segment. Since device status information changes in real time with the device's operating status, the status information of each gateway device, including the initial status information at the time of registration and the subsequent current status information, is packaged and stored in the `gateway.status` data packet. This status information can include the gateway device's network status within the network domain. The working status and device status are defined as follows: the network status can include basic network information such as the network domain to which the device belongs, the device's IP address, whether the device is online, and the network protocols supported / used by the device; the working status can include information indicating the device's working status such as the number of blocks synchronized by the device and their hash values (default is 0 when the device is registered), the number of key aggregation transmissions and their start and end timestamps (default is 0 when the device is registered); the device status can include information indicating the device's operating status such as the number of devices in the network domain to which the device belongs (default is 0 when the device is registered), whether the current operating status of each module of the device is normal, and the hash value of random blocks from the blockchain (default is 0 when the device is registered).
[0097] Ⅰ4. After receiving relevant information, the blockchain generates a Network Domain Identifier (NID) and a Gateway Device Identifier (GID), sends the NID and GID to the corresponding gateway device, and stores a unique identifier (UID) for each gateway device to identify the current network domain, gateway device, and key-consuming device. After receiving the hardware information, initial state information, and DID from each gateway device, the blockchain generates a workspace for that gateway device and stores the received data packets in the private storage space within the workspace, generating a UID = NID - GID - DID. The NID is used to identify the network domain information of the current device, and can be the network domain name, IP segment, etc., as long as it can uniquely identify a network domain. The GID comes from the device's hardware information gateway.hard data packet, and can be the hash digest of the data packet, extracted digest information, etc., as long as it can uniquely identify the device. A single gateway device is sufficient. The DID only needs to uniquely identify the device consuming the key; the specific identification method and format are not required. It's worth noting that because each device has different hardware information and configuration, each device's hardware information corresponds one-to-one with that device. That is, each piece of hardware information corresponds to exactly one device, and vice versa. Furthermore, the device's hardware information should not be frequently changed. If a device is repaired or replaced, the device registration process needs to be repeated to ensure information security. The blockchain can feed the generated UID back to the corresponding gateway device, and the gateway device also stores its own corresponding UID. It's also worth noting that for redundancy and randomness, a network domain must have at least two gateway devices, and these gateway devices must have the same network domain identifier (i.e., the same NID), but different gateway device information (i.e., different GID). An example of device registration information within a network domain in the blockchain is as follows:
[0098] #Network domain a:
[0099] NID = 21D26500329B84E2 / / Network Domain Identifier (NID)
[0100] dev# = [] / / Number of all devices in the domain
[0101] #Gateway device a
[0102] GID = 9739ACC2A33B1C78 / / Gateway device identifier (GID)
[0103] IP = 192.168.1.0 / / Gateway device IP address
[0104] dev# = [] / / Number of devices required to register the key with the gateway device
[0105] #Key Consumption Device a
[0106] DID = 09DD808DBF42EA69 / / Key consuming device identifier (DID)
[0107] IP = 192.168.1.1 / / Key consuming device IP address
[0108] #Key consumption device b
[0109] DID = 36AF258BF7370E64 / / Key consuming device identifier (DID)
[0110] IP = 192.168.1.2 / / Key consuming device IP address
[0111] …
[0112] #Gateway device b
[0113] GID = 3D6B69481578CBA9 / / Gateway device identifier (GID)
[0114] IP = 192.168.1.114 / / Gateway device IP address
[0115] dev# = [] / / Number of devices required to register the key with the gateway device
[0116] #Key Consumption Device a
[0117] DID = 6062255DC90585A8 / / Key Consumption Device Identifier (DID)
[0118] IP = 192.168.1.1 / / Key consuming device IP address
[0119] #Key consumption device b
[0120] DID = 4EFD9E77D10B84A7 / / Key consuming device identifier (DID)
[0121] IP = 192.168.1.2 / / Key consuming device IP address
[0122] …
[0123] #Gateway Device C
[0124] …
[0125] …
[0126] For "key consuming device b" registered in "gateway device b" within "network domain a", its UID = 21D26500329B84E2-3D6B69481578CBA9-4EFD9E77D10B84A7. For the same device, its UID in "gateway device a" within "network domain a" is 21D26500329B84E2-9739ACC2A33B1C78-36AF258BF7370E64.
[0127] At this point, the device blockchain registration process (Section I) is complete.
[0128] Optionally, such as Figure 1 In the key aggregation and transmission method shown, after the blockchain completes the registration of each gateway device based on the second self-information of each gateway device and generates the gateway device identifier (GID) for each gateway device, the method further includes:
[0129] The blockchain obtains the hardware information and initial state information of each gateway device from the second set of self-information, and generates an authentication key for each gateway device based on the hardware information and initial state information of each gateway device. ID ,
[0130] Among them, key ID It is also generated by each gateway device based on its own hardware information and initial state information;
[0131] The blockchain obtains the current status information of each gateway device based on the end message of the previous round of key aggregation and transmission process, and generates a one-time random key keyOTP for each gateway device based on the current status information of each gateway device.
[0132] Among them, keyOTP is also generated by each gateway device based on its current status information obtained from the end message of the previous round of key aggregation transmission process.
[0133] Optionally, such as Figure 1 In the key aggregation and transmission method shown, the blockchain generates an authentication key keyID for each gateway device based on the hardware information and initial state information of each gateway device, specifically including:
[0134] The blockchain calculates a first hash value of the hardware information and a second hash value of the initial state information for each gateway device, and generates a keyID for each gateway device based on the comparison result of the first hash value and the second hash value.
[0135] The blockchain obtains the current state information of each gateway device based on the end message of the previous round of key aggregation and transmission process, and generates a one-time random key keyOTP for each gateway device based on the current state information of each gateway device, specifically including:
[0136] The blockchain generates one or more blocks based on the completion message of the previous key aggregation and transmission process, and randomly selects blocks to participate in the current key aggregation and transmission process.
[0137] The block obtains the current status information of each gateway device, calculates the third hash value of the current status information of each gateway device, and generates the key of each gateway device based on the comparison result of the second hash value and the third hash value. OTP .
[0138] Specifically, in this embodiment, after the device completes the information registration on the blockchain, the blockchain and the gateway device first need to calculate the authentication key of the gateway device used for key aggregation and transmission. ID With one-time random key OTP , where key ID Used for encrypted communication between gateway devices and the blockchain, key OTP Used for carrying and parsing intermediate information of the aggregation key, corresponding to, for example Figure 3 The key aggregation transmission method shown in the key aggregation transmission system, specifically includes step II:
[0139] II.1. The blockchain and each gateway device generate their own authentication key. ID After receiving gateway.hard and gateway.status from the gateway device, the blockchain uses a hash algorithm (MD5, SHA-1, SHA-256, etc., without specific constraints) to calculate the hash value of the two data packets, generating two corresponding sets of hash values. hard With hash status Starting from the first bit of the hash value, compare each bit sequentially. hard With hash status The size of the hash, if it is in a certain position, hard >hash status If the bit is 1, then mark that bit as 1. If it is at a certain bit, hash hard ≤hash status If the value is not specified, then that bit is marked as 0. After comparing the bits as described above, a random binary string consisting of 0s and 1s is obtained. This binary string can then be used as the authentication key for the gateway device generated by the blockchain. ID The gateway device can obtain the same authentication key as the blockchain end by following the same calculation steps as described above, according to preset rules. ID This key can then be used for authentication in subsequent steps, including authentication through multi-round key aggregation transmission, and does not need to be updated if the hardware information of the gateway device remains unchanged.
[0140] II.2. The blockchain and each gateway device generate their own one-time random key for this round of key aggregation and transmission. OTP Blockchain and gateway devices can generate a one-time random key after completing a key aggregation and transmission process. OTP In this update, after the blockchain, gateway device, and key-consuming device complete a key aggregation transmission (i.e., the previous round of key aggregation transmission), the blockchain generates one or more new blocks according to preset rules. Subsequently, the gateway device and the blockchain can generate a key for the next key aggregation transmission (the upcoming round of key aggregation transmission). OTP After the blockchain completes block generation, it notifies the gateway device. Upon receiving this notification, the gateway device synchronizes the latest block information on the blockchain to update its current status information and sends the current status information, gateway.status data packet, to the blockchain. If the hardware information of the device within the domain has changed, the registration information also needs to be updated. The blockchain performs a hash operation on the updated gateway.status to obtain the corresponding hash value, compares the obtained hash value with the hash value of the gateway.status data packet before the update, and obtains a binary string, which is used as the generated key. OTP The gateway device performs the same operations as the blockchain to generate a key. OTP For both the gateway device and the blockchain, the keys they obtain... OTP They should be the same;
[0141] It's worth noting that, because each device has different hardware information and configuration, and each hardware information corresponds one-to-one with a device, the gateway device's hardware information can serve as one of the valid verification credentials for gateway device authentication using the blockchain. Since device status information changes in real time as the device operates, this status information can be used for device authentication and as a one-time key for generating auxiliary aggregation keys for transmission and parsing. Throughout the entire process of gateway device key generation or updating, whether it's the authentication key... ID Or a one-time random key OTPThe blockchain does not interact with the gateway device in any way. The blockchain relies on smart contracts to complete operations, while the gateway device implements this function based on embedded code. After key generation, no verification is required between the two. Theoretically, they should generate the same key. If a difference is found during the key aggregation and transmission process, it indicates a risk of information tampering or leakage in the gateway device's information processing. In this case, the corresponding gateway device can be marked as malicious and excluded from subsequent processes. The purpose of obtaining the key using hash value calculation is to achieve desensitization. Desensitization methods can include directly calculating the hash value, or segmenting and sampling the hash value. As long as the calculation method ensures randomness and does not disclose the specific information of the original hash value, it is considered an effective desensitization method. Furthermore, the key is not necessarily limited to binary. The gateway device can also use its own key... ID Each encrypted key consumes necessary information such as the device name, IP address, DID, and hash digest value of the hardware data packet, which is then sent to the blockchain for storage.
[0142] At this point, the key generation process for the gateway device (Section II) is complete.
[0143] Optionally, such as Figure 1 In the key aggregation transmission method shown, before the blockchain sends the aggregation instruction to the gateway device, the method further includes:
[0144] The blockchain receives the message indicating the start of the current key aggregation and transmission process.
[0145] Among them, the key aggregation transmission process start message is generated and sent by any gateway device in the preset network domain to several key consuming devices in the preset network domain;
[0146] The blockchain begins generating aggregation instructions based on the key aggregation transmission process of this round.
[0147] Optionally, such as Figure 1 In the key aggregation and transmission method shown, before the blockchain receives the start message of the current key aggregation and transmission process, the method further includes:
[0148] The blockchain sends block time thresholds and / or block quantity thresholds to all gateway devices within the preset network domain.
[0149] This ensures that when any gateway device receives key request requests at a time that reaches the block time threshold and / or at a number that reaches the block quantity threshold, it generates a message indicating the start of the current round's key aggregation transmission process.
[0150] Among them, the key request is broadcast by a number of key-consuming devices in the preset network domain to all gateway devices in the preset network domain.
[0151] Optionally, such as Figure 1 In the key aggregation transmission method shown, the gateway device includes a first gateway device and a second gateway device, and the key segment includes a first key sub-segment and a second key sub-segment;
[0152] The method specifically includes:
[0153] The blockchain sends a first aggregation instruction to a first gateway device and a second aggregation instruction to a second gateway device. The first aggregation instruction instructs the provision of first key sub-fractions from each of several key-consuming devices, and the second aggregation instruction instructs the provision of second key sub-fractions from each of several key-consuming devices, and aggregates the first and second key sub-fractions.
[0154] This allows the first gateway device to receive a first aggregation instruction, generate a set data packet based on the first aggregation instruction, and send the set data packet to the second gateway device. The set data packet includes a first key sub-fragment for each of the key-consuming devices.
[0155] This enables the second gateway device to receive the second aggregation instruction and the aggregated data packet, generate an aggregation key based on the second aggregation instruction and the aggregated data packet, and transmit the aggregation key to several key-consuming devices. The aggregation key includes a first key sub-fragment and a second key sub-fragment for each of the key-consuming devices.
[0156] This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
[0157] Optionally, such as Figure 1 In the key aggregation transmission method shown, before the blockchain sends a first aggregation instruction to the first gateway device and a second aggregation instruction to the second gateway device, the method further includes:
[0158] The blockchain randomly selects two gateway devices within a predefined network domain and compares whether the key request received by the two gateway devices is consistent.
[0159] Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain;
[0160] If they match, the two gateway devices will be designated as the first gateway device and the second gateway device, respectively. Otherwise, two new gateway devices will be selected until the key request received by the two selected gateway devices matches. Finally, the two selected gateway devices will be designated as the first gateway device and the second gateway device, respectively.
[0161] Specifically, in this embodiment, the key aggregation transmission method, including a first gateway device and a second gateway device, is applied to the key aggregation transmission system as follows: Figure 4 As shown, it includes:
[0162] S01. The blockchain sends a first aggregation instruction to the first gateway device. The first aggregation instruction instructs the provision of first key sub-fragments of each of several key consuming devices. The second aggregation instruction instructs the provision of second key sub-fragments of each of several key consuming devices and aggregates the first key sub-fragments and the second key sub-fragments.
[0163] S021. The first gateway device receives the first aggregation instruction, generates a collection data packet according to the first aggregation instruction, and sends the collection data packet to the second gateway device. The collection data packet includes a first key sub-fragment of each of the key consuming devices.
[0164] S022. The second gateway device receives the second aggregation instruction and the aggregated data packet, generates an aggregation key according to the second aggregation instruction and the aggregated data packet, and transmits the aggregation key to several key consuming devices. The aggregation key includes the first key sub-fragment and the second key sub-fragment of each of the several key consuming devices.
[0165] S03. Several key-consuming devices consume their respective first key sub-fragments and second key sub-fragments from the aggregated key to obtain their respective required keys.
[0166] Specifically, in this embodiment, as Figure 3 In the key aggregation transmission system shown, the gateway devices include at least a first gateway device (gateway device a) and a second gateway device (gateway device b). The aggregation key is generated and encrypted by the two gateway devices (a and b) according to the instructions of the blockchain, thereby further improving the security of the key. Gateway device a is mainly responsible for key security processing and is randomly selected by the blockchain in a key aggregation transmission process, marked as G. a The first key fragment to be sent is processed, and it is used to generate a set data packet for key aggregation according to the format and security requirements of the aggregated key, and then sent to gateway device b; gateway device b is mainly responsible for key aggregation and distribution, and is also randomly selected by the blockchain and labeled as G. b Upon receiving from G a After aggregating the data packets, they undergo secondary processing and concatenation to add the second key fragment to be sent, generating the final aggregated key. Routing information is then generated for each key-consuming device according to the aggregated key transmission routing table. The aggregated key and routing information are then sent to the key-consuming device. The process of one key aggregation transmission includes: Figure 3 Steps III and IV are included in the process. Step III includes the generation of a first key fragment by the first gateway device, specifically including:
[0167] III1. Several key-consuming devices that require keys broadcast key request requests to all gateway devices within a preset network domain; when a key-consuming device (the 1st to nth hop key-consuming device) needs to request a key, it can broadcast a key request to all gateway devices within the network domain. This request should include key-consuming device information and requested key information. The requested key information includes the type, quantity, and other requirements of the requested key (such as length information, radix requirements, etc.); it is worth noting that the aggregated key can ultimately be generated and transmitted in binary form. After receiving and parsing the aggregated key, the key-consuming device can restore its own key to the required radix as needed;
[0168] III2. The gateway device sends a key aggregation transmission start message to the blockchain based on the received key request. When the number of key request messages received by the gateway device reaches a set threshold, a key aggregation transmission process can begin. There are two main types of thresholds: one is a preset default block time threshold, denoted as T. B This value can be set by the blockchain, such as setting it as the maximum interval for the blockchain to generate a new block, in T. B Within a given time period, the gateway device continuously receives key request requests from key-consuming devices within the domain. If T B If the number of key request requests received by the gateway within a given time period does not reach the set block production threshold, then T can be used. B One criterion is that any gateway device sends a key aggregation transmission start message to the blockchain, initiating the key aggregation process; another is a block count threshold, denoted as N. B This value can be an empirical value, N B The system should achieve maximum performance while ensuring system stability, within a time period t after the gateway device begins receiving key request requests, and t <T B In the case where the number of key request requests received by the gateway device is greater than N B Then N B As a criterion, any gateway device sends a key aggregation transmission start message to the blockchain, and the blockchain initiates the key aggregation process based on the start message. It is worth noting that, regardless of the criterion used to start the key aggregation process, after sending the start message, the counts of all criteria are reset to zero, and the process waits for the start of the next key aggregation transmission.
[0169] III.3. The blockchain randomly selects gateway device a and gateway device b according to the start message of this round of process. After the start of this round of key aggregation, the blockchain first randomly selects two gateway devices from the gateway devices in this network domain to obtain all key request requests received by each device for this round of key aggregation (key request requests sent by each of the 1st to nth hop key consuming devices) and compares them one by one. If the key request requests received by the two devices are the same, the key generation step of this round of aggregation can begin. Otherwise, other gateway devices in the domain are selected for supplementary comparison. Gateway devices with inconsistent key request requests are marked as malicious devices and prevented from participating in subsequent processes. The two gateway devices with consistent key request requests are selected as the gateway devices participating in this key aggregation, and one of them is selected as the key security processing gateway and marked as G. a The other is a key aggregation and distribution gateway, labeled G. b ;
[0170] III.4. The blockchain sends a first aggregation instruction to gateway device a, instructing several key-consuming devices to generate their respective first key sub-fractions, and sends a second aggregation instruction to gateway device b, instructing several key-consuming devices to generate their respective second key sub-fractions, and aggregating the first and second key sub-fractions; the blockchain sends a... a and G b Send aggregation instructions in parallel to instruct G a and G b Together, generate the keys required by each of the 1-n hop key-consuming devices;
[0171] III.5. Gateway device a generates a first key sub-fragment and a parameter matrix P for parsing the first key sub-fragment for several key-consuming devices; G a Based on the key requirements collected from the key demand requests, generate the first key sub-fragment for each key-consuming device in hops 1-n; the architecture of the key fragment for each key-consuming device in the aggregate key is as follows: Figure 5 As shown, it is pre-defined in each gateway device, and it can also be agreed that each field is stored as a binary number, such as... Figure 5 In the architecture shown, each key fragment consists of four fields, each used to carry a random string (K). M ), authentication field (K) I ), key string (including first key segment key1 and second key segment key2), such as Figure 5 The first and second fields are used to fill in K. M / K I In this architecture, the order of the two is variable, and during a single key aggregation transmission process, the order is randomly determined for different key-consuming devices, and is determined by G in the key sub-segment.a Generate K M K I And key1 and fill in the first 3 fields, by G b Generate key2 and fill it into the 4th field position, G a The specific steps include:
[0172] (1)G a Based on the key request received from the key-consuming device, generate a binary key with a length shorter than the key length required by the device, and mark it as key1 as the first key sub-fragment with a length of L. K1 ;
[0173] (2)G a Use a verification random number R for each key-consuming device. V Generate your own one-time key T And record R V The key is also converted to binary form for easier subsequent use; G a Generate R for each key-consuming device V According to R V Generate a key using the hardware information in the pre-received dev.hard data packet. T ;
[0174] (3)G a Based on the randomly selected K M / K I Generate K in sequence M K I ;
[0175] If the order is "K" M -K I Then: first generate a length L M =L K1 A random binary string, used as the K sub-fragment of the aggregation key. M Segment storage, and then obtain the key consumption device identifier (DID) of each of the key consuming devices in the first gateway device. a Calculate DID using binary multiplication a ×key T ×L M The calculated result is used as the K of the key segment. I Segment storage, K I The length of the segment key is L I ;
[0176] If the order is "K" I -K MThen: First, obtain the key consumption device identifier (DID) of each of the key consumption devices on the first gateway device. a Calculate DID using binary multiplication a ×key T ×L K1 The calculated result is used as the K of the key segment. I Segment storage, K I The length of the segment key is L I Generate a length L M =L I A random binary string, used as the K sub-fragment of the aggregation key. M Segment storage;
[0177] (4) According to Figure 4 The architecture shown specifically addresses K in the sub-segments of the three generated aggregation keys. I K M Regarding the key1 field, the key1 segment of the generated key is filled into the third field mentioned above, and K I K M Fields can be ordered by K I K M or K M K I The order of these parameters is filled into the corresponding first / second field. This order serves as one of the key aggregation parameters to encrypt (de-identify) key1.
[0178] At this point, the first key sub-fragment requested by a key-consuming device is included in the processed aggregated key sub-fragment, and the sub-fragment corresponds one-to-one with the request of the key-consuming device;
[0179] G a After processing the above-mentioned aggregated key sub-fragment, a parameter matrix P is also generated for the key-consuming device to parse this first key sub-fragment. This matrix is used to inform the key-consuming device to verify the random number R. V The length of the start field of the aggregate key sub-fragment (L) M or L I (which can be uniformly labeled as L) and the sub-fragment K of the aggregation key. M K I Depending on the order of the fields, one possible step in generating this matrix is as follows:
[0180] (1) For a certain key-consuming device, take the one-time random key generated in the previous round of key aggregation and transmission process on this device. T The verification random number R used V With key fragment K M Field length L M And labeled as R respectively V'with L M ';
[0181] (2) The parameters L and R used in this round of key aggregation and transmission process V 、and K M K I The order information of the fields generates two 1×3 matrices; one possible approach is to use +1 or -1 to denote the order information K. I K M The order of the two in the key sub-fragment, if the order of the two is K. I K M If the order is +1, then the sequence information is +1; otherwise, it is -1. It's worth noting that this method of marking the order is only one possible order; it only needs to clearly represent two permutations. Here, ±1 is used as an example, but in practice it can be {±1}, {±2}, {+1,-2}, etc., without specific requirements. When generating the matrix, a reference format is matrix 1: Matrix 2: When generating two matrices, the order and format of the elements within the matrices are not specifically required, but they must at least contain the parameters L and R mentioned above. V Regarding the sequential information elements, matrices 1 and 2 mentioned above are only one possible implementation.
[0182] (3) Calculate the final parameter matrix P, using the R... V 'with L M Perform operations and processes on matrices M1 and M2, and then merge the processed matrices M1 and M2 to generate a matrix that can be recovered at the key-consuming device. Some possible methods are given below:
[0183] P = R V '·M1+L M '·M2;
[0184] P = R V '·M2+L M '·M1;
[0185] …
[0186] It is worth noting that the above is only one possible way to securely generate the parameter matrix, as long as it can ensure that the key-consuming device obtains the device verification random number R. V Enter the length of the sub-fragment corresponding to the start field of the aggregation key (L). M or L I ), and the sub-fragment K of the aggregation key M K IThe order of the fields is irrelevant; for example, if the network is secure enough, the gateway device can directly package the above parameters into a 1×3 matrix and transmit it directly without any encryption; or, a more complex method than described above can be used to generate the matrix, but the method of generating the matrix must be reversible and use a method agreed upon in advance with the key-consuming device so that the key-consuming device can obtain the relevant parameters.
[0187] Optionally, such as Figure 1 In the key aggregation transmission method shown, after the first gateway device sends the aggregated data packet to the second gateway device, the method further includes:
[0188] The blockchain receives a one-time random key from the first gateway device via the second gateway device. OTPa The first request,
[0189] Among them, key OTPa The first gateway device is used to encrypt the collection of data packets;
[0190] The blockchain sends a key to the second gateway device based on the first request. OTPa ,
[0191] So that the second gateway device can use the key OTPa Parse the collection of data packets.
[0192] Optionally, such as Figure 1 In the key aggregation transmission method shown, before the second gateway device generates the aggregation key based on the aggregated data packets, the method further includes:
[0193] The blockchain generates a routing table RT, which randomly arranges the identifiers of several key-consuming devices.
[0194] The blockchain receives a second request from the second gateway device to obtain the RT;
[0195] The blockchain sends an RT to the second gateway device based on the second request.
[0196] So that the second gateway device arranges the key fragments of several key consuming devices in the order of RT to form an aggregate key, and transmits the aggregate key to several key consuming devices in the order of RT.
[0197] Optionally, such as Figure 1 In the key aggregation and transmission method shown, the blockchain generates RT, specifically including:
[0198] Based on the key request received by the second gateway device, the blockchain obtains the Key Consumption Device Identifier (DID) of several key-consuming devices participating in this round of key aggregation and transmission process on the second gateway device. b Randomly arrange DID bTo generate RT.
[0199] Optionally, such as Figure 1 In the key aggregation and transmission method shown, the key sent by the blockchain to the second gateway device OTPa Alternatively, RT can use the authentication key of the second gateway device. IDb encryption;
[0200] Sending a key from the blockchain to the second gateway device OTPa Or after RT, the method further includes:
[0201] The blockchain receives either the sixth or seventh hash value.
[0202] The sixth hash value is obtained by the second gateway device using the key. IDb Parse key OTPa The seventh hash value is obtained by the second gateway device using keyIDb to parse RT;
[0203] The blockchain verifies the sixth or seventh hash value. If the verification fails, it sends a termination instruction to the second gateway device, indicating the end of this round of key aggregation and transmission.
[0204] This ensures that if the second gateway device receives a termination command, it terminates the current key aggregation transmission process according to the termination command; otherwise, the second gateway device continues the current key aggregation transmission process.
[0205] Specifically, in this embodiment, in G a After obtaining the first key fragment and P, P needs to be sent to several key-consuming devices in this round of key aggregation transmission, and the first key fragment needs to be sent to G. b To continue the subsequent key aggregation and transmission process, such as Figure 3 The illustrated step III also includes the generation of a second key fragment by the second gateway device, specifically including:
[0206] Ⅲ6.G a The generated parameter matrix P is sent to several key-consuming devices; it is worth noting that after the key-consuming devices receive the parameter matrix P, each of them sends it to the gateway G. a The data acquisition message is returned. Once all key-consuming devices have successfully acquired the information in this round, then G... a Notify G b Start generating the second key fragment;
[0207] Ⅲ7.G a After completing the secure processing of several aggregated key fragments, combine the processed aggregated key fragments with several R... V Packaged into a collection of data packets, using its own one-time random key. OTPaEncrypt the collection data packets and send them to the key aggregation and distribution gateway G. b ;
[0208] Ⅲ8.G b Authentication via blockchain; G b Request G from the blockchain a One-time random key OTPa Blockchain uses G b authentication key IDb For key OTPa Encrypt the data and send it to G. b G b Use the key calculated by itself IDb Decrypt the received encrypted information and recover G. a key used in this round of key aggregation and transmission process OTPa After parsing is complete, the key will be... OTPa The sixth hash value is returned to the blockchain for comparison. If the sixth hash value obtained by the blockchain comparison is the same as the sixth hash value calculated by itself, then it means that G... b Authentication succeeds; otherwise, it indicates the presence of a malicious device, and authentication fails. In this case, the blockchain indicates to G... b Terminate the current key aggregation process;
[0209] Ⅲ9.G b Using the parsed key OTPa The aggregated data packets sent by the first gateway device are parsed to recover the aggregated key fragments and R after security processing. V According to R V The keys for each of the key-consuming devices are obtained from the hardware information of the key-consuming devices received in advance. T ;
[0210] III10. The blockchain generates an aggregated key transmission routing table RT based on the key requirement request for this round of aggregated key transmission and the second gateway device. RT contains the DIDs of the key-consuming devices registered in the second gateway device. b Randomly arrange the order; the blockchain obtains the information of the key-consuming devices (hop 1-n) that issued key request requests in this round of the process, and randomly arranges them to generate the key-consuming devices in G. b DID obtained during registration b The key transmission routing table RT is formed; it is worth noting that if a key-consuming device requests multiple keys within a key aggregation period, it is considered as a request from multiple key-consuming devices, that is, the key-consuming device appears repeatedly in RT.
[0211] Ⅲ11.G bRequest RT from the blockchain, the blockchain uses the key IDb RT is encrypted and sent to G. b G b Use the key calculated by itself IDb Decrypt the received encrypted information to obtain RT;
[0212] Ⅲ12.G b Generate an aggregate key comprising a first key sub-fragment and a second key sub-fragment, including:
[0213] (1)G b Following the order in RT, G b Arrange the parsed aggregated key fragments in order, and obtain the binary sequence number n of each key-consuming device in RT. Then, find the sequence number n of each key-consuming device in G. b The corresponding DID b The information is mapped one-to-one with the aggregated key fragments;
[0214] (2)G b Based on the key request sent by each key-consuming device, it generates a binary key segment, key2, with a length shorter than the length required by the key-consuming device. The length of the key required by the key-consuming device is equal to the sum of key1 and key2. This binary key is then encrypted (de-identified) and stored. Figure 4 The fourth field, key2, of the aggregate key shown has a length of L. K2 The encryption (de-identification) method can be to use the binary sequence number n and the binary key to perform a binary multiplication operation. Thus, each key consumes the second key fragment of the device to generate;
[0215] (3)G b The aggregated key fragments are concatenated according to the order in RT. The format of the concatenated aggregated key is as follows: Figure 6 As shown, this includes n key fragments, each key fragment comprising 4 fields. Figure 6 In this context, A represents K. I B represents K M C1 represents key1, C2 represents key2, and the order of A and B is random.
[0216] (4)G b Based on the information in RT, the previous and next hop information of each key-consuming device participating in this round of key aggregation transmission is extracted, and a routing information data packet for this key-consuming device is generated. This data packet is used for subsequent aggregation key transmission, verification, and parsing steps. A routing information data packet for reference is given below:
[0217] route.info = {
[0218] ID b =[]; / / Gateway G b The GID and the current device in the gateway G b DID information generated during registration
[0219] queue = []; / / The binary sequence number n of the current device in RT.
[0220] DID b.pre = []; / / The previous hop device is in G b DID information generated during registration
[0221] DID b.next = []; / / Next-hop device in G b DID information generated during registration
[0222] L K2 =[]; / / Length of the key2 key segment of the current device}
[0223] At this point, Section III, Key Aggregation, is complete, and we can proceed to the next step, Section IV, Key Transmission.
[0224] Optionally, such as Figure 1 In the key aggregation transmission method shown, after the second gateway device generates the aggregation key based on the aggregated data packets, the method further includes:
[0225] The blockchain receives the eighth hash value.
[0226] The eighth hash value is generated and sent by the second gateway device based on the first and second key sub-fragments of each of the several key consuming devices.
[0227] The blockchain stores the eighth hash value in the private storage space of the second gateway device;
[0228] After one of the key-consuming devices consumes its own first and second key sub-fragments from the aggregated key to obtain its own required key, the method further includes:
[0229] The blockchain receives the ninth hash value.
[0230] The ninth hash value is generated and sent by a key-consuming device based on its own first and second key fragments obtained from the aggregated key.
[0231] The blockchain compares the ninth hash value with the corresponding eighth hash value to verify whether the key obtained by a key-consuming device is accurate. If it is inaccurate, a key-discarding instruction is sent to the key-consuming device.
[0232] This allows a key-consuming device to discard its own key obtained in the current key aggregation transmission process according to the discard key instruction, and to rebroadcast its own key request.
[0233] Optionally, such as Figure 1 In the key aggregation transmission method shown, after several key-consuming devices consume their respective key fragments from the aggregated key to obtain their respective required keys, the method further includes:
[0234] The blockchain receives a message indicating the end of the current key aggregation and transmission process.
[0235] Specifically, the end message of this round of key aggregation and transmission process is sent from the last hop key consuming device among the key consuming devices participating in this round of key aggregation and transmission process to the blockchain and gateway device.
[0236] Specifically, in this embodiment, in G b After obtaining the aggregated key and the routing information data packets of all key-consuming devices in this key aggregation transmission process, the system begins the subsequent key aggregation transmission process to complete key distribution and parsing, such as... Figure 3 The specific components of stage IV shown are:
[0237] IV1.G b Calculate the eighth hash value of the aggregate key and send the eighth hash value to the blockchain storage;
[0238] IV2.G b The current device's DID from the route.info data packet. b Each field corresponds one-to-one with the key-consuming device for hops 1-n, and each sends its own routing information data packet to the key-consuming device. Each routing information data packet can be used with the key-consuming device's own one-time random key. T Encryption is performed; it is worth noting that after the key-consuming device obtains the route.info data packet, it sends it to the gateway G. b The data acquisition message is returned. Once all devices have successfully acquired the information in this round of the process, then G... b The key distribution process can now begin;
[0239] IV3.G b Based on the aggregated key transmission routing table RT generated by the blockchain, the first-hop key consuming device information in RT is read, and the aggregated key is sent to it, thus starting the key distribution and parsing process;
[0240] IV4. The first-hop key-consuming device receives a key from G. b After the aggregated key is obtained, the device consumes the first-hop key from the blockchain in G. a Registered DID a This is used for subsequent parsing of the aggregated parameters of the key; it is worth noting that the key consuming device can also directly obtain its own DID on the corresponding gateway device, and can obtain it promptly after registration;
[0241] IV5. The first hop key consumes the device parsing parameter matrix P and recovers the verification random number R. V The length L of the start field of the aggregate key sub-fragment and the sub-fragment K of the aggregate key. M K I The order of the fields is restored by obtaining the inverse operation of the parameter matrix P; for example, the first-hop key-consuming device reads R used in the previous calculation. V 'with L M Based on the parameter matrix P, recover matrices M1 and M2, and obtain the parameter R from M1 and M2 according to the pre-constrained parameters. V L and the order; obtain R V Afterwards, the first-hop key consuming device consumes data based on its own dev.hard data packet and R. V The one-time random key used in this round is calculated. T In the gateway device and the key-consuming device, each obtains R... V After the dev.hard data packet is processed, keyT is calculated separately. This process does not require a blockchain; during a single round of key aggregation and transmission, G... a R V It is randomly generated by itself; the dev.hard data packet is sent by the key-consuming device, such as during registration, G. b Receive G a Sending R V The key-consuming device receives the dev.hard data packet sent by the key-consuming device. a Sending R V The dev.hard data package is collected by itself; R V The data type can be any number in any format or base; there are no specific requirements. Calculate the hash value of the dev.hard data packet after filling in the verification random number. After obtaining the hash value, perform de-identification processing on the obtained hash value. It is worth noting that the de-identification method can be to compare the calculated hash value with the unupdated R... V The binary value is obtained by comparing the previous hash value (see key generation). OTPThe method can be used to directly calculate its hash value, or the hash value can be segmented or sampled. As long as the calculation method ensures randomness and does not disclose the specific information of the original hash value, it is considered an effective desensitization method. After completing the above steps, the desensitized string is the one-time random key for the key-consuming device, marked as key. T The same key consumes the key in each round of key aggregation and transmission process of the device. T They are all different; the first-hop key consumption device obtains its own key. T Then, the encrypted routing information (route.info) data packet can be parsed to read the device information consuming the previous hop key and the device information consuming the next hop key. These are used to determine the source path of the aggregated key received by itself and the target transmission path of the remaining aggregated key after stripping its own key fragments, respectively. At the same time, the length information L of the key2 key segment of the aggregated key fragment is obtained. k2 ', and its binary sequence number n; it is worth noting that the "DID" carried in the routing information of the first-hop key consuming device. b.pre The field is empty; the last-hop key consumes the "DID" carried in the routing information of the device. b.next "The field is empty; at this point, the parameter parsing step in the key-consuming device is complete, and the key parsing step can begin; the key-consuming device begins the key parsing and acquisition steps, specifically including:"
[0242] (1) Obtain the key1 key segment, and based on the obtained aggregated key sub-segment K M K I Calculate the key1 key segment based on the order of the fields;
[0243] If the order is "K" I -K M "Analyze to find L = L I The first L of the aggregation key I The bit string corresponds to the authentication string K. I According to K I =DID a ×key T ×L M Perform the inverse operation, based on the key obtained in the previous step. T Information and DID a Information, calculation to obtain a random string K M Length L M From the Lth I Starting with +1 bit, obtain the last L of the aggregation key. M The bit string is the random string K. M From the Lth I +L MStarting from +1, obtain L. K1 The string is the key1 key segment;
[0244] If the order is "K" M -K I "Analyze to find L = L M The first L of the aggregation key M The bit string corresponds to the random string K. M From the Lth M Starting with +1 bit, obtain the last L of the aggregation key. M The bit string is the authentication string K. I According to K I =DID a ×key T ×L K1 Perform the inverse operation, based on the key obtained in the previous step. T Information and DID a Information, obtain the length L of key1 key segment. K1 From the Lth M +L I Starting from +1, obtain L. K1 The string is the key1 key segment;
[0245] (2) Obtain the key2 key segment. Based on the binary sequence information n carried in the routing information and the length of the key2 key segment, start from the Lth... I +L M +L K1 Starting from +1, obtain L. K2 The string is the processed key2 key segment. By performing the inverse binary multiplication operation between n and the obtained string, the unprocessed key2 key segment can be obtained.
[0246] (3) By concatenating the key1 key segment and the key2 key segment, the key requested by the key consuming device can be obtained in this round of key aggregation and transmission process;
[0247] IV6. After completing key concatenation, the key-consuming device verifies the authenticity and integrity of the obtained key with the blockchain. The blockchain reads the key hash digest value stored for the corresponding device and compares it with the key hash digest value obtained by the device concatenation. If they are the same, the key is accurate; otherwise, it indicates that there is a calculation or communication error, or that there is a malicious node. The blockchain can send a third instruction to the key-consuming device to discard the key, so that the key-consuming device discards its own key obtained in this round. After discarding, the key-consuming device can rebroadcast its own key request to the network.
[0248] IV3. After the first-hop key-consuming device completes its own key acquisition, it sends the aggregated key after deleting its own key fragments, according to the next-hop key-consuming device information indicated in the routing information; after receiving the aggregated key, the next-hop key-consuming device first checks the DID of the previous-hop key-consuming device that sent the aggregated key. b Is the information consistent with that from gateway G? b The "DID" in the route.info data packet b.pre "If the information matches, parsing can begin; otherwise, it indicates a system communication error, and the current process will terminate."
[0249] After the next-hop key consuming device completes the comparison, the steps IV4, IV5, and IV6 performed are the same as those of the first-hop key consuming device. After each next-hop key consuming device obtains the key it requests, it sequentially transmits the remaining aggregated key to its own next-hop key consuming device until the aggregated key is transmitted to the last-hop key consuming device.
[0250] IV7. After the last-hop key consuming device completes parsing and obtains its own key, the remaining aggregated key length is 0, the key aggregation and transmission process of this round is completed, and the last-hop key consuming device notifies the first gateway device a, the second gateway device b, and the blockchain of the end of this round of process;
[0251] After this round of the process is completed, the key-consuming device, gateway device, and blockchain can update and synchronize their one-time parameters and prepare for the next round of key aggregation and transmission. Figure 3 The process in the middle is re-executed starting from II2.
[0252] Embodiment 1 of this invention proposes a key aggregation and transmission method, which enables a blockchain-based key aggregation and parsing transmission mechanism. This mechanism includes steps such as device on-chain registration, key fragment generation, aggregated key generation, and parsing and transmission of the aggregated key in the key-consuming device. This mechanism can overcome the shortcomings of current IoT and other scenarios with massive network devices, where network congestion and service interruptions occur due to a large number of devices requesting keys concurrently. While reducing network resource consumption, it can improve the security of key transmission in multiple dimensions. The gateway device involved can be used to generate key fragments, use key fragments to generate aggregated keys, and control the transmission of aggregated keys to key-consuming devices according to routing information. Simultaneously, the gateway device also performs multi-factor authentication to ensure key security. The gateway device can be subdivided into a first gateway device and a second gateway device according to specific functions, each implementing different functions and business operations, and jointly realizing key aggregation and distribution. The proposed aggregated key divides each requested key into two segments, key1 and key2, and uses a random string K... M Authentication string K IThe positions of key1 and key2 in the aggregated key are hidden, and multiple fragments are spliced together to achieve secure and reliable key carrying.
[0253] Example 2:
[0254] like Figure 3 As shown, Embodiment 7 of the present invention provides a key aggregation transmission method, characterized in that it is applied to a gateway device, and the method includes:
[0255] S21. The gateway device generates an aggregation key according to the aggregation instruction. The aggregation key includes key fragments from several key consuming devices.
[0256] The aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys of several key-consuming devices in an aggregated form.
[0257] S22. The gateway device transmits the aggregated key to several key-consuming devices.
[0258] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0259] Optionally, before the blockchain sends the aggregation instruction to the gateway device, the method further includes:
[0260] The gateway device receives the first registration information.
[0261] The first registration information is generated by each key-consuming device within the preset network domain based on its own first self-information and a verification random number R. V The default value is sent to each gateway device within the preset network domain;
[0262] The gateway device sends its second registration information to the blockchain based on its second self-information and the first registration information.
[0263] This enables the blockchain to complete the registration of the gateway device based on the second registration information and to consume the identifier of each key that sends the first registration information to the gateway device.
[0264] Optionally, the gateway device sends second registration information to the blockchain based on its second self-information and the first registration information, specifically including:
[0265] The gateway device obtains its own information from the first registration information, completes the registration of each key-consuming device based on the first self-information, and generates a Key Consumption Device Identifier (DID) for each key-consuming device.
[0266] The gateway device obtains its own hardware information and initial state information to form second self information, and combines the second self information with the DID of each key-consuming device to form second registration information, and sends the second registration information to the blockchain;
[0267] After the gateway device sends the second registration information to the blockchain based on its second self-information and the first registration information, the method further includes:
[0268] The gateway device receives the network domain identifier (NID) of the preset network domain sent by the blockchain and the gateway device identifier (GID) of the gateway device itself, and stores the unique identifier (UID) of each key-consuming device registered with the gateway device. The UID includes the NID, GID, and DID in sequence.
[0269] Among them, NID is generated by the blockchain, GID is generated by the blockchain based on the second self information of the gateway device to complete the registration of the gateway device, and UID is also stored by the blockchain in a private storage space set up for the gateway device.
[0270] Optionally, after the gateway device receives its own GID from the blockchain, the method further includes:
[0271] The gateway device obtains its own hardware information and initial state information, and generates its own authentication key based on its hardware information and initial state information. ID ,
[0272] Among them, key ID It is also generated by the blockchain based on the hardware information and initial state information of the gateway device in the second registration information;
[0273] The gateway device obtains its current status information based on the end message of the previous round of key aggregation and transmission process, and generates its own one-time random key based on its current status information. OTP ,
[0274] Among them, key OTP It is also generated by the blockchain based on the current status information of the gateway device obtained from the end message of the previous round of key aggregation and transmission process.
[0275] Optionally, the gateway device generates its own key based on its hardware information and initial state information. ID Specifically, it includes:
[0276] The gateway device calculates a first hash value of its own hardware information and a second hash value of its initial state information, and generates its own key based on the comparison result of the first and second hash values. ID ;
[0277] The gateway device obtains its current status information based on the end message of the previous round of key aggregation and transmission process, and generates its own key based on its current status information. OTP Specifically, it includes:
[0278] The gateway device obtains its current state information based on the end message of the previous round of key aggregation and transmission process, and then sends its current state information to the blockchain.
[0279] This enables the blockchain to generate a key for the gateway device based on the received current state information of the gateway device. OTP ,
[0280] The gateway device calculates the third hash value of its current state information and generates its own key based on the comparison result between the second and third hash values. OTP .
[0281] Optionally, before the blockchain sends the aggregation instruction to the gateway device, the method further includes:
[0282] The gateway device generates a key aggregation and transmission process start message for several key-consuming devices within a preset network domain, and sends the key aggregation and transmission process start message to the blockchain.
[0283] This enables the blockchain to initiate message generation and aggregation instructions based on the current key aggregation transmission process.
[0284] Optionally, the gateway device generates a start message for the current round key aggregation and transmission process for several key-consuming devices within a preset network domain, specifically including:
[0285] The gateway device receives the block time threshold and / or block quantity threshold sent by the blockchain.
[0286] The gateway device receives key request requests broadcast by several key-consuming devices within a preset network domain that have key requirements.
[0287] When the time of the key request received by the gateway device reaches the block time threshold and / or the number of requests reaches the block number threshold, the gateway device generates a message to start the key aggregation and transmission process for this round.
[0288] Optionally, the gateway device is a first gateway device, and the key fragment includes a first key sub-fragment;
[0289] The method specifically includes:
[0290] The first gateway device receives the first aggregation instruction.
[0291] The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of several key consumption devices' respective first key sub-fragments;
[0292] The first gateway device generates a collection data packet according to the first aggregation instruction. The collection data packet includes a first key sub-fragment of each of the key consuming devices.
[0293] The first gateway device sends a collection data packet to the second gateway device.
[0294] This enables the second gateway device to receive the aggregated data packet, generate an aggregated key based on the second aggregation instruction and the aggregated data packet, and transmit the aggregated key to several key-consuming devices. The aggregated key includes a first key sub-fragment and a second key sub-fragment for each of the key-consuming devices.
[0295] Specifically, the second aggregation instruction is sent from the blockchain to the second gateway device, instructing the provision of second key sub-fragments from several key-consuming devices, and aggregating the first and second key sub-fragments.
[0296] This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
[0297] Optionally, before the first gateway device receives the first aggregation instruction, the method further includes:
[0298] The first gateway device sends the key request it received to the blockchain.
[0299] Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain;
[0300] So that, after comparing the key request received by the first gateway device and the second gateway device, the blockchain sends a first aggregation instruction to the first gateway device.
[0301] Optionally, the first gateway device generates a collection data packet according to the first aggregation instruction, specifically including:
[0302] The first gateway device obtains the key request it received after the end of the previous key aggregation transmission process and before the start of the current key aggregation transmission process according to the first aggregation instruction;
[0303] The first gateway device determines several key-consuming devices to participate in this round of key aggregation and transmission process based on the key request it receives.
[0304] The first gateway device randomly generates several sequences of length L. K1 Each of the key-consuming devices has its own first key fragment key1;
[0305] The first gateway device fills key1 with a key fragment in a preset format, and then combines several key fragments containing key1 into a set data packet.
[0306] Optionally, the first gateway device fills key1 with a key fragment in a preset format, specifically including:
[0307] The first gateway device obtains the key-consuming device identifier (DID) of each of the several key-consuming devices on the first gateway device. a It obtains the hardware information of several key-consuming devices and generates a verification random number R for each key-consuming device. V ;
[0308] The first gateway device, based on the hardware information and R of several key-consuming devices, V Generate several key consumption devices, each with its own one-time random key. T ;
[0309] The first gateway device randomly generates several keys, each consuming a random string K. M And based on the DID of each of the key-consuming devices a and key T Generate several keys, each consuming the device's own authentication string K. I ;
[0310] The first gateway device will K M K I Enter the first and second fields of the preset format key fragment in the selected order, and enter key1 in the third field.
[0311] The preset format key fragment also includes a fourth field, which is used to carry the second key sub-fragment key2 in the second gateway device.
[0312] Optionally, the first gateway device obtains hardware information of several key-consuming devices, specifically including:
[0313] The first gateway device obtains the hardware information of each of the key-consuming devices from the first registration information sent to the first gateway device by the key-consuming devices.
[0314] The first gateway device, based on the hardware information and R of several key-consuming devices, V Generating several keys consumes the key of each device. T Specifically, it includes:
[0315] The first gateway device consumes several keys, each with its own hardware information and R. V The fourth hash value is calculated by combining the hardware information of several key-consuming devices and R. VThe default value combination is used to calculate the fifth hash value. Based on the comparison result of the fourth and fifth hash values, several keys are generated, each consuming a key for its respective device. T .
[0316] Optionally, the first gateway device generates several keys, consuming the respective R of each device. V Subsequently, the method further includes:
[0317] The first gateway device will R V Send to the second gateway device.
[0318] This allows the second gateway device to obtain the hardware information of each of the key-consuming devices from the first registration information sent to the second gateway device by the key-consuming devices, and combine it with R V Generating several keys consumes the key of each device. T .
[0319] Optionally, the first gateway device randomly generates several keys, each consuming the K key of its respective device. M And based on the DID of each of the key-consuming devices a and key T Generating several keys consumes the K of each device. I Specifically, it includes:
[0320] The first gateway device randomly selects several key-consuming devices, each with their own K... M K I The order in which the first and second fields of the key fragment are filled in is: K M K I , or K I K M ;
[0321] If the selected order is: K M K I Then the first gateway device randomly generates a segment of length L for the corresponding key-consuming device. M =L K1 K M And calculate K for the corresponding key-consuming device. I =DID a ×key T ×L M To obtain a segment of length L I K I ;
[0322] If the selected order is: K I K M Then the first gateway device calculates K for the corresponding key-consuming device. I =DID a ×keyT ×L K1 To obtain a segment of length L I K I And randomly generate a segment of length L for the corresponding key-consuming device. M =L I K M .
[0323] Optionally, after the first gateway device fills key1 into a key fragment of a preset format, the method further includes:
[0324] The first gateway device generates parameter matrices P for several key-consuming devices, where P includes K for each key-consuming device. M and K I Sequence identifier, first field length L and R V ;
[0325] The first gateway device sends P to several key-consuming devices.
[0326] So that several key-consuming devices can obtain their respective key1 from the aggregate key according to P.
[0327] Optionally, the first gateway device generates several keys, each consuming the P of its respective key, specifically including:
[0328] The first gateway device obtains the K of each of the key-consuming devices in this round of key aggregation and transmission process. M and K I Sequence identifier, L and R V And obtain K from the previous round of key aggregation and transmission process. M 'Length L M '、and verify random number R V ';
[0329] The first gateway devices are arranged in different orders according to pre-constrained conditions. M and K I Sequence identifier, L, R V Form matrices M1 and M2, using L M 'and R V The operations with M1 and M2 generate several keys, each consuming the P of its respective device.
[0330] Optionally, the first gateway device sends a collection data packet to the second gateway device, specifically including:
[0331] The first gateway device sends a one-time random key to the second gateway device. OTPa Encrypted collection of data packets,
[0332] This enables the second gateway device to obtain a key from the blockchain.OTPa And based on the key OTPa Parse the collection of data packets.
[0333] Optionally, the gateway device is a second gateway device, and the key fragment includes a second key sub-fragment;
[0334] The method specifically includes:
[0335] The second gateway device receives the second aggregation command and the aggregated data packet.
[0336] Specifically, the second aggregation instruction is sent from the blockchain to the second gateway device, instructing the provision of second key sub-fragments from several key-consuming devices, and aggregating the first and second key sub-fragments.
[0337] The aggregated data packet is generated by the first gateway device after receiving the first aggregation instruction, and then sent to the second gateway device. The aggregated data packet includes several first key sub-fragments from each of the key-consuming devices.
[0338] The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of several key consumption devices' respective first key sub-fragments;
[0339] The second gateway device generates an aggregation key based on the second aggregation instruction and the aggregate data packet. The aggregation key includes a first key sub-fragment and a second key sub-fragment of each of the key consuming devices.
[0340] The second gateway device transmits the aggregated key to several key-consuming devices.
[0341] This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
[0342] Optionally, before the second gateway device receives the second aggregation instruction, the method further includes:
[0343] The second gateway device sends the key request it received to the blockchain.
[0344] Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain;
[0345] This allows the blockchain to send a second aggregation instruction to the second gateway device after comparing the key request received by the first gateway device and the second gateway device to ensure they are consistent.
[0346] Optionally, the second gateway device generates an aggregation key based on the second aggregation instruction and the aggregated data packet, specifically including:
[0347] The second gateway device obtains several key fragments based on the aggregated data packets. Each key-consuming device fills in a key fragment of the first key sub-fragment key1 in a preset format, and the length of key1 is L. K1 ;
[0348] The second gateway device randomly generates several sequences of length L according to the second aggregation instruction. K2 Each of the key-consuming devices has its own second key fragment, key2, L K1 +L K2 =L K L K Each key consumes the required key length for its respective device.
[0349] The second gateway device fills key2 into a key fragment in a preset format, and combines several key fragments containing key1 and key2 into an aggregate key.
[0350] Optionally, the second gateway device obtains several key fragments of a preset format, each filled with key1, based on the aggregated data packet. These fragments specifically include:
[0351] The second gateway device sends a one-time random key to the blockchain to obtain the first gateway device's key. OTPa The first request,
[0352] Among them, key OTPa The first gateway device is used to encrypt the collection of data packets;
[0353] The second gateway device receives the key sent by the blockchain. OTPa ;
[0354] The second gateway device uses the key. OTPa Parse the collection data packet to obtain the K values of several key-consuming devices in the collection data packet, which are filled into the first, second, and third fields in a selected order. M / K I K I / K M The key fragment in the preset format of key1.
[0355] Optionally, the second gateway device fills key2 into a key fragment of a preset format, and combines several key fragments containing key1 and key2 into an aggregate key, specifically including:
[0356] The second gateway device sends a second request to the blockchain to obtain the routing table RT.
[0357] RT is generated by the blockchain, and the identifiers of several key-consuming devices are randomly arranged in RT.
[0358] The second gateway device receives the RT sent by the blockchain;
[0359] The second gateway device uses the sequence number n of each key consumption device in RT to encrypt key2, and the encrypted result has a length of L. K2 Enter the fourth field of the key fragment in the preset format in key2;
[0360] The second gateway device arranges several key consumption devices' key fragments in the order of RT to form an aggregate key.
[0361] Optionally, the key received by the second gateway device OTPa Alternatively, RT can be used by the blockchain with the authentication key of a second gateway device. IDb encryption;
[0362] The second gateway device receives the key sent by the blockchain. OTPa Or after RT, the method further includes:
[0363] The second gateway device uses a key. IDb Parse key OTPa Obtain the sixth hash value, or use the key on the second gateway device. IDb Parse RT to obtain the seventh hash value;
[0364] The second gateway device sends the sixth or seventh hash value to the blockchain.
[0365] This allows the blockchain to verify either the sixth or seventh hash value. If the verification fails, a termination instruction for this round of key aggregation and transmission is sent to the second gateway device.
[0366] If the second gateway device receives a termination command, it terminates the current key aggregation transmission process according to the termination command; otherwise, the second gateway device continues the current key aggregation transmission process.
[0367] Optionally, the RT randomly arranges several key-consuming devices into a second gateway device's key-consuming device identifier (DID). b ;
[0368] Before the second gateway device transmits the aggregated key to several key-consuming devices, the method further includes:
[0369] The second gateway device will arrange each DID in RT. b Compared to the DID listed first b.pre and the next DID b.next Each DID b In RT, the permutation numbers n and L K2 'Combines routing information data packets;'
[0370] The second gateway device sends its respective routing information data packets to several key-consuming devices.
[0371] So that, after receiving the aggregated key, several key-consuming devices, according to DID b.pre Verify the correctness of the source of the aggregate key received by each entity, and based on n and L... K2 'Retrieve key2 from the aggregated key, and after stripping the key fragments from the received aggregated key, send the remaining aggregated key to DID.' b.next Key-consuming devices.
[0372] Optionally, the second gateway device sends its respective routing information data packets to several key-consuming devices, specifically including:
[0373] The second gateway device obtains the hardware information of each of the key-consuming devices from the first registration information sent to it by the key-consuming devices, and receives the verification random number R of each of the key-consuming devices sent by the first gateway device. V ;
[0374] The second gateway device, based on the hardware information and R of several key-consuming devices, V Generate several key consumption devices, each with its own one-time random key. T ;
[0375] The second gateway device uses a key. T Encrypt the routing information data packets and send the encrypted routing information data packets to several key-consuming devices.
[0376] So that several key-consuming devices obtain R from the first gateway device V It generates its own key by combining its own hardware information. T And based on the key T Parse the routing information data packet.
[0377] Optionally, the gateway device transmits the aggregated key to several key-consuming devices, specifically including:
[0378] The gateway device sends the aggregated key to the first-hop key-consuming device among the several key-consuming devices participating in this round of key aggregation transmission process.
[0379] This allows each hop key-consuming device among the several key-consuming devices participating in this round of key aggregation and transmission process to receive the aggregated key in sequence, and after obtaining its own key, to strip its own key fragment from the aggregated key it received, and send the remaining aggregated key to its next hop key-consuming device.
[0380] Optionally, after several key-consuming devices obtain their respective keys based on their respective key fragments, the method further includes:
[0381] The gateway device receives the end message of the current key aggregation transmission process.
[0382] Specifically, the end message of this round of key aggregation and transmission process is sent by the last hop key consuming device participating in this round of key aggregation and transmission process, after stripping its own key fragment from the aggregated key it received, and when it detects that the remaining aggregated key length is 0, to the blockchain and gateway devices.
[0383] Example 3:
[0384] like Figure 8 As shown, Embodiment 3 of the present invention provides a key aggregation and transmission method, applied to a key consumption device, the method comprising:
[0385] S31. The key-consuming device consumes its own key fragments from the aggregated key to obtain its own required key.
[0386] The aggregated key is generated by the gateway device according to the aggregation instruction and transmitted to several key-consuming devices. The aggregated key includes key fragments from each of the key-consuming devices.
[0387] In this process, the aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys for each key-consuming device in an aggregated form.
[0388] Optionally, before the blockchain sends the aggregation instruction to the gateway device, the method further includes:
[0389] The key-consuming device uses its own first self-information and verification random number R V The default value sends the first registration information to each gateway device within the preset network domain.
[0390] This allows each gateway device to send its second registration information to the blockchain based on its second self-information and first registration information.
[0391] This enables the blockchain to complete the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
[0392] Optionally, the key-consuming device uses its own first self-information and R V The default value sends the first registration information to each gateway device in the preset network domain, specifically including:
[0393] The key-consuming device obtains its own hardware information to form first self-information, and then combines the first self-information with R. VThe default values form the first registration information, and the first registration information is sent to each gateway device in the preset network domain.
[0394] This allows each gateway device to obtain its own information from the first registration information, and to complete the registration of each key-consuming device based on the first self-information, thereby generating a key-consuming device identifier (DID) for each key-consuming device. The DID is then added to the second registration information and sent to the blockchain.
[0395] This enables the blockchain to generate a network domain identifier (NID) for a preset network domain and a gateway device identifier (GID) for each gateway device, and then sends the corresponding NID and GID to each gateway device.
[0396] Optionally, before the blockchain sends the aggregation instruction to the gateway device, the method further includes:
[0397] The key-consuming device broadcasts its key request to all gateway devices within the preset network domain.
[0398] This allows any gateway device to send a key aggregation and transmission process start message to the blockchain based on the key request it receives.
[0399] This enables the blockchain to initiate message generation and aggregation instructions based on the current key aggregation transmission process.
[0400] Optionally, the key-consuming device consumes its own key fragment from the aggregated key to obtain its own required key, specifically including:
[0401] The key-consuming device receives the aggregated key;
[0402] The key-consuming device obtains its own key fragment from the aggregated key, and obtains its own key based on its own key fragment;
[0403] The key-consuming device strips its own key fragment from the aggregated key and sends the remaining aggregated key to its next-hop key-consuming device.
[0404] Optionally, the key consuming device receives the aggregated key, specifically including:
[0405] If the key-consuming device is the first-hop key-consuming device in this round of key aggregation transmission process, then the first-hop key-consuming device receives the aggregated key sent by the gateway device; otherwise, the non-first-hop key-consuming device receives the remaining aggregated key sent by the previous-hop key-consuming device.
[0406] Optionally, the gateway device includes a first gateway device and a second gateway device, and the key fragment includes a first key sub-fragment and a second key sub-fragment;
[0407] The first-hop key consuming device receives the aggregated key sent by the gateway device, specifically including:
[0408] The first-hop key-consuming device receives the aggregated key sent by the second gateway device.
[0409] The aggregation key is generated by the second gateway device after receiving the second aggregation instruction and the aggregation data packet, and then sent to the first hop key consuming device. The aggregation key includes first key sub-fragments and second key sub-fragments for each of the key consuming devices.
[0410] The second aggregation instruction is sent from the blockchain to the second gateway device, instructing it to provide the second key sub-fragments of each of the several key consuming devices, and to aggregate the first key sub-fragments and the second key sub-fragments.
[0411] The aggregated data packet is generated by the first gateway device after receiving the first aggregation instruction, and then sent to the second gateway device. The aggregated data packet includes several first key sub-fragments from each of the key-consuming devices.
[0412] The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of first key sub-fragments of each of the key-consuming devices.
[0413] Optionally, the key consuming device obtains its own key fragment from the aggregated key, and obtains its own key based on its own key fragment, specifically including:
[0414] The key-consuming device obtains its own first key fragment from the aggregated key;
[0415] The key-consuming device obtains its own second key fragment from the aggregated key;
[0416] The key-consuming device concatenates the first key fragment and the second key fragment to obtain its own key.
[0417] Optionally, before the key-consuming device obtains its own first key fragment from the aggregated key, the method further includes:
[0418] The key-consuming device receives a parameter matrix P sent by the first gateway device, where P includes the key-consuming device's own verification random number R. V The length L of the first field in the key fragment, and the random string K. M and authentication string K I Sequence identifier;
[0419] The key-consuming device obtains its own hardware information and retrieves R based on P. V And based on its own hardware information and R VGenerate your own one-time random key T .
[0420] Optionally, the key-consuming device determines the amount of key consumption based on its own hardware information and R. V Generate your own one-time random key T Specifically, it includes:
[0421] The key-consuming device will send its own hardware information and R V Combine and calculate the fourth hash value, including its own hardware information and R. V The default value combination is used to calculate the fifth hash value, and the key is generated based on the comparison result between the fourth and fifth hash values. T .
[0422] Optionally, the key consuming device obtains its own first key fragment from the aggregated key, specifically including:
[0423] The key-consuming device obtains its own Key-Consuming Device Identifier (DID) from the first gateway device. a And obtain L and K based on P. M and K I The order,
[0424] Among them, K M and K I The first or second field of a key fragment in a preset format is generated by the first gateway device and filled in according to the selected order;
[0425] Key-consuming devices based on DID a L, K M and K I The order and key T Obtain its first key fragment key1 from the aggregate key.
[0426] Optionally, the key-consuming device obtains its own R based on P. V L, K M and K I The order specifically includes:
[0427] The key-consuming device obtains its own verification random number R from the previous round of key aggregation and transmission process. V 'with random string K M 'Length L M ';
[0428] Key-consuming devices use R V 'with L M 'Analyze P to obtain matrices M1 and M2, in which R is arranged in different orders according to pre-defined constraints.' V L, K M and KI Sequence identifier;
[0429] The key-consuming device obtains its own R from M1 and M2 according to pre-constrained conditions for the current round of key aggregation and transmission process. V L, K M and K I The sequence identifier, according to K M and K I Obtaining K from the sequence identifier M and K I The order.
[0430] Optionally, the key-consuming device is based on the DID. a L, K M and K I The order and key T The first key fragment key1 is obtained from the aggregated key, specifically including:
[0431] If K M and K I The order is: K M K I Then the key-consuming device obtains a length of L starting from the first bit of the aggregated key. M =L of K M From the Lth M Starting from position +1, we obtain a length of L. I =L M K I According to K I =DID a ×key T ×L K1 The inverse operation yields the length L of key1. K1 From the Lth I +L M Starting from position +1, we obtain a length of L. K1 key1;
[0432] If K M and K I The order is: K I K M Then the key-consuming device obtains a length of L starting from the first bit of the aggregated key. I =L of K I According to K I =DID a ×key T ×L M The inverse operation of K is obtained M Length L M From the Lth I Starting from position +1, we obtain a length of L.M K M From the Lth I +L M Starting from position +1, we obtain a length of L. K1 =L M key1.
[0433] Optionally, before the key-consuming device obtains its own second key fragment from the aggregated key, the method further includes:
[0434] The key-consuming device receives routing information data packets sent by the second gateway device.
[0435] Among them, the routing information data packet is generated by the second gateway device using the one-time random key of the key consumption device. T encryption;
[0436] Key consumption device uses key T Parse the routing information data packet, which includes the DID of the device that consumed the previous hop key. b.pre and the DID of the next-hop key consuming device b.next The key consumption device's own sequence number n, and the length L of the encrypted second key fragment key2. K2 '.
[0437] Optionally, the key consuming device obtains its own second key fragment from the aggregated key, specifically including:
[0438] The key-consuming device obtains its own L from the routing information data packet. K2 'and n,
[0439] Among them, L K2 'The key2 is generated by the second gateway device and then encrypted using n. n is obtained by the second gateway device from the routing table RT.'
[0440] The RT is generated by the blockchain, and several key-consuming devices' key-consuming device identifiers (DIDs) are randomly arranged in the RT on the second gateway device. b ;
[0441] Key consumption device from L I +L M +L K1 Starting from position +1, we obtain a length of L. K2 'Use n to encrypt key2, and use n to decrypt the encrypted key2 to obtain a result of length L. K2 key2.
[0442] Optionally, the key-consuming device uses a key. T After parsing the routing information data packet, the method further includes:
[0443] The key-consuming device obtains the DID from the routing information data packet. b.pre ;
[0444] Key-consuming devices based on DID b.pre Verify that the source of the aggregated key is correct. If it is incorrect, terminate the current key aggregation and transmission process.
[0445] Optionally, the key-consuming device strips its own key fragment from the aggregated key and sends the remaining aggregated key to its next-hop key-consuming device, specifically including:
[0446] The key-consuming device obtains the DID from the routing information data packet. b.next ;
[0447] The key-consuming device extracts its own key fragments from the aggregated key, based on the DID. b.next The remaining aggregated key after stripping its own key fragment is sent to the next-hop key-consuming device.
[0448] Optionally, after the key-consuming device concatenates the first key fragment and the second key fragment to obtain its own key, the method further includes:
[0449] The key-consuming device generates a ninth hash value based on its own key and sends the ninth hash value to the blockchain.
[0450] This allows the blockchain to compare the ninth hash value with the corresponding eighth hash value to verify whether the key obtained by the key-consuming device is accurate. If it is inaccurate, a key-discarding instruction is sent to the key-consuming device.
[0451] The eighth hash value is generated by the second gateway device by splicing together the first key sub-fragments and second key sub-fragments of each of the key consumption devices, and then sent to the blockchain, where it is stored in the private storage space of the second gateway device.
[0452] If a key-consuming device receives a key-discard instruction, it discards its own key obtained in the current key aggregation and transmission process according to the key-discard instruction, and rebroadcasts its own key request.
[0453] Optionally, after the key-consuming device strips its own key fragments from the aggregated key, the method further includes:
[0454] The key-consuming device checks whether the length of the remaining aggregated key after stripping its own key fragment is 0. If so, it sends a message to the blockchain and gateway devices indicating the end of the current key aggregation transmission process.
[0455] Example 4:
[0456] like Figure 9 As shown, Embodiment 4 of the present invention provides a blockchain, including an instruction module 11, used to:
[0457] The blockchain sends an aggregation command to the gateway device, instructing it to provide the required keys for several key-consuming devices in an aggregated form.
[0458] This enables the gateway device to generate an aggregation key based on the aggregation instruction, and transmit the aggregation key to several key-consuming devices. The aggregation key includes key fragments for each of the key-consuming devices.
[0459] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0460] Optionally, the blockchain also includes a third registration module for enabling:
[0461] The blockchain receives the second registration information.
[0462] Specifically, the second registration information is sent to the blockchain by each gateway device within the preset network domain based on its own second self-information and the first registration information.
[0463] The first registration information is sent by each key-consuming device in the preset network domain to each gateway device according to its own first self-information;
[0464] The blockchain completes the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
[0465] Optionally, the third registration module is specifically used to:
[0466] The blockchain obtains the second self-information of each gateway device from the second registration information and the key consumption device identifier (DID) of each key consumption device registered with each gateway device.
[0467] Among them, DID is generated by each gateway device obtaining its own information from the first registration information and registering each key-consuming device based on its own information.
[0468] The blockchain generates a network domain identifier (NID) for a preset network domain, and generates a gateway device identifier (GID) for each gateway device by registering each gateway device based on its second self-information.
[0469] The blockchain sets up its own private storage space for each gateway device, and stores the unique identifier UID of each key-consuming device registered by each gateway device in the private storage space. The UID includes NID, GID and DID in sequence.
[0470] The blockchain sends an NID and a GID to each gateway device.
[0471] This allows each gateway device to store the UID of each key-consuming device that it has registered.
[0472] Optionally, the blockchain also includes a first device key generation module for enabling:
[0473] The blockchain obtains the hardware information and initial state information of each gateway device from the second set of self-information, and generates an authentication key for each gateway device based on the hardware information and initial state information of each gateway device. ID ,
[0474] Among them, key ID It is also generated by each gateway device based on its own hardware information and initial state information;
[0475] The blockchain obtains the current status information of each gateway device based on the end message of the previous round of key aggregation and transmission process, and generates a one-time random key for each gateway device based on the current status information of each gateway device. OTP ,
[0476] Among them, key OTP It is also generated by each gateway device based on its current status information obtained from the end message of the previous round of key aggregation transmission process.
[0477] Optionally, the first device key generation module is specifically used to:
[0478] The blockchain calculates a first hash value for the hardware information and a second hash value for the initial state information of each gateway device, and generates a key for each gateway device based on the comparison result of the first and second hash values. ID ;
[0479] The blockchain generates one or more blocks based on the completion message of the previous key aggregation and transmission process, and randomly selects blocks to participate in the current key aggregation and transmission process.
[0480] The block obtains the current status information of each gateway device, calculates the third hash value of the current status information of each gateway device, and generates the key of each gateway device based on the comparison result of the second hash value and the third hash value. OTP .
[0481] Optionally, the blockchain also includes a first start module for enabling:
[0482] The blockchain receives the message indicating the start of the current key aggregation and transmission process.
[0483] In this round, the key aggregation and transmission process start message is generated and sent by any gateway device in the preset network domain to several key consuming devices in the preset network domain;
[0484] The blockchain begins generating aggregation instructions based on the key aggregation transmission process of this round.
[0485] Optionally, the first start module is also used to enable:
[0486] The blockchain sends block time thresholds and / or block quantity thresholds to all gateway devices within the preset network domain.
[0487] This ensures that when any gateway device receives key request requests at a time that reaches the block time threshold and / or at a number that reaches the block quantity threshold, it generates a message indicating the start of the current round of key aggregation and transmission.
[0488] Among them, the key request is broadcast by a number of key-consuming devices in the preset network domain to all gateway devices in the preset network domain.
[0489] Optionally, the gateway device includes a first gateway device and a second gateway device, and the key fragment includes a first key sub-fragment and a second key sub-fragment;
[0490] Instruction module 11 is specifically used to:
[0491] The blockchain sends a first aggregation instruction to a first gateway device and a second aggregation instruction to a second gateway device. The first aggregation instruction instructs the provision of first key sub-fractions from each of several key-consuming devices, and the second aggregation instruction instructs the provision of second key sub-fractions from each of several key-consuming devices, and aggregates the first and second key sub-fractions.
[0492] This allows the first gateway device to receive a first aggregation instruction, generate a set data packet based on the first aggregation instruction, and send the set data packet to the second gateway device. The set data packet includes a first key sub-fragment for each of the key-consuming devices.
[0493] This enables the second gateway device to receive the second aggregation instruction and the aggregated data packet, generate an aggregation key based on the second aggregation instruction and the aggregated data packet, and transmit the aggregation key to several key-consuming devices. The aggregation key includes a first key sub-fragment and a second key sub-fragment for each of the key-consuming devices.
[0494] This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
[0495] Optionally, the blockchain also includes an extraction module for enabling:
[0496] The blockchain randomly selects two gateway devices within a predefined network domain and compares whether the key request received by the two gateway devices is consistent.
[0497] Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain;
[0498] If they match, the two gateway devices will be designated as the first gateway device and the second gateway device, respectively. Otherwise, two new gateway devices will be selected until the key request received by the two selected gateway devices matches. Finally, the two selected gateway devices will be designated as the first gateway device and the second gateway device, respectively.
[0499] Optionally, the block also includes a first information providing module for enabling:
[0500] The blockchain receives a one-time random key from the first gateway device via the second gateway device. OTPa The first request,
[0501] Among them, key OTPa The first gateway device is used to encrypt the collection of data packets;
[0502] The blockchain sends a key to the second gateway device based on the first request. OTPa ,
[0503] So that the second gateway device can use the key OTPa Parse the collection of data packets.
[0504] Optionally, the first information providing module is also used to:
[0505] The blockchain generates a routing table RT, which randomly arranges the identifiers of several key-consuming devices.
[0506] The blockchain receives a second request from the second gateway device to obtain the RT;
[0507] The blockchain sends an RT to the second gateway device based on the second request.
[0508] So that the second gateway device arranges the key fragments of several key consuming devices in the order of RT to form an aggregate key, and transmits the aggregate key to several key consuming devices in the order of RT.
[0509] Optionally, the first information providing module is further used to:
[0510] Based on the key request received by the second gateway device, the blockchain obtains the Key Consumption Device Identifier (DID) of several key-consuming devices participating in this round of key aggregation and transmission process on the second gateway device. b Randomly arrange DIDb To generate RT.
[0511] Optionally, the key sent by the blockchain to the second gateway device OTPa Alternatively, RT can use the authentication key of the second gateway device. IDb encryption;
[0512] Instruction module 11 is also used to:
[0513] The blockchain receives either the sixth or seventh hash value.
[0514] The sixth hash value is obtained by the second gateway device using the key. IDb Parse key OTPa The seventh hash value is obtained by the second gateway device using the key. IDb Obtained by parsing RT;
[0515] The blockchain verifies the sixth or seventh hash value. If the verification fails, it sends a termination instruction to the second gateway device, indicating the end of this round of key aggregation and transmission.
[0516] This ensures that if the second gateway device receives a termination command, it terminates the current key aggregation transmission process according to the termination command; otherwise, the second gateway device continues the current key aggregation transmission process.
[0517] Optionally, instruction module 11 is also used to:
[0518] The blockchain receives the eighth hash value.
[0519] The eighth hash value is generated and sent by the second gateway device based on the first and second key sub-fragments of each of the several key consuming devices.
[0520] The blockchain stores the eighth hash value in the private storage space of the second gateway device;
[0521] After one of the key-consuming devices consumes its own first and second key sub-fragments from the aggregated key to obtain its own required key, the method further includes:
[0522] The blockchain receives the ninth hash value.
[0523] The ninth hash value is generated and sent by a key-consuming device based on its own first and second key fragments obtained from the aggregated key.
[0524] The blockchain compares the ninth hash value with the corresponding eighth hash value to verify whether the key obtained by a key-consuming device is accurate. If it is inaccurate, a key-discarding instruction is sent to the key-consuming device.
[0525] This allows a key-consuming device to discard its own key obtained in the current key aggregation transmission process according to the discard key instruction, and to rebroadcast its own key request.
[0526] Optionally, the blockchain also includes a first termination module for enabling:
[0527] The blockchain receives a message indicating the end of the current key aggregation and transmission process.
[0528] Specifically, the end message of this round of key aggregation and transmission process is sent from the last hop key consuming device among the key consuming devices participating in this round of key aggregation and transmission process to the blockchain and gateway device.
[0529] Example 5:
[0530] like Figure 10 As shown, Embodiment 5 of the present invention provides a gateway device, comprising:
[0531] Aggregation module 21 is used to enable the gateway device to generate an aggregation key according to the aggregation instruction. The aggregation key includes key fragments from several key consuming devices.
[0532] The aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys of several key-consuming devices in an aggregated form.
[0533] Transmission module 22, connected to aggregation module 21, is used to enable the gateway device to transmit the aggregation key to several key-consuming devices.
[0534] This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys.
[0535] Optionally, the gateway device further includes a second registration module for enabling:
[0536] The gateway device receives the first registration information.
[0537] The first registration information is generated by each key-consuming device within the preset network domain based on its own first self-information and a verification random number R. V The default value is sent to each gateway device within the preset network domain;
[0538] The gateway device sends its second registration information to the blockchain based on its second self-information and the first registration information.
[0539] This enables the blockchain to complete the registration of the gateway device based on the second registration information and to consume the identifier of each key that sends the first registration information to the gateway device.
[0540] Optionally, the second registration module is specifically used to:
[0541] The gateway device obtains its own information from the first registration information, completes the registration of each key-consuming device based on the first self-information, and generates a Key Consumption Device Identifier (DID) for each key-consuming device.
[0542] The gateway device obtains its own hardware information and initial state information to form second self information, and combines the second self information with the DID of each key-consuming device to form second registration information, and sends the second registration information to the blockchain;
[0543] The gateway device receives the network domain identifier (NID) of the preset network domain sent by the blockchain and its own gateway device identifier (GID). It also stores the unique identifier (UID) of each key-consuming device registered with the gateway device. The UID includes the NID, GID, and DID in sequence.
[0544] Among them, NID is generated by the blockchain, GID is generated by the blockchain based on the second self information of the gateway device to complete the registration of the gateway device, and UID is also stored by the blockchain in a private storage space set up for the gateway device.
[0545] Optionally, the gateway device further includes a second device key generation module for enabling:
[0546] The gateway device obtains its own hardware information and initial state information, and generates its own authentication key based on its hardware information and initial state information. ID ,
[0547] Among them, key ID It is also generated by the blockchain based on the hardware information and initial state information of the gateway device in the second registration information;
[0548] The gateway device obtains its current status information based on the end message of the previous round of key aggregation and transmission process, and generates its own one-time random key based on its current status information. OTP ,
[0549] Among them, key OTP It is also generated by the blockchain based on the current status information of the gateway device obtained from the end message of the previous round of key aggregation and transmission process.
[0550] Optionally, the second device key generation module is specifically used to:
[0551] The gateway device calculates a first hash value of its own hardware information and a second hash value of its initial state information, and generates its own key based on the comparison result of the first and second hash values. ID ;
[0552] The gateway device obtains its current state information based on the end message of the previous round of key aggregation and transmission process, and then sends its current state information to the blockchain.
[0553] This enables the blockchain to generate a key for the gateway device based on the received current state information of the gateway device. OTP ,
[0554] The gateway device calculates the third hash value of its current state information and generates its own key based on the comparison result between the second and third hash values. OTP .
[0555] Optionally, the gateway device also includes a second start module for enabling:
[0556] The gateway device generates a key aggregation and transmission process start message for several key-consuming devices within a preset network domain, and sends the key aggregation and transmission process start message to the blockchain.
[0557] This enables the blockchain to initiate message generation and aggregation instructions based on the current key aggregation transmission process.
[0558] Optionally, the second starting module is specifically used to:
[0559] The gateway device receives the block time threshold and / or block quantity threshold sent by the blockchain.
[0560] The gateway device receives key request requests broadcast by several key-consuming devices within a preset network domain that have key requirements.
[0561] When the time of the key request received by the gateway device reaches the block time threshold and / or the number of requests reaches the block number threshold, the gateway device generates a message to start the key aggregation and transmission process for this round.
[0562] Optionally, the gateway device is a first gateway device, and the key fragment includes a first key sub-fragment;
[0563] Gateway devices, specifically including:
[0564] The first receiving module is used to enable the first gateway device to receive the first aggregation command.
[0565] The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of several key consumption devices' respective first key sub-fragments;
[0566] The aggregation module 21 includes a first aggregation module connected to the first receiving module, used to enable the first gateway device to generate a set data packet according to the first aggregation instruction, wherein the set data packet includes a first key sub-fragment of each of several key consuming devices;
[0567] Transmission module 22 includes a first transmission module connected to the first aggregation module, used to enable the first gateway device to send aggregated data packets to the second gateway device.
[0568] This enables the second gateway device to receive the aggregated data packet, generate an aggregated key based on the second aggregation instruction and the aggregated data packet, and transmit the aggregated key to several key-consuming devices. The aggregated key includes a first key sub-fragment and a second key sub-fragment for each of the key-consuming devices.
[0569] Specifically, the second aggregation instruction is sent from the blockchain to the second gateway device, instructing the provision of second key sub-fragments from several key-consuming devices, and aggregating the first and second key sub-fragments.
[0570] This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
[0571] Optionally, the first gateway device further includes a second information providing module, used to enable:
[0572] The first gateway device sends the key request it received to the blockchain.
[0573] Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain;
[0574] This allows the blockchain to send a first aggregation instruction to the first gateway device after comparing the key request received by the first gateway device and the second gateway device to ensure they are consistent.
[0575] Optionally, the first aggregation module specifically includes:
[0576] The first acquisition unit is used to enable the first gateway device to acquire the key request it received after the end of the previous key aggregation transmission process and before the start of the current key aggregation transmission process according to the first aggregation instruction.
[0577] The first determining unit is used to enable the first gateway device to determine, based on the key request it receives, several key consuming devices that will participate in the key aggregation and transmission process in this round.
[0578] The first segment generation unit is used to enable the first gateway device to randomly generate several segments of length L. K1 Each of the key-consuming devices has its own first key fragment key1;
[0579] The first combination unit is used to enable the first gateway device to fill key1 into a key fragment of a preset format, and to combine several key fragments filled with key1 into a set data packet.
[0580] Optionally,
[0581] The first acquisition unit is further configured to enable the first gateway device to acquire the key-consuming device identifier (DID) of each of the several key-consuming devices in the first gateway device. a It obtains the hardware information of several key-consuming devices and generates a verification random number R for each key-consuming device. V ;
[0582] The first gateway device also includes a third device key generation module, used to enable the first gateway device to consume the hardware information and R of each device according to several keys. V Generate several key consumption devices, each with its own one-time random key. T ;
[0583] The first fragment generation unit is also used to enable the first gateway device to randomly generate several random strings K for each key consumption device. M And based on the DID of each of the key-consuming devices a and key T Generate several keys, each consuming the device's own authentication string K. I ;
[0584] The first combination unit is also used to enable the first gateway device to transmit K M K I Enter the first and second fields of the preset format key fragment in the selected order, and enter key1 in the third field.
[0585] The preset format key fragment also includes a fourth field, which is used to carry the second key sub-fragment key2 in the second gateway device.
[0586] Optionally, the first acquisition unit is specifically used to:
[0587] The first gateway device obtains the hardware information of each of the key-consuming devices from the first registration information sent to the first gateway device by the key-consuming devices.
[0588] The third device key generation module is specifically used to:
[0589] The first gateway device consumes several keys, each with its own hardware information and R. V The fourth hash value is calculated by combining the hardware information of several key-consuming devices and R. V The default value combination is used to calculate the fifth hash value. Based on the comparison result of the fourth and fifth hash values, several keys are generated, each consuming a key for its respective device. T .
[0590] Optionally, the second information providing module is also used to:
[0591] The first gateway device will R V Send to the second gateway device.
[0592] This allows the second gateway device to obtain the hardware information of each of the key-consuming devices from the first registration information sent to the second gateway device by the key-consuming devices, and combine it with R V Generating several keys consumes the key of each device. T .
[0593] Optionally, the first fragment generation unit is further configured to:
[0594] The first gateway device randomly selects several key-consuming devices, each with their own K... M K I The order in which the first and second fields of the key fragment are filled in is: K M K I , or K I K M ;
[0595] If the selected order is: K M K I Then the first gateway device randomly generates a segment of length L for the corresponding key-consuming device. M =L K1 K M And calculate K for the corresponding key-consuming device. I =DID a ×key T ×L M To obtain a segment of length L I K I ;
[0596] If the selected order is: K I K M Then the first gateway device calculates K for the corresponding key-consuming device. I =DID a ×key T ×L K1 To obtain a segment of length L I K I And randomly generate a segment of length L for the corresponding key-consuming device. M =L I K M .
[0597] Optionally, the second information providing module is also used to:
[0598] The first gateway device generates parameter matrices P for several key-consuming devices, where P includes K for each key-consuming device. M and KI Sequence identifier, first field length L and R V ;
[0599] The first gateway device sends P to several key-consuming devices.
[0600] So that several key-consuming devices can obtain their respective key1 from the aggregate key according to P.
[0601] Optionally, the second information providing module is specifically used to:
[0602] The first gateway device obtains the K values of several key-consuming devices in this round of key aggregation and transmission process. M and K I Sequence identifier, L and R V And obtain K from the previous round of key aggregation and transmission process. M 'Length L M '、and verify random number R V ';
[0603] The first gateway devices are arranged in different orders according to pre-constrained conditions. M and K I Sequence identifier, L, R V Form matrices M1 and M2, using L M 'and R V The operations with M1 and M2 generate several keys, each consuming the P of its respective device.
[0604] Optionally, the first transmission module is specifically used to:
[0605] The first gateway device sends a one-time random key to the second gateway device. OTPa Encrypted collection of data packets,
[0606] This enables the second gateway device to obtain a key from the blockchain. OTPa And based on the key OTPa Parse the collection of data packets.
[0607] Optionally, the gateway device is a second gateway device, and the key fragment includes a second key sub-fragment;
[0608] The second gateway device also includes:
[0609] The second receiving module is used to enable the second gateway device to receive the second aggregation command and the aggregated data packet.
[0610] Specifically, the second aggregation instruction is sent from the blockchain to the second gateway device, instructing the provision of second key sub-fragments from several key-consuming devices, and aggregating the first and second key sub-fragments.
[0611] The aggregated data packet is generated by the first gateway device after receiving the first aggregation instruction, and then sent to the second gateway device. The aggregated data packet includes several first key sub-fragments from each of the key-consuming devices.
[0612] The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of several key consumption devices' respective first key sub-fragments;
[0613] The aggregation module 21 includes a second aggregation module connected to the second receiving module, which enables the second gateway device to generate an aggregation key according to the second aggregation instruction and the aggregated data packet. The aggregation key includes a first key sub-fragment and a second key sub-fragment of each of several key consuming devices.
[0614] Transmission module 22 includes a second transmission module connected to the second aggregation module, used to enable the second gateway device to transmit the aggregation key to several key-consuming devices.
[0615] This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
[0616] Optionally, the second gateway device further includes a third information providing module for enabling:
[0617] The second gateway device sends the key request it received to the blockchain.
[0618] Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain;
[0619] This allows the blockchain to send a second aggregation instruction to the second gateway device after comparing the key request received by the first gateway device and the second gateway device to ensure they are consistent.
[0620] Optionally, the second aggregation module specifically includes:
[0621] The second acquisition unit is used to enable the second gateway device to acquire, based on the aggregated data packet, a preset format key fragment containing the first key sub-fragment key1 from each of the key-consuming devices, wherein the length of key1 is L. K1 ;
[0622] The second fragment generation unit is used to enable the second gateway device to randomly generate several fragments of length L according to the second aggregation instruction. K2 Each of the key-consuming devices has its own second key fragment, key2, L K1 +L K2 =L K L KEach key consumes the required key length for its respective device.
[0623] The second combination unit is used to enable the second gateway device to fill key2 into a key fragment of a preset format, and to combine several key fragments filled with key1 and key2 into an aggregate key.
[0624] Optionally, the second acquisition unit is specifically used to:
[0625] The second gateway device sends a one-time random key to the blockchain to obtain the first gateway device's key. OTPa The first request,
[0626] Among them, key OTPa The first gateway device is used to encrypt the collection of data packets;
[0627] The second gateway device receives the key sent by the blockchain. OTPa ;
[0628] The second gateway device uses the key. OTPa Parse the collection data packet to obtain the K values of several key-consuming devices in the collection data packet, which are filled into the first, second, and third fields in a selected order. M / K I K I / K M The key fragment in the preset format of key1.
[0629] Optionally, the second combining unit is specifically used to:
[0630] The second gateway device sends a second request to the blockchain to obtain the routing table RT.
[0631] RT is generated by the blockchain, and the identifiers of several key-consuming devices are randomly arranged in RT.
[0632] The second gateway device receives the RT sent by the blockchain;
[0633] The second gateway device uses the sequence number n of each key consumption device in RT to encrypt key2, and the encrypted result has a length of L. K2 Enter the fourth field of the key fragment in the preset format in key2;
[0634] The second gateway device arranges several key consumption devices' key fragments in the order of RT to form an aggregate key.
[0635] Optionally, the key received by the second gateway device OTPa Alternatively, RT can be used by the blockchain with the authentication key of a second gateway device. IDb encryption;
[0636] The second gateway device also includes a termination determination module, used to:
[0637] The second gateway device uses a key. IDb Parse key OTPa Obtain the sixth hash value, or use the key on the second gateway device. IDb Parse RT to obtain the seventh hash value;
[0638] The second gateway device sends the sixth or seventh hash value to the blockchain.
[0639] This allows the blockchain to verify either the sixth or seventh hash value. If the verification fails, a termination instruction for this round of key aggregation and transmission is sent to the second gateway device.
[0640] If the second gateway device receives a termination command, it terminates the current key aggregation transmission process according to the termination command; otherwise, the second gateway device continues the current key aggregation transmission process.
[0641] Optionally, the RT randomly arranges several key-consuming devices into a second gateway device's key-consuming device identifier (DID). b ;
[0642] The third information providing module is also used to enable:
[0643] The second gateway device will arrange each DID in RT. b Compared to the DID listed first b.pre and the next DID b.next Each DID b In RT, the permutation numbers n and L K2 'Combines routing information data packets;'
[0644] The second gateway device sends its respective routing information data packets to several key-consuming devices.
[0645] So that, after receiving the aggregated key, several key-consuming devices, according to DID b.pre Verify the correctness of the source of the aggregate key received by each entity, and based on n and L... K2 'Retrieve key2 from the aggregated key, and after stripping the key fragments from the received aggregated key, send the remaining aggregated key to DID.' b.next Key-consuming devices.
[0646] Optionally,
[0647] The second acquisition unit is further configured to enable the second gateway device to acquire the hardware information of each of the key-consuming devices from the first registration information sent to the second gateway device by the key-consuming devices, and to receive the verification random number R of each of the key-consuming devices sent by the first gateway device. V ;
[0648] The second gateway device also includes a fourth device key generation module, used to enable the second gateway device to consume the hardware information and R of each device according to several keys. V Generate several key consumption devices, each with its own one-time random key. T ;
[0649] The third information providing module is also specifically used to enable the second gateway device to use the key. T Encrypt the routing information data packets and send the encrypted routing information data packets to several key-consuming devices.
[0650] So that several key-consuming devices obtain R from the first gateway device V It generates its own key by combining its own hardware information. T And based on the key T Parse the routing information data packet.
[0651] Optionally, the transmission module 22 is specifically used to:
[0652] The gateway device sends the aggregated key to the first-hop key-consuming device among the several key-consuming devices participating in this round of key aggregation transmission process.
[0653] This allows each hop key-consuming device among the several key-consuming devices participating in this round of key aggregation and transmission process to receive the aggregated key in sequence, and after obtaining its own key, to strip its own key fragment from the aggregated key it received, and send the remaining aggregated key to its next hop key-consuming device.
[0654] Optionally, the gateway device further includes a second termination module for enabling:
[0655] The gateway device receives the end message of the current key aggregation transmission process.
[0656] Specifically, the end message of this round of key aggregation and transmission process is sent by the last hop key consuming device participating in this round of key aggregation and transmission process, after stripping its own key fragment from the aggregated key it received, and when it detects that the remaining aggregated key length is 0, to the blockchain and gateway devices.
[0657] Example 6:
[0658] like Figure 11 As shown, Embodiment 6 of the present invention provides a key consumption device, comprising:
[0659] Consumption module 31 is used to enable the key consumption device to consume its own key fragments from the aggregated key to obtain its own required key.
[0660] The aggregated key is generated by the gateway device according to the aggregation instruction and transmitted to several key-consuming devices. The aggregated key includes key fragments from each of the key-consuming devices.
[0661] In this process, the aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys for each key-consuming device in an aggregated form.
[0662] Optionally, the key-consuming device further includes a first registration module for enabling:
[0663] The key-consuming device uses its own first self-information and verification random number R V The default value sends the first registration information to each gateway device within the preset network domain.
[0664] This allows each gateway device to send its second registration information to the blockchain based on its second self-information and first registration information.
[0665] This enables the blockchain to complete the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
[0666] Optionally, the first registration module is specifically used to:
[0667] The key-consuming device obtains its own hardware information to form first self-information, and then combines the first self-information with R. V The default values form the first registration information, and the first registration information is sent to each gateway device in the preset network domain.
[0668] This allows each gateway device to obtain its own information from the first registration information, and to complete the registration of each key-consuming device based on the first self-information, thereby generating a key-consuming device identifier (DID) for each key-consuming device. The DID is then added to the second registration information and sent to the blockchain.
[0669] This enables the blockchain to generate a network domain identifier (NID) for a preset network domain and a gateway device identifier (GID) for each gateway device, and then sends the corresponding NID and GID to each gateway device.
[0670] Optionally, the key-consuming device also includes a broadcast module for enabling:
[0671] The key-consuming device broadcasts its key request to all gateway devices within the preset network domain.
[0672] This allows any gateway device to send a key aggregation and transmission process start message to the blockchain based on the key request it receives.
[0673] This enables the blockchain to initiate message generation and aggregation instructions based on the current key aggregation transmission process.
[0674] Optionally, the consumption module 31 specifically includes:
[0675] The third receiving unit is used to enable the key consuming device to receive the aggregated key;
[0676] The third acquisition unit is used to enable the key consuming device to obtain its own key fragment from the aggregated key, and to obtain its own key based on its own key fragment;
[0677] The stripping unit is used to enable the key consuming device to strip its own key fragment from the aggregated key and send the remaining aggregated key to its next-hop key consuming device.
[0678] Optionally, the third receiving unit is specifically used to:
[0679] If the key-consuming device is the first-hop key-consuming device in this round of key aggregation transmission process, then the first-hop key-consuming device receives the aggregated key sent by the gateway device; otherwise, the non-first-hop key-consuming device receives the remaining aggregated key sent by the previous-hop key-consuming device.
[0680] Optionally, the gateway device includes a first gateway device and a second gateway device, and the key fragment includes a first key sub-fragment and a second key sub-fragment;
[0681] The third receiving unit of the first-hop key consumption device is specifically used to:
[0682] The first-hop key-consuming device receives the aggregated key sent by the second gateway device.
[0683] The aggregation key is generated by the second gateway device after receiving the second aggregation instruction and the aggregation data packet, and then sent to the first hop key consuming device. The aggregation key includes first key sub-fragments and second key sub-fragments for each of the key consuming devices.
[0684] The second aggregation instruction is sent from the blockchain to the second gateway device, instructing it to provide the second key sub-fragments of each of the several key consuming devices, and to aggregate the first key sub-fragments and the second key sub-fragments.
[0685] The aggregated data packet is generated by the first gateway device after receiving the first aggregation instruction, and then sent to the second gateway device. The aggregated data packet includes several first key sub-fragments from each of the key-consuming devices.
[0686] The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of first key sub-fragments of each of the key-consuming devices.
[0687] Optionally, the third acquisition unit specifically includes:
[0688] The first fragment acquisition subunit is used to enable the key consuming device to obtain its own first key fragment from the aggregated key;
[0689] The second fragment acquisition subunit is used to enable the key consuming device to obtain its own second key fragment from the aggregated key;
[0690] The key splicing subunit is used to enable the key consuming device to splice the first key sub-fragment and the second key sub-fragment to obtain its own required key.
[0691] Optionally,
[0692] The third receiving unit is also used to enable the key-consuming device to receive the parameter matrix P sent by the first gateway device, wherein P includes the key-consuming device's own verification random number R. V The length L of the first field in the key fragment, and the random string K. M and authentication string K I Sequence identifier;
[0693] The key-consuming device also includes a fifth device key generation module, used to enable the key-consuming device to obtain its own hardware information and obtain R based on P. V And based on its own hardware information and R V Generate your own one-time random key T .
[0694] Optionally, the fifth device key generation module is specifically used to:
[0695] The key-consuming device will send its own hardware information and R V Combine and calculate the fourth hash value, including its own hardware information and R. V The default value combination is used to calculate the fifth hash value, and the key is generated based on the comparison result between the fourth and fifth hash values. T .
[0696] Optionally, the first segment acquires sub-units, specifically for the purpose of:
[0697] The key-consuming device obtains L and K based on P. M and K I The order,
[0698] Among them, K M and K IThe first or second field of a key fragment in a preset format is generated by the first gateway device and filled in according to the selected order;
[0699] The key-consuming device obtains its own Key-Consuming Device Identifier (DID) from the first gateway device. a And obtain L and K based on P. M and K I The order,
[0700] Among them, K M and K I The first or second field of a key fragment in a preset format is generated by the first gateway device and filled in according to the selected order;
[0701] Key-consuming devices based on DID a L, K M and K I The order and key T Obtain its first key fragment key1 from the aggregate key.
[0702] Optionally, the first segment acquires sub-units, specifically for the purpose of:
[0703] The key-consuming device obtains its own verification random number R from the previous round of key aggregation and transmission process. V 'with random string K M 'Length L M ';
[0704] Key-consuming devices use R V 'with L M 'Analyze P to obtain matrices M1 and M2, in which R is arranged in different orders according to pre-defined constraints.' V L, K M and K I Sequence identifier;
[0705] The key-consuming device obtains its own R from M1 and M2 according to pre-constrained conditions for the current round of key aggregation and transmission process. V L, K M and K I The sequence identifier, according to K M and K I Obtaining K from the sequence identifier M and K I The order.
[0706] Optionally, the first segment acquires sub-units, specifically for the purpose of:
[0707] If K M and K I The order is: K M K IThen the key-consuming device obtains a length of L starting from the first bit of the aggregated key. M =L of K M From the Lth M Starting from position +1, we obtain a length of L. I =L M K I According to K I =DID a ×key T ×L K1 The inverse operation yields the length L of key1. K1 From the Lth I +L M Starting from position +1, we obtain a length of L. K1 key1;
[0708] If K M and K I The order is: K I K M Then the key-consuming device obtains a length of L starting from the first bit of the aggregated key. I =L of K I According to K I =DID a ×key T ×L M The inverse operation of K is obtained M Length L M From the Lth I Starting from position +1, we obtain a length of L. M K M From the Lth I +L M Starting from position +1, we obtain a length of L. K1 =L M key1.
[0709] Optionally, the third receiving unit is also used to:
[0710] The key-consuming device receives routing information data packets sent by the second gateway device.
[0711] Among them, the routing information data packet is generated by the second gateway device using the one-time random key of the key consumption device. T encryption;
[0712] The third acquisition unit is also used to enable the key-consuming device to use the key. T Parse the routing information data packet, which includes the DID of the device that consumed the previous hop key. b.pre and the DID of the next-hop key consuming device b.nextThe key consumption device's own sequence number n, and the length L of the encrypted second key fragment key2. K2 '.
[0713] Optionally, the second segment acquires sub-units, specifically for the purpose of:
[0714] The key-consuming device obtains its own L from the routing information data packet. K2 'and n,
[0715] Among them, L K2 'The key2 is generated by the second gateway device and then encrypted using n. n is obtained by the second gateway device from the routing table RT.'
[0716] The RT is generated by the blockchain, and several key-consuming devices' key-consuming device identifiers (DIDs) are randomly arranged in the RT on the second gateway device. b ;
[0717] Key consumption device from L I +L M +L K1 Starting from position +1, we obtain a length of L. K2 'Use n to encrypt key2, and use n to decrypt the encrypted key2 to obtain a result of length L. K2 key2.
[0718] Optionally, the key consumption device further includes a termination determination unit for causing:
[0719] The key-consuming device obtains the DID from the routing information data packet. b.pre ;
[0720] Key-consuming devices based on DID b.pre Verify that the source of the aggregated key is correct. If it is incorrect, terminate the current key aggregation and transmission process.
[0721] Optionally, the stripping unit is specifically used to:
[0722] The key-consuming device obtains the DID from the routing information data packet. b.next ;
[0723] The key-consuming device extracts its own key fragments from the aggregated key, based on the DID. b.next The remaining aggregated key after stripping its own key fragment is sent to the next-hop key-consuming device.
[0724] Optionally, the key consumption device also includes a discard decision module for enabling:
[0725] The key-consuming device generates a ninth hash value based on its own key and sends the ninth hash value to the blockchain.
[0726] This allows the blockchain to compare the ninth hash value with the corresponding eighth hash value to verify whether the key obtained by the key-consuming device is accurate. If it is inaccurate, a key-discarding instruction is sent to the key-consuming device.
[0727] The eighth hash value is generated by the second gateway device by splicing together the first key sub-fragments and second key sub-fragments of each of the key consumption devices, and then sent to the blockchain, where it is stored in the private storage space of the second gateway device.
[0728] If a key-consuming device receives a key-discard instruction, it discards its own key obtained in the current key aggregation and transmission process according to the key-discard instruction, and rebroadcasts its own key request.
[0729] Optionally, the key-consuming device also includes a third termination module for enabling:
[0730] The key-consuming device checks whether the length of the remaining aggregated key after stripping its own key fragment is 0. If so, it sends a message to the blockchain and gateway devices indicating the end of the current key aggregation transmission process.
[0731] Example 7:
[0732] Embodiment 7 of the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements the key aggregation transmission method as described in Embodiment 1, 2 or 3.
[0733] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.
[0734] In addition, the present invention may also provide a computer device including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the key aggregation transmission method as described in Embodiment 1, 2 or 3.
[0735] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.
[0736] Alternatively, the present invention may also provide a key aggregation and transmission system, including a blockchain, a gateway device, and a key consumption device as described in embodiments 4, 5, and 6.
[0737] Embodiments 1-7 of this invention provide a key aggregation and transmission method, a blockchain, a gateway device, key consuming devices, and a computer-readable storage medium. The blockchain sends an aggregation instruction to the gateway device, instructing the gateway device to provide an aggregated key to several key consuming devices. This allows each key consuming device to obtain its required key through the aggregated key. While breaking the one-time pad cryptographic mechanism and improving the efficiency of key provision, the blockchain manages the participation of multiple devices in the key aggregation and transmission process to ensure key security. It can ensure the reasonable use of network resources when faced with a large number of key requests, avoiding network congestion and service interruption.
[0738] It is understood that the above embodiments 1-7 are mutually corresponding and can be understood and explained in combination. The above embodiments are merely exemplary implementations used to illustrate the principles of the present invention; however, the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A key aggregation transmission method, characterized in that, Applied to blockchain, the method includes: The blockchain receives the message indicating the start of the current key aggregation and transmission process. In this round of key aggregation and transmission process, the start message is generated and sent by any gateway device within the preset network domain for several key-consuming devices based on the key requirement requests it receives. Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain; The blockchain begins generating aggregation instructions based on the key aggregation transmission process of this round; The blockchain sends an aggregation command to the gateway device, instructing it to provide the required keys for several key-consuming devices in an aggregated form. This enables the gateway device to generate an aggregation key based on the aggregation instruction, and transmit the aggregation key to several key-consuming devices. The aggregation key includes key fragments for each of the key-consuming devices. This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys. Before the blockchain sends the aggregation command to the gateway device, the method further includes: The blockchain receives the second registration information. Specifically, the second registration information is sent to the blockchain by each gateway device within the preset network domain based on its own second self-information and the first registration information. The first registration information is sent by each key-consuming device in the preset network domain to each gateway device according to its own first self-information; The blockchain completes the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
2. The method according to claim 1, characterized in that, The blockchain completes the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information, specifically including: The blockchain obtains the second self-information of each gateway device from the second registration information and the key consumption device identifier (DID) of each key consumption device registered with each gateway device. Among them, DID is generated by each gateway device obtaining its own information from the first registration information and registering each key-consuming device based on its own information. The blockchain generates a network domain identifier (NID) for a preset network domain and generates a gateway device identifier (GID) for each gateway device by registering each gateway device based on its second self-information. The blockchain sets up its own private storage space for each gateway device, and stores the unique identifier UID of each key-consuming device registered by each gateway device in the private storage space. The UID includes NID, GID and DID in sequence. The blockchain sends an NID and a GID to each gateway device. This allows each gateway device to store the UID of each key-consuming device that it has registered.
3. The method according to claim 2, characterized in that, After the blockchain completes the registration of each gateway device based on the second self-information of each gateway device and generates the gateway device identifier (GID) for each gateway device, the method further includes: The blockchain obtains the hardware information and initial state information of each gateway device from the second set of self-information, and generates an authentication key for each gateway device based on the hardware information and initial state information of each gateway device. ID , Among them, key ID It is also generated by each gateway device based on its own hardware information and initial state information; The blockchain obtains the current status information of each gateway device based on the end message of the previous round of key aggregation and transmission process, and generates a one-time random key for each gateway device based on the current status information of each gateway device. OTP , Among them, key OTP It is also generated by each gateway device based on its current status information obtained from the end message of the previous round of key aggregation transmission process.
4. The method according to claim 3, characterized in that, The blockchain generates an authentication key for each gateway device based on its hardware information and initial state information. ID Specifically, it includes: The blockchain calculates a first hash value for the hardware information and a second hash value for the initial state information of each gateway device, and generates a key for each gateway device based on the comparison result of the first and second hash values. ID ; The blockchain obtains the current status information of each gateway device based on the end message of the previous round of key aggregation and transmission process, and generates a one-time random key for each gateway device based on the current status information of each gateway device. OTP Specifically, it includes: The blockchain generates one or more blocks based on the completion message of the previous key aggregation and transmission process, and randomly selects blocks to participate in the current key aggregation and transmission process. The block obtains the current status information of each gateway device, calculates the third hash value of the current status information of each gateway device, and generates the key of each gateway device based on the comparison result of the second hash value and the third hash value. OTP .
5. The method according to claim 1, characterized in that, Before the blockchain receives the message indicating the start of the current key aggregation transmission process, the method further includes: The blockchain sends block time thresholds and / or block quantity thresholds to all gateway devices within the preset network domain. This enables any gateway device to generate a key aggregation transmission process start message when the time of the key request it receives reaches the block time threshold and / or the number of requests reaches the block quantity threshold.
6. The method according to any one of claims 1-5, characterized in that, The gateway device includes a first gateway device and a second gateway device, and the key fragment includes a first key sub-fragment and a second key sub-fragment; The method specifically includes: The blockchain sends a first aggregation instruction to a first gateway device and a second aggregation instruction to a second gateway device. The first aggregation instruction instructs the provision of first key sub-fractions from each of several key-consuming devices, and the second aggregation instruction instructs the provision of second key sub-fractions from each of several key-consuming devices, and aggregates the first and second key sub-fractions. This allows the first gateway device to receive a first aggregation instruction, generate a set data packet based on the first aggregation instruction, and send the set data packet to the second gateway device. The set data packet includes a first key sub-fragment for each of the key-consuming devices. This enables the second gateway device to receive the second aggregation instruction and the aggregated data packet, generate an aggregation key based on the second aggregation instruction and the aggregated data packet, and transmit the aggregation key to several key-consuming devices. The aggregation key includes a first key sub-fragment and a second key sub-fragment for each of the key-consuming devices. This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
7. The method according to claim 6, characterized in that, Before the blockchain sends a first aggregation instruction to the first gateway device and a second aggregation instruction to the second gateway device, the method further includes: The blockchain randomly selects two gateway devices within a predefined network domain and compares whether the key request received by the two gateway devices is consistent. Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain; If they match, the two gateway devices will be designated as the first gateway device and the second gateway device, respectively. Otherwise, two new gateway devices will be selected until the key request received by the two selected gateway devices matches. Finally, the two selected gateway devices will be designated as the first gateway device and the second gateway device, respectively.
8. The method according to claim 7, characterized in that, After the first gateway device sends a collection data packet to the second gateway device, the method further includes: The blockchain receives a one-time random key from the first gateway device via the second gateway device. OTPa The first request, Among them, key OTPa The first gateway device is used to encrypt the collection of data packets; The blockchain sends a key to the second gateway device based on the first request. OTPa , So that the second gateway device can use the key OTPa Parse the collection of data packets.
9. The method according to claim 7, characterized in that, Before the second gateway device generates the aggregate key based on the aggregated data packets, the method further includes: The blockchain generates a routing table RT, which randomly arranges the identifiers of several key-consuming devices. The blockchain receives a second request from the second gateway device to obtain the RT; The blockchain sends an RT to the second gateway device based on the second request. So that the second gateway device arranges the key fragments of several key consuming devices in the order of RT to form an aggregate key, and transmits the aggregate key to several key consuming devices in the order of RT.
10. The method according to claim 9, characterized in that, Blockchain generates RT, specifically including: Based on the key request received by the second gateway device, the blockchain obtains the Key Consumption Device Identifier (DID) of several key-consuming devices participating in this round of key aggregation and transmission process on the second gateway device. b Randomly arrange DID b To generate RT.
11. The method according to any one of claims 8-10, characterized in that, The key sent by the blockchain to the second gateway device OTPa Alternatively, RT can use the authentication key of the second gateway device. IDb encryption; Sending a key from the blockchain to the second gateway device OTPa Or after RT, the method further includes: The blockchain receives either the sixth or seventh hash value. The sixth hash value is obtained by the second gateway device using the key. IDb Parse key OTPa The seventh hash value is obtained by the second gateway device using the key. IDb Obtained by parsing RT; The blockchain verifies the sixth or seventh hash value. If the verification fails, it sends a termination command for this round of key aggregation and transmission to the second gateway device. This ensures that if the second gateway device receives a termination command, it terminates the current key aggregation transmission process according to the termination command; otherwise, the second gateway device continues the current key aggregation transmission process.
12. The method according to claim 6, characterized in that, After the second gateway device generates the aggregation key based on the aggregated data packets, the method further includes: The blockchain receives the eighth hash value. The eighth hash value is generated and sent by the second gateway device based on the first and second key sub-fragments of each of the several key consuming devices. The blockchain stores the eighth hash value in the private storage space of the second gateway device; After one of the key-consuming devices consumes its own first and second key sub-fragments from the aggregated key to obtain its own required key, the method further includes: The blockchain receives the ninth hash value. The ninth hash value is generated and sent by a key-consuming device based on its own first and second key fragments obtained from the aggregated key. The blockchain compares the ninth hash value with the corresponding eighth hash value to verify whether the key obtained by a key-consuming device is accurate. If it is inaccurate, a key-discarding instruction is sent to the key-consuming device. This allows a key-consuming device to discard its own key obtained in the current key aggregation transmission process according to the discard key instruction, and to rebroadcast its own key request.
13. The method according to any one of claims 1-5, characterized in that, After several key-consuming devices consume their respective key fragments from the aggregated key to obtain their respective required keys, the method further includes: The blockchain receives a message indicating the end of the current key aggregation and transmission process. Specifically, the end message of this round of key aggregation and transmission process is sent from the last hop key consuming device among the key consuming devices participating in this round of key aggregation and transmission process to the blockchain and gateway device.
14. A key aggregation transmission method, characterized in that, Applied to a gateway device, the method includes: The gateway device receives key request requests broadcast by several key-consuming devices within a preset network domain that have key requirements. The gateway device generates a key aggregation and transmission process start message for several key-consuming devices within a preset network domain based on the key request it receives, and sends the key aggregation and transmission process start message to the blockchain. This enables the blockchain to begin generating aggregation instructions based on the current key aggregation transmission process. The gateway device generates an aggregation key based on the aggregation command. The aggregation key includes key fragments from several key-consuming devices. The aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys of several key-consuming devices in an aggregated form. The gateway device transmits the aggregated key to several key-consuming devices. This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys. Before the blockchain sends the aggregation command to the gateway device, the method further includes: The gateway device receives the first registration information. The first registration information is sent by each key-consuming device in the preset network domain to each gateway device in the preset network domain according to its own first self-information. The gateway device sends its second registration information to the blockchain based on its second self-information and the first registration information. This enables the blockchain to complete the registration of the gateway device based on the second registration information and to consume the identifier of each key that sends the first registration information to the gateway device.
15. The method according to claim 14, characterized in that, in: The first registration information is generated by each key-consuming device within the preset network domain based on its own first self-information and a verification random number R. V The default value is sent to each gateway device within the preset network domain.
16. The method according to claim 15, characterized in that, The gateway device sends its second registration information to the blockchain based on its second self-information and the first registration information, specifically including: The gateway device obtains its own information from the first registration information, completes the registration of each key-consuming device based on the first self-information, and generates a Key Consumption Device Identifier (DID) for each key-consuming device. The gateway device obtains its own hardware information and initial state information to form second self information, and combines the second self information with the DID of each key-consuming device to form second registration information, and sends the second registration information to the blockchain; After the gateway device sends the second registration information to the blockchain based on its second self-information and the first registration information, the method further includes: The gateway device receives the network domain identifier (NID) of the preset network domain sent by the blockchain and its own gateway device identifier (GID). It also stores the unique identifier (UID) of each key-consuming device registered with the gateway device. The UID includes the NID, GID, and DID in sequence. Among them, NID is generated by the blockchain, GID is generated by the blockchain based on the second self information of the gateway device to complete the registration of the gateway device, and UID is also stored by the blockchain in a private storage space set up for the gateway device.
17. The method according to claim 16, characterized in that, After the gateway device receives its own GID from the blockchain, the method further includes: The gateway device obtains its own hardware information and initial state information, and generates its own authentication key based on its hardware information and initial state information. ID , Among them, key ID It is also generated by the blockchain based on the hardware information and initial state information of the gateway device in the second registration information; The gateway device obtains its current status information based on the end message of the previous round of key aggregation and transmission process, and generates its own one-time random key based on its current status information. OTP , Among them, key OTP It is also generated by the blockchain based on the current status information of the gateway device obtained from the end message of the previous round of key aggregation and transmission process.
18. The method according to claim 17, characterized in that, The gateway device generates its own key based on its hardware information and initial state information. ID Specifically, it includes: The gateway device calculates a first hash value of its own hardware information and a second hash value of its initial state information, and generates its own key based on the comparison result of the first and second hash values. ID ; The gateway device obtains its current status information based on the end message of the previous round of key aggregation and transmission process, and generates its own key based on its current status information. OTP Specifically, it includes: The gateway device obtains its current state information based on the end message of the previous round of key aggregation and transmission process, and then sends its current state information to the blockchain. This enables the blockchain to generate a key for the gateway device based on the received current state information of the gateway device. OTP , The gateway device calculates the third hash value of its current state information and generates its own key based on the comparison result between the second and third hash values. OTP .
19. The method according to claim 14, characterized in that, The gateway device generates a key aggregation and transmission process start message for several key-consuming devices within a preset network domain based on the key request it receives. This message specifically includes: The gateway device receives the block time threshold and / or block quantity threshold sent by the blockchain; When the time of the key request received by the gateway device reaches the block time threshold and / or the number of requests reaches the block number threshold, the gateway device generates a message to start the key aggregation and transmission process for this round.
20. The method according to any one of claims 14-19, characterized in that, The gateway device is a first gateway device, and the key fragment includes a first key sub-fragment; The method specifically includes: The first gateway device receives the first aggregation instruction. The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of several key consumption devices' respective first key sub-fragments; The first gateway device generates a collection data packet according to the first aggregation instruction. The collection data packet includes a first key sub-fragment of each of the key consuming devices. The first gateway device sends a collection data packet to the second gateway device. This enables the second gateway device to receive the aggregated data packet, generate an aggregated key based on the second aggregation instruction and the aggregated data packet, and transmit the aggregated key to several key-consuming devices. The aggregated key includes a first key sub-fragment and a second key sub-fragment for each of the key-consuming devices. Specifically, the second aggregation instruction is sent from the blockchain to the second gateway device, instructing the provision of second key sub-fragments from several key-consuming devices, and aggregating the first and second key sub-fragments. This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
21. The method according to claim 20, characterized in that, Before the first gateway device receives the first aggregation instruction, the method further includes: The first gateway device sends the key request it received to the blockchain. Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain; This allows the blockchain to send a first aggregation instruction to the first gateway device after comparing the key request received by the first gateway device and the second gateway device to ensure they are consistent.
22. The method according to claim 21, characterized in that, The first gateway device generates a set of data packets according to the first aggregation instruction, specifically including: The first gateway device obtains the key request it received from the end of the previous key aggregation transmission process to the start of the current key aggregation transmission process according to the first aggregation instruction; The first gateway device determines several key-consuming devices to participate in this round of key aggregation and transmission process based on the key request it receives. The first gateway device randomly generates several sequences of length L. K1 Each of the key-consuming devices has its own first key fragment key1; The first gateway device fills key1 with a key fragment in a preset format, and then combines several key fragments containing key1 into a set data packet.
23. The method according to claim 22, characterized in that, The first gateway device fills key1 with a key fragment in a preset format, specifically including: The first gateway device obtains the key-consuming device identifier (DID) of each of the several key-consuming devices on the first gateway device. a It obtains the hardware information of several key-consuming devices and generates a verification random number R for each key-consuming device. V ; The first gateway device, based on the hardware information and R of several key-consuming devices, V Generate several key consumption devices, each with its own one-time random key. T ; The first gateway device randomly generates several keys, each consuming a random string K. M And based on the DID of each of the key-consuming devices a and key T Generate several keys, each consuming the device's own authentication string K. I ; The first gateway device will K M K I Enter the first and second fields of the preset format key fragment in the selected order, and enter key1 in the third field. The preset format key fragment also includes a fourth field, which is used to carry the second key sub-fragment key2 in the second gateway device.
24. The method according to claim 23, characterized in that, The first gateway device obtains several key consumption devices' respective hardware information, specifically including: The first gateway device obtains the hardware information of each of the key-consuming devices from the first registration information sent to the first gateway device by the key-consuming devices. The first gateway device, based on the hardware information and R of several key-consuming devices, V Generating several keys consumes the key of each device. T Specifically, it includes: The first gateway device consumes several keys, each with its own hardware information and R. V The fourth hash value is calculated by combining the hardware information of several key-consuming devices and R. V The default value combination is used to calculate the fifth hash value. Based on the comparison result of the fourth and fifth hash values, several keys are generated, each consuming a key for its respective device. T .
25. The method according to claim 23, characterized in that, The first gateway device generates several keys, consuming the respective R of each device. V Subsequently, the method further includes: The first gateway device will R V Send to the second gateway device. This allows the second gateway device to obtain the hardware information of each of the key-consuming devices from the first registration information sent to the second gateway device by the key-consuming devices, and combine it with R V Generating several keys consumes the key of each device. T .
26. The method according to claim 25, characterized in that, The first gateway device randomly generates several keys, consuming the K keys of each device. M And based on the DID of each of the key-consuming devices a and key T Generating several keys consumes the K of each device. I Specifically, it includes: The first gateway device randomly selects several key-consuming devices, each with their own K... M K I The order in which the first and second fields of the key fragment are filled in is: K M K I , or K I K M ; If the selected order is: K M K I Then the first gateway device randomly generates a segment of length L for the corresponding key-consuming device. M =L K1 K M And calculate K for the corresponding key-consuming device. I =DID a × key T ×L M To obtain a segment of length L I K I ; If the selected order is: K I K M Then the first gateway device calculates K for the corresponding key-consuming device. I =DID a × key T × L K1 To obtain a segment of length L I K I And randomly generate a segment of length L for the corresponding key-consuming device. M =L I K M .
27. The method according to any one of claims 23-26, characterized in that, After the first gateway device fills key1 into a key fragment of a preset format, the method further includes: The first gateway device generates parameter matrices P for several key-consuming devices, where P includes K for each key-consuming device. M and K I Sequence identifier, first field length L and R V ; The first gateway device sends P to several key-consuming devices. So that several key-consuming devices can obtain their respective key1 from the aggregate key according to P.
28. The method according to claim 27, characterized in that, The first gateway device generates several keys, each consuming the P of its respective device, specifically including: The first gateway device obtains the K values of several key-consuming devices in this round of key aggregation and transmission process. M and K I Sequence identifier, L and R V And obtain K from the previous round of key aggregation and transmission process. M 'Length L M '、and verify random number R V '; The first gateway devices are arranged in different orders according to pre-constrained conditions. M and K I Sequence identifier, L, R V Form matrices M1 and M2, using L M 'and R V The operations with M1 and M2 generate several keys, each consuming the P of its respective device.
29. The method according to claim 20, characterized in that, The first gateway device sends a collection data packet to the second gateway device, specifically including: The first gateway device sends a one-time random key to the second gateway device. OTPa Encrypted collection of data packets, This enables the second gateway device to obtain a key from the blockchain. OTPa And based on the key OTPa Parse the collection of data packets.
30. The method according to any one of claims 14-19, characterized in that, The gateway device is a second gateway device, and the key fragment includes a second key sub-fragment; The method specifically includes: The second gateway device receives the second aggregation command and the aggregated data packet. Specifically, the second aggregation instruction is sent from the blockchain to the second gateway device, instructing the provision of second key sub-fragments from several key-consuming devices, and aggregating the first and second key sub-fragments. The aggregated data packet is generated by the first gateway device after receiving the first aggregation instruction, and then sent to the second gateway device. The aggregated data packet includes several first key sub-fragments from each of the key-consuming devices. The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of several key consumption devices' respective first key sub-fragments; The second gateway device generates an aggregation key based on the second aggregation instruction and the aggregate data packet. The aggregation key includes a first key sub-fragment and a second key sub-fragment of each of the key consuming devices. The second gateway device transmits the aggregated key to several key-consuming devices. This allows several key-consuming devices to consume their respective first and second key sub-fractions from the aggregated key to obtain their respective required keys.
31. The method according to claim 30, characterized in that, Before the second gateway device receives the second aggregation instruction, the method further includes: The second gateway device sends the key request it received to the blockchain. Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain; This allows the blockchain to send a second aggregation instruction to the second gateway device after comparing the key request received by the first gateway device and the second gateway device to ensure they are consistent.
32. The method according to claim 31, characterized in that, The second gateway device generates an aggregation key based on the second aggregation instruction and the aggregated data packet, specifically including: The second gateway device obtains several key fragments based on the aggregated data packets. Each key-consuming device fills in a key fragment of the first key sub-fragment key1 in a preset format, and the length of key1 is L. K1 ; The second gateway device randomly generates several sequences of length L according to the second aggregation instruction. K2 Each of the key-consuming devices has its own second key fragment, key2, L K1 + L K2 = L K L K Each key consumes the required key length for its respective device. The second gateway device fills key2 into a key fragment in a preset format, and combines several key fragments containing key1 and key2 into an aggregate key.
33. The method according to claim 32, characterized in that, The second gateway device obtains several key fragments based on the aggregated data packets. Each key-consuming device has filled in a key1-preset format key fragment, specifically including: The second gateway device sends a one-time random key to the blockchain to obtain the first gateway device's key. OTPa The first request, Among them, key OTPa The first gateway device is used to encrypt the collection of data packets; The second gateway device receives the key sent by the blockchain. OTPa ; The second gateway device uses the key. OTPa Parse the collection data packet to obtain the K values of several key-consuming devices in the collection data packet, which are filled into the first, second, and third fields in a selected order. M / K I K I / K M The key fragment in the preset format of key1.
34. The method according to claim 32, characterized in that, The second gateway device fills key2 into a key fragment of a preset format, and combines several key fragments containing key1 and key2 into an aggregate key, specifically including: The second gateway device sends a second request to the blockchain to obtain the routing table RT. RT is generated by the blockchain, and the identifiers of several key-consuming devices are randomly arranged in RT. The second gateway device receives the RT sent by the blockchain; The second gateway device uses the sequence number n of each key consumption device in RT to encrypt key2, and the encrypted result has a length of L. K2 Enter the fourth field of the key fragment in the preset format in key2; The second gateway device arranges several key consumption devices' key fragments in the order of RT to form an aggregate key.
35. The method according to claim 33 or 34, characterized in that, The key received by the second gateway device OTPa Alternatively, RT can be used by the blockchain with the authentication key of a second gateway device. IDb encryption; The second gateway device receives the key sent by the blockchain. OTPa Or after RT, the method further includes: The second gateway device uses a key. IDb Parse key OTPa Obtain the sixth hash value, or use the key on the second gateway device. IDb Parse RT to obtain the seventh hash value; The second gateway device sends the sixth or seventh hash value to the blockchain. This allows the blockchain to verify either the sixth or seventh hash value. If the verification fails, a termination instruction for this round of key aggregation and transmission is sent to the second gateway device. If the second gateway device receives a termination command, it terminates the current key aggregation transmission process according to the termination command; otherwise, the second gateway device continues the current key aggregation transmission process.
36. The method according to claim 34, characterized in that, The RT randomly arranges several key-consuming devices into key-consuming device identifiers (DIDs) on the second gateway device. b ; Before the second gateway device transmits the aggregated key to several key-consuming devices, the method further includes: The second gateway device will arrange each DID in RT. b Compared to the DID listed first b.pre and the next DID b .next, each DID b In RT, the permutation numbers n and L K2 'Combines routing information data packets;' The second gateway device sends its respective routing information data packets to several key-consuming devices. So that, after receiving the aggregated key, several key-consuming devices, according to DID b.pre Verify the correctness of the source of the aggregate key received by each entity, and based on n and L... K2 'Retrieve key2 from the aggregated key, and after stripping the key fragments from the received aggregated key, send the remaining aggregated key to DID.' b The key consumption device for .next.
37. The method according to claim 36, characterized in that, The second gateway device sends its respective routing information data packets to several key-consuming devices, specifically including: The second gateway device obtains the hardware information of each of the key-consuming devices from the first registration information sent to it by the key-consuming devices, and receives the verification random number R of each of the key-consuming devices sent by the first gateway device. V ; The second gateway device, based on the hardware information and R of several key-consuming devices, V Generate several key consumption devices, each with its own one-time random key. T ; The second gateway device uses a key. T Encrypt the routing information data packets and send the encrypted routing information data packets to several key-consuming devices. So that several key-consuming devices obtain R from the first gateway device V It generates its own key by combining its own hardware information. T And based on the key T Parse the routing information data packet.
38. The method according to any one of claims 14-19, characterized in that, The gateway device transmits the aggregated key to several key-consuming devices, specifically including: The gateway device sends the aggregated key to the first-hop key-consuming device among the several key-consuming devices participating in this round of key aggregation transmission process. This allows each hop key-consuming device among the several key-consuming devices participating in this round of key aggregation and transmission process to receive the aggregated key in sequence, and after obtaining its own key, it to strip its own key fragment from the aggregated key it received, and send the remaining aggregated key to its next hop key-consuming device.
39. The method according to claim 38, characterized in that, After several key-consuming devices obtain their respective keys based on their respective key fragments, the method further includes: The gateway device receives the end message of the current key aggregation transmission process. The end message of this round of key aggregation and transmission process is sent by the last hop key consuming device participating in this round of key aggregation and transmission process when it detects that the remaining aggregate key length is 0 after stripping its own key fragment from the aggregate key it received.
40. A key aggregation transmission method, characterized in that, Applied to key-consuming devices, the method includes: The key-consuming device broadcasts its key request to all gateway devices within the preset network domain. This allows any gateway device to send a key aggregation and transmission process start message to the blockchain based on the key request it receives. This enables the blockchain to begin generating aggregation instructions based on the current key aggregation transmission process. The key-consuming device consumes its own key fragments from the aggregated key to obtain its own required key. The aggregated key is generated by the gateway device according to the aggregation instruction and transmitted to several key-consuming devices. The aggregated key includes key fragments from each of the key-consuming devices. The aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys of several key-consuming devices in an aggregated form. Before the blockchain sends the aggregation command to the gateway device, the method further includes: The key-consuming device sends its first registration information to each gateway device within the preset network domain based on its own first self-information. This allows each gateway device to send its second registration information to the blockchain based on its second self-information and first registration information. This enables the blockchain to complete the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
41. The method according to claim 40, characterized in that, in: The key-consuming device uses its own first self-information and verification random number R V The default value sends the first registration information to each gateway device within the preset network domain.
42. The method according to claim 41, characterized in that, The key-consuming device uses its own first self-information and R V The default value sends the first registration information to each gateway device in the preset network domain, specifically including: The key-consuming device obtains its own hardware information to form first self-information, and then combines the first self-information with R. V The default values form the first registration information, and the first registration information is sent to each gateway device in the preset network domain. This allows each gateway device to obtain its own information from the first registration information, and to complete the registration of each key-consuming device based on the first self-information, thereby generating a key-consuming device identifier (DID) for each key-consuming device. The DID is then added to the second registration information and sent to the blockchain. This enables the blockchain to generate a network domain identifier (NID) for a preset network domain and a gateway device identifier (GID) for each gateway device, and then sends the corresponding NID and GID to each gateway device.
43. The method according to any one of claims 40-42, characterized in that, The key-consuming device consumes its own key fragments from the aggregated key to obtain its required key, specifically including: The key-consuming device receives the aggregated key; The key-consuming device obtains its own key fragment from the aggregated key, and obtains its own key based on its own key fragment; The key-consuming device strips its own key fragment from the aggregated key and sends the remaining aggregated key to its next-hop key-consuming device.
44. The method according to claim 43, characterized in that, The key-consuming device receives the aggregated key, specifically including: If the key-consuming device is the first-hop key-consuming device in this round of key aggregation transmission process, then the first-hop key-consuming device receives the aggregated key sent by the gateway device; otherwise, the non-first-hop key-consuming device receives the remaining aggregated key sent by the previous-hop key-consuming device.
45. The method according to claim 44, characterized in that, The gateway device includes a first gateway device and a second gateway device, and the key fragment includes a first key sub-fragment and a second key sub-fragment; The first-hop key consuming device receives the aggregated key sent by the gateway device, specifically including: The first-hop key-consuming device receives the aggregated key sent by the second gateway device. The aggregation key is generated by the second gateway device after receiving the second aggregation instruction and the aggregation data packet, and then sent to the first hop key consuming device. The aggregation key includes first key sub-fragments and second key sub-fragments for each of the key consuming devices. The second aggregation instruction is sent from the blockchain to the second gateway device, instructing it to provide the second key sub-fragments of each of the several key consuming devices, and to aggregate the first key sub-fragments and the second key sub-fragments. The aggregated data packet is generated by the first gateway device after receiving the first aggregation instruction, and then sent to the second gateway device. The aggregated data packet includes several first key sub-fragments from each of the key-consuming devices. The first aggregation instruction is sent from the blockchain to the first gateway device, instructing the provision of first key sub-fragments of each of the several key-consuming devices.
46. The method according to claim 45, characterized in that, The key-consuming device obtains its own key fragment from the aggregated key, and obtains its own key based on its own key fragment, specifically including: The key-consuming device obtains its own first key fragment from the aggregated key; The key-consuming device obtains its own second key fragment from the aggregated key; The key-consuming device concatenates the first key fragment and the second key fragment to obtain its own key.
47. The method according to claim 46, characterized in that, Before the key-consuming device obtains its own first key fragment from the aggregated key, the method further includes: The key-consuming device receives a parameter matrix P sent by the first gateway device, where P includes the key-consuming device's own verification random number R. V The length L of the first field in the key fragment, and the random string K. M and authentication string K I Sequence identifier; The key-consuming device obtains its own hardware information and retrieves R based on P. V And based on its own hardware information and R V Generate your own one-time random key T .
48. The method according to claim 47, characterized in that, The key-consuming device consumes key information based on its own hardware information and R. V Generate your own one-time random key T Specifically, it includes: The key-consuming device will send its own hardware information and R V Combine and calculate the fourth hash value, including its own hardware information and R. V The default value combination is used to calculate the fifth hash value, and the key is generated based on the comparison result between the fourth and fifth hash values. T .
49. The method according to claim 48, characterized in that, The key-consuming device obtains its own first key fragment from the aggregated key, specifically including: The key-consuming device obtains its own Key-Consuming Device Identifier (DID) from the first gateway device. a And obtain L and K based on P. M and K I The order, Among them, K M and K I The first or second field of a key fragment in a preset format is generated by the first gateway device and filled in according to the selected order; Key-consuming devices based on DID a L, K M and K I The order and key T Obtain its first key fragment key1 from the aggregate key.
50. The method according to claim 49, characterized in that, The key-consuming device obtains its own R based on P. V L, K M and K I The order specifically includes: The key-consuming device obtains its own verification random number R from the previous round of key aggregation and transmission process. V 'with random string K M 'Length L M '; Key-consuming devices use R V 'with L M 'Analyze P to obtain matrices M1 and M2, in which R is arranged in different orders according to pre-defined constraints.' V L, K M and K I Sequence identifier; The key-consuming device obtains its own R from M1 and M2 according to pre-constrained conditions for the current round of key aggregation and transmission process. V L, K M and K I The sequence identifier, according to K M and K I Obtaining K from the sequence identifier M and K I The order.
51. The method according to claim 49, characterized in that, Key-consuming devices based on DID a L, K M and K I The order and key T The first key fragment key1 is obtained from the aggregated key, specifically including: If K M and K I The order is: K M K I Then the key-consuming device obtains a length of L starting from the first bit of the aggregated key. M =L of K M From the Lth M Starting from position +1, we obtain a length of L. I =L M K I According to K I = DID a × key T × L K1 The inverse operation yields the length L of key1. K1 From the Lth I +L M Starting from position +1, we obtain a length of L. K1 key1; If K M and K I The order is: K I K M Then the key-consuming device obtains a length of L starting from the first bit of the aggregated key. I =L of K I According to K I = DID a × key T × L M The inverse operation of K is obtained M Length L M From the Lth I Starting from position +1, we obtain a length of L. M K M From the Lth I +L M Starting from position +1, we obtain a length of L. K1 =L M key1.
52. The method according to claim 47 or 48, characterized in that, Before the key-consuming device obtains its own second key fragment from the aggregated key, the method further includes: The key-consuming device receives routing information data packets sent by the second gateway device. Among them, the routing information data packet is generated by the second gateway device using a one-time random key of the key consumption device. T encryption; Key consumption device uses key T Parse the routing information data packet, which includes the DID of the device that consumed the previous hop key. b.pre and the DID of the next-hop key consumption device b .next, the sequence number n of the key-consuming device itself, and the length L of the encrypted second key fragment key2. K2 '.
53. The method according to claim 52, characterized in that, The key-consuming device obtains its own second key fragment from the aggregated key, specifically including: The key-consuming device obtains its own L from the routing information data packet. K2 'and n, Among them, L K2 'The key2 is generated by the second gateway device and then encrypted using n. n is obtained by the second gateway device from the routing table RT.' The RT is generated by the blockchain, and several key-consuming devices' key-consuming device identifiers (DIDs) are randomly arranged in the RT on the second gateway device. b ; Key consumption device from L I +L M +L K1 Starting from position +1, we obtain a length of L. K2 'Use n to encrypt key2, and use n to decrypt the encrypted key2 to obtain a result of length L. K2 key2.
54. The method according to claim 52, characterized in that, Key consumption device uses key T After parsing the routing information data packet, the method further includes: The key-consuming device obtains the DID from the routing information data packet. b.pre ; Key-consuming devices based on DID b.pre Verify that the source of the aggregated key is correct. If it is incorrect, terminate the current key aggregation and transmission process.
55. The method according to claim 52, characterized in that, The key-consuming device strips its own key fragment from the aggregated key and sends the remaining aggregated key to its next-hop key-consuming device, specifically including: The key-consuming device obtains the DID from the routing information data packet. b.next ; The key-consuming device extracts its own key fragments from the aggregated key, based on the DID. b.next The remaining aggregated key after stripping its own key fragment is sent to the next-hop key-consuming device.
56. The method according to claim 46, characterized in that, After the key-consuming device concatenates the first key fragment and the second key fragment to obtain its own key, the method further includes: The key-consuming device generates a ninth hash value based on its own key and sends the ninth hash value to the blockchain. This allows the blockchain to compare the ninth hash value with the corresponding eighth hash value to verify whether the key obtained by the key-consuming device is accurate. If it is inaccurate, a key-discarding instruction is sent to the key-consuming device. The eighth hash value is generated by the second gateway device by splicing together the first key sub-fragments and second key sub-fragments of each of the key consumption devices, and then sent to the blockchain, where it is stored in the private storage space of the second gateway device. If a key-consuming device receives a key-discard instruction, it discards its own key obtained in the current key aggregation and transmission process according to the key-discard instruction, and rebroadcasts its own key request.
57. The method according to claim 43, characterized in that, After the key-consuming device strips its own key fragments from the aggregated key, the method further includes: The key-consuming device checks whether the length of the remaining aggregated key after stripping its own key fragment is 0. If so, it sends a message to the blockchain and gateway devices indicating the end of the current key aggregation transmission process.
58. A blockchain, characterized in that, include: The first module is used to enable: The blockchain receives the message indicating the start of the current key aggregation and transmission process. In this round of key aggregation and transmission process, the start message is generated and sent by any gateway device within the preset network domain for several key-consuming devices based on the key requirement requests it receives. Among them, the key request is broadcast by a number of key-consuming devices with key requirements in the preset network domain to all gateway devices in the preset network domain; The blockchain begins generating aggregation instructions based on the key aggregation transmission process of this round; The instruction module is used to enable the blockchain to send aggregation instructions to the gateway device. The aggregation instructions instruct the delivery of the required keys to several key-consuming devices in an aggregated form. This enables the gateway device to generate an aggregation key based on the aggregation instruction, and transmit the aggregation key to several key-consuming devices. The aggregation key includes key fragments for each of the key-consuming devices. This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys. The third registration module is used to enable: The blockchain receives the second registration information. Specifically, the second registration information is sent to the blockchain by each gateway device within the preset network domain based on its own second self-information and the first registration information. The first registration information is sent by each key-consuming device in the preset network domain to each gateway device according to its own first self-information; The blockchain completes the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
59. A gateway device, characterized in that, include: The second starting module is used to enable: The gateway device receives key request requests broadcast by several key-consuming devices within a preset network domain that have key requirements. The gateway device generates a key aggregation and transmission process start message for several key-consuming devices within a preset network domain based on the key request it receives, and sends the key aggregation and transmission process start message to the blockchain. This enables the blockchain to begin generating aggregation instructions based on the current key aggregation transmission process. The aggregation module enables gateway devices to generate an aggregation key based on aggregation instructions. The aggregation key includes key fragments from several key-consuming devices. The aggregation instruction is sent from the blockchain to the gateway device, instructing it to provide the required keys of several key-consuming devices in an aggregated form. The transmission module, connected to the aggregation module, enables the gateway device to transmit the aggregated key to several key-consuming devices. This allows several key-consuming devices to consume their respective key fragments from the aggregated key to obtain their respective required keys. The second registration module is used to enable: The gateway device receives the first registration information. The first registration information is sent by each key-consuming device in the preset network domain to each gateway device in the preset network domain according to its own first self-information. The gateway device sends its second registration information to the blockchain based on its second self-information and the first registration information. This enables the blockchain to complete the registration of the gateway device based on the second registration information and to consume the identifier of each key that sends the first registration information to the gateway device.
60. A key consumption device, characterized in that, include: The broadcast module enables the key-consuming device to broadcast its key request to all gateway devices within a preset network domain. This allows any gateway device to send a key aggregation and transmission process start message to the blockchain based on the key request it receives. This enables the blockchain to begin generating aggregation instructions based on the current key aggregation transmission process. The consumption module enables the key consumption device to consume its own key fragments from the aggregated key to obtain its required key. The aggregated key is generated by the gateway device according to the aggregation instruction and transmitted to several key-consuming devices. The aggregated key includes key fragments from each of the key-consuming devices. The aggregation instruction is sent from the blockchain to the gateway device, instructing it to aggregate and form the required keys for each of the key-consuming devices. The first registration module is used to enable: The key-consuming device sends its first registration information to each gateway device within the preset network domain based on its own first self-information. This allows each gateway device to send its second registration information to the blockchain based on its second self-information and first registration information. This enables the blockchain to complete the registration of each gateway device and the identification of each key-consuming device that sends the first registration information to each gateway device based on the second registration information.
61. A computer-readable storage medium, characterized in that, It stores a computer program, which, when executed by a processor, implements the key aggregation transmission method as described in any one of claims 1-13, 14-39, or 40-57.
Citation Information
Patent Citations
Contract management method based on block chain and combined key and related equipment
CN115085934A