A key acquisition method and related apparatus
By generating pre-shared keys between nodes and utilizing freshness parameters and key negotiation algorithms, security threats in node communication are addressed, ensuring the reliability of authentication and the stability of the system, thereby improving the security of the vehicle communication system.
Patent Information
- Application Number
- CN202310200972.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-29
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2040-05-29
AI Technical Summary
The security of existing node communication is difficult to guarantee, especially in vehicle communication systems, which are vulnerable to hacker attacks and untrusted connections, thus threatening user privacy and security.
By generating a pre-shared key (PSK) between nodes, and utilizing freshness parameters and key negotiation algorithms, the security of node authentication is ensured, and association with untrusted nodes is avoided.
It improves the security of node communication, prevents attackers from forging identities, and ensures that connections are only allowed after both parties have passed identity authentication, thereby enhancing the stability and security of the system.
Smart Images

Figure CN116437323B_ABST
Abstract
Description
[0001] This application is a divisional application, the original application number is 202080015291.5, the original application date is May 29, 2020, and the entire contents of the original application are incorporated herein by reference. TECHNICAL FIELD
[0002] The present application relates to the field of communication technology, especially the field of short-distance communication technology, such as cabin domain communication. Specifically, it relates to a key acquisition method and related devices. BACKGROUND
[0003] In today's rapid development of informatization, mobile terminals, whether mobile phones, tablets or other portable intelligent terminals, are important personal intelligent tools that we cannot do without. While we are enjoying the convenience brought by informatization, we are also facing the threat of security vulnerabilities and privacy leaks. Taking smart cars as an example, with the widespread application of vehicle communication, wireless communication has brought a series of safety hazards to cars. For example, through existing distance communication technology, hackers can hack into the vehicle information system, obtain vehicle information, and even remotely control the car, posing a high threat to user privacy and vehicle safety, affecting millions of cars worldwide.
[0004] Therefore, in order to ensure the security of communication, before two nodes communicate, a pairing mode is usually used for association. When two nodes are associated, the existing method usually pairs by inputting a password or directly uses an open mode. For example, when pairing a Bluetooth headset, you can connect by directly clicking the other party's name. For another example, open Wi-Fi in public places often does not require a password to be entered. Even if a password is required, since Wi-Fi passwords are usually easy to leak, it is often difficult to ensure the security of communication, which can lead to data leakage and threaten user privacy and security. For a communication system, especially for a vehicle communication system, this situation can easily cause the vehicle to be connected by an untrusted connection, leading to communication between the vehicle and an untrusted attacker, endangering the personal safety of the driver and passengers.
[0005] Therefore, how to improve the security of node communication is a technical problem that those skilled in the art are studying. SUMMARY
[0006] The embodiments of the present application disclose a key acquisition method and related devices, which can improve the security of communication.
[0007] In a first aspect, the embodiments of the present application disclose a key acquisition method, which comprises:
[0008] The first node receives a first association request message from the second node, and the first association request message comprises a first freshness parameter;
[0009] The first node obtains a first pre-shared key (PSK); wherein the first PSK corresponds to an identity of the second node; and the first PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from the first node. Further, the first PSK is used to verify the identity of the second node.
[0010] In the above method, the PSK is a secret value shared between the first node and the second node. The first node generates the first PSK according to the second freshness parameter from the second node and the third freshness parameter from the first node, and the first PSK corresponds to the identity of the second node, and is used to verify the identity of the second node (for example, the second node generates identity authentication information according to the PSK, and the first node can verify the identity authentication information of the second node by using the first PSK; for another example, the second node encrypts or integrity protects the message content by using the PSK (or a key derived from the PSK), and the first node can obtain the message content from the second node by using the first PSK). In this way, if an attacker wants to impersonate the identity of the second node to associate with the first node, since the second freshness parameter and the third freshness parameter used to generate the first PSK can be obtained before the first association request message, for example, can be obtained when the first node and the second node are associated for the first time, since the data obtained before is usually difficult to be cracked, so that the attacker cannot forge the PSK, and thus cannot pass the identity verification of the first node, thereby avoiding the connection of the first node with an untrusted node, and improving the communication security of the first node.
[0011] In a possible implementation of the first aspect, the above method further comprises:
[0012] The first node sends a first authentication request message to the second node, wherein the first authentication request message comprises first identity authentication information and a fourth freshness parameter, and the first identity authentication information is generated according to the first PSK and a first freshness parameter.
[0013] In the above method, since the PSK is a secret value shared between the first node and the second node, the first PSK in the first node usually has the same value as the second PSK in the second node. The first node generates the first identity authentication information according to the first PSK and the first freshness parameter, so that the second node can verify the identity of the first node according to the second PSK. If the second PSK stored in the second node cannot pass the verification, it means that the identity of the first node is untrusted, thereby avoiding the association of the second node with an untrusted node, and improving the security of the communication of the second node.
[0014] In another possible implementation of the first aspect, the method further comprises:
[0015] The first node receives a first authentication response message from the second node, the first authentication response message comprising second identity authentication information;
[0016] If the second identity authentication information is verified by the first node according to the first PSK and the fourth freshness parameter, the first node sends a first association response message to the second node.
[0017] In the above method, before the first node and the second node communicate, the first node and the second node determine the identities of both sides through the identity authentication information. After the identity authentication is passed, the communication is allowed, thereby avoiding the access of untrusted nodes and improving the security of node communication.
[0018] In a further possible implementation form of the first aspect, the first node obtains the first pre-shared key PSK, comprising:
[0019] The first PSK is obtained according to the correspondence between the first PSK and the identity of the second node.
[0020] In the above method, the correspondence between the first PSK and the identity of the second node in the first node indicates that the second node has been associated with the first node before or the identity of the second node is pre-configured with the first PSK in the first node, so that the first node can obtain the first PSK according to the correspondence.
[0021] In a further possible implementation form of the first aspect, the first node has a first correspondence set; the first node obtains the first pre-shared key PSK, comprising:
[0022] The first PSK is obtained according to the correspondence between the first PSK and the identity of the second node through the first correspondence set.
[0023] It can be seen that the first node can store the correspondence between the first PSK and the identity of the second node in the form of the correspondence set.
[0024] In a further possible implementation form of the first aspect, the first node obtains the first pre-shared key PSK, comprising:
[0025] The first node generates the first PSK according to the first freshness parameter and the fourth freshness parameter; wherein the first freshness parameter is the second freshness parameter and the fourth freshness parameter is the third freshness parameter.
[0026] In the method, the first PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter from the first node. Generally, when the first node is associated with the second node for the first time or the first node deletes the corresponding relationship, there is no PSK corresponding to the identity of the second node in the first node, and thus the first node can generate a new first PSK according to the first freshness parameter and the fourth freshness parameter for verifying the identity of the second node.
[0027] In a further possible implementation of the first aspect, before the first node generates the first PSK according to the first freshness parameter and the fourth freshness parameter, the method further comprises:
[0028] The first node obtains first confirmation indication information, the first confirmation indication information indicating that the association with the second node is allowed.
[0029] It can be seen that when the new first PSK is generated, the confirmation of the user is needed. In this way, when an attacker connects the first node by using the identity of the attacker, since there is no PSK corresponding to the identity of the attacker in the first node, the identity of the new node can be verified by the user, and the first PSK is generated after the first confirmation indication information is obtained, so that the first node is prevented from being associated with an untrusted node, and the security of the communication of the first node is ensured.
[0030] In a further possible implementation of the first aspect, the first node generates the first PSK according to the first freshness parameter and the fourth freshness parameter, and the method comprises:
[0031] The first node generates the first PSK according to the first freshness parameter, the fourth freshness parameter and a first password, the first password being an access password of the first node.
[0032] In an optional design, the access password is a password that needs to be input when another node requests to access the first node, for example, a password that needs to be input when connecting to a Wi-Fi. It can be seen that when the first password is the access password of the first node, the second node connects to the first node by inputting the first password, and thus the first password is used to participate in the generation of the first PSK, so that an attacker who does not obtain the first password cannot crack the first PSK, and thus the first node is prevented from being associated with the attacker who does not obtain the first password.
[0033] In a further possible implementation of the first aspect, the first association request message further comprises a first key agreement algorithm parameter; and the first node generates the first PSK according to the first freshness parameter and the fourth freshness parameter, and the method comprises:
[0034] The first node generates the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first key agreement algorithm parameter.
[0035] The first key agreement algorithm parameter is an algorithm parameter generated in a key agreement process. The key agreement is a process in which two communication parties obtain a secret value by exchanging some parameters. The algorithm used for the key agreement is referred to as a key agreement algorithm, which can also be referred to as a key exchange algorithm. For example, in the Diffie-Hellman (DH) algorithm, two nodes use the same large prime number p and the same random number g (i.e., the prime number p and the random number g are public keys between the first node and the second node), and generate random numbers a and b (i.e., the random number a is a private key of the second node, and the random number b is a private key of the first node). The prime number p, the random number g, the random number a, and the random number b can be regarded as parameters of the key agreement algorithm. The second node sends a value A (i.e., A = g a mod p, A is the first key agreement algorithm parameter) generated by raising g to the power of a modulo (mod) p to the first node. The first node performs a b-th power operation on the received value A to generate a secret value K. The first node sends a value B (i.e., B = g b mod p, B is the second key agreement algorithm parameter) generated by raising g to the power of b modulo p to the second node. The second node performs an a-th power operation on the received value B to generate the secret value K. Since K = A b mod p = (g a mod p) b mod p = g ab mod p = (g b mod p) a mod p = B a mod p, the secret value K generated by the first node and the second node is the same. In the key agreement algorithm process, an attacker cannot infer the generated secret value only by the algorithm parameters transmitted by the first node and the second node. For example, in the DH algorithm, since the values of the prime number p, the random number g, the random number a, and the random number b selected in the actual algorithm are very large, it is difficult to calculate the secret value K according to the prime number p, the random number g, the value A, and the value B transmitted over the network. Therefore, the secret value obtained by the DH algorithm has security.
[0036] In the embodiments of the present application, the second node carries the first key agreement algorithm parameter in the first association request message, and the first key agreement algorithm parameter is determined based on the first key agreement algorithm. The first node can determine the first PSK based on the first key agreement algorithm, the first freshness parameter, the fourth freshness parameter, and the first password according to the first key agreement algorithm parameter. In this way, even if an attacker impersonates the identity information of the second node later, and obtains the first freshness parameter and the fourth freshness parameter used when the first PSK is generated, the attacker cannot crack the first PSK, and thus cannot communicate with the first node, thereby improving the security of communication of the first node.
[0037] In a further possible implementation form of the first aspect, the first association request message further comprises a first key agreement algorithm parameter; and the first node generates the first PSK based on the first freshness parameter and the fourth freshness parameter, comprising:
[0038] generating the first PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and an intermediate key, the first password being an access password; wherein the intermediate key is generated based on the first freshness parameter, the fourth freshness parameter, and the first key agreement algorithm parameter.
[0039] In a further possible implementation form of the first aspect, the first association request message further comprises a first key agreement algorithm parameter, and the first key agreement algorithm parameter is determined based on a first key agreement algorithm; and the first node generates the first PSK based on the first freshness parameter and the fourth freshness parameter, comprising:
[0040] The first node determines a third key agreement algorithm parameter.
[0041] The first node determines a third key agreement algorithm parameter.
[0042] The first node determines a third key agreement algorithm parameter.
[0043] It can be seen that after the first node receives the first key agreement algorithm parameter from the second node, the third key agreement algorithm parameter (or the private key of the first node) is determined. The first node determines the first intermediate key based on the first key agreement algorithm, the first key agreement algorithm parameter, and the third key agreement algorithm parameter, and then generates the first PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0044] In a further possible implementation form of the first aspect, the first association request message further comprises a first key derivation algorithm parameter, the first key derivation algorithm parameter being determined based on a first key derivation algorithm; and the generating the first PSK based on the first freshness parameter and the fourth freshness parameter comprises:
[0045] obtaining a third key derivation algorithm parameter;
[0046] determining a first intermediate key based on the first key derivation algorithm parameter and the third key derivation algorithm parameter based on the first key derivation algorithm;
[0047] determining a second intermediate key based on the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0048] generating the first PSK based on the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0049] In a further possible implementation form of the first aspect, the method further comprises:
[0050] storing, by the first node, a correspondence between the identity of the second node and the first PSK.
[0051] It can be seen that after the first PSK is generated, the first node stores the correspondence between the identity of the second node and the first PSK, and when the first node receives an association request from the second node again later, the first PSK can be obtained based on the correspondence without generating the first PSK again.
[0052] In a further possible implementation form of the first aspect, the method further comprises:
[0053] deleting, by the first node, the correspondence between the identity of the second node and the first PSK if the first password is updated.
[0054] In a further possible implementation form of the first aspect, the first authentication request message further comprises update indication information, the update indication information being used to indicate an update of the PSK.
[0055] It can be seen that after the first PSK is generated based on the first freshness parameter and the fourth freshness parameter, the first node can remind the second node to update the PSK, so as to avoid that the second node uses a previous old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0056] In a further possible implementation form of the first aspect, the method further comprises:
[0057] If the first node verifies that the second identity authentication information does not pass according to the first PSK and the fourth freshness parameter, the first node generates a third PSK according to the first freshness parameter and the fourth freshness parameter.
[0058] The first node sends a second authentication request message to the second node, and the second authentication request message includes third identity authentication information, wherein the third identity authentication information is generated according to the third PSK and the first freshness parameter.
[0059] It can be seen that, in the case that the first node acquires the first PSK according to the corresponding relationship, if the first node verifies that the second identity authentication information does not pass, it may be because the second node generates the second identity authentication information using a newly generated PSK. Therefore, the first node also generates a new PSK (i.e., the third PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates authentication according to the new PSK, thereby improving the stability of the system.
[0060] In another possible implementation of the first aspect, the above-mentioned if the first node verifies that the second identity authentication information does not pass according to the first PSK and the fourth freshness parameter, the first node generates a third PSK according to the first freshness parameter and the fourth freshness parameter, including:
[0061] If the first node verifies that the second identity authentication information does not pass according to the first PSK and the fourth freshness parameter, the first node acquires second confirmation indication information, and the second confirmation indication information represents that the third PSK is allowed to be generated;
[0062] The first node generates a third PSK according to the first freshness parameter and the fourth freshness parameter.
[0063] In another possible implementation of the first aspect, the above-mentioned method further includes:
[0064] The first node receives a second authentication response message from the second node, and the second authentication response message includes fourth identity authentication information;
[0065] If the first node verifies that the fourth identity authentication information passes according to the third PSK and the fourth freshness parameter, the first node sends a second association response message to the second node.
[0066] It can be seen that, after the first node reinitiates authentication according to the new PSK (i.e., the third PSK), the fourth identity authentication information is received from the second node, and if the fourth identity authentication information passes according to the third PSK and the fourth freshness parameter, it indicates that the identity of the second node is trusted, thereby allowing communication with the second node.
[0067] In a second aspect, the embodiments of the present application disclose a key obtaining method, which comprises the following steps:
[0068] The second node sends a first association request message to the first node, wherein the first association request message comprises a first freshness parameter;
[0069] The second node receives a first authentication request message from the first node, wherein the first authentication request message comprises a fourth freshness parameter;
[0070] The second node obtains a second PSK, wherein the second PSK corresponds to an identity of the first node, and the second PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from the first node, and the second PSK is used to verify the identity of the first node.
[0071] In the method, the PSK is a secret value shared between the second node and the first node. The second node generates the second PSK according to the second freshness parameter from the second node and the third freshness parameter from the first node, and the second PSK corresponds to the identity of the first node and is used to verify the identity of the first node (for example, the first node generates identity authentication information according to the PSK, and the second node can verify the identity authentication information of the first node according to the second PSK; for another example, the first node encrypts or integrity protects the message content according to the PSK (or a key derived according to the PSK), and the second node can obtain the message content from the second node according to the first PSK). In this way, if an attacker wants to impersonate the identity of the first node to associate with the second node, since the second freshness parameter and the third freshness parameter used to generate the second PSK can be obtained before the first association request message, for example, can be obtained when the second node associates with the first node for the first time, since the previously obtained data is usually difficult to be cracked, the attacker cannot forge the PSK, and thus cannot pass the identity verification of the second node, thereby avoiding the association of the second node with an untrusted node, and improving the communication security of the second node.
[0072] In a possible implementation of the second aspect, the method further comprises the following steps:
[0073] If the second node verifies that the first identity authentication information is correct according to the second PSK and the first freshness parameter, the second node sends a first authentication response message to the first node, wherein the first authentication response message comprises second identity authentication information, and the second identity authentication information is generated according to the second PSK and the fourth freshness parameter;
[0074] The second node receives a first association response message from the first node.
[0075] In the method, the second PSK in the second node is usually the same as the first PSK in the first node, because the PSK is a secret value shared between the second node and the first node. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, so the second node can verify the identity authentication information of the first node according to the second PSK and the first freshness parameter. If the second PSK stored in the second node cannot be verified, it means that the identity of the first node is not trusted, so the second node can avoid associating with the untrusted node, and the security of the communication of the second node is improved. Correspondingly, the second node also generates the second identity authentication information according to the second PSK and the fourth freshness parameter, for the first node to verify the identity of the second node. After the identity authentication of both parties is passed, the node is allowed to communicate with the node at the opposite end, and the security of the node communication is improved.
[0076] In a further possible implementation form of the second aspect, the second node obtaining the second pre-shared key PSK comprises:
[0077] The second PSK is obtained according to the correspondence between the second PSK and the identity of the first node.
[0078] In the method, the second node has the correspondence between the second PSK and the identity of the first node, which means that the second node has associated with the first node before or that the second node has preconfigured the second PSK corresponding to the identity of the first node, so the second node can obtain the second PSK according to the correspondence.
[0079] In a further possible implementation form of the second aspect, the second node has a second set of correspondences; and the second node obtaining the second pre-shared key PSK comprises:
[0080] The second PSK is obtained according to the correspondence between the second PSK and the identity of the first node, by using the second set of correspondences.
[0081] It can be seen that the second node can store the correspondence between the second PSK and the identity of the first node in the form of the set of correspondences.
[0082] In a further possible implementation form of the second aspect, the second node obtaining the second PSK comprises:
[0083] The second node generates the second PSK according to the first freshness parameter and the fourth freshness parameter; the first freshness parameter is the second freshness parameter, and the fourth freshness parameter is the third freshness parameter.
[0084] In the method, the second PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter in the first authentication request message. Generally, when the second node is associated with the first node for the first time or the second node deletes the corresponding relationship, the second PSK corresponding to the identity of the first node does not exist in the second node, and thus the second node can generate a new second PSK according to the first freshness parameter and the fourth freshness parameter, for verifying the identity of the first node.
[0085] In a further possible implementation manner of the second aspect, before the second node generates the second PSK according to the first freshness parameter and the fourth freshness parameter, the method further includes:
[0086] The second node obtains third confirmation indication information, the third confirmation indication information indicating that the second PSK is allowed to be generated.
[0087] It can be seen that when the new second PSK is generated, the confirmation of the user is needed. In this way, when an attacker connects the second node by using the identity of the attacker, since the second node does not have the PSK corresponding to the identity of the attacker, the identity of the new node can be verified by the user, and the second PSK is generated after the third confirmation indication information is obtained, so that the second node is prevented from being associated with an untrusted node, and the security of the communication of the second node is ensured.
[0088] In a further possible implementation manner of the second aspect, the second node generates the second PSK according to the first freshness parameter and the fourth freshness parameter, and includes:
[0089] The second node generates the second PSK according to the first freshness parameter, the fourth freshness parameter and a first password, the first password being an access password of the first node.
[0090] In an optional design, the access password is a password that needs to be input when another node requests to access the first node, for example, a password that needs to be input when connecting to a Wi-Fi. It can be seen that when the first password is the access password of the first node, the second node connects to the first node by inputting the first password, and thus the first password is used to participate in the generation of the second PSK, so that an attacker who does not obtain the first password cannot crack the second PSK, and thus the second node is prevented from being associated with the attacker who does not obtain the first password.
[0091] In a further possible implementation manner of the second aspect, the first authentication request message further includes a second key agreement algorithm parameter; and the second node generates the second PSK according to the first freshness parameter and the fourth freshness parameter, and includes:
[0092] The second node generates a second PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the second key agreement algorithm parameter.
[0093] The second key agreement algorithm parameter is an algorithm parameter generated in a key agreement process, and the key agreement is a process in which two communication parties obtain a secret value by interacting with a part of parameters. An algorithm used for key agreement is referred to as a key agreement algorithm, which can also be referred to as a key exchange algorithm. For example, in the Diffie-Hellman (DH) algorithm, two nodes use the same large prime number p and the same random number g (i.e., the prime number p and the random number g are public keys between the first node and the second node), and generate random numbers a and b (i.e., the random number a is a private key of the second node, and the random number b is a private key of the first node). The second node sends a value A generated by raising the random number g to the power of a modulo (mod) the prime number p (i.e., A = g a mod p, A is the first key agreement algorithm parameter) to the first node, and the first node generates a secret value K by raising the received value A to the power of b. The first node sends a value B generated by raising the random number g to the power of b modulo (mod) the prime number p (i.e., B = g b mod p, B is the second key agreement algorithm parameter) to the second node, and the second node generates the secret value K by raising the received value B to the power of a. Since K = A b mod p = (g a mod p) b mod p = g ab mod p = (g b mod p) a mod p = B a mod p, the secret value K generated by the first node and the second node is the same. In the key agreement process, an attacker cannot infer the generated secret value by only the algorithm parameters transmitted by the first node and the second node. For example, in the DH algorithm, since the values of the prime number p, the random number g, the random number a, and the random number b are very large in the actual algorithm, it is difficult to calculate the secret value K according to the prime number p, the random number g, the value A, and the value B transmitted over the network, and thus the secret value obtained by the DH algorithm has security.
[0094] In the embodiments of the present application, the first node carries a second key agreement algorithm parameter in the first authentication request message, and the second key agreement algorithm parameter is determined based on the first key agreement algorithm. The second node can determine the second PSK based on the first key agreement algorithm, the second key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter and the first password. In this way, even if an attacker impersonates the identity information of the first node and obtains the first freshness parameter and the fourth freshness parameter used when the second PSK is generated, the attacker cannot crack the PSK and thus cannot communicate with the second node, thereby improving the security of communication of the second node.
[0095] In a further possible implementation form of the second aspect, the first authentication request message further comprises a second key agreement algorithm parameter; and the second node generates the second PSK based on the first freshness parameter and the fourth freshness parameter, comprising:
[0096] generating the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password and an intermediate key, the first password being an access password; and wherein the intermediate key is generated based on the first freshness parameter, the fourth freshness parameter and the second key agreement algorithm parameter.
[0097] In a further possible implementation form of the second aspect, the first association request message further comprises a first key agreement algorithm parameter, the first key agreement algorithm parameter being determined based on the first key agreement algorithm and the fourth key agreement algorithm parameter; and the first authentication request message further comprises a second key agreement algorithm parameter, the second key agreement algorithm parameter being determined by the first node based on the first key agreement algorithm and the third key agreement algorithm parameter; and the second node generates the second PSK based on the first freshness parameter and the fourth freshness parameter, comprising:
[0098] The second node determines a first intermediate key based on the second key agreement algorithm parameter and the fourth key agreement algorithm parameter.
[0099] The second node generates the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key.
[0100] As can be seen, the first key agreement algorithm parameter in the first association request message is generated based on the private key of the second node (i.e. the fourth key agreement algorithm parameter). After the second node receives the second key agreement algorithm parameter from the first node, the second node determines a first intermediate key based on the second key agreement algorithm parameter and the private key of the second node (i.e. the fourth key agreement algorithm parameter), and the first intermediate key is the secret value obtained through key agreement between the first node and the second node. The second node then generates the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key.
[0101] In a further possible implementation form of the second aspect, the first authentication request message further comprises a second key agreement algorithm parameter, the second key agreement algorithm parameter being determined based on the first key agreement algorithm; and the generating the second PSK based on the first freshness parameter and the fourth freshness parameter comprises:
[0102] obtaining a fourth key agreement algorithm parameter;
[0103] determining a first intermediate key based on the second key agreement algorithm parameter and the fourth key agreement algorithm parameter according to the first key agreement algorithm;
[0104] determining a second intermediate key based on the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0105] generating the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0106] In a further possible implementation form of the second aspect, the method further comprises:
[0107] storing, by the second node, a correspondence between the identity of the first node and the second PSK.
[0108] It can be seen that after the second PSK is generated, the second node stores the correspondence between the identity of the first node and the second PSK, and when associated with the first node again later, the second PSK can be obtained according to the correspondence without the need to generate the second PSK again.
[0109] In a further possible implementation form of the second aspect, the method further comprises:
[0110] deleting, by the second node, the correspondence between the identity of the first node and the second PSK if the first password is updated.
[0111] In a further possible implementation form of the second aspect, the first authentication request message further comprises update indication information, the update indication information being used to indicate the update of the PSK.
[0112] It can be seen that after the second PSK is generated based on the first freshness parameter and the fourth freshness parameter, the first node reminds the second node to update the second PSK through the update indication information, so as to avoid that the second node uses the previous old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0113] In a further possible implementation form of the second aspect, the method further comprises:
[0114] If the second node verifies that the first identity authentication information fails according to the second PSK and the first freshness parameter, the second node generates a fourth PSK according to the first freshness parameter and a fourth freshness parameter.
[0115] The second node sends a third authentication response message to the first node, and the third authentication response message includes third identity authentication information generated according to the fourth PSK and the fourth freshness parameter.
[0116] It can be seen that, when the second node acquires the second PSK according to the correspondence, if the first identity authentication information fails to be verified by the second node, it may be that the first identity authentication information is generated by using a newly generated PSK in the first node. Therefore, a new PSK (i.e., the fourth PSK) is generated in the second node according to the first freshness parameter and the fourth freshness parameter, and the authentication is reinitiated according to the new PSK, thereby improving the stability of the system.
[0117] In a further possible implementation form of the second aspect, the method further includes:
[0118] The second node receives a third association response message from the first node.
[0119] In a further possible implementation form of the second aspect, if the second node verifies that the first identity authentication information fails according to the second PSK, the second node generates a fourth PSK according to the first freshness parameter and a fourth freshness parameter, including:
[0120] If the second node verifies that the first identity authentication information fails according to the second PSK, the second node acquires fourth confirmation indication information, and the fourth confirmation indication information indicates that the fourth PSK is allowed to be generated;
[0121] The first node generates a fourth PSK according to the first freshness parameter and the fourth freshness parameter.
[0122] In a further possible implementation form of the second aspect, the method further includes:
[0123] If the second node verifies that the second identity authentication information fails according to the second PSK and the first freshness parameter, the second node deletes the second PSK;
[0124] The second node sends a second association request message to the first node, and the second association request message includes a fifth freshness parameter.
[0125] In a third aspect, the embodiments of the present application disclose an apparatus, including:
[0126] The receiving unit is configured to receive a first association request message from a second node, and the first association request message includes a first freshness parameter.
[0127] a processing unit, configured to obtain a first pre-shared key (PSK); wherein the first PSK corresponds to an identity of the second node; and the first PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from the apparatus. Further, the first PSK is used to verify the identity of the second node.
[0128] It can be seen that the PSK is a secret value shared between the apparatus and the second node. The apparatus generates the first PSK according to the second freshness parameter from the second node and the third freshness parameter from the apparatus, and the first PSK corresponds to the identity of the second node, which is used to verify the identity of the second node (for example, the second node generates identity authentication information according to the PSK, and the first node can verify the identity authentication information of the second node by using the first PSK; for another example, the second node encrypts or integrity protects the message content by using the PSK (or a key derived from the PSK), and the first node can obtain the message content from the second node by using the first PSK). In this way, if an attacker wants to impersonate the identity of the second node to associate with the apparatus, since the second freshness parameter and the third freshness parameter used to generate the first PSK can be obtained before the first association request message, for example, can be obtained when the apparatus and the second node are associated for the first time, since the data obtained before is usually difficult to be cracked, so that the attacker cannot forge the PSK, and thus cannot pass the identity verification of the apparatus, thereby avoiding the apparatus connecting with an untrusted node, and improving the communication security of the apparatus.
[0129] In a possible implementation of the third aspect, the apparatus further includes:
[0130] a sending unit, configured to send a first authentication request message to the second node, wherein the first authentication request message includes first identity authentication information and a fourth freshness parameter, and the first identity authentication information is generated according to the first PSK and a first freshness parameter.
[0131] It can be seen that since the PSK is a secret value shared between the apparatus and the second node, the first PSK in the apparatus usually has the same value as the second PSK in the second node. The apparatus generates the first identity authentication information according to the first PSK and the first freshness parameter, so that the second node can verify the identity of the apparatus according to the second PSK, and if the second PSK stored in the second node cannot pass the verification, the second node can be prevented from associating with an untrusted node, and the security of the communication of the second node is improved.
[0132] In a further possible implementation form of the third aspect, the receiving unit is further configured to receive a first authentication response message from the second node, the first authentication response message comprising the second identity authentication information.
[0133] The sending unit is further configured to send a first association response message to the second node if the second identity authentication information is verified by the apparatus according to the first PSK and the fourth nonce (NONCEa).
[0134] It can be seen that before the apparatus communicates with the second node, the apparatus and the second node determine their identities through the identity authentication information. After the identity authentication is passed, the communication is allowed, thereby avoiding the access of untrusted nodes and improving the security of node communication.
[0135] In a further possible implementation form of the third aspect, the processing unit is specifically configured to obtain the first PSK according to a correspondence between the first PSK and the identity of the second node.
[0136] It can be seen that the correspondence between the first PSK and the identity of the second node in the apparatus indicates that the second node has been associated with the apparatus before or the identity of the second node is preconfigured with the first PSK in the apparatus, and thus the apparatus can obtain the first PSK according to the correspondence.
[0137] In a further possible implementation form of the third aspect, the processing unit is specifically configured to:
[0138] obtain the first PSK according to the correspondence between the first PSK and the identity of the second node through the first correspondence set.
[0139] It can be seen that the apparatus can store the correspondence between the first PSK and the identity of the second node in the form of the correspondence set.
[0140] In a further possible implementation form of the third aspect, the processing unit is specifically configured to generate the first PSK according to a first nonce and a fourth nonce; the first nonce is the second nonce, and the fourth nonce is the third nonce.
[0141] It can be seen that the first PSK is generated according to the first nonce in the first association request message and the fourth nonce from the apparatus. Generally, when the apparatus performs association with the second node for the first time or the apparatus deletes the correspondence, there is no PSK corresponding to the identity of the second node in the apparatus, and thus the apparatus can generate a new first PSK according to the first nonce and the fourth nonce, for verifying the identity of the second node.
[0142] In a further possible implementation form of the third aspect, the processing unit is further configured to obtain first confirmation indication information, the first confirmation indication information being indicative of allowing the second node to associate with the apparatus.
[0143] It can be seen that when the new first PSK is generated, the confirmation of the user needs to be obtained. In this way, when the attacker connects the apparatus using his own identity, since there is no PSK corresponding to the identity of the attacker in the apparatus, the identity of the new node can be verified by the user, and the first PSK is generated only after the first confirmation indication information is obtained, so that the apparatus is prevented from associating with the untrusted node, and the security of the communication of the apparatus is ensured.
[0144] In a further possible implementation form of the third aspect, the processing unit is specifically configured to generate the first PSK according to the first freshness parameter, the fourth freshness parameter and a first password, the first password being an access password of the apparatus.
[0145] The access password is a password that needs to be input by other nodes when requesting to access the apparatus, for example, the password of a Wi-Fi needs to be input when connecting the Wi-Fi. It can be seen that when the first password is the access password of the apparatus, the second node connects the apparatus by inputting the first password, so that the attacker who does not obtain the first password can not crack the first PSK by participating in the generation of the first PSK through the first password, so that the apparatus is prevented from associating with the attacker who does not obtain the first password.
[0146] In a further possible implementation form of the third aspect, the first association request message further comprises a first key agreement algorithm parameter; and the processing unit is specifically configured to generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the first key agreement algorithm parameter.
[0147] It can be seen that the second node carries the first key agreement algorithm parameter in the first association request message, and the first key agreement algorithm parameter is determined based on the first key agreement algorithm. The apparatus can determine the first PSK based on the first key agreement algorithm, the first key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter and the first password. In this way, even if the attacker impersonates the identity of the second node later and obtains the first freshness parameter and the fourth freshness parameter used when the first PSK is generated, the attacker can not crack the first PSK, so that the attacker can not communicate with the apparatus, and the security of the communication of the apparatus is improved.
[0148] In a further possible implementation form of the third aspect, the first association request message further comprises a first key derivation algorithm parameter; and the processing unit is specifically configured to:
[0149] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key, the first password being an access password; wherein the intermediate key is generated according to the first freshness parameter, the fourth freshness parameter and the first key derivation algorithm parameter.
[0150] In a further possible implementation form of the third aspect, the first association request message further comprises a first key derivation algorithm parameter, the first key derivation algorithm parameter being determined based on a first key derivation algorithm; and the processing unit is specifically configured to:
[0151] obtain a third key derivation algorithm parameter;
[0152] determine the first intermediate key based on the first key derivation algorithm, the first key derivation algorithm parameter and the third key derivation algorithm parameter;
[0153] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key.
[0154] It can be seen that after the apparatus receives the first key derivation algorithm parameter from the second node, the third key derivation algorithm parameter (or the private key of the apparatus) is determined. The apparatus determines the first intermediate key based on the first key derivation algorithm, the first key derivation algorithm parameter and the second key derivation algorithm parameter, and generates the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key.
[0155] In a further possible implementation form of the third aspect, the first association request message further comprises a first key derivation algorithm parameter, the first key derivation algorithm parameter being determined based on a first key derivation algorithm; and the processing unit is specifically configured to:
[0156] obtain a third key derivation algorithm parameter;
[0157] determine the first intermediate key based on the first key derivation algorithm, the first key derivation algorithm parameter and the third key derivation algorithm parameter;
[0158] determine a second intermediate key according to the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0159] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0160] In a further possible implementation form of the third aspect, the processing unit is further configured to save the correspondence between the identity of the second node and the first PSK.
[0161] It can be seen that after the first PSK is generated, the correspondence between the identity of the second node and the first PSK is saved, and when the first node receives the association request from the second node again later, the first PSK can be obtained according to the correspondence without generating the first PSK again.
[0162] In a further possible implementation form of the third aspect, the processing unit is further configured to delete the correspondence between the identity of the second node and the first PSK if the first password is updated.
[0163] In a further possible implementation form of the third aspect, the first authentication request message further comprises update indication information, the update indication information being used to indicate the update of the PSK.
[0164] It can be seen that after the first PSK is generated according to the first freshness parameter and the fourth freshness parameter, the second node can be reminded to update the PSK, so as to avoid using the old PSK before the second node to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0165] In a further possible implementation form of the third aspect, the processing unit is further configured to generate a third PSK according to the first freshness parameter and the fourth freshness parameter if the second identity authentication information is verified as failed according to the first PSK and the fourth freshness parameter.
[0166] The sending unit is further configured to send a second authentication request message to the second node, the second authentication request message comprising third identity authentication information, wherein the third identity authentication information is generated according to the third PSK and the first freshness parameter.
[0167] It can be seen that in the case where the first PSK is obtained by the apparatus according to the correspondence, if the second identity authentication information is verified as failed, it may be because the second identity authentication information is generated by using the newly generated PSK in the second node. Therefore, the apparatus generates a new PSK (i.e., the third PSK) according to the first freshness parameter and the fourth freshness parameter, and initiates authentication again according to the new PSK, thereby improving the stability of the system.
[0168] In a further possible implementation form of the third aspect, the processing unit is further configured to obtain second confirmation indication information if the second identity authentication information is verified as failed according to the first PSK and the fourth freshness parameter, the second confirmation indication information representing that the third PSK is allowed to be generated.
[0169] The processing unit is further configured to generate a third PSK according to the first freshness parameter and the fourth freshness parameter.
[0170] In a further possible implementation form of the third aspect, the receiving unit is further configured to receive a second authentication response message from the second node, the second authentication response message comprising fourth identity authentication information.
[0171] The sending unit is further configured to send a second association response message to the second node if the fourth identity authentication information is verified to be passed according to the third PSK and the fourth freshness parameter.
[0172] It can be seen that, after the above apparatus reinitiates authentication according to the new PSK, the fourth identity authentication information sent by the second node is received again, and if the fourth identity authentication information is verified to be passed, it indicates that the identity of the second node is trusted, and thus the apparatus can allow communication with the second node.
[0173] In a fourth aspect, an embodiment of the present application discloses an apparatus, which comprises:
[0174] The sending unit is configured to send a first association request message to the first node, the first association request message comprising a first freshness parameter.
[0175] The receiving unit is configured to receive a first authentication request message from the first node, the first authentication request message comprising a fourth freshness parameter.
[0176] The obtaining unit is configured to obtain a second PSK, wherein the second PSK corresponds to an identity identifier of the first node; the second PSK is a PSK generated according to a second freshness parameter from the apparatus and a third freshness parameter from the first node, and the second PSK is used to verify the identity of the first node.
[0177] It can be seen that the PSK is a secret value shared between the device and the first node. The device generates the second PSK through the second freshness parameter and the third freshness parameter from the device, and the second PSK corresponds to the identity of the first node, and is used to verify the identity of the first node (for example, the first node generates identity authentication information according to the PSK, and the second node can verify the identity authentication information of the first node through the second PSK; for another example, the first node encrypts or integrity protects the message content through the PSK (or a key derived from the PSK), and the second node can obtain the message content from the second node through the first PSK). In this way, if an attacker wants to impersonate the identity of the first node to associate with the device, since the second freshness parameter and the third freshness parameter for generating the second PSK can be obtained before the first association request message, for example, can be obtained when the device and the first node are associated for the first time, since the previously obtained data is usually difficult to crack, so that the attacker cannot fake the PSK, and thus cannot pass the identity verification of the device, thereby avoiding the association of the device with an untrusted node, and improving the communication security of the device.
[0178] In a possible implementation of the fourth aspect, the sending unit is further configured to send, if the first identity authentication information is verified to be passed according to the second PSK and the first freshness parameter, a first authentication response message to the first node, wherein the first authentication response message includes second identity authentication information, and the second identity authentication information is generated according to the second PSK and a fourth freshness parameter.
[0179] The receiving unit is further configured to receive a first association response message from the first node.
[0180] It can be seen that since the PSK is a secret value shared between the device and the first node, the second PSK in the device usually has the same value as the first PSK in the first node. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, so the device can verify the identity authentication information of the first node according to the second PSK and the first freshness parameter. If the second PSK stored in the device cannot be verified, it means that the identity of the first node is untrusted, so that the device can be avoided to associate with an untrusted node, and the security of the communication of the device is improved. Correspondingly, the device also generates the second identity authentication information according to the second PSK and the fourth freshness parameter, which is used by the first node to verify the identity of the device. After the identity authentication of both parties is passed, the node at the opposite end is allowed to communicate, and the security of the node communication is improved.
[0181] In a further possible implementation form of the fourth aspect, the processing unit is specifically configured to obtain the second PSK according to a correspondence between the second PSK and the identity of the first node.
[0182] It can be seen that the correspondence between the second PSK and the identity of the first node in the above apparatus can indicate that the above apparatus has been associated with the first node or the second node preconfigured with the second PSK corresponding to the identity of the first node, and thus the above apparatus can obtain the second PSK according to the correspondence.
[0183] In a further possible implementation form of the fourth aspect, the processing unit is specifically configured to:
[0184] The second PSK is obtained according to the correspondence between the second PSK and the identity of the first node through the second set of correspondences.
[0185] It can be seen that the correspondence between the second PSK and the identity of the first node in the above apparatus can be stored in the form of the set of correspondences.
[0186] In a further possible implementation form of the fourth aspect, the processing unit is specifically configured to generate the second PSK according to a first freshness parameter and a fourth freshness parameter, the first freshness parameter being the second freshness parameter, and the fourth freshness parameter being the third freshness parameter.
[0187] It can be seen that the second PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter in the first authentication request message. Generally, the second PSK corresponding to the identity of the first node does not exist in the above apparatus when the above apparatus is associated with the first node for the first time or the above apparatus deletes the correspondence, and thus the above apparatus can generate a new second PSK according to the first freshness parameter and the fourth freshness parameter to verify the identity of the first node.
[0188] In a further possible implementation form of the fourth aspect, the processing unit is further configured to obtain third confirmation indication information, the third confirmation indication information indicating that the second PSK is allowed to be generated.
[0189] It can be seen that the user's confirmation is needed when the new second PSK is generated. In this way, when an attacker connects the above apparatus using his own identity, the second PSK corresponding to the identity of the attacker does not exist in the above apparatus, and thus the identity of the new node can be verified by the user, and the second PSK is generated only after the third confirmation indication information is obtained, thereby avoiding the association of the above apparatus with the untrusted node and ensuring the security of the communication of the above apparatus.
[0190] In a further possible implementation form of the fourth aspect, the processing unit is specifically configured to generate the second PSK according to the first freshness parameter, the fourth freshness parameter, and the first password, the first password being an access password of the first node.
[0191] In an alternative design, the access password is a password required to be inputted by other nodes when requesting to access the first node, for example, a password required to be inputted when connecting to a Wi-Fi. It can be seen that in the case that the first password is the access password of the first node, the apparatus connects to the first node by inputting the first password, and thus participates in the generation of the second PSK by the first password, so that an attacker who does not obtain the first password cannot crack the second PSK, thereby avoiding the apparatus from being associated with the attacker who does not obtain the first password.
[0192] In a further possible implementation form of the fourth aspect, the processing unit is specifically configured to generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and a second key agreement algorithm parameter.
[0193] It can be seen that the first node carries the second key agreement algorithm parameter in the first authentication request message, the second key agreement algorithm parameter being determined based on the first key agreement algorithm. The apparatus can determine the second PSK based on the first key agreement algorithm, the second key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter, and the first password. In this way, even if an attacker impersonates the identity information of the first node and obtains the first freshness parameter and the fourth freshness parameter used when generating the second PSK, the attacker cannot crack the PSK, and thus cannot communicate with the apparatus, thereby improving the security of the communication of the apparatus.
[0194] In a further possible implementation form of the fourth aspect, the first authentication request message further comprises a second key agreement algorithm parameter; and the processing unit is specifically configured to:
[0195] generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and an intermediate key, the first password being an access password; wherein the intermediate key is generated according to the first freshness parameter, the fourth freshness parameter, and the second key agreement algorithm parameter.
[0196] In a further possible implementation form of the fourth aspect, the first association request message further comprises a first key agreement algorithm parameter, the first key agreement algorithm parameter being determined based on a first key agreement algorithm according to a fourth key agreement algorithm parameter; the first authentication request message further comprises a second key agreement algorithm parameter, the second key agreement algorithm parameter being determined by the first node based on the first key agreement algorithm according to a third key agreement algorithm parameter; and the processing unit is specifically configured to:
[0197] determine the first intermediate key according to the second key agreement algorithm parameter and the fourth key agreement algorithm parameter;
[0198] generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key.
[0199] It can be seen that the second key agreement algorithm parameter in the first association request message is generated based on the private key of the device (i.e. the fourth key agreement algorithm parameter). After the device receives the second key agreement algorithm parameter from the first node, the second node determines the first intermediate key according to the second key agreement algorithm parameter and the private key of the device (i.e. the fourth key agreement algorithm parameter). The first intermediate key is the secret value obtained through key agreement between the first node and the device. The device generates the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key.
[0200] In a possible implementation form of the fourth aspect, the first authentication request message further comprises a second key agreement algorithm parameter, and the second key agreement algorithm parameter is determined based on a first key agreement algorithm. The processing unit is specifically configured to:
[0201] obtain a fourth key agreement algorithm parameter;
[0202] determine the first intermediate key according to the second key agreement algorithm parameter and the fourth key agreement algorithm parameter based on the first key agreement algorithm;
[0203] determine a second intermediate key according to the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0204] generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0205] In a possible implementation form of the fourth aspect, the processing unit is further configured to save the correspondence between the identity of the first node and the second PSK.
[0206] It can be seen that after the second PSK is generated, the device saves the correspondence between the identity of the first node and the second PSK. When the device is associated with the first node again later, the second PSK can be obtained according to the correspondence without generating the PSK again.
[0207] In a possible implementation form of the fourth aspect, the processing unit is further configured to delete the correspondence between the identity of the first node and the second PSK if the first password is updated.
[0208] In a further possible implementation form of the fourth aspect, the first authentication request message further comprises update indication information, the update indication information being used to indicate an update of the PSK.
[0209] It can be seen that after the second PSK is generated according to the first freshness parameter and the fourth freshness parameter, the first node can remind the apparatus to update the second PSK through the update indication information, so as to avoid that the apparatus uses the previous old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0210] In a further possible implementation form of the fourth aspect, the processing unit is further configured to generate a fourth PSK according to the first freshness parameter and a fourth freshness parameter if the first identity authentication information is not verified successfully according to the second PSK and the first freshness parameter.
[0211] The sending unit is further configured to send, to the first node, a third authentication response message, the third authentication response message comprising third identity authentication information, the third identity authentication information being generated according to the fourth PSK and the fourth freshness parameter.
[0212] It can be seen that when the apparatus obtains the second PSK according to the correspondence relationship, if the first identity authentication information is not verified successfully by the apparatus, it may be that the first identity authentication information is generated by using the newly generated PSK in the first node. Therefore, the apparatus also generates a new PSK (i.e., the fourth PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates authentication according to the new PSK, thereby improving the stability of the system.
[0213] In a further possible implementation form of the fourth aspect, the receiving unit is further configured to receive a third association response message from the first node.
[0214] In a further possible implementation form of the fourth aspect, the processing unit is further configured to obtain fourth confirmation indication information if the first identity authentication information is not verified successfully according to the second PSK, the fourth confirmation indication information representing that the fourth PSK is allowed to be generated.
[0215] The processing unit is further configured to generate the fourth PSK according to the first freshness parameter and the fourth freshness parameter.
[0216] In a further possible implementation form of the fourth aspect, the processing unit is further configured to delete the second PSK if the second identity authentication information is not verified successfully according to the second PSK and the first freshness parameter.
[0217] The sending unit is further configured to send, to the first node, a second association request message, the second association request message comprising a fifth freshness parameter.
[0218] In a fifth aspect, an apparatus is disclosed, which comprises at least one processor and a communication interface, the processor invoking a computer program stored in at least one memory to implement the method described in the first aspect or any possible implementation of the first aspect.
[0219] In a possible implementation of the fifth aspect, the processor is specifically configured to:
[0220] receive, through the communication interface, a first association request message from a second node, the first association request message comprising a first freshness parameter;
[0221] obtain a first pre-shared key (PSK); wherein the first PSK corresponds to an identity of the second node; the first PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from the apparatus; and further, the first PSK is used to verify the identity of the second node.
[0222] It can be seen that the PSK is a secret value shared between the apparatus and the second node. The apparatus generates the first PSK through the second freshness parameter from the second node and the third freshness parameter from the apparatus, and uses the first PSK corresponding to the identity of the second node to verify the identity of the second node (for example, the second node generates identity authentication information according to the PSK, and the first node can verify the identity authentication information of the second node through the first PSK; for another example, the second node encrypts or integrity protects the message content through the PSK (or a key derived from the PSK), and the first node can obtain the message content from the second node through the first PSK). In this way, if an attacker wants to impersonate the identity of the second node to associate with the apparatus, since the second freshness parameter and the third freshness parameter for generating the first PSK can be obtained before the first association request message, for example, can be obtained when the apparatus and the second node are associated for the first time, since the data obtained before is usually difficult to be cracked, so that the attacker cannot fake the PSK, and thus cannot pass the identity verification of the apparatus, thereby avoiding the connection between the apparatus and the untrusted node, and improving the communication security of the apparatus.
[0223] In another possible implementation of the fifth aspect, the processor is further configured to:
[0224] send, to the second node, a first authentication request message, the first authentication request message comprising first identity authentication information and a fourth freshness parameter, wherein the first identity authentication information is generated according to the first PSK and the first freshness parameter.
[0225] It can be seen that the first PSK in the device is usually of the same value as the second PSK in the second node because the PSK is a secret value shared between the device and the second node. The device generates the first identity authentication information according to the first PSK and the first freshness parameter, so that the second node can verify the identity of the device according to the second PSK, and if the second PSK stored in the second node cannot be verified, the second node can be prevented from being associated with an untrusted node, thereby improving the security of communication of the second node.
[0226] In a further possible implementation form of the fifth aspect, the processor is further configured to:
[0227] receive, through the communication interface, a first authentication response message from the second node, the first authentication response message comprising second identity authentication information;
[0228] if the second identity authentication information is verified according to the first PSK and the fourth freshness parameter, send a first association response message to the second node through the communication interface.
[0229] It can be seen that before the device and the second node communicate, the device and the second node first determine the identities of both parties through the identity authentication information. After the identity authentication is passed, communication is allowed, thereby avoiding access of untrusted nodes and improving the security of node communication.
[0230] In a further possible implementation form of the fifth aspect, the processor is specifically configured to:
[0231] obtain the first PSK according to the correspondence between the first PSK and the identity identifier of the second node.
[0232] It can be seen that the correspondence between the first PSK and the identity identifier of the second node in the device indicates that the second node has been associated with the device before or the first PSK corresponding to the identity identifier of the second node is preconfigured in the device, so that the device can obtain the first PSK according to the correspondence.
[0233] In a further possible implementation form of the fifth aspect, the memory has a first correspondence set; and the processor is specifically configured to:
[0234] obtain the first PSK according to the correspondence between the first PSK and the identity identifier of the second node through the first correspondence set.
[0235] It can be seen that the device can store the correspondence between the first PSK and the identity identifier of the second node in the form of the correspondence set.
[0236] In a further possible implementation form of the fifth aspect, the processor is specifically configured to:
[0237] generate the first PSK according to the first freshness parameter and the fourth freshness parameter, the first freshness parameter being the second freshness parameter and the fourth freshness parameter being the third freshness parameter.
[0238] It can be seen that the first PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter from the apparatus. Generally, when the apparatus associates with the second node for the first time or the apparatus deletes the corresponding relationship, there is no PSK corresponding to the identity of the second node in the apparatus, and thus the apparatus can generate a new first PSK according to the first freshness parameter and the fourth freshness parameter, for verifying the identity of the second node.
[0239] In a further possible implementation form of the fifth aspect, the apparatus further includes an input module, and the processor is further configured to:
[0240] obtain the first confirmation indication information through the input module, the first confirmation indication information indicating that the second node is allowed to associate with the apparatus.
[0241] It can be seen that when the new first PSK is generated, the confirmation of the user is required. In this way, when an attacker connects the apparatus using his own identity, since there is no PSK corresponding to the identity of the attacker in the apparatus, the identity of the new node can be verified by the user, and the first PSK is generated only after the first confirmation indication information is obtained, so that the apparatus is prevented from associating with an untrusted node, and the security of the communication of the apparatus is ensured.
[0242] In a further possible implementation form of the fifth aspect, the processor is specifically configured to:
[0243] generate the first PSK according to the first freshness parameter, the fourth freshness parameter and the first password, the first password being an access password of the apparatus.
[0244] It can be seen that when the first password is the access password of the apparatus, the second node connects the apparatus by inputting the first password, and thus the first password is used to participate in the generation of the first PSK, so that an attacker who does not obtain the first password cannot crack the first PSK, and thus the apparatus is prevented from associating with the attacker who does not obtain the first password.
[0245] In a further possible implementation form of the fifth aspect, the first association request message further comprises a first key agreement algorithm parameter; and the processor is specifically configured to:
[0246] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first key agreement algorithm parameter.
[0247] It can be seen that the second node carries the first key agreement algorithm parameter in the first association request message, which is determined based on the first key agreement algorithm. The apparatus can determine the first PSK according to the first key agreement algorithm, the first key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter, and the first password. In this way, even if an attacker impersonates the identity information of the second node later and obtains the first freshness parameter and the fourth freshness parameter used when generating the first PSK, the attacker cannot crack the first PSK, and thus cannot communicate with the apparatus, thereby improving the security of communication of the apparatus.
[0248] In a further possible implementation form of the fifth aspect, the first association request message further comprises a first key agreement algorithm parameter; and the processor is specifically configured to:
[0249] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the intermediate key, the first password being an access password; and the intermediate key being generated according to the first freshness parameter, the fourth freshness parameter, and the first key agreement algorithm parameter.
[0250] In a further possible implementation form of the fifth aspect, the first association request message further comprises a first key agreement algorithm parameter, which is determined based on a first key agreement algorithm; and the processor is specifically configured to:
[0251] determine a third key agreement algorithm parameter;
[0252] determine a first intermediate key according to the first key agreement algorithm and the third key agreement algorithm based on the first key agreement algorithm;
[0253] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0254] It can be seen that after the apparatus receives the first key agreement algorithm parameter from the second node, the apparatus determines a third key agreement algorithm parameter (or a private key of the apparatus). The apparatus determines a first intermediate key according to the first key agreement algorithm parameter and the second key agreement algorithm parameter based on the first key agreement algorithm, and then generates the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0255] In a further possible implementation form of the fifth aspect, the first association request message further comprises a first key derivation algorithm parameter, the first key derivation algorithm parameter being determined based on a first key derivation algorithm; and the processor is specifically configured to:
[0256] obtain a third key derivation algorithm parameter;
[0257] determine a first intermediate key based on the first key derivation algorithm, the first key derivation algorithm parameter and the third key derivation algorithm parameter;
[0258] determine a second intermediate key based on the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0259] generate the first PSK based on the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0260] In a further possible implementation form of the fifth aspect, the processor is further configured to:
[0261] save a correspondence between the identity of the second node and the first PSK.
[0262] It can be seen that after the first PSK is generated, the above apparatus saves the correspondence between the identity of the second node and the first PSK, and when the first node receives an association request from the second node again later, the first PSK can be obtained according to the correspondence without generating the first PSK again.
[0263] In a further possible implementation form of the fifth aspect, the processor is further configured to:
[0264] if the first password is updated, delete the correspondence between the identity of the second node and the first PSK.
[0265] In a further possible implementation form of the fifth aspect, the first authentication request message further comprises update indication information, the update indication information being used to indicate an update of the PSK.
[0266] It can be seen that after the first PSK is generated based on the first freshness parameter and the fourth freshness parameter, the above apparatus can remind the second node to update the PSK, so as to avoid that the second node uses a previous old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0267] In a further possible implementation form of the fifth aspect, the processor is further configured to:
[0268] if the second identity authentication information is not verified based on the first PSK and the fourth freshness parameter, generate a third PSK based on the first freshness parameter and the fourth freshness parameter.
[0269] sending, by the communication interface, a second authentication request message to the second node, the second authentication request message comprising third identity authentication information, wherein the third identity authentication information is generated according to a third PSK and a first freshness parameter.
[0270] It can be seen that, in the case where the device obtains the first PSK according to the correspondence relationship, if the second identity authentication information fails to pass the verification by the device, the second identity authentication information can be generated by using a newly generated PSK in the second node. Therefore, the device generates a new PSK (i.e., the third PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates the authentication according to the new PSK, thereby improving the stability of the system.
[0271] In a possible implementation form of the fifth aspect, the processor is specifically configured to:
[0272] if the second identity authentication information fails to pass the verification according to the first PSK and the fourth freshness parameter, obtaining, by the communication interface, second confirmation indication information, the second confirmation indication information indicating that the third PSK is allowed to be generated;
[0273] generating, by the processor, the third PSK according to the first freshness parameter and the fourth freshness parameter.
[0274] In a possible implementation form of the fifth aspect, the processor is further configured to:
[0275] receiving, by the communication interface, a second authentication response message from the second node, the second authentication response message comprising fourth identity authentication information;
[0276] if the fourth identity authentication information passes the verification according to the third PSK and the fourth freshness parameter, sending, by the communication interface, a second association response message to the second node.
[0277] It can be seen that, after the device reinitiates the authentication according to the new PSK, the fourth identity authentication information sent by the second node is received again, and if the fourth identity authentication information passes the verification, it indicates that the identity of the second node is trusted, thereby allowing the communication with the second node.
[0278] In a sixth aspect, an embodiment of the present application discloses a device, which comprises at least one processor and a communication interface, the processor invoking a computer program stored in at least one memory to implement the method described in the second aspect or any possible implementation form of the second aspect.
[0279] In a possible implementation form of the sixth aspect, the processor is specifically configured to:
[0280] sending, to the first node via the communication interface, a first association request message, the first association request message comprising a first freshness parameter;
[0281] receiving, from the first node via the communication interface, a first authentication request message, the first authentication request message comprising a fourth freshness parameter;
[0282] obtaining a second PSK, wherein the second PSK corresponds to an identity of the first node, and the second PSK is a PSK generated according to the second freshness parameter from the apparatus and the third freshness parameter from the first node, and the second PSK is used to verify the identity of the first node.
[0283] It can be seen that the PSK is a secret value shared between the apparatus and the first node. The apparatus generates the second PSK according to the second freshness parameter and the third freshness parameter from the apparatus, and the second PSK corresponds to the identity of the first node, and is used to verify the identity of the first node (for example, the first node generates identity authentication information according to the PSK, and the second node can verify the identity authentication information of the first node by the second PSK; for another example, the first node encrypts or integrity protects the message content by the PSK (or a key derived from the PSK), and the second node can obtain the message content from the second node by the first PSK). In this way, if an attacker wants to impersonate the identity of the first node to associate with the apparatus, since the second freshness parameter and the third freshness parameter for generating the second PSK can be obtained before the first association request message, for example, can be obtained when the apparatus and the first node are associated for the first time, since the previously obtained data is usually difficult to be cracked, so that the attacker cannot fake the PSK, and thus cannot pass the identity verification of the apparatus, thereby avoiding the apparatus from being associated with an untrusted node, and improving the communication security of the apparatus.
[0284] In a possible implementation of the sixth aspect, the processor is further configured to:
[0285] if the first identity authentication information is verified to be passed according to the second PSK and the first freshness parameter, sending, to the first node via the communication interface, a first authentication response message, the first authentication response message comprising second identity authentication information, the second identity authentication information being generated according to the second PSK and the fourth freshness parameter;
[0286] receiving, from the first node via the communication interface, a first association response message.
[0287] It can be seen that the second PSK in the device is usually the same as the first PSK in the first node because the PSK is a secret value shared between the device and the first node. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, so the device can verify the identity authentication information of the first node according to the second PSK and the first freshness parameter. If the second PSK stored in the device cannot be verified, it means that the identity of the first node is not trusted, thereby avoiding the device from being associated with an untrusted node, and improving the security of communication of the device. Correspondingly, the device also generates the second identity authentication information according to the second PSK and the fourth freshness parameter, which is used by the first node to verify the identity of the device. After the identity authentication of both parties is passed, the device is allowed to communicate with the node at the opposite end, thereby improving the security of node communication.
[0288] In a further possible implementation form of the sixth aspect, the processor is specifically configured to:
[0289] According to the correspondence between the second PSK and the identity of the first node, the second PSK is obtained.
[0290] It can be seen that the correspondence between the second PSK and the identity of the first node in the device can indicate that the device has been associated with the first node or the second node preconfigured with the second PSK corresponding to the identity of the first node, so the device can obtain the second PSK according to the correspondence.
[0291] In a further possible implementation form of the sixth aspect, the memory stores a second correspondence set; and the processor is specifically configured to:
[0292] According to the correspondence between the second PSK and the identity of the first node, the second PSK is obtained through the second correspondence set.
[0293] It can be seen that the device can store the correspondence between the second PSK and the identity of the first node in the form of the correspondence set.
[0294] In a further possible implementation form of the sixth aspect, the processor is specifically configured to:
[0295] The second PSK is generated according to the first freshness parameter and the fourth freshness parameter, the first freshness parameter being the second freshness parameter, and the fourth freshness parameter being the third freshness parameter.
[0296] It can be seen that the second PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter in the first authentication request message. Generally, when the device associates with the first node for the first time or when the device deletes the corresponding relationship, the second PSK corresponding to the identity of the first node does not exist in the device, and therefore the device can generate a new second PSK according to the first freshness parameter and the fourth freshness parameter, for verifying the identity of the first node.
[0297] In a further possible implementation form of the sixth aspect, the device further comprises an input module; and the processor is further configured to:
[0298] The third confirmation indication information is obtained through the input module, and the third confirmation indication information indicates that the second PSK is allowed to be generated.
[0299] It can be seen that when the new second PSK is generated, the confirmation of the user is required. In this way, when an attacker connects the device using his own identity, since the PSK corresponding to the identity of the attacker does not exist in the device, the identity of the new node can be verified by the user, and the second PSK is generated only after the third confirmation indication information is obtained, so that the device is prevented from associating with an untrusted node, and the security of the communication of the device is ensured.
[0300] In a further possible implementation form of the sixth aspect, the processor is specifically configured to:
[0301] The second PSK is generated according to the first freshness parameter, the fourth freshness parameter and a first password, the first password being an access password of the device.
[0302] In an optional design, the access password is a password that needs to be input when another node requests to access the first node, for example, a password that needs to be input when connecting to a Wi-Fi. It can be seen that when the first password is the access password of the first node, the device connects to the first node by inputting the first password, and therefore the second PSK is generated by participating in the first password, so that an attacker who does not obtain the first password cannot crack the second PSK, and the device is prevented from associating with the attacker who does not obtain the first password.
[0303] In a further possible implementation form of the sixth aspect, the first authentication request message further comprises a second key agreement algorithm parameter; and the processor is specifically configured to:
[0304] The second PSK is generated according to the first freshness parameter, the fourth freshness parameter, the first password and the second key agreement algorithm parameter.
[0305] It can be seen that the first node carries the second key agreement algorithm parameter in the first authentication request message, and the second key agreement algorithm parameter is determined based on the first key agreement algorithm. The device can determine the second PSK based on the first key agreement algorithm, the second key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter, and the first password. In this way, even if an attacker impersonates the identity information of the first node later and obtains the first freshness parameter and the fourth freshness parameter used when generating the second PSK, the attacker cannot crack the PSK and thus cannot communicate with the device, thereby improving the security of communication of the device.
[0306] In a possible implementation form of the sixth aspect, the first authentication request message further comprises a second key agreement algorithm parameter; and the processor is specifically configured to:
[0307] generate the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key, the first password being an access password; and wherein the first intermediate key is generated based on the first freshness parameter, the fourth freshness parameter, and the second key agreement algorithm parameter.
[0308] In a possible implementation form of the sixth aspect, the first association request message further comprises a first key agreement algorithm parameter, and the first key agreement algorithm parameter is determined based on a first key agreement algorithm and a fourth key agreement algorithm parameter; the first authentication request message further comprises a second key agreement algorithm parameter, and the second key agreement parameter is determined by the first node based on the first key agreement algorithm and a third key agreement algorithm parameter; and the processor is specifically configured to:
[0309] determine a first intermediate key based on the second key agreement algorithm parameter and the fourth key agreement algorithm parameter;
[0310] generate the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0311] It can be seen that the first key agreement algorithm parameter in the first association request message is generated based on the private key of the second node (i.e., the fourth key agreement algorithm parameter). After the device receives the second key agreement algorithm parameter from the first node, the device determines the first intermediate key based on the second key agreement algorithm parameter and the private key of the device (i.e., the fourth key agreement algorithm parameter), and the first intermediate key is the secret value obtained through key agreement between the first node and the device. The device generates the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0312] In a further possible implementation form of the sixth aspect, the first authentication request message further comprises a second key agreement algorithm parameter, the second key agreement algorithm parameter being determined based on the first key agreement algorithm; and the processor is specifically configured to:
[0313] obtain a fourth key agreement algorithm parameter;
[0314] determine a first intermediate key based on the second key agreement algorithm parameter and the fourth key agreement algorithm parameter according to the first key agreement algorithm;
[0315] determine a second intermediate key according to the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0316] generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0317] In a further possible implementation form of the sixth aspect, the processor is further configured to:
[0318] save a correspondence between the identity of the first node and the second PSK.
[0319] It can be seen that after the second PSK is generated, the above apparatus saves the correspondence between the identity of the first node and the second PSK, and when associated with the first node again later, the second PSK can be obtained according to the correspondence without generating the PSK again.
[0320] In a further possible implementation form of the sixth aspect, the processor is further configured to:
[0321] if the first password is updated, delete the correspondence between the identity of the first node and the second PSK.
[0322] In a further possible implementation form of the sixth aspect, the first authentication request message further comprises update indication information, the update indication information being used to indicate the update of the PSK.
[0323] It can be seen that after the second PSK is generated according to the first freshness parameter and the fourth freshness parameter, the first node can remind the above apparatus to update the second PSK through the update indication information, so as to avoid that the above apparatus uses the old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0324] In a further possible implementation form of the sixth aspect, the processor is further configured to:
[0325] if the first identity authentication information is not verified according to the second PSK and the first freshness parameter, generate a fourth PSK according to the first freshness parameter and the fourth freshness parameter;
[0326] The third authentication response message including third identity authentication information is sent to the first node through the communication interface, and the third identity authentication information is generated according to the fourth PSK and the fourth freshness parameter.
[0327] It can be seen that when the device obtains the second PSK according to the corresponding relationship, if the first identity authentication information fails to pass the verification of the device, the first identity authentication information may be generated by the newly generated PSK used in the first node. Therefore, the device also generates a new PSK (that is, the fourth PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates authentication according to the new PSK, so that the stability of the system can be improved.
[0328] In another possible implementation of the sixth aspect, the processor is further configured to:
[0329] The third association response message from the first node is received through the communication interface.
[0330] In another possible implementation of the sixth aspect, the device further comprises an input module, and the processor is further configured to:
[0331] If the first identity authentication information fails to pass the verification according to the second PSK, the fourth confirmation indication information is obtained through the input module, and the fourth confirmation indication information indicates that the fourth PSK is allowed to be generated;
[0332] The fourth PSK is generated according to the first freshness parameter and the fourth freshness parameter.
[0333] In another possible implementation of the sixth aspect, the processor is further configured to:
[0334] If the second identity authentication information fails to pass the verification according to the first PSK and the first freshness parameter, the second PSK is deleted;
[0335] The second association request message including the fifth freshness parameter is sent to the first node through the communication interface.
[0336] In the seventh aspect, an embodiment of the present application provides a key acquisition system, the key acquisition system comprising a first node and a second node, wherein the first node is the device described in the third aspect or any possible implementation of the third aspect, or the fifth aspect or any possible implementation of the fifth aspect, and the second node is the device described in the fourth aspect or any possible implementation of the fourth aspect, or the sixth aspect or any possible implementation of the sixth aspect.
[0337] In a possible implementation of the seventh aspect, the first node stores a first PSK corresponding to the identity of the second node, and the first PSK is preconfigured in the first node.
[0338] If the second node is replaced by a third node, the first node can request association with the third node by the second aspect or any of the possible implementation methods of the second aspect.
[0339] For example, in the case where the CDC of a vehicle is the first node and the microphone of the vehicle is the second node, if the old microphone of the vehicle is replaced by a new microphone, since the PSK between the old microphone and the CDC is preconfigured and the new microphone cannot receive the operation instruction of the user, the first association request message can be sent to the new microphone by the CDC to obtain a new PSK.
[0340] In another possible implementation of the seventh aspect, the first node stores a correspondence between the identity of the second node and the first PSK, and the first PSK is preconfigured in the first node; if the first node is replaced by a fourth node, the fourth node can obtain the correspondence in the first node to obtain the second PSK corresponding to the identity of the second node.
[0341] For example, in the case where the CDC of a vehicle is the first node, when the vehicle replaces the CDC, the correspondence between the identity of the second node and the first PSK saved by the old CDC can be configured on the new CDC. The configuration can be copying from the old CDC to the new CDC through a computer storage medium, or the new CDC can receive the correspondence from the old CDC.
[0342] In the eighth aspect, the embodiments of the present application disclose a computer readable storage medium, which stores a computer program. When the computer program runs on one or more processors, the method described in the first aspect, any of the possible implementation methods of the first aspect, the second aspect, or any of the possible implementation methods of the second aspect is executed.
[0343] In the ninth aspect, the embodiments of the present application disclose a chip system, which includes at least one processor, a memory, and an interface circuit. The interface circuit is used to provide information input / output for the at least one processor. The memory stores a computer program. When the computer program runs on one or more processors, the method described in the first aspect, any of the possible implementation methods of the first aspect, the second aspect, or any of the possible implementation methods of the second aspect is executed.
[0344] Tenthly, embodiments of this application disclose a vehicle, the vehicle including a first node (e.g., a vehicle cockpit domain controller (CDC), wherein the first node is the device described in the third aspect or any possible implementation of the third aspect, or the device described in the fifth aspect or any possible implementation of the fifth aspect. Further, the vehicle also includes a second node (e.g., at least one of modules such as a camera, screen, microphone, audio system, radar, electronic key, keyless entry or start system controller, etc.), the second node being the device described in the fourth aspect or any possible implementation of the fourth aspect, or the device described in the sixth aspect or any possible implementation of the sixth aspect. Attached Figure Description
[0345] The accompanying drawings used in the embodiments of this application are described below.
[0346] Figure 1 This is a schematic diagram illustrating the principle of a DH algorithm provided in an embodiment of this application;
[0347] Figure 2 This is a schematic diagram of a cryptographic derivation algorithm provided in an embodiment of this application;
[0348] Figure 3 This is a schematic diagram of the architecture of a communication system provided in an embodiment of this application;
[0349] Figure 4 This is a schematic diagram illustrating a use case of a key acquisition method provided in an embodiment of this application;
[0350] Figure 5 This is a flowchart illustrating a key acquisition method provided in an embodiment of this application;
[0351] Figure 6 This is a schematic diagram of a method for obtaining a first PSK provided in an embodiment of this application;
[0352] Figure 7 This is a schematic diagram of another method for obtaining a first PSK provided in an embodiment of this application;
[0353] Figure 8 This is a flowchart illustrating another key acquisition method provided in an embodiment of this application;
[0354] Figure 9 This is a flowchart illustrating another key acquisition method provided in an embodiment of this application;
[0355] Figure 10 This is a flowchart illustrating another key acquisition method provided in an embodiment of this application;
[0356] Figure 11is a flowchart of another key acquisition method provided by an embodiment of the present application;
[0357] Figure 12 is a flowchart of another key acquisition method provided by an embodiment of the present application;
[0358] Figure 13 is a flowchart of another key acquisition method provided by an embodiment of the present application;
[0359] Figure 14 is a structural diagram of a device provided by an embodiment of the present application;
[0360] Figure 15 is a structural diagram of another device provided by an embodiment of the present application;
[0361] Figure 16 is a structural diagram of another device provided by an embodiment of the present application;
[0362] Figure 17 is a structural diagram of another device provided by an embodiment of the present application;
[0363] Figure 18 is an architectural diagram of a key acquisition system provided by an embodiment of the present application;
[0364] Figure 19 is an architectural diagram of another key acquisition system provided by an embodiment of the present application. DETAILED DESCRIPTION
[0365] The embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. It should be noted that in the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design scheme described as "exemplary" or "for example" in the present application should not be interpreted as being more preferred or advantageous than other embodiments or design schemes. Rather, the use of the words "exemplary" or "for example" is intended to present related concepts in a specific way.
[0366] The related technologies and professional terms involved in the present application will be briefly introduced below to facilitate understanding.
[0367] I. Node (Node)
[0368] A node is an electronic device with data transceiving capability. For example, the node can be a Cockpit Domain device, or one of the modules in the Cockpit Domain device (one or more of the following modules: cockpit domain controller (CDC), camera, screen, microphone, audio, electronic key, keyless entry or start system controller, etc.). In specific implementation, the node can be a data relay device such as a router, a repeater, a bridge or a switch, or a terminal device such as various types of user equipment (UE), mobile phone, pad, desktop computer, earphone, audio, etc., or a machine intelligent device such as self-driving device, transportation safety device, virtual reality (VR) terminal device, augmented reality (AR) terminal device, machine type communication (MTC) device, industrial control device, remote medical device, smart grid device, smart city device, wearable device (such as smart watch, smart bracelet, pedometer, etc.), etc. In some technical scenarios, the name of a device with similar data transceiving capability can not be called a node, but for the convenience of description, the electronic device with data transceiving capability is collectively referred to as a node in the embodiments of the present application.
[0369] II. Key agreement
[0370] Key agreement is a process in which both parties of communication agree on a key by interacting with a part of parameters. The cryptographic algorithm used for key agreement is also called key agreement algorithm or key exchange algorithm. Commonly used key agreement algorithms include Diffie-Hellman (DH) algorithm, Elliptic Curve Diffie-Hellman (ECDH) algorithm based on elliptic curve cryptography (ECC), Oakley algorithm, and national cryptographic algorithm (such as SM1, SM2, SM3 and SM4).
[0371] Wherein, taking the DH algorithm as an example, two nodes use the same value of a large prime number p and a random number g, and respectively generate random numbers a and b. The second node sends the value generated by g raised to the power of a mod P to the first node, the first node sends the value generated by g raised to the power of b mod P to the second node, the second node performs a power operation on the received result, and the first node performs a power operation on the received result, finally the password is formed, and the key exchange is completed, wherein mod represents a modulus operation.
[0372] Referring to Figure 1 , Figure 1 is a principle diagram of the DH algorithm provided by the embodiment of the present application, and the steps of the DH algorithm for exchanging keys are as follows:
[0373] Step 1: The second node determines a prime number p, a random number g and a random number a.
[0374] Step 2: The second node generates a first calculation value A, wherein A = g a mod p.
[0375] Step 3: The second node sends the prime number p, the random number g and the first calculation value A to the first node.
[0376] Step 4: The first node determines a random number b.
[0377] Step 5: The first node calculates a second calculation value B, wherein B = g b mod p.
[0378] Step 6: The first node determines a key s, wherein s = A b mod p.
[0379] Step 7: The first node sends the second calculation value B to the second node.
[0380] Step 8: The second node determines a key s, wherein s = B a mod p.
[0381] Since s = A b mod p = (g a mod p) b mod p = g ab mod p = (g b mod p) a mod p = B amodp, so the key s calculated by the first node and the second node is the same. Since the key s is not transmitted on the network, and since the values of the prime number p, the random number g, the random number a and the random number b selected by the actual algorithm are very large, it is difficult to calculate the key s according to the prime number p, the random number g, the first calculation value A and the second calculation value B transmitted on the network, so the key obtained by the DH algorithm has security.
[0382] III. Key derivation
[0383] Key derivation is to derive one or more keys from a secret value, and the algorithm used to derive the key is called a key derivation function (KDF), also known as a key derivation function. For example, a new key DK derived from a secret value Key can be expressed as: DK = KDF(Key, fresh). Where fresh is a freshness parameter used to derive a new key.
[0384] Common key derivation algorithms include password-based key derivation functions (PBKDF), scrypt algorithms, etc. The PBKDF algorithm includes PBKDF1 and PBKDF2. Optionally, some KDF algorithms use a hash algorithm to hash the input secret value during key derivation, so the KDF function can also receive an algorithm identifier as input to indicate which hash algorithm to use.
[0385] For example, PBKDF2, the new secret value DK derived from the old secret value Key by the PBKDF2 algorithm can be expressed as: DK = PBKDF2(PRF, Key, salt, c, dk_len), where the parameter PRF indicates the identifier of the hash algorithm to be used; salt is a randomly generated salt, which can be regarded as a freshness parameter; c is the iteration count, which can be defaulted; dk_len is the length of the generated new secret value DK, which can also be referred to as the block size, which can be defaulted. See Figure 2 , Figure 2 is a schematic diagram of a key derivation algorithm provided by an embodiment of the present application. According to the old secret value 201 and the freshness parameter 202, a new secret value 204 can be obtained by the key derivation function 203.
[0386] IV. Freshness parameter
[0387] The freshness parameter is a parameter used for participating in the generation of the key, and can also be referred to as freshness or a fresh parameter, and can include at least one of a random number value (NONCE), a counter value, a serial number, and the like, wherein the NONCE is a random number value used only once (or non-repeated). Freshness parameters generated at different times are generally different, that is, the specific value of the freshness parameter changes each time the freshness parameter is generated, so that the freshness parameter used for generating the key this time is different from the freshness parameter used for generating the key last time, and the security of the generated key can be improved.
[0388] For example, the freshness parameter can be a random number obtained by a random number generator of the node.
[0389] For another example, the freshness parameter includes a packet data convergence protocol count (PDCP COUNT), and the PDCP COUNT can include an uplink PDCP COUNT and a downlink PDCP COUNT. The uplink PDCP COUNT is incremented by 1 each time the second node sends an uplink PDCP data packet, and the downlink PDCP COUNT is incremented by 1 each time the first node sends a downlink PDCP data packet. Since the PDCP COUNT is always changing, the key generated by the PDCP COUNT each time is different from the key generated by the PDCP COUNT last time.
[0390] The system architecture and the business scenario of the embodiments of the present application are described below. It should be noted that the system architecture and the business scenario described in the present application are used to more clearly illustrate the technical solutions of the present application, and do not constitute a limitation on the technical solutions provided by the present application. Those skilled in the art can know that, with the evolution of the system architecture and the appearance of new business scenarios, the technical solutions provided by the present application are also applicable to similar technical problems.
[0391] Please refer to Figure 3 , Figure 3is a schematic diagram of an architecture of a communication system provided by an embodiment of the present application, comprising a first node 301 and a second node 302. The first node 301 can be requested to access by the second node 302, and after the access is successful, the first node 301 can communicate with the second node 302 through a data link. Optionally, the data link through which the first node 301 communicates with the second node 302 can include various types of connection media, such as a wireless link, which can be Wi-Fi, Bluetooth, zigbee, and other wireless links (such as universal wireless short-range transmission technology), and a wired link, such as a fiber link.
[0392] Optionally, the first node 301 can be the initiator of the communication, which can be referred to as a master node or an access point (AP), and correspondingly, the second node 302 is the receiver of the communication, which can be referred to as a slave node.
[0393] Among them, the first node 301 and the second node 302 can be the same type of device, or can be different types of devices. For example, please refer to Figure 4 , Figure 4 is a schematic diagram of a use scenario of a key acquisition method provided by an embodiment of the present application. The cockpit domain controller (CDC) 401 is the control center in the intelligent cockpit device, which can be regarded as the first node 301. The smart phone 402 is a device with data transceiving capability, which can be regarded as the second node 302. Among them, the CDC 401 can access through Bluetooth, and the smart phone 402 supports Bluetooth function, so it requests to access the CDC 401. Since the existing Bluetooth technology usually adopts pairing or just work mode for connection, in the just work mode, the opposite end identifier can be directly clicked to connect through Bluetooth. Therefore, after the CDC 401 opens the Bluetooth, the smart phone 402 can directly click the Bluetooth name of the CDC 401 to access the CDC 401, at this time, if an attacker impersonates the identity of the smart phone 402 to connect the CDC 401, the CDC 401 is difficult to identify the attacker, so as to cause the CDC 401 to communicate with the attacker, and the privacy and security of the CDC 401 are threatened. Similarly, in some other scenarios, the node is also often difficult to avoid connection with an attacker with unknown identity, thereby affecting the security of the communication. In order to solve this problem, the present application provides the following method.
[0394] Please refer to Figure 5 , Figure 5 is a schematic diagram of a flow of a key acquisition method provided by an embodiment of the present application. The key acquisition method can be implemented based on the architecture shown in Figure 3 , and the method at least includes the following steps:
[0395] Step S501: The second node sends a first association request message to the first node.
[0396] Specifically, the first association request message includes a fresh parameter. For the convenience of description, the fresh parameter in the first association request message is referred to as a first fresh parameter in each embodiment of the present application. The fresh parameter can include at least one of a number once (NONCE), a counter, a number, and the like, and the fresh parameter at different times is usually different.
[0397] The second node can send the first association request message to the first node through a wireless link (for example, one of Wi-Fi, Bluetooth, Zigbee, or other short-range wireless links) or a wired link (for example, an optical fiber). Correspondingly, the first node receives the first association request message from the second node.
[0398] Optionally, the first node can broadcast a message, and the second node can receive the broadcasted message of the first node, thereby sending the first association request message to the first node. Specifically, the message broadcasted by the first node can carry at least one of an identity of the first node, description information of the first node, and indication information for indicating access of other nodes, and the second node receives the broadcasted message and sends the first association request message to the first node to request association with the first node.
[0399] Step S502: The first node acquires a first pre-shared key (PSK).
[0400] Specifically, the PSK is a secret value shared between the first node and the second node, which can be generated based on a fresh parameter from the second node and a fresh parameter from the first node, or can be pre-configured in the first node and the second node. For the convenience of description, the PSK between the first node and the second node saved in the first node is referred to as a first PSK, the fresh parameter from the second node used to generate the first PSK is referred to as a second fresh parameter, and the fresh parameter from the first node used to generate the first PSK is referred to as a third fresh parameter. Optionally, the second fresh parameter can be the first fresh parameter in the first association request message, or can be a fresh parameter from the second node before the first association request message.
[0401] The first PSK is a PSK corresponding to an identity of the second node. The identity of the second node is also referred to as a device identity of the second node, and can be an ID of the second node, a media access control (MAC) address, a domain name, a domain address, or another custom identity. The ID of the second node can be a fixed ID or a temporary ID. For example, the first node has been assigned a temporary ID before receiving the first association request message, and thus the second node can connect to the first node by using the once-assigned temporary ID.
[0402] Before obtaining the first PSK, the first node can obtain the identity of the second node. The first node can obtain the identity of the second node in at least two ways.
[0403] In the first way, the first association request message includes the identity of the second node. Specifically, the second node can carry the identity of the second node in the first association request message, and the first node receives the first association request message from the second node, thereby obtaining the identity of the second node.
[0404] In the second way, the second node can inform the first node of the identity of the second node through another message. For example, in the case where the first node uses the first password as an access password, the second node accesses the first node by inputting the first password before sending the first association request message. The second node can send the first password and the identity of the second node to the first node, and the first node thus obtains the identity of the second node. The access password is a password that needs to be input when another node requests to access the first node, such as a password that needs to be input when connecting to a Wi-Fi.
[0405] The first node obtains the first PSK in at least three ways.
[0406] In the first way, the first node obtains the first PSK according to a correspondence between the first PSK and the second node. The correspondence can be preconfigured in the first node or saved after the first PSK is generated. It should be noted that, in the case where the correspondence is preconfigured, the first PSK preconfigured in the first node is the same as the PSK preconfigured in the second node, and in the case where the correspondence is saved after the PSK is generated, the first node and the second node use the same method to generate the PSK and use the same parameters.
[0407] The form of the correspondence stored in the first node can be one or more of a correspondence set, a data table, a database, and the like, and the present application does not limit the same. For example, referring to Table 1, Table 1 is a possible correspondence set of the first PSK and the identity of the second node provided by an embodiment of the present application, which includes the identity of a plurality of nodes, the corresponding PSK, and the type of the PSK. For example, the node with the identity "ID1" has a temporary ID "ID1.1", the corresponding PSK is "PSK1", and the type of the PSK is preconfigured; for another example, the node with the identity "ID2" has a temporary ID "ID2.1", the corresponding PSK is "PSK2", and the type of the PSK is generated, i.e., PSK2 is generated according to the second freshness parameter from the second node and the third freshness parameter from the first node. For the convenience of description, the correspondence set stored in the first node in the embodiment of the present application is referred to as the first correspondence set.
[0408] Table 1: Correspondence of the first PSK and the identity of the second node
[0409] Identity identifier PSK type ID1 (Temporary ID1.1) PSK1 Pre-configuration ID2 (Temporary ID2.1) PSK2 generate ID3 (Temporary ID3.1) PSK3 generate
[0410] It can be understood that the correspondence of the first PSK and the identity of the second node in the first node can indicate that the second node has been associated with the first node before or that the first node is preconfigured with the PSK corresponding to the identity of the second node, so that the first node can obtain the first PSK according to the correspondence.
[0411] Case two: the first node generates the first PSK according to the first freshness parameter and a fourth freshness parameter from the first node, wherein the fourth freshness parameter is a freshness parameter determined by the first node. Optionally, when the first node and the second node request to be associated for the first time or in the case that the first node deletes the correspondence, the first node does not have the first PSK corresponding to the identity of the second node, so that the first node can generate a new first PSK according to the first freshness parameter and the fourth freshness parameter, for verifying the identity of the second node. Further, the first node determines the first PSK according to the first freshness parameter and the fourth freshness parameter, which can have the following implementation manners:
[0412] Implementation manner one: the first node generates the first PSK according to the first freshness parameter and the fourth freshness parameter through the KDF. For example, taking the first freshness parameter as NONCEe and the fourth freshness parameter as NONCEa, the generated first PSK satisfies: first PSK = KDF(NONCEe, NONCEa). It should be noted that in the embodiments of the present application, the order of the parameters in the formula is only an example, and other arrangement orders can exist in actual processing, and the present application does not limit the order of the parameters.
[0413] Implementation two: the first node uses the first password as an access password (password), so the first node can generate the first PSK according to the first freshness parameter, the fourth freshness parameter and the first password. For example, the first node generates the first PSK according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first password password1 through the KDF, that is: the first PSK = KDF (NONCEe, NONCEa, password1).
[0414] Implementation three: the first node uses the first password as an access password (password), so the first node can generate the first PSK according to the identity of the first node, the identity of the second node, the first freshness parameter, the fourth freshness parameter and the first password. For example, see Figure 6 , Figure 6 is a possible method for generating the first PSK provided by the embodiment of the application, and the first node generates the first PSK 602 through the KDF 601 according to the identity IDa of the first node, the identity IDe of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first password password1, that is: the first PSK 602 = KDF 601 (IDa, IDe, NONCEe, NONCEa, password1).
[0415] Case three: the first association request message further includes a first key agreement algorithm parameter, and the first node generates the first PSK according to the first freshness parameter, the fourth freshness parameter and the first key agreement algorithm parameter. The first key agreement algorithm parameter is a parameter of the key agreement algorithm. Optionally, the first node can broadcast information of one or more key agreement algorithms supported by the first node, and the second node determines the one or more key agreement algorithms and carries the first key agreement algorithm parameter based on the first key agreement algorithm (optionally, the identification information of the first key agreement algorithm can also be carried) in the first association request message. The first node generates the first PSK based on the first key agreement algorithm according to the first freshness parameter, the fourth freshness parameter and the first key agreement algorithm parameter. Further, the first node can have the following implementation manners for generating the first PSK according to the first freshness parameter, the fourth freshness parameter and the first key agreement algorithm parameter:
[0416] In an implementation, the first node generates the first PSK based on the first freshness parameter, the fourth freshness parameter, and the first key agreement algorithm parameter via the KDF. For example, the first freshness parameter is NONCEe, the fourth freshness parameter is NONCEa, and the first key agreement algorithm parameter is KEe. The first PSK is generated as follows: PSK = KDF(NONCEe, NONCEa, KEe).
[0417] The first key agreement algorithm parameter KEe is an algorithm parameter generated by the second node based on a used key agreement algorithm in a key agreement process. For example, the used key agreement algorithm is the DH algorithm. The first node and the second node use the same large prime number p and the same random number g. The second node sends a number A (A = g a mod p) generated by raising g to the power of a mod P to the first node. The number A can be regarded as the first key agreement algorithm parameter KEe, where a is the private key of the second node. The first node can determine a random number b (the private key of the first node, which is referred to as the third key agreement algorithm parameter in the embodiments of the present application for the sake of description) based on the number A and the DH algorithm. In the DH algorithm, the first node can obtain a secret value of the key agreement by raising the received number A to the power of b mod P, i.e., the secret value of the key agreement is A b mod p, which can be used to generate the first PSK. Therefore, the first node generates the first PSK based on the DH algorithm, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1, and the first key agreement algorithm parameter A b mod p) via the KDF.
[0418] Further, the first node sends a number B (B = g b mod p) generated by raising g to the power of b mod P to the second node. The second node can obtain a secret value of the key agreement by raising the received number B to the power of a mod P, i.e., the secret value of the key agreement is A b mod p, where a is the private key of the second node, which is referred to as the fourth key agreement algorithm parameter for the sake of description. Since A b mod p = (g a mod p) b mod p = g ab mod p = (g b mod p) amod p = B a mod p, so the secret value obtained by the first node and the second node through the key agreement is the same. In the process of key agreement, the attacker cannot infer the secret value only through the algorithm parameters transmitted by the first node and the second node. For example, in the DH algorithm, since the values of the prime number p, the random number g, the random number a and the random number b selected by the actual algorithm are very large, it is difficult to calculate the secret value according to the prime number p, the random number g, the first key agreement algorithm parameter A and the second key agreement algorithm parameter B transmitted by the network, so the secret value obtained through the DH algorithm has security.
[0419] Implementation manner five: the first node uses the first password as an access password (password), so the first node can generate the first PSK according to the first freshness parameter, the fourth freshness parameter and the first password. For example, the first node generates the first PSK through the KDF according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the first key agreement algorithm parameter KEe, that is: the first PSK = KDF (NONCEe, NONCEa, password1, KEe).
[0420] Implementation manner six: the first node can generate the first PSK according to the identity of the first node, the identity of the second node, the first freshness parameter, the fourth freshness parameter, the first password and the first key agreement algorithm parameter. For example, the first node generates the first PSK through the KDF according to the identity of the first node IDa, the identity of the second node IDe, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the first key agreement algorithm parameter KEe, that is: the first PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KEe).
[0421] Implementation seven: the first node can generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and an intermediate key. The intermediate key is generated according to the first freshness parameter, the fourth freshness parameter, and the first key agreement algorithm parameter. For example, the first node first generates an intermediate key Kmid according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, and the first key agreement algorithm parameter KEe, that is, Kmid = F(NONCEe, NONCEa, KEe), where F is a cryptographic algorithm for generating an intermediate key; and then generates the first PSK according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1, and the intermediate key Kmid, that is, the first PSK = KDF(NONCEe, NONCEa, password1, Kmid). Of course, in actual processing, it can also be completed in one step, and the intermediate key Kmid is only an intermediate result, that is, the way of generating the first PSK satisfies: the first PSK = KDF(NONCEe, NONCEa, password1, F(NONCEe, NONCEa, KEe)).
[0422] Implementation eight: the first node generates the first PSK according to the identity of the first node, the identity of the second node, the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key (or the second intermediate key). Specifically, the first node first determines the third key agreement algorithm parameter (or the private key of the first node), and then determines the first intermediate key based on the first key agreement algorithm according to the first key agreement algorithm parameter and the third key agreement algorithm parameter.
[0423] For example, taking the DH algorithm as an example, the first intermediate key Kdh generated by the first node based on the first key agreement algorithm parameter A and the third key agreement algorithm parameter b satisfies: Kdh = A bmod p. Further, the second intermediate key Kgt can also be determined according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first intermediate key Kdh, i.e. the second intermediate key Kgt satisfies: Kgt = KDF(NONCEe, NONCEa, Kdh). The first node generates the first PSK according to the identity of the first node, the identity of the second node, the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key (or the second intermediate key). For example, the first node generates the first PSK according to the identity of the first node IDa, the identity of the second node IDe, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password passwordl and the first intermediate key Kdh (or the second intermediate key kgt) by KDF, i.e. PSK = KDF(IDa, IDe, NONCEe, NONCEa, passwordl, Kdh (or kgt)). See Figure 7 , Figure 7 is a possible diagram for generating the first PSK provided by the embodiments of the present application. The first node generates the first PSK 702 according to the identity of the first node IDa, the identity of the second node 90 IDe, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password passwordl and the first intermediate key Kdh (or the second intermediate key kgt) by KDF 701.
[0424] It should be noted that the above is to more clearly illustrate the scheme, so as to explain how to obtain the first PSK in multiple steps. In actual processing, the first intermediate key Kdh or the second intermediate key Kgt can also be obtained by one step. The first intermediate key Kdh or the second intermediate key Kgt is only an intermediate result, i.e. the way of determining the first PSK satisfies: the first PSK = KDF(IDa, IDe, NONCEe, NONCEa, passwordl, KDF(NONCEe, NONCEa, Kdh)) or the way of determining the first PSK satisfies: the first PSK = KDF(IDa, IDe, NONCEe, NONCEa, passwordl, KDF(NONCEe, NONCEa, A b Further, the first node can also derive (or derive) other intermediate keys according to the first intermediate key Kdh or the second intermediate key Kgt, and then participate in generating the first PSK according to the derived other intermediate keys.
[0425] Optionally, before generating the first PSK, the first node obtains first confirmation indication information indicating that the first node is allowed to associate with the second node, and then the first node can generate the first PSK. Specifically, the first confirmation indication information is indication information obtained according to a confirmation operation input by a user, and the confirmation operation can be a confirmation of prompt information output. For example, the first node can output first prompt information to remind the user that a new node is accessing, and after receiving a confirmation operation of the user to obtain the first confirmation indication information, the first node generates the first PSK in the manners described in case two or case three. In this way, if an attacker connects to the first node using his own identity identifier, since there is no PSK corresponding to the identity identifier of the attacker in the first node, the user can be reminded that a new node requests association, and the user can verify the identity of the new node, so that the first node can be prevented from associating with an untrusted node, and the security of communication of the first node is ensured.
[0426] Optionally, the first association request message can further include indication information indicating whether the second PSK corresponding to the identity identifier of the first node exists in the second node. For example, the first association request message includes a first field, and the first field is "0" indicating that the second PSK corresponding to the identity identifier of the first node does not exist in the second node, so that the first node can generate the first PSK in the manners described in case two or case three, instead of obtaining the first PSK through a pre-stored correspondence, to avoid subsequent failure of verifying the identity authentication information of the other party.
[0427] As can be seen from the above, the first PSK corresponds to the identity identifier of the second node, and thus can be used to verify the identity of the second node. Specifically, the PSK is a secret value shared between the first node and the second node, that is, the first PSK in the first node and the second PSK in the second node usually have the same value, so that the second node can generate identity authentication information according to the second PSK or encrypt message content through the second PSK (or a key derived according to the second PSK), for the first node to verify the identity of the second node. For example, the second node generates identity authentication information according to the second PSK, and the first node can verify the identity authentication information of the second node through the first PSK; for another example, the second node encrypts or integrity protects message content through the second PSK (or a key derived according to the second PSK), and the first node can obtain the message content from the second node through the first PSK (or a key derived according to the first PSK), so as to verify the identity of the second node.
[0428] Optionally, after the first PSK is generated, the first node can save a correspondence between the first PSK and the identity of the second node, and when the association request message from the second node is received next time, the first PSK can be determined according to the correspondence without re-generating the first PSK. Further optionally, in the case that the access password of the first node is the first password or the first PSK is generated by the first password, if the first password is updated, the first node can delete the correspondence between the first PSK and the identity of the second node.
[0429] In Figure 5 In the method shown, the PSK is a secret value shared between the first node and the second node, and the first PSK in the first node corresponds to the identity of the second node, so it can be used to verify the identity of the second node, avoid the first node accessing an untrusted node, and improve the security of communication.
[0430] Optionally, the embodiments of the present application can further include step S503 or further include step S503-step S504, and step S503-S504 are specifically as follows:
[0431] Step S503: The first node sends a first authentication request message to the second node.
[0432] Specifically, the first authentication request message includes the aforementioned fourth freshness parameter. Optionally, the first authentication request message can further include a message authentication code (MAC). The MAC is a message authentication code generated according to a symmetric key and an integrity protection algorithm, and is used to protect the integrity of the first authentication request message.
[0433] The first node sends the first authentication request message to the second node, and correspondingly, the second node receives the first authentication request message from the first node.
[0434] Optionally, the first authentication request message can further include update indication information. Specifically, in the case that the first node generates the first PSK in the case two or case three, the first node can send the update indication information to the second node to indicate the update of the PSK. Further, after the first node generates the new PSK, the first node can remind the second node to update the second PSK through the update indication information, so as to avoid the second node using the previous old PSK to verify the identity authentication information, thereby avoiding the failure of the second node to verify the identity authentication information and affecting the user experience. Further optionally, the update indication information can be a character or a string in the first authentication request message, for example, the first authentication request message includes an "update" field, and "1" in the field indicates that the second node can generate the second PSK in the method two or method three, and "0" in the field means meaningless.
[0435] Step S504: The second node acquires the second PSK.
[0436] Specifically, the PSK is a secret value shared between the first node and the second node, which can be generated based on the freshness parameter from the second node and the freshness parameter from the first node, or can be pre-configured in the first node and the second node. For convenience of description, in the embodiments of the present application, the pre-shared key between the first node and the second node existing in the second node is referred to as the second PSK, the freshness parameter from the second node when the second PSK is generated is referred to as the second freshness parameter, and the freshness parameter from the first node when the first PSK is generated is referred to as the third freshness parameter. The freshness parameter from the second node can be the first freshness parameter in the first association request message, or the freshness parameter from the second node before the first association request message. Similarly, the freshness parameter from the first node can be the fourth freshness parameter in the first authentication request message, or the freshness parameter from the second node before the first authentication request message.
[0437] The second PSK corresponds to the identity of the first node. The identity of the first node is also referred to as the device identity of the first node, and the identity of the first node can be the ID of the first node, the media access control (MAC) address, the domain name, the domain address or other customized identity.
[0438] Before acquiring the second PSK, the second node can first acquire the identity of the first node. The second node acquires the identity of the first node in at least the following three schemes:
[0439] Scheme one: obtaining the identity of the first node through the broadcast message of the first node. Specifically, the first node carries the identity of the first node in the broadcast message, and the second node can obtain the identity of the first node by receiving the broadcast message of the first node.
[0440] Scheme two: the identity of the first node is also included in the first authentication request message. Specifically, the first node can carry the identity of the first node in the first authentication request message, and the second node receives the first authentication request message from the first node, thereby obtaining the identity of the first node.
[0441] Scheme three: the second node receives the input identity of the first node. Specifically, the user requests access to the first node by inputting the identity of the first node, and the second node receives the identity of the first node input by the user, thereby obtaining the identity of the first node.
[0442] The second node obtains the second PSK, including at least the following three methods:
[0443] Method one: the second node obtains the second PSK according to the correspondence between the second PSK and the identity of the first node. The correspondence can be pre-configured in the second node, or saved after the second PSK is generated. The form of the second node storing the correspondence can be one or more of a correspondence set, a data table, a database, etc., which is not limited in the present application. For example, see Table 2, which is a possible correspondence set between the second PSK and the identity of the first node provided by an embodiment of the present application. The correspondence set includes the identity of multiple nodes, the corresponding PSK, and the type of PSK. For example, the node with the identity "ID4" corresponds to the PSK "PSK4", and the type of PSK is pre-configured. For another example, the node with the identity "ID5" corresponds to the PSK "PSK5", and the type of PSK is generated, i.e. the PSK5 is generated according to the second freshness parameter from the second node and the third freshness parameter from the first node. For convenience of description, the correspondence set stored in the second node in the embodiment of the present application is referred to as the second correspondence set.
[0444] Table 2: Correspondence between second PSK and identity of first node
[0445] Identity identifier PSK type ID4 PSK4 Configuration key ID5 PSK5 generate ID6 PSK6 generate
[0446] It can be understood that the correspondence between the second PSK and the identity of the first node in the second node indicates that the first node has been associated with the second node before or that the second node has pre-configured the second PSK corresponding to the identity of the first node, so the second node can obtain the second PSK according to the correspondence.
[0447] Method two: the second node generates a second PSK according to the first freshness parameter and the fourth freshness parameter, and the second PSK is used to verify the identity of the first node. For example, when the second node associates with the first node for the first time or the second node deletes the corresponding relationship, there is no second PSK corresponding to the identity identifier of the first node in the second node, so the second node can generate a new second PSK according to the first freshness parameter and the fourth freshness parameter, and the second PSK is used to verify the identity of the first node. Further, the second node determines the second PSK according to the first freshness parameter and the fourth freshness parameter from the first node, which can have the following implementation manners:
[0448] Implementation manner nine: the second node generates the second PSK through the KDF according to the first freshness parameter and the fourth freshness parameter. For example, taking the first freshness parameter as NONCEe and the fourth freshness parameter as NONCEa, the generated second PSK satisfies: second PSK = KDF (NONCEe, NONCEa).
[0449] Implementation manner ten: the second node accesses the first node through the input first password, so the second node can generate the first PSK according to the first freshness parameter, the fourth freshness parameter and the first password. For example, the second node generates the second PSK through the KDF according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first password password1, that is: second PSK = KDF (NONCEe, NONCEa, password1).
[0450] Implementation manner eleven: the second node accesses the first node through the input first password, so the second node can generate the second PSK according to the identity identifier of the first node, the identity identifier of the second node, the first freshness parameter, the fourth freshness parameter and the first password. For example, the second node generates the second PSK through the KDF according to the identity identifier IDa of the first node, the identity identifier IDe of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first password password1, that is: second PSK = KDF (Ida, Ide, NONCEe, NONCEa, password1).
[0451] Method three: the second key agreement algorithm parameter is included in the first authentication request message, and the second node generates the second PSK according to the first freshness parameter, the fourth freshness parameter and the second key agreement algorithm parameter. Further, the second node generates the second PSK according to the first freshness parameter, the fourth freshness parameter and the second key agreement algorithm parameter, which can have the following implementation manners:
[0452] Implementation twelve: the second node generates the second PSK through the KDF according to the first freshness parameter, the fourth freshness parameter, and the second key agreement algorithm parameter. For example, taking the first freshness parameter as NONCEe, the fourth freshness parameter as NONCEa, and the second key agreement algorithm parameter as KEa as an example, the second PSK generated through the KDF is: second PSK = KDF (NONCEe, NONCEa, KEa).
[0453] The second key agreement algorithm parameter KEa is an algorithm parameter generated in the key agreement process. For example, taking the DH algorithm as an example, the first node sends the value B (that is, B = g b mod p, which can be regarded as the second key agreement algorithm parameter KEa) generated by raising g to the power of b mod P to the second node, and the second node provides the random number a (which is the private key of the second node and is referred to as the fourth key agreement algorithm parameter for convenience of description). In the DH algorithm, the second node raises the received value B to the power of a to obtain the secret value of the key agreement, that is, the secret value obtained through the agreement is B a mod p, which can be used to generate the second PSK. The second node generates the second PSK through the KDF according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1, the value B a mod p).
[0454] Further, the second node can carry the first key agreement algorithm parameter A (or KEe) in the first association request message or other messages, which is generated according to the fourth key agreement algorithm parameter a. The first node raises the received first key agreement algorithm parameter A to the power of b to obtain the secret value of the key agreement, that is, the secret value obtained through the agreement is A b mod p, wherein b is the private key of the first node. Since A b mod p = (g a mod p) b mod p = g ab mod p = (g b mod p) a mod p = B a mod p, the secret value obtained through the key agreement between the first node and the second node is the same, so that the second PSK generated has the same value as the first PSK generated in implementation four.
[0455] Implementation thirteen: the second node accesses the first node through the input first password, and the second node can generate the second PSK according to the first freshness parameter, the fourth freshness parameter and the first password. For example, the second node generates the second PSK through the KDF according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the second key agreement algorithm parameter KEa, that is: the second PSK = KDF (NONCEe, NONCEa, password1, KEa).
[0456] Implementation fourteen: the second node accesses the first node through the input first password, and the second node can generate the second PSK according to the identity of the first node, the identity of the second node, the first freshness parameter, the fourth freshness parameter, the first password and the second key agreement algorithm parameter. For example, the second node generates the second PSK through the KDF according to the identity of the first node IDa, the identity of the second node IDe, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the second key agreement algorithm parameter KEa, that is: the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KEa).
[0457] Implementation fifteen: the second node can generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the intermediate key. The intermediate key is generated according to the first freshness parameter, the fourth freshness parameter and the second key agreement algorithm parameter. For example, the second node first generates the intermediate key Kmid according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the second key agreement algorithm parameter KEa, that is: Kmid = F (NONCEe, NONCEa, KEa), wherein F is a cryptographic algorithm for generating the intermediate key; then the second node generates the second PSK according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the intermediate key Kmid, that is: the second PSK = KDF (NONCEe, NONCEa, password1, Kmid). Of course, in actual processing, it can also be completed in one step, and the intermediate key Kmid is only an intermediate result, that is, the way of generating the second PSK satisfies: the second PSK = KDF (NONCEe, NONCEa, password1, F (NONCEe, NONCEa, KEa)).
[0458] Implementation 16: The second node accesses the first node by the input first password, and the second node generates the second PSK according to the identity of the first node, the identity of the second node, the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key (or the second intermediate key). Specifically, taking the DH algorithm as an example, the second node first calculates the first intermediate key according to the second key agreement algorithm parameter and the fourth key agreement algorithm parameter (or the private key of the second node). For example, taking the DH algorithm as an example, the first intermediate key Kdh generated by the second node based on the second key agreement algorithm parameter B and the fourth key agreement algorithm parameter a is: Kdh = B a mod p. The second node generates the second PSK by KDF according to the identity of the first node IDa, the identity of the second node IDe, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the first intermediate key Kdh, that is: the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, Kdh).
[0459] Further, the second node can also determine the second intermediate key according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first intermediate key Kdh, that is, the second intermediate key Kgt is: Kgt = KDF (NONCEe, NONCEa, Kdh). The second node generates the second PSK by KDF according to the identity of the first node IDa, the identity of the second node IDe, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the second intermediate key Kgt, that is: the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, Kgt).
[0460] It should be noted that this is to more clearly illustrate the scheme, so the multiple steps explain how to get the first PSK, in actual processing, it can also be completed by one step, the first intermediate key Kdh or the second intermediate key Kgt is only an intermediate result, that is, the way to determine the second PSK satisfies: the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KDF (NONCEe, NONCEa, Kdh)) or the way to determine the second PSK satisfies: the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KDF (NONCEe, NONCEa, A bFurther alternatively, the second node can further derive (or said, derive) other intermediate keys according to the first intermediate key Kdh or the second intermediate key Kgt, and then participate in generating the second PSK according to the derived other intermediate keys.
[0461] Generally, the first node generates the first PSK by using the method shown in the implementation manner, and correspondingly, the second node generates the second PSK by using the method shown in the corresponding implementation manner, so that the first PSK generated by the first node is the same as the second PSK generated by the second node, facilitating the verification of the identity of the opposite node.
[0462] Optionally, before generating the second PSK, the second node obtains third confirmation indication information, which indicates that the second PSK is allowed to be generated. Specifically, the third confirmation indication information is obtained according to a confirmation operation input by a user, and the confirmation operation can be a confirmation of the output prompt information. For example, the second node can output third prompt information to remind the user to access the new node, and after receiving the user confirmation operation to obtain the third confirmation indication information, the second PSK is generated according to the first freshness parameter and the fourth freshness parameter. In this way, if an attacker connects the second node using his own identity identifier, since there is no PSK corresponding to the identity identifier of the attacker in the second node, the user can be reminded of the new node association request, and the identity of the new node can be verified by the user, so that the second node can be associated with an untrusted node, and the security of the communication of the second node is ensured.
[0463] Optionally, after generating the second PSK, the second node can save the correspondence between the second PSK and the identity identifier of the first node, and the second PSK can be determined according to the correspondence when associating with the first node next time, without the need to generate the second PSK again. Optionally, when the second node accesses the first node by using the first password or the second PSK is generated by participating in the generation of the first password, if the first password is updated, the second node can delete the correspondence between the second PSK and the identity identifier of the first node.
[0464] Optionally, the key obtaining method described in the embodiments of the present application can further include Figure 8 The step S801 or S801-S802, and the steps S801-S802 are specifically as follows:
[0465] Step S801: If the first identity authentication information is verified to be passed by the second node according to the second PSK and the first freshness parameter, the second node sends a first authentication response message to the first node.
[0466] Specifically, the first authentication request message further comprises first identity authentication information, which is generated by the first node according to the first PSK and the first freshness parameter. For example, the first node generates the first identity authentication information AUTHa according to the first PSK and the first freshness parameter NONCEe through KDF, i.e., AUTHa = KDF (first PSK, NONCEe). Optionally, in actual processing, the parameters for generating the first identity authentication information of the first node can further comprise other information. For example, the generated first identity authentication information AUTHa can satisfy AUTHa = KDF (first PSK, first association request message), wherein the first association request message comprises the first freshness parameter NONCEe; for another example, the generated first identity authentication information AUTHa can further satisfy AUTHa = KDF (first PSK, NONCEa, first association request message), wherein NONCEa is a fourth freshness parameter.
[0467] Since the first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, the second node can verify whether the first identity authentication information is correct according to the second PSK and the first freshness parameter. In an optional scheme, according to the protocol, the first node uses what parameters to generate the first identity authentication information, and then the second node should also use the same parameters to generate the information for checking, if the information for checking is the same as the first identity authentication information, it is considered that the verification is passed. For example, the first identity authentication information is generated through KDF, therefore the second node can generate the information for checking, also called check value check1, through KDF, and then verify whether the first identity authentication information is correct through the information for checking. The following is an example:
[0468] For example, if the first identity authentication information AUTHa is KDF (first PSK, NONCEe), the second node generates the check value check1 = KDF (second PSK, NONCEe) through KDF according to the second PSK and the first freshness parameter, if the check value check1 is the same as AUTHa, the verification is passed.
[0469] If the first identity authentication information is verified, the second node sends a first authentication response message to the first node, wherein the second authentication response message includes second identity authentication information. Optionally, the second identity authentication information is used by the first node to verify the identity of the second node. The second identity authentication information is generated according to the second PSK and the fourth freshness parameter. For example, the second node generates the second identity authentication information AUTHe according to the second PSK and the fourth freshness parameter NONCEa through KDF, i.e., AUTHe = KDF (second PSK, NONCEa). Optionally, in actual processing, the parameters used by the second node to generate the second identity authentication information can also include other information, for example, the generated second identity authentication information AUTHe can satisfy AUTHe = KDF (second PSK, first authentication request message), wherein the first authentication request message includes the fourth freshness parameter NONCEa; for another example, the generated second identity authentication information AUTHe can also satisfy AUTHe = KDF (second PSK, NONCEe, first authentication request message), wherein NONCEe is the first freshness parameter.
[0470] Optionally, if the first identity authentication information is not verified, the second node can generate a new second PSK through the method two or the method three, for the convenience of description, the generated new second PSK is called the fourth PSK. The second node verifies the first identity authentication information again through the fourth PSK and the first freshness parameter, if the verification is passed, the second node sends a first authentication response message to the first node, wherein the second response message includes second identity authentication information. The second identity authentication information is generated according to the fourth PSK and the fourth freshness parameter, and is used by the first node to verify the identity of the second node.
[0471] Optionally, before generating the fourth PSK, the second node obtains fourth confirmation indication information, which indicates that the fourth PSK is allowed to be generated. Specifically, the fourth confirmation indication information is obtained according to the confirmation operation input by the user, and the confirmation operation can be the confirmation of the output prompt information. For example, the second node can output fourth prompt information to remind the user to generate the fourth PSK for the first node, and after receiving the confirmation operation of the user to obtain the fourth confirmation indication information, the fourth PSK is generated through the method two or the method three. In this way, the identity of the first node is verified by the user, so that the second node can be associated with an untrusted node, and the security of the communication of the second node is ensured.
[0472] Optionally, if the first identity authentication information is not verified, the second node can delete the second PSK corresponding to the identity of the first node. Further, the second node can also re-determine a new freshness parameter and re-initiate a new association request message. For the convenience of description, the re-determined freshness parameter is referred to as a fifth freshness parameter, and the re-initiated new association request message is referred to as a second association request message, so as to re-obtain the PSK.
[0473] Optionally, if the first identity authentication information is not verified, and the second node does not pre-store the PSK corresponding to the identity of the first node (or the second PSK is obtained by the method two or the method three), the second node can instruct the user to delete the PSK corresponding to the identity of the second node stored in the first node. After the second node obtains the confirmation indication information input by the user, the second node sends the second association request message to the first node, so as to re-obtain the PSK.
[0474] Optionally, the first authentication response message can also include a message authentication code (MAC). The MAC is a message authentication code generated according to a symmetric key and an integrity protection algorithm, and is used to protect the integrity of the first authentication request message. The symmetric key and / or the integrity protection algorithm can be agreed by the first node and the second node through other messages, or can be generated according to existing parameters. For example, in the implementation manner eight, the first intermediate key Kdh generated by the first node is B a mod p, and in the implementation manner sixteen, the first intermediate key Kdh generated by the second node is A b mod p, and A b mod p = B a mod p, so the first intermediate key Kdh can also be used as the symmetric key between the first node and the second node, and can be used for integrity protection of the first authentication request message.
[0475] Step S802: If the second identity authentication information is verified by the first node according to the first PSK and the fourth freshness parameter, the first node sends a first association response message to the second node.
[0476] Specifically, since the second identity authentication information is generated by the second node according to the second PSK and the fourth freshness parameter, the first node can verify whether the second identity authentication information is correct according to the first PSK and the fourth freshness parameter.
[0477] In an alternative, according to the agreement, the second node uses what parameters to generate the second identity authentication information, the first node should also use the same parameters to generate the information for checking, if the information for checking is the same as the second identity authentication information, it is considered that the verification is passed. For example, the second identity authentication information is generated by KDF, therefore the first node can generate the information for checking, also called check2, by KDF, and then verify whether the second identity authentication information is correct by the information for checking. The following is an example:
[0478] For example, if the second identity authentication information AUTHe is KDF (second PSK, NONCEa), the first node gets the check2 = KDF (first PSK, NONCEa) by KDF according to the first PSK and the fourth freshness parameter, if the check2 is the same as AUTHe, the verification is passed.
[0479] If the second identity authentication information is passed, the first node sends the first association response message to the second node, which can represent that the first node is allowed to communicate with the second node, and correspondingly, the second node receives the first association response message and can start to communicate with the first node. Alternatively, in a possible solution, the first association response message can not be sent, for example, after the second identity authentication information is passed, the first node directly starts to communicate with the second node. Alternatively, the first node can allocate a temporary ID for the second node, so that the second node can communicate with the first node through the temporary ID.
[0480] Alternatively, if the second identity authentication information is not passed, and the first node is in the case of acquiring the first PSK by the method shown in case one, the first node can generate a new first PSK by the method shown in case two or case three, for convenience of description, the generated new first PSK is called third PSK, and then generate a new identity authentication information according to the generated third PSK and the first freshness parameter, for convenience of description, it is called third identity authentication information. Further, the first node re-sends the second identity authentication request message to the first node, which includes the third identity authentication message and the fourth freshness parameter. Correspondingly, the second node receives the second identity authentication information from the first node, and after the authentication is passed, it can send the second identity response message to the first node, which includes the identity authentication information of the second node. Correspondingly, the first node allows to communicate with the second node after verifying that the identity authentication information of the second node is passed.
[0481] Optionally, before generating the third PSK, the first node obtains second confirmation indication information, the second confirmation indication information indicating that the third PSK is allowed to be generated. Specifically, the second confirmation indication information is indication information obtained according to a confirmation operation input by a user, and the confirmation operation can be a confirmation of the output prompt information. For example, the first node can output second prompt information to remind the user that the third PSK needs to be generated for the second node, and after receiving the confirmation operation of the user and obtaining the second confirmation indication information, the third PSK is generated by the method described in case two or case three. In this way, the identity of the second node is verified by the user, so that the first node is prevented from being associated with an untrusted node, and the security of communication of the first node is ensured.
[0482] Optionally, the first authentication response message can further include a message authentication code (MAC). The MAC is a message authentication code generated according to a symmetric key and an integrity protection algorithm, and is used to protect the integrity of the first authentication request message. The symmetric key and / or the integrity protection algorithm can be agreed upon by the first node and the second node through other messages, or can be generated according to existing parameters. For example, the first intermediate key or the second intermediate key in the eighth implementation manner can be used as the symmetric key between the first node and the second node. Figure 5 In the described method, the PSK is a secret value shared between the first node and the second node. The first node and the second node generate the PSK by using a second freshness parameter from the second node and a third freshness parameter from the first node, and use the PSK to identify the identity of the node at the opposite end, to verify the identity of the node at the opposite end. In this way, if an attacker wants to use the identity of the node to request association, since the second freshness parameter and the third freshness parameter used to generate the PSK can be obtained before the first association request message, for example, can be obtained when the first node and the second node are associated for the first time, since the data obtained before is usually difficult to crack, so that the attacker cannot fake the PSK, and thus cannot pass the identity verification of the first node, thereby avoiding the connection of the first node with an untrusted node, and improving the communication security of the first node.
[0483] The above Figure 5 Or Figure 8 The method embodiment shown in the method embodiment contains many possible implementation schemes, and the following will be described with reference to Figure 9 , Figure 10 , Figure 11 some implementation schemes, and it should be noted that Figure 9 , Figure 10 , Figure 11 unexplained related concepts or operations or logical relationships can be referred to Figure 5 or Figure 8 The corresponding description in the illustrated embodiments will therefore not be repeated.
[0484] Referring to Figure 9 , Figure 9 The method provided in the embodiments of the present application is another key acquisition method, and the method comprises the following steps:
[0485] Step S901: The second node sends a first association request message to the first node.
[0486] Specifically, the first association request message comprises a first freshness parameter, which can comprise at least one of a random number (NONCE), a counter value, a sequence number, etc. The freshness parameter at different times is usually different.
[0487] Correspondingly, the first node receives the first association request message from the second node.
[0488] Step S902: The first node acquires a fourth freshness parameter.
[0489] Specifically, the fourth freshness parameter can be a random number, a counter value or a sequence number, etc. The fourth freshness parameter can be generated (or said to be generated) by the first node, for example, the first node generates a random number through a random number generator, and takes the random number as the fourth freshness parameter. The fourth freshness parameter can also be a counter value or a sequence number acquired by the first node, for example, the first node records a PDCP COUNT, and the first node can acquire the recorded PDCP COUNT as the fourth freshness parameter.
[0490] Step S903: The first node generates a first PSK according to the identity of the first node, the identity of the second node, the first password, the first freshness parameter and the fourth freshness parameter.
[0491] Specifically, the first node uses the first password as an access password (password), and the first node can generate the first PSK through KDF according to the identity IDa of the first node, the identity IDe of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first password password1, that is: PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1).
[0492] Optionally, before the first PSK is generated, the first node outputs first prompt information, the first prompt information being used to prompt whether to allow association with the second node or whether to allow generation of the first PSK. Further, the first node obtains first confirmation indication information according to a confirmation operation of a user, the first confirmation indication information representing that association with the second node is allowed or that the first PSK is allowed, so that the first PSK is generated according to the identity of the first node, the identity of the second node, the first password, the first freshness parameter and the fourth freshness parameter.
[0493] Step S904: The first node sends a first authentication request message to the second node.
[0494] Specifically, the fourth freshness parameter and the first identity authentication information are included in the first authentication request message. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter. For example, the first node generates the first identity authentication information AUTHa by KDF according to the first PSK and the first freshness parameter NONCEe, i.e., AUTHa = KDF (first PSK, NONCEe). Optionally, in actual processing, the parameter for generating the first identity authentication information by the first node can also include other information, for example, the generated first identity authentication information AUTHa can satisfy: AUTHa = KDF (first PSK, first association request message), wherein the first association request message includes the first freshness parameter NONCEe; for another example, the generated first identity authentication information AUTHa can also satisfy: AUTHa = KDF (first PSK, NONCEa, first association request message), wherein NONCEa is the fourth freshness parameter.
[0495] The first node sends the first authentication request message to the second node, and accordingly, the second node receives the first authentication request message from the first node.
[0496] Step S905: The second node generates a second PSK according to the identity of the first node, the identity of the second node, the first password, the first freshness parameter and the fourth freshness parameter.
[0497] Specifically, the second node accesses the first node through the first password, and the second node can generate the second PSK by KDF according to the identity IDa of the first node, the identity IDe of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first password password1, i.e., PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1).
[0498] Optionally, before generating the second PSK, the second node outputs third prompt information for prompting whether to allow generation of the second PSK. Further, the second node obtains third confirmation indication information according to a confirmation operation of the user, the third confirmation indication information representing that the generation of the third PSK is allowed, so as to generate the second PSK according to the identity of the first node, the identity of the second node, the first password, the first freshness parameter and the fourth freshness parameter.
[0499] Step S906: If the first identity authentication information is verified to be passed according to the second PSK and the first freshness parameter, the second node sends a first authentication response message to the first node.
[0500] Specifically, the first identity authentication information is generated according to the first PSK and the first freshness parameter, so the second node can verify whether the first identity authentication information is correct according to the second PSK and the first freshness parameter. Generally speaking, if the first node uses what parameter to generate the first identity authentication information, the second node should also use the same parameter to generate the information for verification. If the information for verification is the same as the first identity authentication information, it is considered that the verification is passed. For example, if the first identity authentication information AUTHa is KDF (first PSK, NONCEe), the second node obtains a check value check1 = KDF (second PSK, NONCEe) through KDF according to the second PSK and the first freshness parameter, and if the check value check1 is the same as AUTHa, the verification is passed.
[0501] If the first identity authentication information is verified to be passed, the second node sends a first authentication response message to the first node. The first authentication response message includes second identity authentication information. The second identity authentication information is generated by the second node according to the second PSK and the fourth freshness parameter, and is used for the first node to verify the identity of the second node. Optionally, in actual processing, the parameters of the second identity authentication information generated by the second node can also include other information, for example, the generated second identity authentication information AUTHe can satisfy: AUTHe = KDF (second PSK, first authentication request message), wherein the first authentication request message includes the fourth freshness parameter NONCEa; for another example, the generated second identity authentication information AUTHe can also satisfy: AUTHe = KDF (first PSK, NONCEe, second authentication request message), wherein NONCEe is the first freshness parameter.
[0502] The first node sends a first authentication request message to the second node, and correspondingly, the second node receives the first authentication request message from the first node.
[0503] Step S907: If the second identity authentication information is verified to be passed according to the first PSK and the fourth freshness parameter, the first node sends a first association response message to the second node.
[0504] Specifically, the second identity authentication information is generated according to the second PSK and the fourth freshness parameter, and thus the first node can verify the second identity authentication information according to the first PSK and the fourth freshness parameter. Generally, if the second node uses what parameter to generate the second identity authentication information, the first node should also use the same parameter to generate the check information, and if the check information is the same as the second identity authentication information, it is considered to be verified to be passed. For example, if the second identity authentication information AUTHe is KDF (second PSK, NONCEa), the first node obtains a check value check2 = KDF (first PSK, NONCEa) by KDF according to the first PSK and the fourth freshness parameter, and if the check value check2 is the same as AUTHe, it is verified to be passed.
[0505] If the first identity authentication information is verified to be passed, the second node sends a first association response message to the first node. The association response message indicates that the first node is allowed to communicate with the second node.
[0506] Optionally, the embodiments of the present application can further include step S908 or can further include steps S908-S909, and the steps S908-S909 are specifically as follows:
[0507] Step S908: The first node saves the correspondence between the first PSK and the identity of the second node.
[0508] Specifically, the first node stores a first correspondence set of PSKs and identities of nodes, and the first node adds the correspondence between the first PSK and the identity of the second node to the first correspondence set.
[0509] Step S909: The second node saves the correspondence between the second PSK and the identity of the first node.
[0510] Specifically, the second node stores a second correspondence set of PSKs and identities of nodes, and the second node adds the correspondence between the second PSK and the identity of the first node to the second correspondence set.
[0511] In Figure 9In the illustrated embodiment, since the PSK is a secret value shared between the first node and the second node, the first PSK in the first node usually has the same value as the second PSK in the second node. The first node generates the first identity authentication information according to the first PSK and the first freshness parameter, so that the second node can verify the identity of the first node according to the second PSK. If the second PSK stored in the second node cannot be verified, it means that the identity of the first node is not trusted, so that the second node can be prevented from being associated with an untrusted node, and the security of communication of the second node is improved. Correspondingly, the first node can also verify the identity of the second node, so that the first node can be prevented from being associated with an untrusted node, and the security of communication of the first node is improved.
[0512] Referring to Figure 10 , Figure 10 The method provided in the embodiment of the present application is another key acquisition method, which comprises the following steps:
[0513] Step S1001: The second node sends a first association request message to the first node.
[0514] Specifically, the first association request message comprises a first freshness parameter and a first key agreement algorithm parameter. The first key agreement algorithm parameter is generated by the second node based on a fourth key agreement algorithm according to a fourth key agreement algorithm parameter, and the fourth key agreement algorithm is a private key of the second node. For example, taking the DH algorithm as an example, the first node and the second node use the same large prime number p and the same random number g for key agreement. The second node determines a random number a (i.e. the private key of the second node, or the fourth key agreement algorithm parameter), and the second node sends a number A generated by raising g to the power of a modulo P to the first node, i.e. A = ga mod p. The number A is the first key agreement algorithm parameter. a
[0515] Optionally, the first node can broadcast one or more key agreement algorithms supported by the first node. After the second node receives the one or more key agreement algorithms, the second node carries the first key agreement algorithm parameter determined based on the first key agreement algorithm in the first association request message (optionally, in the case of supporting multiple key agreement algorithms, the first key agreement algorithm can also carry identification information of the first key agreement algorithm). Correspondingly, the first node can receive the first association request message from the second node.
[0516] Step S1002: The first node acquires a fourth freshness parameter and a third key agreement algorithm parameter.
[0517] Specifically, the fourth freshness parameter can be a random number, a counter value, or a sequence number, etc. The fourth freshness parameter can be generated (or said to be generated) by the first node, for example, the first node generates a random number through a random number generator, and takes the random number as the fourth freshness parameter, or the first node can obtain a counter value or a sequence number, etc. For example, the first node records a PDCP COUNT, and the first node can obtain the recorded PDCP COUNT as the fourth freshness parameter.
[0518] The third key agreement algorithm parameter obtained by the first node can also be referred to as a private key of the first node, and generally can be a random number with a large value.
[0519] Step S1003: The first node determines a first intermediate key according to the first key agreement algorithm parameter and the third key agreement algorithm parameter.
[0520] Specifically, the first node can determine a secret value obtained through key agreement according to the first key agreement algorithm parameter and the third key agreement algorithm parameter based on the first key agreement algorithm, and the secret value can be regarded as the first intermediate key. For example, taking the DH algorithm as an example, the first node can determine the first intermediate key Kdh as Kdh=A b mod p according to the first key agreement algorithm parameter A and the third key agreement algorithm parameter b.
[0521] Optionally, the first intermediate key can be used as a shared key between the first node and the second node, and is used for encrypting a message or performing integrity protection.
[0522] Step S1004: The first node generates a first PSK according to the identity of the first node, the identity of the second node, the first password, and the first intermediate key.
[0523] Specifically, the first node uses the first password as an access password (password). The first node generates the first PSK through KDF according to the identity IDa of the first node, the identity ID2 of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1, and the first intermediate key Kdh, that is, the first PSK=KDF(IDa, ID2, NONCEe, NONCEa, password1, Kdh).
[0524] Optionally, the first node can first determine the second intermediate key Kgt through the KDF according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first intermediate key Kdh, i.e. Kgt = KDF (NONCEe, NONCEa, Kdh). Then generate the first PSK through the KDF according to the identity IDa of the first node, the identity IDe of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the second intermediate key Kgt, i.e. the first PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, Kgt).
[0525] It should be noted that, here, in order to make the scheme more clear, the multiple steps are used to explain how to obtain the first PSK, in actual processing, it can also be completed through one step, the first intermediate key Kdh or the second intermediate key Kgt is only an intermediate result, i.e. the way of determining the first PSK satisfies: the first PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KDF (NONCEe, NONCEa, Kdh)) or the way of determining the first PSK satisfies: the first PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KDF (NONCEe, NONCEa, A b mod p)).
[0526] Optionally, before generating the first PSK, the first node outputs the first prompt information, and the first prompt information is used to prompt whether to allow the generation of the first PSK. Further, the first node obtains the first confirmation indication information according to the user's confirmation operation, and the first confirmation indication information represents that the generation of the first PSK is allowed.
[0527] Step S1005: The first node sends the first authentication request message to the second node.
[0528] Specifically, the first authentication request message includes the fourth freshness parameter, the second key agreement algorithm parameter and the first identity authentication information. The second key agreement algorithm parameter is a parameter determined by the first node based on the first key agreement algorithm according to the third key agreement algorithm (or the private key of the first node). For example, taking the DH algorithm as an example, the first node sends the value B generated by g raised to the power of b mod P to the second node, i.e. B = g b mod p, and the value B can be regarded as the second key agreement algorithm parameter.
[0529] The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, and is used for the second node to verify the identity of the first node. For example, the first node generates the first identity authentication information AUTHa according to the first PSK and the first freshness parameter NONCEe through the KDF, that is, AUTHa = KDF (first PSK, NONCEe). Optionally, in actual processing, the parameters for the first node to generate the first identity authentication information can also include other information, for example, the generated first identity authentication information AUTHa can satisfy: AUTHa = KDF (first PSK, first association request message), wherein the first association request message includes the first freshness parameter NONCEe; for another example, the generated first identity authentication information AUTHa can also satisfy: AUTHa = KDF (first PSK, NONCEa, first association request message), wherein NONCEa is the fourth freshness parameter.
[0530] Optionally, the first authentication request message can also include a message authentication code MAC, which is a message authentication code generated according to the first intermediate key, and is used to protect the integrity of the first authentication request message.
[0531] The first node sends the first authentication request message to the second node, and correspondingly, the second node receives the first authentication request message from the first node.
[0532] Step S1006: The second node determines the first intermediate key according to the second key agreement algorithm parameter and the fourth key agreement algorithm parameter.
[0533] Specifically, the second node can determine the secret value obtained through the key agreement according to the second key agreement algorithm parameter and the fourth key agreement algorithm parameter (or the private key of the second node). For example, taking the DH algorithm as an example, the second node determines the first intermediate key Kdh according to the received second key agreement algorithm parameter B and the fourth key agreement algorithm parameter a, and Kdh satisfies: Kdh = B a mod p. Since Kdh = A b mod p = (g a mod p) b mod p = g ab mod p = (g b mod p) a mod p = B a mod p, the first intermediate key determined by the first node and the second node has the same value.
[0534] Step S1007: The second node generates a second PSK according to the identity of the first node, the identity of the second node, the first password and the first intermediate key.
[0535] Specifically, the second node accesses the first node by the first password. The second node generates the second PSK by the KDF according to the identity IDa of the first node, the identity IDe of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the first intermediate key Kdh, i.e., the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, Kdh).
[0536] Optionally, the second node can first determine the second intermediate key Kgt by the KDF according to the first freshness parameter NONCEe, the fourth freshness parameter NONCEa and the first intermediate key Kdh, i.e., Kgt = KDF (NONCEe, NONCEa, Kdh), and then generate the second PSK by the KDF according to the identity IDa of the first node, the identity IDe of the second node, the first freshness parameter NONCEe, the fourth freshness parameter NONCEa, the first password password1 and the second intermediate key Kgt, i.e., the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, Kgt).
[0537] It should be noted that the above is to more clearly illustrate the scheme, so the multiple steps are explained how to obtain the second PSK, and in actual processing, the first intermediate key Kdh or the second intermediate key Kgt can be only an intermediate result, i.e., the way of determining the second PSK satisfies: the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KDF (NONCEe, NONCEa, Kdh)) or the way of determining the second PSK satisfies: the second PSK = KDF (IDa, IDe, NONCEe, NONCEa, password1, KDF (NONCEe, NONCEa, A b mod p)).
[0538] Optionally, before generating the second PSK, the second node outputs third prompt information, the third prompt information being used to prompt whether to allow the generation of the second PSK. Further, the second node obtains third confirmation indication information according to a confirmation operation of a user, the third confirmation indication information representing that the generation of the third PSK is allowed, so as to generate the second PSK.
[0539] Step S1008: If the first identity authentication information is verified to be passed according to the second PSK and the first freshness parameter, the second node sends a first authentication response message to the first node.
[0540] For a detailed description, please refer to step S906.
[0541] Step S1009: If the verification of the second identity authentication information is successful based on the first PSK and the fourth freshness parameter, the first node sends a first association response message to the second node.
[0542] For a detailed description, please refer to step S907.
[0543] Optionally, the embodiments of this application may further include step S1010 or steps S1010-S1011, wherein steps S1010-S1011 are as follows:
[0544] Step S1010: The first node saves the correspondence between the first PSK and the identity identifier of the second node.
[0545] Specifically, the first node stores a first set of correspondences between PSK and node identity identifiers. The first node adds the correspondence between the first PSK and the identity identifier of the second node to the first set of correspondences.
[0546] Step S1011: The second node saves the correspondence between the second PSK and the identity identifier of the first node.
[0547] Specifically, the second node stores a second set of correspondences between PSK and node identity identifiers. The second node adds the correspondence between the second PSK and the identity identifier of the first node to the second set of correspondences.
[0548] exist Figure 10 In the illustrated embodiment, the second node carries first key negotiation algorithm parameters in the first association request message, and the first node provides second key negotiation algorithm parameters. The first PSK is determined by combining the key negotiation algorithm parameters provided by both parties, the first freshness parameter, the fourth freshness parameter, and the first password. This way, even if an attacker subsequently impersonates the second node and obtains the first and fourth freshness parameters used to generate the first PSK, they cannot crack the PSK and therefore cannot communicate with the first node, thus improving the security of communication between the first node and the second node. Similarly, even if an attacker subsequently impersonates the first node and obtains the first and fourth freshness parameters used to generate the second PSK, they cannot crack the PSK and therefore cannot communicate with the second node, further improving the security of communication between the first node and the second node.
[0549] See Figure 11 , Figure 11The method can be applied to a case that there is no first PSK in the first node and there is second PSK in the second node, for example, a case that data is lost due to formatting in the first node, or a case that the correspondence between the PSK and the identity of the node is deleted in the first node. The method at least includes the following steps:
[0550] Step S1101: The second node sends a first association request message to the first node.
[0551] Specifically, the first association request message includes a first freshness parameter. Correspondingly, the first node can receive the first association request message from the second node.
[0552] Step S1102: The first node acquires a fourth freshness parameter.
[0553] Specifically, the fourth freshness parameter can be a random number, a counter value or a sequence number, etc. The fourth freshness parameter can be generated (or said to be generated) by the first node, for example, the first node generates a random number by a random number generator, and takes the random number as the fourth freshness parameter, or the first node acquires a counter value or a sequence number, etc., for example, the first node records a PDCP COUNT, and the first node can acquire the recorded PDCP COUNT as the fourth freshness parameter.
[0554] Step S1103: The first node generates a first PSK according to the first freshness parameter and the fourth freshness parameter.
[0555] Specifically, the detailed description can refer to the detailed description of case two and case three in step S502.
[0556] Step S1104: The first node sends a first authentication request message to the second node.
[0557] Specifically, the first authentication request message includes the fourth freshness parameter and first identity authentication information. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, and is used for the second node to verify the identity of the first node. Optionally, in actual processing, the parameters for the first node to generate the first identity authentication information can also include other information, for example, the generated first identity authentication information AUTHa can satisfy: AUTHa=KDF(first PSK, first association request message), wherein the first association request message includes the first freshness parameter NONCEe; for another example, the generated first identity authentication information AUTHa can also satisfy: AUTHa=KDF(first PSK, NONCEa, first association request message), wherein NONCEa is the fourth freshness parameter.
[0558] Step S1105: The second node determines the second PSK according to the correspondence between the second PSK and the identity of the first node.
[0559] Specifically, the detailed description can refer to the detailed description of the method one in step S504.
[0560] Step S1106: If the first identity authentication information is not verified according to the second PSK and the first freshness parameter, the second node generates a fourth PSK according to the first freshness parameter and a fourth freshness parameter.
[0561] Specifically, the second PSK is determined according to the correspondence between the second PSK and the identity of the first node. If the first identity authentication information is not verified according to the second PSK and the first freshness parameter, it is possible that a new first PSK is generated in the first node, thereby leading to the authentication failure. Therefore, the second node generates a fourth PSK according to the first freshness parameter and a fourth freshness parameter, and verifies the identity of the second node by the fourth PSK and the first freshness parameter.
[0562] Step S1107: If the first identity authentication information is verified according to the fourth PSK and the first freshness parameter, the second node sends a first authentication response message to the first node.
[0563] Specifically, the first authentication response message includes second identity authentication information, which is generated according to the fourth PSK and the fourth freshness parameter. Optionally, in actual processing, the parameters of the second identity authentication information generated by the second node can also include other information, for example, the generated second identity authentication information AUTHe can satisfy: AUTHe=KDF (fourth PSK, first authentication request message), wherein the first authentication request message includes NONCEa; for another example, the generated second identity authentication information AUTHe can also satisfy: AUTHe=KDF (fourth PSK, NONCEe, first authentication request message), wherein NONCEe is the first freshness parameter.
[0564] Step S1108: If the second identity authentication information is verified according to the first PSK and the fourth freshness parameter, the first node sends a first association response message to the second node.
[0565] Specifically, the first association response message indicates that the first node is allowed to communicate with the second node. Correspondingly, the second node receives the first association response message from the first node.
[0566] Optionally, the embodiments of the present application can also include step S1109 or can also include step S1109-step S1110, which are specifically as follows:
[0567] Step S1109: The first node saves the correspondence between the first PSK and the identity identifier of the second node.
[0568] Step S1110: The second node saves the correspondence between the identity identifier of the fourth PSK and the first node.
[0569] exist Figure 11 In the illustrated embodiment, if the second node fails to verify the first identity authentication information when obtaining the second PSK based on the correspondence, it may be because the first identity authentication information was generated using a newly generated PSK in the first node. Therefore, the second node also generates a new PSK (i.e., a fourth PSK) based on the first freshness parameter and the fourth freshness parameter, and re-initiates authentication based on the new PSK, thereby improving the stability of the system.
[0570] See Figure 12 , Figure 12 This is another key acquisition method provided in the embodiments of this application. This method can be applied when the first node lacks a first PSK, but the second node possesses a second PSK. For example, the first node may have lost data due to formatting, or the mapping between the PSK and the node's identity identifier may have been deleted in the first node. The method includes at least the following steps:
[0571] Step S1201: The second node sends a first association request message to the first node.
[0572] Specifically, the first association request message includes a first freshness parameter. Correspondingly, the first node can receive the first association request message from the second node.
[0573] Step S1202: The first node obtains the fourth freshness parameter.
[0574] Specifically, the fourth freshness parameter can be a random number, a counter value, or a sequence number, etc. This fourth freshness parameter can be generated (or produced) by the first node; for example, the first node generates a random number using a random number generator and uses that random number as the fourth freshness parameter. Alternatively, it can be a counter value or sequence number obtained by the first node. For example, if the first node records a PDCP COUNT, it can obtain the recorded PDCP COUNT as the fourth freshness parameter. Step S1203: The first node generates the first PSK based on the first freshness parameter and the fourth freshness parameter.
[0575] For a detailed description, please refer to the detailed descriptions of cases two and three in step S502.
[0576] Step S1204: The first node sends a first authentication request message to the second node.
[0577] Specifically, the first authentication request message includes a fourth freshness parameter and first identity authentication information. This first identity authentication information is generated by the first node based on the first PSK and the first freshness parameter, and is used by the second node to verify the identity of the first node. Optionally, in actual processing, the parameters used by the first node to generate the first identity authentication information may also include other information. For example, the generated first identity authentication information AUTHa may satisfy: AUTHa = KDF(first PSK, first association request message), where the first association request message includes the first freshness parameter NONCEe; or, the generated first identity authentication information AUTHa may also satisfy: AUTHa = KDF(first PSK, NONCEa, first association request message), where NONCEa is the fourth freshness parameter.
[0578] Step S1205: The second node determines the second PSK based on the correspondence between the second PSK and the identity identifier of the first node.
[0579] For a detailed description, please refer to the detailed description of Method 1 in step S504.
[0580] Step S1206: If the verification of the first identity authentication information based on the second PSK and the first freshness parameter fails, the second node deletes the second PSK.
[0581] Specifically, the second node can delete the second PSK, or delete the correspondence between the second PSK and the identity identifier of the first node.
[0582] Step S1207: The second node sends a second association request message to the first node.
[0583] Specifically, the second association request message includes a fifth freshness parameter. This second association request message indicates that the second node has re-initiated the association request process.
[0584] exist Figure 12 In the illustrated embodiment, if the second node fails to verify the first identity authentication information when obtaining the second PSK based on the correspondence, it may be because the first identity authentication information was generated using a newly generated PSK in the first node. Therefore, the second node deletes the second PSK to facilitate re-initiating the access process, re-requesting access to the first node, and negotiating a new PSK.
[0585] See Figure 13 , Figure 13The method provided in the embodiment of the present application is another method for obtaining a key. The method can be applied to a case where a first PSK exists in the first node and no second PSK exists in the second node, for example, a case where data is lost due to formatting in the second node or a case where a correspondence between a PSK and an identity of a node is deleted in the second node. The method comprises at least the following steps:
[0586] Step S1301: The second node sends a first association request message to the first node.
[0587] Specifically, the first association request message comprises a first freshness parameter. Correspondingly, the first node can receive the first association request message from the second node.
[0588] Step S1302: The first node obtains a fourth freshness parameter.
[0589] Specifically, the fourth freshness parameter can be a random number, a counter value or a sequence number, etc. The fourth freshness parameter can be generated (or said to be generated) by the first node, for example, the first node generates a random number by using a random number generator and uses the random number as the fourth freshness parameter, or the fourth freshness parameter can be a counter value or a sequence number obtained by the first node, for example, the first node records a PDCP COUNT, and the first node can obtain the recorded PDCP COUNT as the fourth freshness parameter. Step S1303: The first node determines the first PSK according to the correspondence between the first PSK and the identity of the second node.
[0590] Specifically, the detailed description can refer to the detailed description of case one in step S502.
[0591] Step S1304: The first node sends a first authentication request message to the second node.
[0592] Specifically, the first authentication request message comprises the fourth freshness parameter and first identity authentication information. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, and is used for the second node to verify the identity of the first node. Optionally, in actual processing, the parameters used by the first node to generate the first identity authentication information can further comprise other information, for example, the generated first identity authentication information AUTHa can satisfy: AUTHa=KDF(first PSK, first association request message), wherein the first association request message comprises the first freshness parameter NONCEe; for another example, the generated first identity authentication information AUTHa can further satisfy: AUTHa=KDF(first PSK, NONCEa, first association request message), wherein NONCEa is the fourth freshness parameter.
[0593] Step S1305: The second node generates a second PSK according to the first freshness parameter and the fourth freshness parameter.
[0594] In particular, the detailed description can refer to the detailed description of the method two or the method three in step S504.
[0595] In step S1306, if the first identity authentication information is not verified according to the second PSK and the first freshness parameter, the second node sends a first authentication response message to the first node.
[0596] In particular, the second PSK is generated according to the first freshness parameter and the fourth freshness parameter. If the first identity authentication information is not verified according to the second PSK and the first freshness parameter, it indicates that the PSK of the first node is not the same as the PSK of the second node. Therefore, the second node can send a first authentication response message to the first node, wherein the first authentication response message includes second identity authentication information, which is generated according to the second PSK and the fourth freshness parameter. After receiving the second identity authentication information, if the authentication is not passed, the first node can re-determine the first PSK.
[0597] Optionally, the second node can add update indication information in the first authentication response message to remind the first node to update the PSK, so as to avoid the first node using the previous old PSK to verify the identity authentication information, thereby avoiding the first node verifying the identity authentication information fails, affecting the user experience. Further optionally, the update indication information can be a character or a string in the first authentication response message, for example, the first authentication response message includes an "update" field, and "1" is used in the field to indicate that the first node updates the PSK, and "0" is used in the field to indicate meaningless.
[0598] In step S1307, if the first identity authentication information is not verified according to the first PSK and the first freshness parameter, the first node generates a third PSK according to the first freshness parameter and the fourth freshness parameter.
[0599] Optionally, before generating the third PSK, the first node obtains second confirmation indication information, which indicates that the third PSK is allowed to be generated. In particular, the second confirmation indication information is obtained according to the user's input confirmation operation, and the confirmation operation can be a confirmation of the output prompt information. For example, the first node can output second prompt information to remind the user to generate the third PSK for the second node. After receiving the user's confirmation operation and obtaining the second confirmation indication information, the third PSK is generated by the method described in case two or case three. In this way, the user verifies the identity of the second node, thereby avoiding the first node being associated with an untrusted node, and ensuring the security of the first node communication.
[0600] In step S1308, the first node sends a second authentication request message to the second node.
[0601] Specifically, after the third PSK is generated in the first node, a second authentication request message is sent to the second node, and the second authentication request message includes third identity authentication information, which is generated according to the third PSK and the first freshness parameter. Optionally, in actual processing, the parameter for the second node to generate the third identity authentication information can also include other information, for example, the generated third identity authentication information AUTHt can satisfy: AUTHt = KDF (third PSK, first association request message), wherein the first association request message includes NONCEa; for another example, the generated third identity authentication information AUTHt can also satisfy: AUTHt = KDF (third PSK, NONCEa, first association request message), wherein NONCEa is the fourth freshness parameter.
[0602] Step S1309: If the third identity authentication information is verified to be passed according to the second PSK and the first freshness parameter, a second authentication response message is sent to the first node.
[0603] Specifically, the second authentication response message includes fourth identity authentication information, which is generated according to the second PSK and the fourth freshness parameter. Optionally, in actual processing, the parameter for the second node to generate the second identity authentication information can also include other information, for example, the generated fourth identity authentication information AUTHf can satisfy: AUTHf = KDF (second PSK, second authentication request message), wherein the first authentication request message includes NONCEa; for another example, the generated second identity authentication information AUTHf can also satisfy: AUTHf = KDF (first PSK, NONCEe, second authentication request message), wherein NONCEe is the first freshness parameter.
[0604] Step S1310: If the second identity authentication information is verified to be passed according to the third PSK and the fourth freshness parameter, the first node sends a first authentication response message to the second node.
[0605] Specifically, the first authentication response message indicates that the first node is allowed to communicate with the second node. Correspondingly, the second node receives the first authentication response message from the first node.
[0606] Optionally, the embodiments of the present application can also include step S1311 or can also include step S1311-step S1312, which are specifically as follows:
[0607] Step S1311: The first node saves the corresponding relationship between the third PSK and the identity identifier of the second node.
[0608] Step S1312: The second node stores the correspondence between the second PSK and the identity of the first node.
[0609] In Figure 13 In the embodiment shown in the figure, when the first node acquires the first PSK according to the correspondence, if the first node fails to verify the second identity authentication information, it is possible that the second identity authentication information is generated by using the newly generated PSK in the second node. Therefore, the first node also uses the newly generated PSK to reinitiate the authentication process, and negotiates a new PSK to improve the stability of the system.
[0610] The above describes the method of the embodiments of the present application in detail, and the following provides the apparatus of the embodiments of the present application.
[0611] Please refer to Figure 14 , Figure 14 is a structural schematic diagram of an apparatus 140 provided by the embodiments of the present application. The apparatus 140 can be a node, or a device such as a chip or an integrated circuit in an electronic device with data transceiving capability. The apparatus 140 can include a receiving unit 1401 and a processing unit 1402. The descriptions of the units are as follows.
[0612] The receiving unit 1401 is configured to receive a first association request message from a second node, the first association request message including a first freshness parameter.
[0613] The processing unit 1402 is configured to acquire a first pre-shared key PSK, wherein the first PSK corresponds to an identity of the second node; the first PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from the apparatus 140. Further, the first PSK is used to verify the identity of the second node.
[0614] It can be seen that the PSK is a secret value shared between the device 140 and the second node. The device 140 generates the first PSK by the second freshness parameter from the second node and the third freshness parameter from the device 140, and corresponds the first PSK to the identity of the second node, to verify the identity of the second node (for example, the second node generates identity authentication information according to the PSK, and the first node can verify the identity authentication information of the second node by the first PSK; for another example, the second node encrypts or integrity protects the message content by the PSK (or a key derived from the PSK), and the first node can obtain the message content from the second node by the first PSK). In this way, if an attacker wants to impersonate the identity of the second node to associate with the device, since the second freshness parameter and the third freshness parameter for generating the first PSK can be obtained before the first association request message, for example, can be obtained when the device 140 and the second node are associated for the first time, since the previously obtained data is usually difficult to be cracked, so that the attacker cannot forge the PSK, and thus cannot pass the identity verification of the device 140, thereby avoiding the device 140 connecting with an untrusted node, and improving the communication security of the device 140.
[0615] It should be noted that the division of the above plurality of units is only a logical division according to functions, and does not limit the specific structure of the device 140. In specific implementation, some of the function modules can be subdivided into more detailed function modules, and some of the function modules can be combined into one function module, but regardless of whether the function modules are subdivided or combined, the general process performed by the device 140 in the key acquisition process is the same. For example, the above plurality of units can also be transformed into a communication unit and a processing unit, and the communication unit is used to implement the function of the receiving unit 1401. Generally, each unit corresponds to a respective program code (or program instruction), and the respective program code of each unit causes the unit to perform the corresponding process when running on the processor, thereby implementing the corresponding function.
[0616] In a possible implementation, the device 140 further includes:
[0617] The sending unit 1403 is configured to send a first authentication request message to the second node, the first authentication request message including first identity authentication information and a fourth freshness parameter, wherein the first identity authentication information is generated according to the first PSK and the first freshness parameter.
[0618] It can be seen that the first PSK in the device 140 is usually the same as the second PSK in the second node because the PSK is a secret value shared between the device 140 and the second node. The device 140 generates the first identity authentication information according to the first PSK and the first freshness parameter, so that the second node can verify the identity of the device 140 according to the second PSK, and if the second PSK stored in the second node cannot be verified, the second node can be prevented from being associated with an untrusted node, thereby improving the security of communication of the second node.
[0619] In another possible implementation, the receiving unit 1401 is further configured to receive a first authentication response message from the second node, the first authentication response message including second identity authentication information.
[0620] The sending unit 1403 is further configured to send a first association response message to the second node if the device 140 verifies that the second identity authentication information passes according to the first PSK and the fourth freshness parameter (NONCEa).
[0621] It can be seen that before the device 140 communicates with the second node, the device 140 and the second node first determine the identities of both parties through the identity authentication information. After the identity authentication passes, communication is allowed, thereby avoiding access of an untrusted node and improving the security of communication of the node.
[0622] In another possible implementation, the processing unit 1402 is specifically configured to obtain the first PSK according to a correspondence between the first PSK and an identity of the second node.
[0623] It can be seen that the correspondence between the first PSK and the identity of the second node in the device 140 indicates that the second node has been associated with the device 140 or that the device 140 is preconfigured with the first PSK corresponding to the identity of the second node, so that the device 140 can obtain the first PSK according to the correspondence.
[0624] In another possible implementation, the processing unit 1402 is specifically configured to:
[0625] The first PSK is obtained according to the correspondence between the first PSK and the identity of the second node through the first correspondence set.
[0626] It can be seen that the device 140 can store the correspondence between the first PSK and the identity of the second node in the form of a correspondence set.
[0627] In a further possible implementation, the processing unit 1402 is specifically configured to generate the first PSK according to the first freshness parameter and a fourth freshness parameter; the first freshness parameter is the second freshness parameter described above, and the fourth freshness parameter is the third freshness parameter described above.
[0628] It can be seen that the first PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter from the device 140 described above. Generally, when the device 140 described above associates with the second node for the first time or when the device 140 described above deletes the corresponding relationship, there is no PSK corresponding to the identity of the second node in the device 140 described above, and therefore the device 140 described above can generate a new first PSK according to the first freshness parameter and the fourth freshness parameter, for verifying the identity of the second node.
[0629] In a further possible implementation, the processing unit 1402 is further configured to obtain first confirmation indication information, the first confirmation indication information indicating that the second node is allowed to associate with the device 140 described above.
[0630] It can be seen that when the new first PSK is generated, the confirmation of the user is required. In this way, when an attacker connects the device 140 described above using his own identity, since there is no PSK corresponding to the identity of the attacker in the device 140 described above, the identity of the new node can be verified by the user, and the first PSK is generated only after the first confirmation indication information is obtained, thereby avoiding the device 140 described above from associating with an untrusted node and ensuring the security of communication of the device 140 described above.
[0631] In a further possible implementation, the processing unit 1402 is specifically configured to generate the first PSK according to the first freshness parameter, the fourth freshness parameter, and a first password, the first password being an access password of the device.
[0632] It can be seen that when the first password is the access password of the device 140 described above, the second node connects the device 140 described above by inputting the first password, and therefore the first password is used to participate in the generation of the first PSK, so that an attacker who does not obtain the first password cannot crack the first PSK, thereby avoiding the device 140 described above from associating with the attacker who does not obtain the first password.
[0633] In a further possible implementation, the first association request message further includes a first key agreement algorithm parameter; and the processing unit 1402 is specifically configured to generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first key agreement algorithm parameter.
[0634] As can be seen, the second node carries the first key negotiation algorithm parameters in the first association request message. These parameters are determined based on the first key negotiation algorithm. The aforementioned device 140 can determine the first PSK based on these parameters, the first freshness parameter, the fourth freshness parameter, and the first password. Therefore, even if an attacker subsequently impersonates the second node and obtains the first and fourth freshness parameters used to generate the first PSK, they cannot crack the first PSK and thus cannot communicate with the aforementioned device 140, improving the security of communication with the aforementioned device 140.
[0635] In another possible implementation, the first association request message further includes first key negotiation algorithm parameters; the processing unit 1402 is specifically used for:
[0636] A first PSK is generated based on a first freshness parameter, a fourth freshness parameter, a first password, and an intermediate key. The first password is the access password. The intermediate key is generated based on the first freshness parameter, the fourth freshness parameter, and the parameters of the aforementioned first key negotiation algorithm.
[0637] In another possible implementation, the first association request message further includes first key negotiation algorithm parameters, which are determined based on a first key negotiation algorithm; the processing unit 1402 is specifically used for:
[0638] Determine the parameters of the third key negotiation algorithm;
[0639] Based on the first key negotiation algorithm described above, the first intermediate key is determined according to the parameters of the first key negotiation algorithm and the parameters of the third key negotiation algorithm.
[0640] The first PSK is generated based on the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0641] It can be seen that after receiving the first key negotiation algorithm parameters from the second node, the device 140 determines the third key negotiation algorithm parameters (or the private key of the device 140). Based on the first key negotiation algorithm, the device 140 determines the first intermediate key according to the first key negotiation algorithm parameters and the second key negotiation algorithm parameters, and then generates the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the first intermediate key.
[0642] In another possible implementation, the first association request message further includes first key negotiation algorithm parameters, which are determined based on a first key negotiation algorithm; the processing unit 1402 is specifically used for:
[0643] obtaining third key agreement algorithm parameters;
[0644] determining a first intermediate key based on the first key agreement algorithm parameters and the third key agreement algorithm parameters according to the first key agreement algorithm;
[0645] determining a second intermediate key according to the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0646] generating the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0647] In yet another possible implementation, the processing unit 1402 is further configured to save a correspondence between the identity of the second node and the first PSK.
[0648] As can be seen, after the first PSK is generated, the apparatus 140 saves the correspondence between the identity of the second node and the first PSK, and when the first node receives an association request from the second node again later, the first PSK can be obtained according to the correspondence without the need to generate the first PSK again.
[0649] In yet another possible implementation, the processing unit 1402 is further configured to delete the correspondence between the identity of the second node and the first PSK if the first password is updated.
[0650] In yet another possible implementation, the first authentication request message further includes update indication information, which is used to indicate the update of the PSK.
[0651] As can be seen, after the first PSK is generated according to the first freshness parameter and the fourth freshness parameter, the apparatus 140 can remind the second node to update the PSK, so as to avoid the use of the old PSK by the second node to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0652] In yet another possible implementation, the processing unit 1402 is further configured to generate a third PSK according to the first freshness parameter and the fourth freshness parameter if the second identity authentication information is verified to be failed by the apparatus 140 according to the first PSK and the fourth freshness parameter.
[0653] The sending unit 1403 is further configured to send a second authentication request message to the second node, where the second authentication request message includes third identity authentication information, and the third identity authentication information is generated according to the third PSK and the first freshness parameter.
[0654] It can be seen that in the case that the device 140 acquires the first PSK according to the correspondence relationship, if the device 140 verifies that the second identity authentication information fails, it can be due to that the second identity authentication information is generated by using the newly generated PSK in the second node. Therefore, the device 140 generates a new PSK (i.e., a third PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates authentication according to the new PSK, so that the stability of the system can be improved.
[0655] In yet another possible implementation, the processing unit 1402 is further configured to acquire second confirmation indication information if the second identity authentication information fails to be verified according to the first PSK and the fourth freshness parameter, the second confirmation indication information indicating that the third PSK is allowed to be generated.
[0656] The processing unit 1402 is further configured to generate the third PSK according to the first freshness parameter and the fourth freshness parameter.
[0657] In yet another possible implementation, the receiving unit 1401 is further configured to receive a second authentication response message from the second node, the second authentication response message including fourth identity authentication information.
[0658] The sending unit 1403 is further configured to send a second association response message to the second node if the fourth identity authentication information passes the verification according to the third PSK and the fourth freshness parameter.
[0659] It can be seen that after the device 140 reinitiates authentication according to the new PSK, the fourth identity authentication information sent by the second node is received again, and if the fourth identity authentication information passes the verification, it indicates that the identity of the second node is trusted, so that the communication with the second node can be allowed.
[0660] It should be noted that the implementation of each unit can also correspond to the description of any one of the embodiments shown in Figure 5 、 Figure 8 、 Figure 9 、 Figure 10 、 Figure 11 、 Figure 12 or Figure 13 . The device 140 can be the first node in any one of the embodiments shown in Figure 5 、 Figure 8 、 Figure 9 、 Figure 10 、 Figure 11 、 Figure 12 or Figure 13 .
[0661] For details, please refer to Figure 15 , Figure 15Figure 1 is a structural schematic diagram of an apparatus 150 provided by an embodiment of the present application. The apparatus 150 can be an electronic device with data transceiving capability, or a component in an electronic device with data transceiving capability, such as a chip or an integrated circuit, etc. The apparatus 150 can include a sending unit 1501, a receiving unit 1502, and a processing unit 1503, which are described as follows.
[0662] The sending unit 1501 is configured to send a first association request message to a first node, wherein the first association request message includes a first freshness parameter.
[0663] The receiving unit 1502 is configured to receive a first authentication request message from the first node, wherein the first authentication request message includes a fourth freshness parameter.
[0664] The processing unit 1503 is configured to obtain a second PSK, wherein the second PSK corresponds to an identity of the first node, and the second PSK is a PSK generated according to a second freshness parameter from the apparatus 150 and a third freshness parameter from the first node, and the second PSK is used to verify the identity of the first node.
[0665] As can be seen, the PSK is a secret value shared between the apparatus 150 and the first node. The apparatus 150 generates the second PSK by using the second freshness parameter and the third freshness parameter from the apparatus 150, and the second PSK corresponds to the identity of the first node and is used to verify the identity of the first node (for example, the first node generates identity authentication information according to the PSK, and the second node can verify the identity authentication information of the first node by using the second PSK; for another example, the first node encrypts or integrity protects the message content by using the PSK (or a key derived from the PSK), and the second node can obtain the message content from the second node by using the first PSK). In this way, if an attacker wants to impersonate the identity of the first node to associate with the apparatus 150, since the second freshness parameter and the third freshness parameter used to generate the second PSK can be obtained before the first association request message, for example, can be obtained when the apparatus 150 and the first node are associated for the first time, since the previously obtained data is usually difficult to be cracked, the attacker cannot fake the PSK, and thus cannot pass the identity verification of the apparatus 150, thereby avoiding the apparatus 150 from being associated with an untrusted node, and improving the communication security of the apparatus 150.
[0666] It should be noted that the above division of the plurality of units is only a logical division according to functions, and does not limit the specific structure of the apparatus 150. In a specific implementation, some of the function modules can be subdivided into more detailed function modules, and some of the function modules can be combined into one function module, but regardless of whether the function modules are subdivided or combined, the general flow performed by the apparatus 150 in the process of key acquisition is the same. For example, the above plurality of units can also be transformed into a communication unit and a processing unit, and the communication unit is used to implement the functions of the sending unit 1501 and the receiving unit 1502. Generally, each unit corresponds to a respective program code (or program instruction), and the respective program code of each unit, when running on the processor, causes the unit to perform the corresponding flow to implement the corresponding function.
[0667] In a possible implementation, the sending unit 1501 is further configured to, if the first identity authentication information is verified to be passed according to the second PSK and the first freshness parameter, send a first authentication response message to the first node, wherein the first authentication response message includes second identity authentication information generated according to the second PSK and a fourth freshness parameter.
[0668] The receiving unit 1502 is further configured to receive a first association response message from the first node.
[0669] It can be seen that, since the PSK is a secret value shared between the apparatus 150 and the first node, the second PSK in the apparatus 150 is generally the same as the first PSK in the first node. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, and therefore the apparatus 150 can verify the identity authentication information of the first node according to the second PSK and the first freshness parameter. If the second PSK stored in the apparatus 150 cannot be verified, it indicates that the identity of the first node is not trusted, thereby avoiding the apparatus 150 from being associated with an untrusted node, and improving the security of communication of the apparatus 150. Correspondingly, the apparatus 150 also generates second identity authentication information according to the second PSK and the fourth freshness parameter, for the first node to verify the identity of the apparatus 150, and only after the identities of both parties are verified, communication with the node at the opposite end is allowed, thereby improving the security of node communication.
[0670] In another possible implementation, the processing unit 1503 is specifically configured to obtain the second PSK according to a correspondence between the first PSK and an identity of the first node.
[0671] It can be seen that the correspondence between the second PSK and the identity of the first node exists in the device 150, which indicates that the device 150 has previously associated the first node or the second node preconfigured with the identity of the first node corresponding to the second PSK, so that the device 150 can obtain the second PSK according to the correspondence.
[0672] In another possible implementation, the processing unit 1503 is specifically configured to:
[0673] The second PSK is obtained according to the correspondence between the second PSK and the identity of the first node through the second set of correspondences.
[0674] It can be seen that the device 150 can store the correspondence between the second PSK and the identity of the first node in the form of the set of correspondences.
[0675] In another possible implementation, the processing unit is specifically configured to generate the second PSK according to the first freshness parameter and the fourth freshness parameter, where the first freshness parameter is the second freshness parameter, and the fourth freshness parameter is the third freshness parameter.
[0676] It can be seen that the second PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter in the first authentication request message. Generally, when the device 150 associates with the first node for the first time or the device 150 deletes the correspondence, the device 150 does not have the second PSK corresponding to the identity of the first node, so that the device 150 can generate a new second PSK according to the first freshness parameter and the fourth freshness parameter to verify the identity of the first node.
[0677] In another possible implementation, the processing unit 1503 is further configured to obtain third confirmation indication information, where the third confirmation indication information indicates that the second PSK is allowed to be generated.
[0678] It can be seen that the user's confirmation is needed when the new second PSK is generated. In this way, when an attacker connects the device 150 using his own identity, the device 150 does not have the PSK corresponding to the identity of the attacker, so that the user can verify the identity of the new node, and the second PSK is generated only after the third confirmation indication information is obtained, thereby avoiding the device 150 from associating with an untrusted node and ensuring the security of communication of the device 150.
[0679] In another possible implementation, the processing unit 1503 is specifically configured to generate the second PSK according to the first freshness parameter, the fourth freshness parameter, and a first password, where the first password is an access password of the first node.
[0680] It can be seen that in the case that the first password is the access password of the first node, the apparatus 150 connects the first node by the input first password, and thus participates in the generation of the second PSK by the first password, so that an attacker who does not obtain the first password cannot crack the second PSK, thereby avoiding the association of the apparatus 150 with the attacker who does not obtain the first password.
[0681] In yet another possible implementation, the processing unit 1503 is specifically configured to generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the second key agreement algorithm parameter.
[0682] It can be seen that the first node carries the first key agreement algorithm parameter in the first authentication request message, which is determined based on the first key agreement algorithm. The apparatus 150 can determine the second PSK based on the second key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter, and the first password according to the first key agreement algorithm. In this way, even if an attacker impersonates the identity information of the first node and obtains the first freshness parameter and the fourth freshness parameter used when generating the second PSK, the attacker cannot crack the PSK, and thus cannot communicate with the apparatus 150, thereby improving the security of the communication of the apparatus.
[0683] In yet another possible implementation, the first authentication request message further includes the second key agreement algorithm parameter; and the processing unit 1503 is specifically configured to:
[0684] generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the intermediate key, the first password being an access password; and the intermediate key being generated according to the first freshness parameter, the fourth freshness parameter, and the second key agreement algorithm parameter. In yet another possible implementation, the first association request message further includes a first key agreement algorithm parameter, which is determined based on the first key agreement algorithm according to a fourth key agreement algorithm parameter; the first authentication request message further includes a second key agreement algorithm parameter, which is determined by the first node based on the first key agreement algorithm according to a third key agreement algorithm parameter; and the processing unit 1503 is specifically configured to:
[0685] determine the first intermediate key according to the second key agreement algorithm parameter and the fourth key agreement algorithm parameter;
[0686] generate the second PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0687] It can be seen that the first key agreement algorithm parameter in the first association request message is generated based on the private key (i.e., the fourth key agreement algorithm parameter) of the device 150, and after the device 150 receives the second key agreement algorithm parameter from the first node, the second node determines the first intermediate key based on the second key agreement algorithm parameter and the private key (i.e., the fourth key agreement algorithm parameter) of the device 150, and the first intermediate key is the secret value obtained through key agreement between the first node and the device.
[0688] In yet another possible implementation, the first authentication request message further includes a second key agreement algorithm parameter, and the second key agreement algorithm parameter is determined based on the first key agreement algorithm; the processing unit 1503 is specifically configured to:
[0689] obtain a fourth key agreement algorithm parameter;
[0690] determine a first intermediate key based on the second key agreement algorithm parameter and the fourth key agreement algorithm parameter based on the first key agreement algorithm;
[0691] determine a second intermediate key based on the first freshness parameter, the fourth freshness parameter, and the first intermediate key;
[0692] generate a second PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the second intermediate key.
[0693] In yet another possible implementation, the processing unit 1503 is further configured to save the correspondence between the identity of the first node and the second PSK.
[0694] It can be seen that after the second PSK is generated, the device 150 saves the correspondence between the identity of the first node and the second PSK, and when the device 150 is associated with the first node again in the future, the second PSK can be obtained based on the correspondence without generating the PSK again.
[0695] In yet another possible implementation, the processing unit 1503 is further configured to delete the correspondence between the identity of the first node and the second PSK if the first password is updated.
[0696] In yet another possible implementation, the first authentication request message further includes update indication information, and the update indication information is used to indicate the update of the PSK.
[0697] It can be seen that after the second PSK is generated according to the first freshness parameter and the fourth freshness parameter, the first node can remind the device 150 to update the second PSK by updating the indication information, so as to avoid that the device 150 uses the previous old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0698] In yet another possible implementation, the processing unit is further configured to generate a fourth PSK according to the first freshness parameter and a fourth freshness parameter if the first identity authentication information fails to pass the verification according to the second PSK and the first freshness parameter.
[0699] The sending unit 1501 is further configured to send a third authentication response message to the first node, where the third authentication response message comprises third identity authentication information generated according to the fourth PSK and the fourth freshness parameter.
[0700] It can be seen that when the device 150 acquires the second PSK according to the correspondence relationship, if the device 150 fails to pass the verification of the first identity authentication information, it may be due to that the first identity authentication information is generated by using the newly generated PSK in the first node. Therefore, the device 150 also generates a new PSK (i.e., the fourth PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates authentication according to the new PSK, thereby improving the stability of the system.
[0701] In yet another possible implementation, the receiving unit 1502 is further configured to receive a third association response message from the first node.
[0702] In yet another possible implementation, the processing unit is further configured to acquire fourth confirmation indication information if the first identity authentication information fails to pass the verification according to the second PSK, where the fourth confirmation indication information indicates that the fourth PSK is allowed to be generated.
[0703] The processing unit is further configured to generate a fourth PSK according to the first freshness parameter and a fourth freshness parameter.
[0704] In yet another possible implementation, the processing unit 1503 is further configured to delete the second PSK if the second identity authentication information fails to pass the verification according to the second PSK and the first freshness parameter.
[0705] The sending unit 1501 is further configured to send a second association request message to the first node, where the second association request message comprises a fifth freshness parameter.
[0706] It should be noted that the implementation of each unit can also be referred to Figure 5 , Figure 8 , Figure 9 , Figure 10 、 Figure 11 、 Figure 12 or Figure 13 the corresponding description of any one of the embodiments shown in Figure 5 、 Figure 8 、 Figure 9 、 Figure 10 、 Figure 11 、 Figure 12 or Figure 13 the second node in any one of the embodiments shown in
[0707] See Figure 16 , Figure 16 is a structural schematic diagram of an apparatus 160 provided by an embodiment of the present application. The apparatus 160 can be an electronic device with data transceiving capability, or a device such as a chip or integrated circuit in an electronic device with data transceiving capability. The apparatus 160 can include at least one memory 1601, at least one processor 1602, and a communication interface 1603. Further optionally, it can also include a bus 1604, wherein the memory 1601, the processor 1602, and the communication interface 1603 are connected through the bus 1604.
[0708] The memory 1601 is configured to provide a storage space, in which data such as an operating system and a computer program can be stored. The memory 1601 includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), or a compact disc read-only memory (CD-ROM).
[0709] The processor 1602 is a module for arithmetic operation and / or logical operation, and can be one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), etc.
[0710] The communication interface 1603 is configured to receive data transmitted from an external device and / or transmit data to the external device, and can be a wired link interface including an Ethernet cable, or a wireless link (Wi-Fi, Bluetooth, etc.) interface. Optionally, the communication interface 1603 can further include a transmitter (e.g., a radio frequency transmitter, an antenna, etc.) coupled to the interface, or a receiver, etc.
[0711] The processor 1602 in the apparatus 160 is configured to read a computer program stored in the memory 1601, and execute the key acquisition method described in any one of the embodiments shown in Figure 5 、 Figure 8 、 Figure 9 、 Figure 10 、 Figure 11 、 Figure 12 or Figure 13 .
[0712] For example, the processor 1602 in the apparatus 160 is configured to read a computer program stored in the memory 1601, and execute the following operations:
[0713] receive, through the communication interface 1603, a first association request message from a second node, the first association request message including a first freshness parameter;
[0714] obtain a first pre-shared key PSK; wherein the first PSK corresponds to an identity of the second node; the first PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from the apparatus 160. Further, the first PSK is used to verify the identity of the second node.
[0715] It can be seen that the PSK is a secret value shared between the device 160 and the second node. The device 160 generates the first PSK by using the second freshness parameter from the second node and the third freshness parameter from the device 160, and uses the first PSK corresponding to the identity of the second node to verify the identity of the second node (for example, the second node generates identity authentication information according to the PSK, and the first node can verify the identity authentication information of the second node by using the first PSK; for another example, the second node encrypts or integrity protects the message content by using the PSK (or a key derived from the PSK), and the first node can obtain the message content from the second node by using the first PSK). In this way, if an attacker wants to impersonate the identity of the second node to associate with the device 160, since the second freshness parameter and the third freshness parameter used to generate the first PSK can be obtained before the first association request message, for example, can be obtained when the device 160 and the second node are associated for the first time, since the previously obtained data is usually difficult to crack, the attacker cannot fake the PSK, and thus cannot pass the identity verification of the device 160, thereby avoiding the device 160 connecting with an untrusted node, and improving the communication security of the device 160.
[0716] In a possible implementation, the processor 1602 is further configured to:
[0717] send, to the second node, a first authentication request message, the first authentication request message including first identity authentication information and a fourth freshness parameter, wherein the first identity authentication information is generated according to the first PSK and the first freshness parameter.
[0718] It can be seen that since the PSK is a secret value shared between the device 160 and the second node, the first PSK in the device 160 usually has the same value as the second PSK in the second node. The device 160 generates the first identity authentication information according to the first PSK and the first freshness parameter, so that the second node can verify the identity of the device 160 according to the second PSK, and if the second PSK stored in the second node cannot pass the verification, the second node can be prevented from associating with an untrusted node, and the security of the communication of the second node is improved.
[0719] In another possible implementation, the processor 1602 is further configured to:
[0720] receive, by the communication interface 1603, a first authentication response message from the second node, the first authentication response message including second identity authentication information;
[0721] If the second identity authentication information is verified to be passed according to the first PSK and the fourth freshness parameter, a first association response message is sent to the second node through the communication interface 1603.
[0722] It can be seen that before the device 160 communicates with the second node, the device 160 and the second node first determine the identities of both sides through identity authentication information. After the identity authentication is passed, communication is allowed, thereby avoiding access of untrusted nodes and improving the security of node communication.
[0723] In another possible implementation, the processor 1602 is specifically configured to:
[0724] According to the correspondence between the first PSK and the identity identifier of the second node, the first PSK is obtained.
[0725] It can be seen that the correspondence between the first PSK and the identity identifier of the second node exists in the device 160, which can indicate that the second node has been associated with the device 160 before or the first PSK corresponding to the identity identifier of the second node is preconfigured in the device 160, so that the device 160 can obtain the first PSK according to the correspondence.
[0726] In another possible implementation, the memory 1601 has a first correspondence set; and the processor 1602 is specifically configured to:
[0727] According to the correspondence between the first PSK and the identity identifier of the second node, the first PSK is obtained through the first correspondence set.
[0728] It can be seen that the device 160 can store the correspondence between the first PSK and the identity identifier of the second node in the form of a correspondence set.
[0729] In another possible implementation, the processor 1602 is specifically configured to:
[0730] The first PSK is generated according to the first freshness parameter and the fourth freshness parameter, the first freshness parameter being the second freshness parameter, and the fourth freshness parameter being the third freshness parameter.
[0731] It can be seen that the first PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter from the device 160. Generally, when the device 160 and the second node are associated for the first time or the device 160 deletes the correspondence, there is no PSK corresponding to the identity identifier of the second node in the device 160, so that the device 160 can generate a new first PSK according to the first freshness parameter and the fourth freshness parameter, for verifying the identity of the second node.
[0732] In a further possible implementation, the apparatus further includes an input module 1605; and the processor 1602 is further configured to:
[0733] The input module 1605 is configured to acquire first confirmation indication information, the first confirmation indication information indicating that the second node is allowed to associate with the apparatus 160.
[0734] It can be seen that when the first PSK is generated, the confirmation of the user is required. In this way, when an attacker connects the apparatus 160 using his own identity, since there is no PSK corresponding to the identity of the attacker in the apparatus 160, the identity of the new node can be verified by the user, and the first PSK is generated only after the first confirmation indication information is acquired, so that the apparatus 160 is prevented from associating with an untrusted node, and the security of communication of the apparatus 160 is ensured.
[0735] In a further possible implementation, the processor 1602 is specifically configured to:
[0736] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, and the first password, the first password being an access password of the apparatus 160.
[0737] It can be seen that when the first password is the access password of the apparatus 160, the second node connects the apparatus 160 by inputting the first password, so that the attacker who does not acquire the first password cannot crack the first PSK by participating in the generation of the first PSK through the first password, and the apparatus 160 is prevented from associating with the attacker who does not acquire the first password.
[0738] In a further possible implementation, the first association request message further includes a first key agreement algorithm parameter; and the processor 1602 is specifically configured to:
[0739] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first key agreement algorithm parameter.
[0740] It can be seen that the second node carries the first key agreement algorithm parameter in the first association request message, and the first key agreement algorithm parameter is determined based on the first key agreement algorithm. The apparatus 160 can determine the first PSK based on the first key agreement algorithm according to the first key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter, and the first password. In this way, even if an attacker impersonates the identity information of the second node later, and obtains the first freshness parameter and the fourth freshness parameter used when the first PSK is generated, the attacker cannot crack the first PSK, and thus cannot communicate with the apparatus 160, thereby improving the security of communication of the apparatus 160.
[0741] In yet another possible implementation, the first association request message further includes a first key agreement algorithm parameter; and the processor 1602 is specifically configured to:
[0742] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key, the first password being an access password; and the first intermediate key being generated according to the first freshness parameter, the fourth freshness parameter, and the first key agreement algorithm parameter.
[0743] In yet another possible implementation, the first association request message further includes a first key agreement algorithm parameter, and the first key agreement algorithm parameter is determined based on a first key agreement algorithm; and the processor 1602 is specifically configured to:
[0744] determine a third key agreement algorithm parameter;
[0745] determine a first intermediate key according to the first key agreement algorithm and the third key agreement algorithm based on the first key agreement algorithm;
[0746] generate the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0747] It can be seen that the apparatus 160 determines the third key agreement algorithm parameter (or the private key of the apparatus 160) after receiving the first key agreement algorithm parameter from the second node. The apparatus 160 determines the first intermediate key according to the first key agreement algorithm parameter and the second key agreement algorithm parameter based on the first key agreement algorithm, and then generates the first PSK according to the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0748] In yet another possible implementation, the first association request message further includes a first key agreement algorithm parameter, and the first key agreement algorithm parameter is determined based on a first key agreement algorithm; and the processor 1602 is specifically configured to:
[0749] obtaining a third key agreement algorithm parameter;
[0750] determining a first intermediate key based on the first key agreement algorithm parameter and the third key agreement algorithm parameter according to the first key agreement algorithm;
[0751] determining a second intermediate key according to the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0752] generating a first PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0753] In yet another possible implementation, the processor 1602 is further configured to:
[0754] saving a correspondence between the identity of the second node and the first PSK.
[0755] It can be seen that after the first PSK is generated, the apparatus 160 saves the correspondence between the identity of the second node and the first PSK, and when the first node receives an association request from the second node again later, the first PSK can be obtained according to the correspondence without generating the first PSK again.
[0756] In yet another possible implementation, the processor 1602 is further configured to:
[0757] if the first password is updated, deleting the correspondence between the identity of the second node and the first PSK.
[0758] In yet another possible implementation, the first authentication request message further includes update indication information, and the update indication information is used to indicate the update of the PSK.
[0759] It can be seen that after the first PSK is generated according to the first freshness parameter and the fourth freshness parameter, the apparatus 160 can remind the second node to update the PSK, so as to avoid that the second node uses the old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0760] In yet another possible implementation, the processor 1602 is further configured to:
[0761] if the second identity authentication information is not verified according to the first PSK and the fourth freshness parameter, generating a third PSK according to the first freshness parameter and the fourth freshness parameter;
[0762] sending, through the communication interface 1603, a second authentication request message to the second node, the second authentication request message including third identity authentication information, wherein the third identity authentication information is generated according to the third PSK and the first freshness parameter.
[0763] It can be seen that in the case that the device 160 acquires the first PSK according to the correspondence relationship, if the device 160 verifies that the second identity authentication information fails, it can be due to that the second identity authentication information is generated by using the newly generated PSK in the second node. Therefore, the device 160 generates a new PSK (i.e., a third PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates authentication according to the new PSK, so that the stability of the system can be improved.
[0764] In yet another possible implementation, the processor 1602 is specifically configured to:
[0765] If the second identity authentication information fails to be verified according to the first PSK and the fourth freshness parameter, the second confirmation indication information is acquired through the communication interface 1603, the second confirmation indication information representing that the third PSK is allowed to be generated;
[0766] The third PSK is generated according to the first freshness parameter and the fourth freshness parameter.
[0767] In yet another possible implementation, the processor 1602 is further configured to:
[0768] The second authentication response message from the second node is received through the communication interface 1603, the second authentication response message including fourth identity authentication information;
[0769] If the fourth identity authentication information passes to be verified according to the third PSK and the fourth freshness parameter, a second association response message is sent to the second node through the communication interface 1603.
[0770] It can be seen that after the device 160 reinitiates authentication according to the new PSK, the fourth identity authentication information sent by the second node is received again, and if the fourth identity authentication information passes to be verified, it indicates that the identity of the second node is trusted, so that the second node can be allowed to communicate.
[0771] It should be noted that the implementation of each of the above modules can also correspond to the description of any one of the embodiments shown in Figure 5 、 Figure 8 、 Figure 9 、 Figure 10 、 Figure 11 、 Figure 12 or Figure 13 . The device 160 is a first node in any one of the embodiments shown in Figure 5 、 Figure 8 、 Figure 9 、 Figure 10 、 Figure 11 、 Figure 12 or Figure 13 .
[0772] Please refer to Figure 17 , Figure 17 is a structural schematic diagram of an apparatus 170 provided by an embodiment of the present application. The apparatus 170 can be an electronic device with data transceiving capability, or a component in an electronic device with data transceiving capability, such as a chip or an integrated circuit, etc. The apparatus 170 can include at least one memory 1701, at least one processor 1702, and a communication interface 1703. Further optionally, a bus 1704 can also be included, wherein the memory 1701, the processor 1702, and the communication interface 1703 are connected through the bus 1704.
[0773] The memory 1701 is configured to provide a storage space, in which data such as an operating system and a computer program can be stored. The memory 1701 includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), or a compact disc read-only memory (CD-ROM).
[0774] The processor 1702 is a module configured to perform arithmetic operations and / or logical operations, and can be one or a combination of a CPU, a GPU, an MPU, an ASIC, an FPGA, a CPLD, etc.
[0775] The communication interface 1703 is configured to receive data sent from an external device and / or send data to an external device, and can be a wired link interface such as an Ethernet cable, or a wireless link (Wi-Fi, Bluetooth, etc.) interface. Optionally, the communication interface 1703 can also include a transmitter (such as a radio frequency transmitter, etc.) coupled to the interface, or a receiver, etc.
[0776] The processor 1702 in the apparatus 170 is configured to read a computer program stored in the memory 1701, and execute the key acquisition method described in any one of the embodiments shown in Figure 5 、 Figure 8 、 Figure 9 、 Figure 10 、 Figure 11 、 Figure 12 or Figure 13 .
[0777] For example, the processor 1702 in the apparatus 170 is configured to read a computer program stored in the memory 1701, and execute the following operations:
[0778] send, through the communication interface 1703, a first association request message to the first node, the first association request message comprising a first freshness parameter;
[0779] receive, through the communication interface 1703, a first authentication request message from the first node, the first authentication request message comprising a fourth freshness parameter;
[0780] obtain a second PSK; wherein the second PSK corresponds to an identity of the first node; the second PSK is a PSK generated according to the second freshness parameter from the apparatus 170 and the third freshness parameter from the first node, and the second PSK is used to verify the identity of the first node.
[0781] It can be seen that the PSK is a secret value shared between the apparatus 170 and the first node. The apparatus 170 generates the second PSK through the second freshness parameter and the third freshness parameter from the apparatus 170, and the second PSK corresponds to the identity of the first node, and is used to verify the identity of the first node (for example, the first node generates identity authentication information according to the PSK, and the second node can verify the identity authentication information of the first node through the second PSK; for another example, the first node encrypts or integrity protects the message content through the PSK (or a key derived from the PSK), and the second node can obtain the message content from the second node through the first PSK). In this way, if an attacker wants to impersonate the identity of the first node to associate with the apparatus 170, since the second freshness parameter and the third freshness parameter for generating the second PSK can be obtained before the first association request message, for example, can be obtained when the apparatus 170 and the first node are associated for the first time, since the previously obtained data is usually difficult to crack, so that the attacker cannot fake the PSK, and thus cannot pass the identity verification of the apparatus 170, thereby avoiding the apparatus 170 from being associated with an untrusted node, and improving the communication security of the apparatus 170.
[0782] In a possible implementation, the processor 1702 is further configured to:
[0783] if the first identity authentication information is verified to be passed according to the second PSK and the first freshness parameter, send, through the communication interface 1703, a first authentication response message to the first node, the first authentication response message comprising second identity authentication information, the second identity authentication information being generated according to the second PSK and the fourth freshness parameter;
[0784] receive, through the communication interface 1703, a first association response message from the first node.
[0785] It can be seen that the second PSK in the device 170 is usually the same as the first PSK in the first node because the PSK is a secret value shared between the device 170 and the first node. The first identity authentication information is generated by the first node according to the first PSK and the first freshness parameter, so the device 170 can verify the identity authentication information of the first node according to the second PSK and the first freshness parameter. If the second PSK stored in the device 170 cannot be verified, it means that the identity of the first node is not trusted, thereby avoiding the device 170 from being associated with an untrusted node, and improving the security of communication of the device 170. Correspondingly, the device 170 also generates the second identity authentication information according to the second PSK and the fourth freshness parameter, which is used by the first node to verify the identity of the device 170. After the identity authentication of both parties is passed, the device 170 is allowed to communicate with the node at the opposite end, thereby improving the security of node communication.
[0786] In yet another possible implementation, the processor 1702 is specifically configured to:
[0787] According to the correspondence between the second PSK and the identity of the first node, the second PSK is obtained.
[0788] It can be seen that the correspondence between the second PSK and the identity of the first node in the device 170 can indicate that the device 170 has been associated with the first node or the second node preconfigured with the second PSK corresponding to the identity of the first node, so the device 170 can obtain the second PSK according to the correspondence.
[0789] In yet another possible implementation, the memory stores a second correspondence set; and the processor 1702 is specifically configured to:
[0790] According to the correspondence between the second PSK and the identity of the first node, the second PSK is obtained through the second correspondence set.
[0791] It can be seen that the device 170 can store the correspondence between the second PSK and the identity of the first node in the form of a correspondence set.
[0792] In yet another possible implementation, the processor 1702 is specifically configured to:
[0793] The second PSK is generated according to the first freshness parameter and the fourth freshness parameter, the first freshness parameter being the second freshness parameter, and the fourth freshness parameter being the third freshness parameter.
[0794] It can be seen that the second PSK is generated according to the first freshness parameter in the first association request message and the fourth freshness parameter in the first authentication request message. Generally, when the device 170 associates with the first node for the first time or when the device 170 deletes the corresponding relationship, the second PSK corresponding to the identity of the first node does not exist in the device 170, and therefore the device 170 can generate a new second PSK according to the first freshness parameter and the fourth freshness parameter, for verifying the identity of the first node.
[0795] In yet another possible implementation, the device 170 further includes an input module 1705; and the processor 1702 is further configured to:
[0796] The third confirmation indication information is obtained by the input module 1705, and the third confirmation indication information indicates that the second PSK is allowed to be generated.
[0797] It can be seen that when the new second PSK is generated, the confirmation of the user is required. In this way, when an attacker connects the device 170 using his own identity, since the identity of the attacker does not correspond to a PSK in the device 170, the identity of the new node can be verified by the user, and the second PSK is generated only after the third confirmation indication information is obtained, thereby avoiding the device 170 from associating with an untrusted node and ensuring the security of communication of the device 170.
[0798] In yet another possible implementation, the processor 1702 is specifically configured to:
[0799] The second PSK is generated according to the first freshness parameter, the fourth freshness parameter, and a first password, the first password being an access password of the device.
[0800] It can be seen that when the first password is the access password of the first node, the device 170 connects the first node by inputting the first password, and therefore the second PSK is generated by participating in the first password, so that an attacker who does not obtain the first password cannot crack the second PSK, thereby avoiding the device 170 from associating with the attacker who does not obtain the first password.
[0801] In yet another possible implementation, the first authentication request message further includes a second key agreement algorithm parameter; and the processor 1702 is specifically configured to:
[0802] The second PSK is generated according to the first freshness parameter, the fourth freshness parameter, the first password, and the second key agreement algorithm parameter.
[0803] It can be seen that the first node carries the second key agreement algorithm parameter in the first authentication request message, and the second key agreement algorithm parameter is determined based on the first key agreement algorithm. The device 170 can determine the second PSK based on the first key agreement algorithm, the second key agreement algorithm parameter, the first freshness parameter, the fourth freshness parameter, and the first password. In this way, even if an attacker impersonates the identity information of the first node later and obtains the first freshness parameter and the fourth freshness parameter used when generating the second PSK, the attacker cannot crack the PSK and thus cannot communicate with the device 170, thereby improving the security of communication of the device 170.
[0804] In another possible implementation, the first authentication request message further includes a second key agreement algorithm parameter; and the processor 1702 is specifically configured to:
[0805] generate the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the intermediate key, the first password being an access password; and the intermediate key being generated based on the first freshness parameter, the fourth freshness parameter, and the second key agreement algorithm parameter.
[0806] In another possible implementation, the first association request message further includes a first key agreement algorithm parameter, and the first key agreement algorithm parameter is determined based on a first key agreement algorithm and a fourth key agreement algorithm parameter; the first authentication request message further includes a second key agreement algorithm parameter, and the second key agreement parameter is determined by the first node based on the first key agreement algorithm and a third key agreement algorithm parameter; and the processor 1702 is specifically configured to:
[0807] determine a first intermediate key based on the second key agreement algorithm parameter and the fourth key agreement algorithm parameter;
[0808] generate the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0809] It can be seen that the first key agreement algorithm parameter in the first association request message is generated based on the private key of the second node (i.e., the fourth key agreement algorithm parameter). After the device 170 receives the second key agreement algorithm parameter from the first node, the device determines the first intermediate key based on the second key agreement algorithm parameter and the private key of the device 170 (i.e., the fourth key agreement algorithm parameter), and the first intermediate key is the secret value obtained through key agreement between the first node and the device. The device 170 generates the second PSK based on the first freshness parameter, the fourth freshness parameter, the first password, and the first intermediate key.
[0810] In a further possible implementation, the first authentication request message further comprises a second key agreement algorithm parameter, the second key agreement algorithm parameter being determined based on the first key agreement algorithm; the processor 1702 is specifically configured to:
[0811] obtain a fourth key agreement algorithm parameter;
[0812] determine a first intermediate key based on the second key agreement algorithm parameter and the fourth key agreement algorithm parameter according to the first key agreement algorithm;
[0813] determine a second intermediate key according to the first freshness parameter, the fourth freshness parameter and the first intermediate key;
[0814] generate a second PSK according to the first freshness parameter, the fourth freshness parameter, the first password and the second intermediate key.
[0815] In a further possible implementation, the processor 1702 is further configured to:
[0816] save a correspondence between the identity of the first node and the second PSK.
[0817] It can be seen that after the second PSK is generated, the apparatus 170 saves the correspondence between the identity of the first node and the second PSK, and when associated with the first node again later, the second PSK can be obtained according to the correspondence without generating the PSK again.
[0818] In a further possible implementation, the processor 1702 is further configured to:
[0819] if the first password is updated, delete the correspondence between the identity of the first node and the second PSK.
[0820] In a further possible implementation, the first authentication request message further comprises update indication information, the update indication information being used to indicate the update of the PSK.
[0821] It can be seen that after the second PSK is generated according to the first freshness parameter and the fourth freshness parameter, the first node can remind the apparatus 170 to update the second PSK through the update indication information, so as to avoid that the apparatus 170 uses the old PSK to verify the identity authentication information, thereby avoiding verification failure and affecting user experience.
[0822] In a further possible implementation, the processor 1702 is further configured to:
[0823] if the first identity authentication information is not verified according to the second PSK and the first freshness parameter, generate a fourth PSK according to the first freshness parameter and the fourth freshness parameter;
[0824] The third authentication response message including third identity authentication information is sent to the first node through the communication interface 1703, and the third identity authentication information is generated according to the fourth PSK and the fourth freshness parameter.
[0825] It can be seen that when the device 170 obtains the second PSK according to the corresponding relationship, if the first identity authentication information fails to pass the verification of the device 170, it may be that the first identity authentication information is generated by using the newly generated PSK in the first node. Therefore, the device 170 also generates a new PSK (i.e., the fourth PSK) according to the first freshness parameter and the fourth freshness parameter, and reinitiates authentication according to the new PSK, so that the stability of the system can be improved.
[0826] In another possible implementation, the processor 1702 is further configured to:
[0827] The third association response message from the first node is received through the communication interface 1703.
[0828] In another possible implementation, the device 170 further includes an input module 1705; and the processor 1702 is further configured to:
[0829] If the first identity authentication information fails to pass the verification according to the second PSK, the fourth confirmation indication information is obtained through the input module 1705, and the fourth confirmation indication information indicates th...
Claims
1. A key acquisition method characterized by comprising: The method comprises: receiving a first association request message from a second node, the first association request message comprising a first freshness parameter; obtaining a first pre-shared key (PSK); wherein the first PSK corresponds to an identity of the second node; the first PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from a first node, the second freshness parameter and the third freshness parameter being obtained before the first association request message; sending a first authentication request message to the second node, the first authentication request message comprising first identity authentication information and a fourth freshness parameter, wherein the first identity authentication information is generated according to the first PSK and the first freshness parameter.
2. The method of claim 1, wherein, The method further comprises: receiving a first authentication response message from the second node, the first authentication response message comprising second identity authentication information; if the second identity authentication information is verified to be correct according to the first PSK and the fourth freshness parameter, sending a first association response message to the second node.
3. The method of claim 1, wherein, The obtaining of the first pre-shared key (PSK) comprises: obtaining the first PSK according to a correspondence between the first PSK and the identity of the second node.
4. The method of claim 1, wherein, The obtaining of the first pre-shared key (PSK) comprises: generating the first PSK according to the first freshness parameter and the fourth freshness parameter; wherein the first freshness parameter is the second freshness parameter, and the fourth freshness parameter is the third freshness parameter.
5. The method of claim 4, wherein, Before the generating of the first PSK according to the first freshness parameter and the fourth freshness parameter, the method further comprises: obtaining first confirmation indication information, the first confirmation indication information indicating that association with the second node is allowed.
6. The method of claim 4, wherein, The generating of the first PSK according to the first freshness parameter and the fourth freshness parameter comprises: generating the first PSK according to the first freshness parameter, the fourth freshness parameter and a first password, the first password being an access password.
7. The method of claim 4, wherein, The first association request message further comprises a first key agreement algorithm parameter; the generating of the first PSK according to the first freshness parameter and the fourth freshness parameter comprises: generating the first PSK according to the first freshness parameter, the fourth freshness parameter, a first password and the first key agreement algorithm parameter, the first password being an access password.
8. The method of claim 4, wherein, The first association request message further comprises a first key agreement algorithm parameter; the generating of the first PSK according to the first freshness parameter and the fourth freshness parameter comprises: generating the first PSK according to the first freshness parameter, the fourth freshness parameter, a first password and an intermediate key, the first password being an access password; wherein the intermediate key is generated according to the first freshness parameter, the fourth freshness parameter and the first key agreement algorithm parameter.
9. The method according to any one of claims 6-8, characterized in that, The method further comprises: if the first password is updated, deleting the correspondence between the identity of the second node and the first PSK.
10. The method according to any one of claims 4-8, characterized in that, The first authentication request message further includes update indication information, and the update indication information is used to indicate the update of the PSK.
11. The method of claim 2, wherein, The method further includes: If the second identity authentication information is verified as failed according to the first PSK and the fourth freshness parameter, a third PSK is generated according to the first freshness parameter and the fourth freshness parameter; A second authentication request message is sent to the second node, and the second authentication request message includes third identity authentication information, wherein the third identity authentication information is generated according to the third PSK and the first freshness parameter.
12. The method of claim 11, wherein, The method further includes: If the second identity authentication information is verified as failed according to the first PSK and the fourth freshness parameter, second confirmation indication information is obtained, and the second confirmation indication information indicates that the third PSK is allowed to be generated; The third PSK is generated according to the first freshness parameter and the fourth freshness parameter.
13. The method according to claim 11 or 12, characterized in that, The method further includes: A second authentication response message is received from the second node, and the second authentication response message includes fourth identity authentication information; If the fourth identity authentication information is verified as passed according to the third PSK and the fourth freshness parameter, a second association response message is sent to the second node.
14. A key acquisition method characterized by comprising: The method further includes: A first association request message is sent to a first node, and the first association request message includes a first freshness parameter; A first authentication request message is received from the first node, and the first authentication request message includes first identity authentication information and a fourth freshness parameter; A second pre-shared key (PSK) is obtained, wherein the second PSK corresponds to an identity of the first node. The second PSK is generated according to a second freshness parameter from a second node and a third freshness parameter from the first node, and the second PSK is used to verify the identity of the first node.
15. The method of claim 14, wherein, The method further includes: If the first identity authentication information is verified as passed according to the second PSK and the first freshness parameter, a first authentication response message is sent to the first node, and the first authentication response message includes second identity authentication information, which is generated according to the second PSK and the fourth freshness parameter; A first association response message is received from the first node.
16. The method according to claim 14 or 15, characterized in that The method further includes: The second PSK is obtained according to a correspondence between the second PSK and the identity of the first node.
17. The method of claim 14, wherein, The method further includes: The second PSK is generated according to the first freshness parameter and the fourth freshness parameter. The first freshness parameter is the second freshness parameter, and the fourth freshness parameter is the third freshness parameter.
18. The method of claim 17, wherein, Before the second PSK is generated according to the first freshness parameter and the fourth freshness parameter, the method further comprises: obtaining third confirmation indication information, the third confirmation indication information representing that the second PSK is allowed to be generated.
19. The method of claim 17, wherein, The second PSK is generated according to the first freshness parameter and the fourth freshness parameter, comprising: The second PSK is generated according to the first freshness parameter, the fourth freshness parameter and a first password, the first password being an access password of the first node.
20. The method of claim 17, wherein, The first authentication request message further comprises a second key agreement algorithm parameter; the second PSK is generated according to the first freshness parameter and the fourth freshness parameter, comprising: The second PSK is generated according to the first freshness parameter, the fourth freshness parameter, a first password and the second key agreement algorithm parameter, the first password being an access password of the first node.
21. The method of claim 17, wherein, The first authentication request message further comprises a second key agreement algorithm parameter; the second PSK is generated according to the first freshness parameter and the fourth freshness parameter, comprising: The second PSK is generated according to the first freshness parameter, the fourth freshness parameter, a first password and an intermediate key, the first password being an access password; wherein the intermediate key is generated according to the first freshness parameter, the fourth freshness parameter and the second key agreement algorithm parameter.
22. The method of any one of claims 19-21, wherein, The method further comprises: If the first password is updated, deleting the correspondence between the identity of the first node and the second PSK.
23. The method of any one of claims 17-21, wherein, The first authentication request message further comprises update indication information, the update indication information being used to indicate the update of the PSK.
24. The method of claim 15, wherein, The method further comprises: If the first identity authentication information is not passed according to the verification of the second PSK and the first freshness parameter, generating a fourth PSK according to the first freshness parameter and the fourth freshness parameter; sending a third authentication response message to the first node, the third authentication response message comprising third identity authentication information, the third identity authentication information being generated according to the fourth PSK and the fourth freshness parameter.
25. The method of claim 24, wherein, The method further comprises: receiving a third association response message from the first node.
26. The method of claim 24, wherein, If the first identity authentication information is not passed according to the verification of the second PSK and the first freshness parameter, the second node generates a fourth PSK according to the first freshness parameter and the fourth freshness parameter, comprising: If the first identity authentication information is not passed according to the verification of the second PSK, obtaining fourth confirmation indication information, the fourth confirmation indication information representing that the fourth PSK is allowed to be generated; The fourth PSK is generated according to the first freshness parameter and the fourth freshness parameter.
27. The method of claim 15, wherein, The method further comprises: If the second identity authentication information is not passed according to the verification of the second PSK and the first freshness parameter, deleting the second PSK; sending a second association request message to the first node, the second association request message comprising a fifth freshness parameter.
28. A key acquisition apparatus characterized by comprising: comprising: receive a first association request message from a second node, the first association request message comprising a first freshness parameter; obtain a first pre-shared key (PSK), wherein the first PSK corresponds to an identity of the second node, and the first PSK is generated according to a second freshness parameter from the second node and a third freshness parameter from the first node, the second freshness parameter and the third freshness parameter being obtained before the first association request message; send a first authentication request message to the second node, the first authentication request message comprising first identity authentication information and a fourth freshness parameter, wherein the first identity authentication information is generated according to the first PSK and the first freshness parameter.
29. The apparatus of claim 28, wherein, receive a first authentication response message from the second node, the first authentication response message comprising second identity authentication information; if the second identity authentication information is verified to be correct according to the first PSK and the fourth freshness parameter, send a first association response message to the second node, the first association response message indicating permission to communicate with the second node.
30. The apparatus of claim 28, wherein, obtain the first PSK according to a correspondence between the first PSK and the identity of the second node.
31. The apparatus of claim 28, wherein, generate the first PSK according to the first freshness parameter and the fourth freshness parameter, wherein the first freshness parameter is the second freshness parameter, and the fourth freshness parameter is the third freshness parameter.
32. The apparatus of claim 31, wherein, obtain first confirmation indication information, the first confirmation indication information indicating permission to associate with the second node.
33. The apparatus of claim 31, wherein, generate the first PSK according to the first freshness parameter, the fourth freshness parameter, and a first password, the first password being an access password of the apparatus.
34. The apparatus of claim 31, wherein, generate the first PSK according to the first freshness parameter, the fourth freshness parameter, a first password, and a first key agreement algorithm parameter, the first password being an access password of the apparatus.
35. The apparatus of claim 31, wherein, generate the first PSK according to the first freshness parameter, the fourth freshness parameter, a first password, and a first key agreement algorithm parameter, the first password being an access password of the apparatus. generate the first PSK according to the first freshness parameter, the fourth freshness parameter, a first password, and a first key agreement algorithm parameter, the first password being an access password of the apparatus.
36. The apparatus of any one of claims 33-35, wherein, if the first password is updated, delete the correspondence between the identity of the second node and the first PSK.
37. The apparatus of any one of claims 31-35, wherein, the first authentication request message further comprises update indication information, the update indication information being used to indicate update of the PSK.
38. The apparatus of claim 29, wherein, The processing unit is further configured to generate a third PSK according to the first freshness parameter and the fourth freshness parameter if the second identity authentication information is verified as failed according to the first PSK and the fourth freshness parameter. The sending unit is further configured to send a second authentication request message to the second node, the second authentication request message comprising third identity authentication information, wherein the third identity authentication information is generated according to the third PSK and the first freshness parameter.
39. The device of claim 38, wherein, The processing unit is further configured to obtain second confirmation indication information if the second identity authentication information is verified as failed according to the first PSK and the fourth freshness parameter, the second confirmation indication information indicating that the third PSK is allowed to be generated. The processing unit is further configured to generate the third PSK according to the first freshness parameter and the fourth freshness parameter.
40. The apparatus of claim 38 or 39, wherein, The receiving unit is further configured to receive a second authentication response message from the second node, the second authentication response message comprising fourth identity authentication information. The sending unit is further configured to send a second association response message to the second node if the fourth identity authentication information is verified as passed according to the third PSK and the fourth freshness parameter.
41. A key acquisition apparatus, characterized by comprising: Comprise: The sending unit is configured to send a first association request message to a first node, the first association request message comprising a first freshness parameter. The receiving unit is configured to receive a first authentication request message from the first node, the first authentication request message comprising first identity authentication information and a fourth freshness parameter. The processing unit is configured to obtain a second PSK, wherein the second PSK corresponds to an identity of the first node. The second PSK is a PSK generated according to a second freshness parameter from the device and a third freshness parameter from the first node, the second PSK being used to verify the identity of the first node, and the second freshness parameter and the third freshness parameter being obtained before the first association request message.
42. The device of claim 41, wherein, The sending unit is further configured to send a first authentication response message to the first node if the first identity authentication information is verified as passed according to the second PSK and the first freshness parameter, the first authentication response message comprising second identity authentication information, the second identity authentication information being generated according to the second PSK and the fourth freshness parameter. The receiving unit is further configured to receive a first association response message from the first node.
43. The device of claim 41 or 42, wherein, The processing unit is specifically configured to obtain the second PSK according to a correspondence between the second PSK and the identity of the first node.
44. The device of claim 41, wherein, The processing unit is specifically configured to generate the second PSK according to the first freshness parameter and the fourth freshness parameter, wherein the first freshness parameter is the second freshness parameter, and the fourth freshness parameter is the third freshness parameter.
45. The device of claim 44, wherein, The processing unit is further configured to obtain third confirmation indication information, the third confirmation indication information indicating that the second PSK is allowed to be generated.
46. The device of claim 44, wherein, The processing unit is specifically configured to generate the second PSK according to the first freshness parameter, the fourth freshness parameter, and a first password, the first password being an access password of the first node.
47. The device of claim 44, wherein, The first authentication request message further comprises a second key agreement algorithm parameter; and the processing unit is specifically configured to generate the second PSK according to the first freshness parameter, the fourth freshness parameter, a first password, and the second key agreement algorithm parameter, the first password being an access password of the first node.
48. The device of claim 44, wherein, The first authentication request message further comprises a second key agreement algorithm parameter; and the processing unit is specifically configured to: generate the second PSK according to the first freshness parameter, the fourth freshness parameter, a first password, and an intermediate key, the first password being an access password; and the intermediate key is generated according to the first freshness parameter, the fourth freshness parameter, and the second key agreement algorithm parameter.
49. The device of any one of claims 46-48, wherein, The processing unit is further configured to delete the correspondence between the identity of the first node and the second PSK if the first password is updated.
50. The device of any one of claims 44-48, wherein, The first authentication request message further comprises update indication information, the update indication information being used to indicate the update of the PSK.
51. The device of claim 42, wherein, The processing unit is further configured to generate a fourth PSK according to the first freshness parameter and the fourth freshness parameter if the first identity authentication information is verified to be failed according to the second PSK and the first freshness parameter. The sending unit is further configured to send a third authentication response message to the first node, the third authentication response message comprising third identity authentication information, the third identity authentication information being generated according to the fourth PSK and the fourth freshness parameter.
52. The device of claim 51, wherein, The receiving unit is further configured to receive a third association response message from the first node.
53. The device of claim 51 or 52, wherein, The processing unit is further configured to obtain fourth confirmation indication information if the first identity authentication information is verified to be failed according to the second PSK, the fourth confirmation indication information representing that the generation of the fourth PSK is allowed. The processing unit is further configured to generate the fourth PSK according to the first freshness parameter and the fourth freshness parameter.
54. The device of claim 42, wherein, The processing unit is further configured to delete the correspondence between the identity of the first node and the second PSK if the second identity authentication information is verified to be failed according to the second PSK and the first freshness parameter. The sending unit is further configured to send a second association request message to the first node, the second association request message comprising a fifth freshness parameter.
55. A key acquisition apparatus, comprising: The apparatus comprises at least one processor and a communication interface, the at least one processor being configured to invoke a computer program stored in at least one memory, so that the apparatus implements the method according to any one of claims 1-27.
56. A key acquisition system, comprising: Comprise: The first node is the key acquisition apparatus according to any one of claims 27-40. The second node is the key acquisition apparatus according to any one of claims 41-54.
57. A computer-readable storage medium, characterized in that, The computer readable storage medium has stored therein computer program, which, when executed on one or more processors, performs a method as claimed in any of claims 1-27.
58. A computer program product comprising computer instructions for implementing a method as claimed in any of claims 1-27.
Citation Information
Patent Citations
Distributed authentication method based on pre-shared key
CN105323754A
PSK generation method and apparatus, user equipment, server, and storage medium
CN108964912A
Safety access method, device and system
CN110831000A
Method and apparatus for establishing security association between nodes of an ad hoc wireless network
US20080065884A1