Method and apparatus for terminal device to access gateway based on key management system
Patent Information
- Application Number
- CN202310675330.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-07
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2043-06-07
AI Technical Summary
[0005]本申请提供一种基于密钥管理系统的终端设备接入网关的方法和装置,用以解决终端设备和网关之间通信安全性的问题
[0067]本申请提供的一种基于密钥管理系统的终端设备接入网关的方法和装置,该方法包括:终端设备向网关发送第一请求消息;网关根据第一请求消息,生成用于获取终端设备的公钥的加密的第二请求消息;将加密后的第二请求消息发送至密钥管理系统;密钥管理系统根据第二请求消息,从预设的终端设备配置表中获取终端设备的公钥和预设的终端密钥;根据预设的网关密钥加密终端设备的公钥得到第一密钥信息,并根据预设的终端密钥加密终端设备的公钥得到第二密钥信息;将第一密钥信息和第二密钥信息发送至网关;网关根据预设网关密钥对第一密钥信息进行解密得到终端设备的公钥;网关通过网关的公钥对终端设备的公钥进行加密,得到第三密钥信息;将第二密钥信息和第三密钥信息发送给终端设备;终端设备对第二密钥信息和第三密钥信息分别进行解密,得到终端设备的公钥和网关的公钥。在这种方法中,网关从密钥管理系统获取终端设备的公钥,并根据获取的公钥对自身公钥进行加密发送到终端设备。终端和网关之间进行公钥交换的过程是加密的,可以避免公钥被拦截和篡改的几率。
Smart Images

Figure CN116866001B_ABST
Abstract
Description
Technical Field
[0001] This application relates to communication technology, and more particularly to a method and apparatus for a terminal device to access a gateway based on a key management system. Background Technology
[0002] A company's local area network (LAN) is one of the key infrastructures for modern enterprise communication and data transmission. Within a company, various terminal devices need to connect and exchange information, and the LAN provides this convenient internal communication environment.
[0003] In a company's local area network (LAN), communication between terminal devices and the gateway requires authentication and key exchange. Typically, this authentication process is conducted via protocols such as Secure Socket Layer (SSL). In this case, the exchange of public keys between the terminal devices and the gateway is a crucial step in ensuring a secure connection. However, there are risks involved in the public key exchange process, as attackers could intercept and tamper with the exchanged public keys, thereby compromising the connection's security.
[0004] Therefore, ensuring the security of communication between terminal devices and gateways within a local area network is an urgent problem to be solved. Summary of the Invention
[0005] This application provides a method and apparatus for a terminal device to access a gateway based on a key management system, in order to solve the problem of communication security between the terminal device and the gateway.
[0006] In a first aspect, this application provides a method for a terminal device to access a gateway based on a key management system, applied to a gateway, comprising:
[0007] The terminal device receives a first request message, which requests the establishment of a communication channel with the gateway, and the first request message includes the identifier of the terminal device.
[0008] Based on the first request message, a second request message for obtaining the public key of the terminal device is generated, and the second request message is encrypted with a preset gateway key to obtain an encrypted second request message. The second request message includes the identifier of the terminal device and the IP of the gateway.
[0009] The encrypted second request message is sent to the key management system;
[0010] The system receives first key information and second key information returned by the key management system, wherein the first key information includes the public key of the terminal device encrypted with a preset gateway key, and the second key information includes the public key of the terminal device encrypted with a preset terminal key.
[0011] The public key of the terminal device is obtained by decrypting the first key information using the gateway key.
[0012] Obtain the public key of the gateway, and encrypt the public key of the gateway using the public key of the terminal device to obtain the third key information;
[0013] The second key information and the third key information are sent to the terminal device.
[0014] Optionally, the method further includes:
[0015] The terminal device receives a third request message, which includes a random number A encrypted with the public key of the gateway and a signature of the random number A with the private key of the terminal device.
[0016] The encrypted random number A in the third request message is decrypted using the private key of the gateway to obtain the random number A.
[0017] Get a random number B;
[0018] Based on the random number A, the random number B, the private key of the gateway, and the public key of the terminal device, obtain the session key K;
[0019] The signature and encrypted random number B and random number A are sent to the terminal device.
[0020] Optionally, obtaining the random number B includes:
[0021] Receive the quantum random number B, encrypted with the gateway key, sent by the key management system;
[0022] Decrypting the encrypted quantum random number B yields another quantum random number B, which is the quantum random number B;
[0023] or,
[0024] The quantum random number B is generated randomly.
[0025] Secondly, this application provides a method for a terminal device to access a gateway based on a key management system, applied to a key management system, the method comprising:
[0026] The system receives a second request message sent by the gateway, which is encrypted using a preset gateway key. The second request message is used to obtain the public key of the terminal device and includes the identifier of the terminal device and the IP address of the gateway.
[0027] Based on the identifier of the terminal device, obtain the public key and the preset terminal key of the terminal device from the preset terminal device configuration table;
[0028] The first key information is obtained by encrypting the public key of the terminal device according to the preset gateway key, and the second key information is obtained by encrypting the public key of the terminal device according to the terminal key.
[0029] Based on the gateway's IP address, the first key information and the second key information are sent to the gateway.
[0030] Optionally, the method further includes:
[0031] Obtain all terminal device data within the company to which the gateway belongs, wherein the terminal device data includes the identifier of each terminal device, the public key of each terminal device, and the preset private key of each terminal device;
[0032] The terminal device configuration table is updated based on the terminal device data.
[0033] Optionally, the method further includes:
[0034] Generate quantum random number B;
[0035] The quantum random number is encrypted using the gateway key, and the encrypted quantum random number B is sent to the gateway.
[0036] Thirdly, this application also provides a method for a terminal device to access a gateway based on a key management system, applied to a terminal device, the method comprising:
[0037] In response to a user operation, a first request message is sent to the gateway. The first request message is used to request the establishment of a communication channel with the gateway. The first request message includes the identifier of the terminal device.
[0038] The system receives second key information and third key information returned by the gateway. The second key information includes the public key of the terminal device encrypted with a preset terminal key, and the third key information includes the public key of the gateway encrypted with the public key of the terminal device.
[0039] The second key information and the third key information are decrypted respectively to obtain the public key of the terminal device and the public key of the gateway.
[0040] Optionally, the method further includes:
[0041] Generate a random number A;
[0042] Send a third request message to the gateway, the third request message including the random number A encrypted with the public key of the gateway and the signature information of the random number A with the private key of the terminal device;
[0043] Receive the signature and encrypted random number B and random number A sent by the gateway;
[0044] Based on the random number A, the random number B, the public key of the gateway, and the private key of the terminal device, obtain the session key K.
[0045] Fourthly, this application also provides an apparatus for a terminal device to access a gateway, the apparatus comprising:
[0046] The receiving module is configured to receive a first request message sent by a terminal device, the first request message being used to request the establishment of a communication channel with the gateway, and the first request message including the identifier of the terminal device;
[0047] The generation module is configured to generate a second request message for obtaining the public key of the terminal device based on the first request message, and encrypt the second request message with a preset gateway key to obtain an encrypted second request message, wherein the second request message includes the identifier of the terminal device and the IP of the gateway;
[0048] The sending module is used to send the encrypted second request message to the key management system;
[0049] The receiving module is further configured to receive first key information and second key information returned by the key management system, wherein the first key information includes the public key of the terminal device encrypted with a preset gateway key, and the second key information includes the public key of the terminal device encrypted with a preset terminal key.
[0050] The decryption module is used to decrypt the first key information according to the gateway key to obtain the public key of the terminal device;
[0051] An encryption module is used to obtain the public key of the gateway and encrypt the public key of the gateway using the public key of the terminal device to obtain third key information;
[0052] The sending module is further configured to send the second key information and the third key information to the terminal device.
[0053] Fifthly, this application also provides an apparatus for a terminal device to access a gateway based on a key management system, the apparatus comprising:
[0054] The receiving module is used to receive a second request message sent by the gateway, which is encrypted using a preset gateway key. The second request message is used to obtain the public key of the terminal device, and includes the identifier of the terminal device and the IP of the gateway.
[0055] The acquisition module is used to obtain the public key and the preset terminal key of the terminal device from a preset terminal device configuration table based on the identifier of the terminal device;
[0056] An encryption module is used to encrypt the public key of the terminal device according to a preset gateway key to obtain the first key information, and to encrypt the public key of the terminal device according to the terminal key to obtain the second key information;
[0057] The sending module is used to send the first key information and the second key information to the gateway according to the gateway's IP address.
[0058] Sixthly, this application provides an apparatus for a terminal device to access a gateway based on a key management system, the apparatus comprising:
[0059] The sending module is used to send a first request message to the gateway in response to a user operation. The first request message is used to request the establishment of a communication channel with the gateway. The first request message includes the identifier of the terminal device.
[0060] The receiving module is configured to receive second key information and third key information returned by the gateway. The second key information includes the public key of the terminal device encrypted with a preset terminal key, and the third key information includes the public key of the gateway encrypted with the public key of the terminal device.
[0061] The decryption module is used to decrypt the second key information and the third key information respectively to obtain the public key of the terminal device and the public key of the gateway.
[0062] In a seventh aspect, this application also provides an electronic device, comprising:
[0063] The processor, the memory communicatively connected to the processor, and the communication interface for interacting with other devices;
[0064] The memory stores computer-executed instructions;
[0065] The processor executes computer execution instructions stored in the memory to implement the method for accessing a terminal device gateway based on a key management system as described in any one of the first to third aspects.
[0066] Eighthly, this application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method for accessing a terminal device gateway based on a key management system as described in any one of the first to third aspects.
[0067] This application provides a method and apparatus for a terminal device to access a gateway based on a key management system. The method includes: the terminal device sending a first request message to the gateway; the gateway generating an encrypted second request message for obtaining the public key of the terminal device based on the first request message; sending the encrypted second request message to the key management system; the key management system obtaining the public key of the terminal device and a preset terminal key from a preset terminal device configuration table based on the second request message; encrypting the public key of the terminal device according to a preset gateway key to obtain first key information, and encrypting the public key of the terminal device according to the preset terminal key to obtain second key information; sending the first key information and the second key information to the gateway; the gateway decrypting the first key information according to a preset gateway key to obtain the public key of the terminal device; the gateway encrypting the public key of the terminal device using its own public key to obtain third key information; sending the second key information and the third key information to the terminal device; and the terminal device decrypting the second key information and the third key information respectively to obtain the public key of the terminal device and the public key of the gateway. In this method, the gateway obtains the public key of the terminal device from the key management system and encrypts its own public key according to the obtained public key before sending it to the terminal device. The process of exchanging public keys between the terminal and the gateway is encrypted, which can avoid the chance of the public key being intercepted or tampered with. Attached Figure Description
[0068] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0069] Figure 1 This is a schematic diagram illustrating a possible application scenario provided by an embodiment of this application;
[0070] Figure 2 A flowchart illustrating a method for a terminal device to access a gateway based on a key management system, provided in this application.
[0071] Figure 3 A flowchart illustrating a second embodiment of a method for a terminal device to access a gateway based on a key management system, provided in this application.
[0072] Figure 4 A flowchart illustrating a third embodiment of a method for a terminal device to access a gateway based on a key management system, provided in this application.
[0073] Figure 5 A schematic diagram of a device embodiment 1 for a terminal device access gateway based on a key management system provided in this application;
[0074] Figure 6 A schematic diagram of a second embodiment of a terminal device access gateway based on a key management system provided in this application;
[0075] Figure 7 A schematic diagram of the structure of a terminal device access gateway based on a key management system provided in this application, according to embodiment three;
[0076] Figure 8 This is a schematic diagram of the structure of an electronic device provided in this application.
[0077] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0078] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0079] First, let me explain the terms used in this application:
[0080] Random numbers: Ordinary random numbers are typically generated through deterministic algorithms or the unpredictability of physical processes, such as using a pseudo-random number generator (PRNG) algorithm. The random number calculation process generates a series of random values. Although a sequence of pseudo-random numbers may appear random in the short term, it will exhibit periodicity or repetition in the long term.
[0081] Quantum random numbers are random numbers generated using quantum physical phenomena. Traditional random number generation methods are based on deterministic algorithms or the unpredictability of physical processes, while quantum random numbers utilize the uncertainty principle in quantum mechanics to achieve stronger randomness. Due to the nature of quantum mechanics, measurement results are truly random and unpredictable or unrepeatable. Because measurement results are unpredictable, the value of a random number cannot be inferred by calculating or observing the state of a quantum system.
[0082] A Local Area Network (LAN) is a computer network interconnected within a relatively small geographical area, such as a home, office, campus, or enterprise, using communication devices. It provides an efficient communication and data exchange platform for internal employees, supporting the smooth operation of business processes. LANs also provide access to external networks (such as the Internet), enabling businesses to conduct secure and reliable remote communication with customers, partners, and suppliers.
[0083] In a local area network (LAN), the gateway plays a crucial role, connecting the LAN to external networks and handling packet forwarding and routing. Through authentication and communication mechanisms, devices can securely interact with the gateway, thereby enabling connection and communication with external networks.
[0084] In existing local area networks (LANs), password authentication is typically used between terminal devices and gateways. This method requires users to enter a username and password for verification, ensuring that only authorized users can access network resources. However, password authentication has several drawbacks. First, passwords are easily guessed, leaked, or forgotten, leading to security vulnerabilities. Second, password authentication is cumbersome for users, requiring them to remember multiple different passwords, which can easily lead to password weakening or reuse. Furthermore, password authentication does not provide protection against man-in-the-middle attacks; that is, public keys exchanged via encryption protocols may be intercepted and tampered with, posing a risk to key security.
[0085] To address this issue, digital certificates can be generated and managed using a Certificate Authority (CA). These digital certificates contain the public keys of the terminal devices and gateways. The terminal devices and gateways can send requests to the key management system to obtain the corresponding digital certificates, thus ensuring the security and authenticity of the public keys. Digital certificate authentication effectively prevents man-in-the-middle attacks and tampering, providing a higher level of security protection.
[0086] However, using CA authentication requires establishing and managing a robust Public Key Infrastructure (PKI) system, including setting up and maintaining authentication servers, issuing and managing digital certificates, and storing and updating keys, which increases the complexity of deployment and management. When using CA authentication, if a device's certificate is revoked or expires, it must be updated and reissued promptly, and the digital certificate must be transmitted and verified during communication, increasing communication overhead and latency.
[0087] In view of the above problems, the inventors discovered during their research in this field that by establishing a trusted key management system for the company system and its internal LAN devices, secure exchange of public keys between terminal devices and gateways can be achieved, ensuring communication security. Furthermore, the authentication process no longer requires username and password verification, simplifying the process for users to access the internet within the LAN. Based on this, this application provides a method and apparatus for terminal devices to access a gateway based on a key management system.
[0088] It should be noted that the key management system can be located either outside or inside the company's local area network (LAN).
[0089] Figure 1 This is a schematic diagram illustrating a possible application scenario provided by an embodiment of this application, such as... Figure 1 As shown, within a local area network, at least one terminal device is connected to at least one gateway and accesses the external network through the gateway. The terminal device can be a mobile phone, computer, printer, smart wearable device, etc., and the gateway device can be a router, switch, proxy server, etc.
[0090] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0091] Figure 2 A flowchart illustrating a method for a terminal device to access a gateway based on a key management system, as provided in this application, is shown below. Figure 2 As shown, the method includes:
[0092] S101. In response to the user's operation, the terminal device sends a first request message to the gateway.
[0093] Accordingly, the gateway receives the first request message sent by the terminal device.
[0094] In this step, the user connects to the local area network (LAN) using a terminal device via a wired or wireless connection. Upon connection, the terminal device automatically assembles its identifier and other necessary request information into a first request message. This first request message is used to establish a communication channel with the gateway. The terminal device identifier can be a Media Access Control Address (MAC address), a Personal Identification Number (PIN), or a unique device identifier (ID), etc. Other necessary request information includes communication requirements, an Internet Protocol (IP) address, communication protocol information, and security parameters. The terminal device then sends the first request message to the gateway.
[0095] S102. Based on the first request message, generate a second request message for obtaining the public key of the terminal device, and encrypt the second request message with a preset gateway key to obtain the encrypted second request message.
[0096] In this step, the gateway receives a first request message from the terminal device, needs to verify the terminal device's identity, and exchanges public keys with the terminal device for subsequent sessions. Therefore, the gateway generates a second request message based on the terminal device's identifier and its own gateway identifier in the first request message. The second request message is used to verify the terminal device's identity and obtain the terminal device's public key. The generated second request message is encrypted with a preset key to obtain an encrypted second request message, which is then sent to the key management system.
[0097] The gateway identifier can be either a gateway IP address or a gateway device ID. The preset key is pre-negotiated and set between the gateway and the key management system, and is stored in the gateway's secure storage area.
[0098] In one possible implementation, the preset key could be set using a secure key exchange protocol, such as Diffie-Hellman key exchange. Through this protocol, the gateway can negotiate and generate a shared preset key with the key management system.
[0099] S103. Send the encrypted second request message to the key management system.
[0100] Correspondingly, the key management system receives a second request message sent by the gateway, which is encrypted using a preset gateway key.
[0101] S104. Based on the identifier of the terminal device, obtain the public key and the preset terminal key of the terminal device from the preset terminal device configuration table.
[0102] In this step, the key management system receives the encrypted second request message, decrypts the second request message using a preset gateway key, and obtains the terminal device identifier and the gateway identifier.
[0103] The system queries a pre-configured authentication table based on the terminal device's identifier to determine if the terminal device is currently eligible to connect to the internet. The pre-configured authentication table stores the internet access eligibility expiration dates for multiple terminal devices.
[0104] If the terminal device's identifier does not qualify for network access, a message indicating that it does not qualify for network access is returned to the gateway. The gateway then sends a network access failure message to the user's terminal device to indicate that the user's terminal device does not qualify for network access.
[0105] If the terminal device's identifier is qualified to connect to the network, then the terminal device's public key and preset terminal key are obtained from the preset terminal device configuration table. The preset terminal device configuration table includes a pre-configured identifier for each terminal device, its corresponding public key, and a preset terminal key. The terminal device's public key is used to send data to the gateway, and the preset terminal key is used for terminal device verification.
[0106] S105. Obtain the first key information by encrypting the public key of the terminal device according to the preset gateway key, and obtain the second key information by encrypting the public key of the terminal device according to the preset terminal key.
[0107] In this step, to ensure the security of the terminal device's key transmission to the gateway, the terminal device's public key is encrypted using a preset gateway key to obtain the first key information. Then, the terminal device's public key is encrypted using a preset terminal key to obtain the second key information.
[0108] In one possible implementation, the key management system is located outside the local area network (LAN). It encrypts the public key of the terminal device using a preset gateway key and a preset terminal key. By using a preset symmetric key, compared to asymmetric key encryption outside the LAN, key leakage due to quantum computing attacks can be prevented during key transmission.
[0109] In one possible implementation, the key management system is located within a local area network (LAN), where the communication channels are trustworthy, making it more secure and increasing the security of key transmission.
[0110] S106. Based on the gateway's IP address, send the first key information and the second key information to the gateway.
[0111] Correspondingly, the gateway receives the first key information and the second key information returned by the key management system.
[0112] Optionally, the IP address of the gateway can be determined based on the IP address in the gateway identifier in the second request message.
[0113] Optionally, the IP address of the gateway can be determined from a preset gateway address table based on the gateway ID in the second request message.
[0114] S107. Decrypt the first key information according to the gateway key to obtain the public key of the terminal device.
[0115] S108. Obtain the gateway's public key and encrypt it using the terminal device's public key to obtain the third key information.
[0116] In this step, the gateway obtains its own public key, which is pre-stored in the gateway. The gateway then encrypts its own public key using the public key of the terminal device to obtain the third key information.
[0117] In one possible implementation, public key data is read directly from the gateway's key storage area.
[0118] In one possible implementation, public key data is obtained through an Application Programming Interface (API) provided by the gateway management interface or configuration interface.
[0119] In one possible implementation, the public key is output to a specified location, such as a configuration file, during the key generation process, and the public key data is read from that location when needed.
[0120] S109. Send the second key information and the third key information to the terminal device.
[0121] Correspondingly, the terminal device receives the second key information and the third key information returned by the gateway.
[0122] S110. Decrypt the second key information and the third key information respectively to obtain the public key of the terminal device and the public key of the gateway.
[0123] In this step, the terminal device decrypts the second key information using a preset terminal key to obtain the terminal public key information, and verifies and compares it with its own terminal public key information to determine the correctness of the second key information. The terminal device then decrypts the third key message using its terminal private key to obtain the gateway public key.
[0124] Optionally, if the terminal public key verification results are inconsistent, an error message indicating that the terminal public key has been obtained is returned to the gateway. The gateway forwards the message to the key management system, which checks the terminal public key corresponding to the terminal device identifier and updates the preset terminal device configuration table.
[0125] This application provides a method for a terminal device to access a gateway based on a key management system. The terminal device sends a first request message to the gateway; the gateway generates an encrypted second request message for obtaining the public key of the terminal device based on the first request message; the encrypted second request message is sent to the key management system; the key management system obtains the public key of the terminal device and a preset terminal key from a preset terminal device configuration table based on the second request message; the gateway encrypts the public key of the terminal device according to the preset gateway key to obtain first key information, and encrypts the public key of the terminal device according to the preset terminal key to obtain second key information; the first key information and the second key information are sent to the gateway; the gateway decrypts the first key information according to the preset gateway key to obtain the public key of the terminal device; the gateway encrypts the public key of the terminal device using the gateway's public key to obtain third key information; the second key information and the third key information are sent to the terminal device; the terminal device decrypts the second key information and the third key information respectively to obtain the public key of the terminal device and the public key of the gateway. The gateway obtains the public key of the terminal device from the key management system, encrypts its own public key based on the obtained public key, and sends it to the terminal device. In this way, the public key exchange process between the terminal and the gateway is encrypted, which can avoid the chance of the public key being intercepted and tampered with.
[0126] After the terminal device and the gateway exchange public keys, encrypted communication can be carried out between the terminal device and the gateway.
[0127] To prevent the possibility of the key being intercepted and cracked during prolonged use, each session communicates using a temporarily generated session key, increasing the security of the access gateway. Based on the above embodiment one, the generation of the session key is described in detail.
[0128] Figure 3 A flowchart illustrating a second embodiment of a method for a terminal device to access a gateway based on a key management system, as provided in this application, is shown below. Figure 3 As shown, the method includes:
[0129] S201. Generate a random number A.
[0130] In this step, to obtain the session key, the terminal device needs to generate a random number and process it with the gateway's random number. The terminal device uses its own hardware or software to obtain the seed value for generating the random number. The seed value includes system clock, mouse movement, keyboard input, MAC address, etc.
[0131] The terminal device uses a pseudo-random number generation algorithm (PRNG) to obtain a random number A based on the seed value. This random number can be a number, a sequence of bytes, or other forms; the specific format is not limited here.
[0132] For example, the MAC address of the terminal device is obtained and converted into binary format. Further processing of the binary MAC address involves hashing it or XORing it with a timestamp to obtain processed binary data. This processed binary data, i.e., the seed value, is then input into a linear congruential generator (LCG). By setting the parameters, a random number A can be obtained.
[0133] S202, Send a third request message to the gateway.
[0134] Correspondingly, the gateway receives the third request message sent by the terminal device.
[0135] In this step, the terminal device encrypts the generated random number A using the public key of the gateway obtained in the above embodiment. It then signs the random number A using its private key. Finally, it generates a third request message by combining the encrypted random number A (obtained using the gateway's public key) and the signature information (obtained using the terminal device's private key) and sends it to the gateway.
[0136] S203. Decrypt the encrypted random number A in the third request message using the gateway's private key to obtain the random number A.
[0137] In this step, after receiving the third request message, the gateway decrypts the third request message according to the gateway's public key, obtains the terminal device's public key according to the terminal device identifier in the request header information, and verifies the random number A.
[0138] S204. Obtain random number B.
[0139] In this step, after successful signature verification, the gateway needs to XOR the random number B with the received random number A to obtain a temporary session key.
[0140] In one possible implementation, the gateway randomly generates a quantum random number B, similar to the process by which the terminal device generates a random number A, which will not be elaborated here.
[0141] In another possible implementation, the gateway uses a network random number generator to obtain a random number B from the internet. If the random number needs to be obtained from the internet, communication security must be ensured; specifically, multiple different random sources can be used, and their outputs can be mixed.
[0142] In another possible implementation, a quantum random number B encrypted with a gateway key is received from the key management system. If the quantum random number B is received from the key management system, steps S2041-S2043 are further included.
[0143] S2041, Generate quantum random number B.
[0144] In this step, the key management system generates the quantum random number B when it receives a request message from the gateway to obtain the quantum random number B or when it receives a second request message.
[0145] Specifically, the True Random Number Generator (TRNG) interface is integrated into the key management system. The key management system can call the TRNG interface to obtain quantum random numbers. These interfaces can include specifying the required number of bits for random numbers, calling the quantum random number generation algorithm, etc.
[0146] Optionally, the request message or second request message sent by the gateway to obtain the quantum random number B may include the number of bits in the quantum random number. The key management system can specify the number of bits in the generated quantum random number in the interface based on the number of bits in the quantum random number. Alternatively, the obtained quantum random number can be truncated or expanded to obtain the quantum random number B.
[0147] For example, the required number of bits is truncated from the beginning of a longer quantum random number as the quantum random number B.
[0148] As another example, if the number of bits in a quantum random number is insufficient, a quantum random number B can be obtained by combining multiple quantum random numbers.
[0149] It should be noted that TRNG utilizes quantum phenomena (such as the quantum state or quantum entanglement of photons) to generate random measurement results. The random numbers generated by TRNG are based on the uncertainty of physical processes, rather than relying on deterministic algorithms.
[0150] S2042. Encrypt the quantum random number using the gateway key, and send the encrypted quantum random number B to the gateway.
[0151] In this step, to ensure the security of quantum random number transmission, the quantum random number is encrypted using the gateway's preset key and then sent to the gateway.
[0152] If the key management system is located outside the company's local area network, the quantum random number and the first and second keys in the above embodiments are encrypted using a preset key. This preset key encryption is a symmetric key encryption, which can effectively prevent quantum computing attacks during key transmission compared to asymmetric encryption.
[0153] S2043. Decrypt the encrypted quantum random number B to obtain the quantum random number B.
[0154] The gateway receives the encrypted quantum random number and decrypts the quantum random number B according to the preset key.
[0155] S205. Obtain the session key K based on random number A, random number B, the gateway's private key, and the terminal device's public key.
[0156] In one possible implementation, the gateway XORs random numbers A and B to obtain a temporary session key K. The gateway then signs random number B using its private key and encrypts random numbers A and B using the terminal's public key.
[0157] In one possible implementation, the gateway uses a Key Derivation Function (KDF) to generate a session key based on random numbers A and B. The KDF can combine random numbers A and B with other additional information, such as a salt or other key material (gateway key, terminal device key), to generate a strong session key. The salt is a random, public, and non-secret value used to increase the uniqueness and security of the derived key.
[0158] For example:
[0159] Random number A: 0x68F92A1B, Random number B: 0x42C75E9, Gateway private key: 0x1F4A6D3B9E8C7F50, Terminal device public key: 0x9B27E4A8F36D7C21.
[0160] Process random number A, random number B, and other additional information: Combine these values in a specific order. For example, concatenate random number A and random number B, then append the gateway's private key and the terminal device's public key to the concatenated value. The resulting combination would be: 0x68F92A1B42C75E9F1F4A6D3B9E8C7F509B27E4A8F36D7C21. Alternatively, XOR random number A and random number B, then append the gateway's private key and the terminal device's public key to the XOR value.
[0161] By selecting an appropriate key derivation function (such as HKDF, PBKDF2, etc.) and suitable parameters, key derivation is performed on the combined data. The key derivation function will perform multiple iterations and other transformation operations to generate the derived key, ultimately yielding the session key.
[0162] S206. Send the signature and encrypted random number B and random number A to the terminal device.
[0163] Correspondingly, the terminal device receives the signature and encrypted random number B and random number A sent by the gateway.
[0164] S207. Obtain the session key K based on random number A, random number B, the gateway's public key, and the terminal device's private key.
[0165] In this step, the terminal device decrypts the signed and encrypted random number B and random number A using its private key, and verifies the signature of random number B using the gateway's public key. After successful verification, it compares whether the random number A obtained from the gateway is consistent with the random number A of the terminal device itself. If the random number A is consistent, the random number A and random number B are processed to obtain the session key K.
[0166] In one possible implementation, a temporary session key K is obtained by XORing random number A and random number B.
[0167] In another possible implementation, a key derivation function (KDF) is used to generate a session key based on random numbers A and B. The specific generation method is similar to that in step S206, where the gateway uses KDF to generate the session key, and will not be elaborated here. It should be noted that the KDF algorithm and additional information used by the terminal device and the gateway must be consistent to ensure the consistency of the session key between the gateway and the terminal device.
[0168] Optionally, if the random number A is inconsistent, a prompt message will be displayed on the terminal device to inform the user that the network is not secure.
[0169] This application provides a method for a terminal device to access a gateway based on a key management system. The terminal device generates a random number A, encrypts it using the gateway's public key, and sends it to the gateway. The gateway receives the encrypted random number A, decrypts it using its private key, and obtains a random number B. Random number B is a quantum random number obtained from the key management system. A session key is then obtained based on random number A and random number B. This method ensures that each session communicates using a temporarily generated session key, increasing the security of gateway access. Furthermore, using the XOR operation of a quantum random number and a random number to generate the session key effectively prevents replay attacks.
[0170] Based on the above Embodiment 1 and Embodiment 2, a detailed description is given of how the key management system manages the terminal devices of the access gateway.
[0171] Figure 4 A flowchart illustrating a third embodiment of a method for a terminal device to access a gateway based on a key management system, as provided in this application, is shown below. Figure 4 As shown, the method includes:
[0172] S301. In response to the user's operation, the terminal device sends a first request message to the gateway.
[0173] Accordingly, the gateway receives the first request message sent by the terminal device.
[0174] S302. Based on the first request message, generate a second request message for obtaining the public key of the terminal device, and encrypt the second request message with a preset gateway key to obtain the encrypted second request message.
[0175] S303. Send the encrypted second request message to the key management system.
[0176] Correspondingly, the key management system receives a second request message sent by the gateway, which is encrypted using a preset gateway key.
[0177] S304. Based on the identifier of the terminal device, obtain the terminal device data from the preset terminal device configuration table.
[0178] Steps S301-S304 are similar to steps S101-S104, and will not be described in detail here.
[0179] S305, Send a request to obtain data from the terminal device.
[0180] In this step, the key management system does not find the terminal device data in the preset terminal device configuration table. The terminal device data includes the device identifier, the terminal device public key, and the preset key. This terminal device may be newly added, so it is necessary to obtain all terminal data to update the terminal device configuration table.
[0181] A company may contain multiple gateways, and different gateways may correspond to different factories, branches, etc. In some cases, network authentication is not universal across different factories or branches; that is, after authentication at branch A, internet access may still be unavailable at branch B. Therefore, it is necessary to obtain data on all terminal devices within the branch to which the gateway belongs.
[0182] A request to obtain terminal device data is generated and sent to the server of the branch office system to which the gateway belongs, based on the gateway identifier in the second request message.
[0183] Optionally, the key management system can be integrated with company systems (e.g., human resources systems, office automation systems) to enable direct access to and retrieval of terminal device information. This can be achieved by providing an API interface or by directly connecting to the company's system database.
[0184] Optionally, the key management system can also obtain gateway device information through the company system.
[0185] Optionally, the key management system can be located outside the company's local area network, and can be connected to an external key management system via a dedicated data line through the company's system.
[0186] S306. Locate and return terminal device data.
[0187] In this step, the company system receives a request from the key management system to retrieve terminal device data, searches for all terminal device data maintained by department personnel within the system, generates a response message, and returns it to the key management system.
[0188] It should be noted that when a user's terminal device needs to connect to the internet, it needs to apply within the company system and provide the terminal device identifier and the public key information of the terminal device used for internet access. After the company system approves the application, it will automatically configure a preset key for the terminal device.
[0189] S307. Update the configuration table of the terminal device based on the terminal device data.
[0190] S308. Based on the identifier of the terminal device, retrieve the data of the terminal device from the updated terminal device configuration table.
[0191] In this step, the terminal device is searched again in the updated terminal device configuration table based on the terminal device identifier. If the terminal device is still not found, it means that the device is not qualified to connect to the network, and a network verification failure response message is generated.
[0192] If the verification is successful, proceed to step S105.
[0193] S309. Send a response message indicating network verification failure to the gateway.
[0194] S310. Send a response message indicating network verification failure to the terminal device.
[0195] In this step, the gateway forwards the verification failure response message to the terminal device.
[0196] This embodiment provides a method for terminal devices to access a gateway based on a key management system. When the key management system verifies the identity of a terminal device, if verification fails, it obtains all terminal device data from the system of the gateway's parent company and updates the terminal device configuration table based on the obtained data. The terminal device identity is then verified again based on the updated configuration table. This method ensures that users can still access the gateway after changing their terminal devices.
[0197] Figure 5 A schematic diagram of a terminal device access gateway based on a key management system provided in this application is shown in Embodiment 1. Figure 5 As shown, the device 500 includes:
[0198] The receiving module 511 is configured to receive a first request message sent by the terminal device, the first request message being used to request the establishment of a communication channel with the gateway, and the first request message including the identifier of the terminal device;
[0199] The generation module 512 is configured to generate a second request message for obtaining the public key of the terminal device based on the first request message, and encrypt the second request message with a preset gateway key to obtain an encrypted second request message. The second request message includes the identifier of the terminal device and the IP of the gateway.
[0200] Sending module 513 is used to send the encrypted second request message to the key management system;
[0201] The receiving module 511 is further configured to receive first key information and second key information returned by the key management system, wherein the first key information includes the public key of the terminal device encrypted with a preset gateway key, and the second key information includes the public key of the terminal device encrypted with a preset terminal key.
[0202] Decryption module 514 is used to decrypt the first key information according to the gateway key to obtain the public key of the terminal device;
[0203] The encryption module 515 is used to obtain the public key of the gateway and encrypt the public key of the gateway using the public key of the terminal device to obtain the third key information;
[0204] The sending module 513 is further configured to send the second key information and the third key information to the terminal device.
[0205] Optionally, the receiving module 511 is further configured to receive a third request message sent by the terminal device, the third request message including a random number A encrypted with the public key of the gateway and a signature information of the random number A with the private key of the terminal device;
[0206] Optionally, the decryption module 514 is further configured to decrypt the encrypted random number A in the third request message according to the private key of the gateway to obtain the random number A;
[0207] Optionally, the device further includes:
[0208] Module 516 is used to obtain a random number B;
[0209] The session key generation module 517 is used to obtain the session key K based on the random number A, the random number B, the private key of the gateway, and the public key of the terminal device;
[0210] The sending module 513 is also used to send the signed and encrypted random number B and random number A to the terminal device.
[0211] The acquisition module 516 is specifically used for:
[0212] Receive the quantum random number B, encrypted with the gateway key, sent by the key management system;
[0213] Decrypting the encrypted quantum random number B yields another quantum random number B, which is the quantum random number B;
[0214] or,
[0215] The quantum random number B is generated randomly.
[0216] The terminal device access gateway based on the key management system provided in this embodiment is used to execute the technical solution on the gateway side of any of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0217] Figure 6 A schematic diagram of a second embodiment of a terminal device access gateway based on a key management system provided in this application is shown below. Figure 6 As shown, the device 600 includes:
[0218] The receiving module 611 is used to receive a second request message sent by the gateway and encrypted with a preset gateway key. The second request message is used to obtain the public key of the terminal device. The second request message includes the identifier of the terminal device and the IP of the gateway.
[0219] The acquisition module 612 is used to obtain the public key and the preset terminal key of the terminal device from a preset terminal device configuration table based on the identifier of the terminal device;
[0220] The encryption module 613 is used to encrypt the public key of the terminal device according to the preset gateway key to obtain the first key information, and to encrypt the public key of the terminal device according to the terminal key to obtain the second key information;
[0221] The sending module 614 is used to send the first key information and the second key information to the gateway according to the gateway's IP address.
[0222] Optionally, the device further includes:
[0223] The acquisition module 612 is also used to acquire all terminal device data within the company to which the gateway belongs, wherein the terminal device data includes the identifier of each terminal device, the public key of each terminal device, and the preset key of each terminal device;
[0224] The configuration update module 615 is used to update the configuration table of the terminal device according to the terminal device data.
[0225] Optionally, the device further includes:
[0226] Quantum random number module 616, used to generate quantum random number B;
[0227] The encryption module 613 is used to encrypt the quantum random number using the gateway key and send the encrypted quantum random number B to the gateway.
[0228] The terminal device access gateway based on the key management system provided in this embodiment is used to execute the technical solution on the key management system side of any of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0229] Figure 7 A schematic diagram of a third embodiment of a terminal device access gateway based on a key management system provided in this application is shown below. Figure 7 As shown, the device 700 includes:
[0230] The sending module 711 is used to send a first request message to the gateway in response to a user operation. The first request message is used to request the establishment of a communication channel with the gateway. The first request message includes the identifier of the terminal device.
[0231] The receiving module 712 is used to receive second key information and third key information returned by the gateway. The second key information includes the public key of the terminal device encrypted with a preset terminal key, and the third key information includes the public key of the gateway encrypted with the public key of the terminal device.
[0232] The decryption module 713 is used to decrypt the second key information and the third key information respectively to obtain the public key of the terminal device and the public key of the gateway.
[0233] Optionally, the device further includes:
[0234] Random number generation module 714 is used to generate random number A;
[0235] The sending module 711 is further configured to send a third request message to the gateway, the third request message including the random number A encrypted with the public key of the gateway and the signature information of the random number A with the private key of the terminal device;
[0236] The receiving module 712 is also used to receive the signature and encrypted random number B and random number A sent by the gateway;
[0237] The key generation module 715 is used to obtain the session key K based on the random number A, the random number B, the public key of the gateway, and the private key of the terminal device.
[0238] The terminal device access gateway based on the key management system provided in this embodiment is used to execute the technical solution on the terminal device side of any of the above method embodiments. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0239] Figure 8 A schematic diagram of the structure of an electronic device provided in this application, such as... Figure 8 As shown, the electronic device 800 includes:
[0240] The processor 811, the memory 812 communicatively connected to the processor, and the communication interface 813 for interacting with other devices;
[0241] The memory 812 stores computer-executed instructions;
[0242] The processor 811 executes computer execution instructions stored in the memory to implement the terminal device access gateway method based on the key management system described in any of the above method embodiments.
[0243] Optionally, the various devices described above in the electronic device 800 can be connected via a system bus.
[0244] The memory 812 can be a separate memory unit or a memory unit integrated into the processor 811. The number of processors 811 can be one or more.
[0245] It should be understood that the processor 811 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0246] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0247] All or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a readable memory. When the program is executed, it performs the steps of the above method embodiments; and the aforementioned memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof.
[0248] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method for accessing a terminal device access gateway based on a key management system as described in any of the foregoing method embodiments.
[0249] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory, electrically erasable programmable read-only memory, erasable programmable read-only memory, programmable read-only memory, read-only memory, magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0250] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium. When the at least one processor executes the computer program, it can implement the method for accessing a terminal device gateway based on a key management system as described in any of the foregoing method embodiments.
[0251] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0252] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for a terminal device to access a gateway based on a key management system, characterized in that, Applied to a gateway, the method includes: The terminal device receives a first request message, which requests the establishment of a communication channel with the gateway, and the first request message includes the identifier of the terminal device. Based on the first request message, a second request message for obtaining the public key of the terminal device is generated, and the second request message is encrypted with a preset gateway key to obtain an encrypted second request message. The second request message includes the identifier of the terminal device and the identifier IP of the gateway. The encrypted second request message is sent to the key management system; The system receives first key information and second key information returned by the key management system, wherein the first key information includes the public key of the terminal device encrypted with a preset gateway key, and the second key information includes the public key of the terminal device encrypted with a preset terminal key. The public key of the terminal device is obtained by decrypting the first key information using the gateway key. Obtain the public key of the gateway, and encrypt the public key of the gateway using the public key of the terminal device to obtain the third key information; The second key information and the third key information are sent to the terminal device.
2. The method according to claim 1, characterized in that, The method further includes: The terminal device receives a third request message, which includes a random number A encrypted with the public key of the gateway and a signature of the random number A with the private key of the terminal device. The encrypted random number A in the third request message is decrypted using the private key of the gateway to obtain the random number A. Get a random number B; Based on the random number A, the random number B, the private key of the gateway, and the public key of the terminal device, obtain the session key K; The signature and encrypted random number B and random number A are sent to the terminal device.
3. The method according to claim 2, characterized in that, The process of obtaining the random number B includes: Receive the quantum random number B, encrypted with the gateway key, sent by the key management system; Decrypting the encrypted quantum random number B yields another quantum random number B, which is the quantum random number B; or, The quantum random number B is generated randomly.
4. A method for a terminal device to access a gateway based on a key management system, characterized in that, Applied to a key management system, the method includes: The system receives a second request message sent by the gateway, which is encrypted using a preset gateway key. The second request message is used to obtain the public key of the terminal device. The second request message includes the identifier of the terminal device and the identifier IP of the gateway. Based on the identifier of the terminal device, obtain the public key and the preset terminal key of the terminal device from the preset terminal device configuration table; The public key of the terminal device is encrypted according to the preset gateway key to obtain the first key information, and the public key of the terminal device is encrypted according to the terminal key to obtain the second key information; Based on the gateway's IP address, the first key information and the second key information are sent to the gateway, causing the gateway to perform the following operations: decrypting the first key information using the gateway key to obtain the public key of the terminal device; obtaining the gateway's public key and encrypting it using the terminal device's public key to obtain third key information; sending the second key information and the third key information to the terminal device, so that the terminal device decrypts the second key information and the third key information respectively to obtain the terminal device's public key and the gateway's public key.
5. The method according to claim 4, characterized in that, The method further includes: Obtain all terminal device data within the company to which the gateway belongs, wherein the terminal device data includes the identifier of each terminal device, the public key of each terminal device, and the preset private key of each terminal device; The terminal device configuration table is updated based on the terminal device data.
6. The method according to claim 4 or 5, characterized in that, The method further includes: Generate quantum random number B; The quantum random number is encrypted using the gateway key, and the encrypted quantum random number B is sent to the gateway.
7. A method for a terminal device to access a gateway based on a key management system, characterized in that, Applied to a terminal device, the method includes: In response to a user operation, a first request message is sent to the gateway. The first request message is used to request the establishment of a communication channel with the gateway. The first request message includes the identifier of the terminal device. The system receives second key information and third key information returned by the gateway. The second key information includes the public key of the terminal device encrypted with a preset terminal key, and the third key information includes the public key of the gateway encrypted with the public key of the terminal device. The second key information and the third key information are decrypted respectively to obtain the public key of the terminal device and the public key of the gateway; In this process, the terminal device responds to a user operation by sending a first request message to the gateway. The gateway receives the first request message, generates an encrypted second request message, and sends it to the key management system. The key management system obtains the public key and a preset terminal key of the terminal device from a preset terminal device configuration table based on the second request message, generates first key information and second key information, and sends them to the gateway. This allows the gateway to decrypt the first key information, generate the third key information, and return it to the terminal device.
8. The method according to claim 7, characterized in that, The method further includes: Generate a random number A; Send a third request message to the gateway, the third request message including the random number A encrypted with the public key of the gateway and the signature information of the random number A with the private key of the terminal device; Receive the signature and encrypted random number B and random number A sent by the gateway; Based on the random number A, the random number B, the public key of the gateway, and the private key of the terminal device, obtain the session key K.
9. A device for connecting a terminal device to a gateway based on a key management system, characterized in that, The device includes: The receiving module is configured to receive a first request message sent by a terminal device, the first request message being used to request the establishment of a communication channel with the gateway, and the first request message including the identifier of the terminal device; The generation module is configured to generate a second request message for obtaining the public key of the terminal device based on the first request message, and encrypt the second request message with a preset gateway key to obtain an encrypted second request message. The second request message includes the identifier of the terminal device and the identifier IP of the gateway. The sending module is used to send the encrypted second request message to the key management system; The receiving module is further configured to receive first key information and second key information returned by the key management system, wherein the first key information includes the public key of the terminal device encrypted with a preset gateway key, and the second key information includes the public key of the terminal device encrypted with a preset terminal key. The decryption module is used to decrypt the first key information according to the gateway key to obtain the public key of the terminal device; An encryption module is used to obtain the public key of the gateway and encrypt the public key of the gateway using the public key of the terminal device to obtain third key information; The sending module is further configured to send the second key information and the third key information to the terminal device.
10. A device for connecting a terminal device to a gateway based on a key management system, characterized in that, The device includes: The receiving module is used to receive a second request message sent by the gateway, which is encrypted using a preset gateway key. The second request message is used to obtain the public key of the terminal device. The second request message includes the identifier of the terminal device and the identifier IP of the gateway. The acquisition module is used to obtain the public key and the preset terminal key of the terminal device from a preset terminal device configuration table based on the identifier of the terminal device; An encryption module is used to encrypt the public key of the terminal device according to a preset gateway key to obtain first key information, and to encrypt the public key of the terminal device according to the terminal key to obtain second key information; The sending module is configured to send the first key information and the second key information to the gateway according to the gateway's IP address, so that the gateway performs the following operations: decrypting the first key information according to the gateway key to obtain the public key of the terminal device; obtaining the public key of the gateway and encrypting the public key of the gateway with the public key of the terminal device to obtain the third key information; and sending the second key information and the third key information to the terminal device, so that the terminal device decrypts the second key information and the third key information respectively to obtain the public key of the terminal device and the public key of the gateway.
11. A device for connecting a terminal device to a gateway based on a key management system, characterized in that, The device includes: The sending module is used to send a first request message to the gateway in response to a user operation. The first request message is used to request the establishment of a communication channel with the gateway. The first request message includes the identifier of the terminal device. The receiving module is configured to receive second key information and third key information returned by the gateway. The second key information includes the public key of the terminal device encrypted with a preset terminal key, and the third key information includes the public key of the gateway encrypted with the public key of the terminal device. The decryption module is used to decrypt the second key information and the third key information respectively to obtain the public key of the terminal device and the public key of the gateway; In this embodiment, after the sending module sends a first request message to the gateway in response to a user operation, the gateway receives the first request message, generates an encrypted second request message, and sends it to the key management system. The key management system obtains the public key and a preset terminal key of the terminal device from a preset terminal device configuration table according to the second request message, and generates first key information and second key information, which are then sent to the gateway so that the gateway decrypts the first key information, generates the third key information, and returns it to the terminal device.
12. An electronic device, characterized in that, include: The processor, the memory communicatively connected to the processor, and the communication interface for interacting with other devices; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method for accessing a terminal device gateway based on a key management system as described in any one of claims 1 to 8.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method for accessing a terminal device gateway based on a key management system as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Secret key management method and device based on power gateway, medium and terminal equipment
CN111556064A
Lightweight authentication method based on equipment identity label and gateway
CN111835752A