A two-way authentication system, method, apparatus, device, and medium

Generating one-time keys using quantum key distribution devices solves the problems of difficult pre-shared key distribution and high security risks in existing technologies, enabling fast and secure two-way authentication and improving communication security.

CN117061100BActive Publication Date: 2026-04-14CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2023-08-03
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing two-way authentication technologies based on symmetric cryptography suffer from difficulties in distributing pre-shared keys and high security risks, resulting in high application costs and insufficient security.

Method used

A quantum key distribution device is used to generate a one-time key. Through key distribution between the communication device and the key device, a fast and secure two-way authentication process is achieved, and the two communicating parties do not need to share the key in advance or pre-share the key.

Benefits of technology

It achieves fast and efficient two-way authentication, improves security, prevents attackers from stealing key information, and reduces security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117061100B_ABST
    Figure CN117061100B_ABST
Patent Text Reader

Abstract

The application discloses a bidirectional authentication system, method, device, equipment and medium, which are used for fast, efficient and safe bidirectional authentication. The first communication equipment can send a first key application to the first key equipment, the first key equipment and the second key equipment perform key distribution, at least one target key is generated, and the first target key and the first target key identifier are sent to the first communication equipment; the first communication equipment generates first authentication data, and sends the first authentication data and the first target key identifier to the second communication equipment; the second communication equipment authenticates the first communication equipment, and if the authentication is passed, the second target key obtained from the second key equipment is used to generate second authentication data, and the second authentication data and the second target key identifier are sent to the first communication equipment; the first communication equipment authenticates the second communication equipment, and based on this, the purpose of fast, efficient and safe bidirectional authentication can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a two-way authentication system, method, apparatus, device, and medium. Background Technology

[0002] Two-way authentication verifies the true identities of both the sender and receiver of information and is a measure to protect network security. Existing authentication technologies mainly include password-based, biometric-based, and cryptographic-based authentication. Cryptographic-based authentication technologies include symmetric cryptography and public-key cryptography. Among these, two-way authentication based on symmetric cryptography primarily employs a pre-shared symmetric key approach. However, this approach faces challenges in distributing pre-shared symmetric keys. Even with a key center, the shared key between the communicating parties and the key center still requires pre-distribution manually, resulting in high application costs and security risks.

[0003] Therefore, there is an urgent need for a technical solution that can perform two-way authentication quickly, efficiently, and securely. Summary of the Invention

[0004] This application provides a two-way authentication system, method, apparatus, equipment, and medium for fast, efficient, and secure two-way authentication.

[0005] In a first aspect, this application provides a two-way authentication system, the system comprising:

[0006] A first communication device is used to send a first key request to a first key device, wherein the first key request carries a first communication device identifier and a second key device identifier corresponding to the second communication device obtained therefrom.

[0007] The first key device is configured to perform key distribution with a second key device corresponding to the second key device identifier, generate at least one target key, and send any first target key and a first target key identifier to the first communication device based on the first communication device identifier.

[0008] The first communication device is further configured to generate first authentication data based on the first target key, and send the first authentication data and the first target key identifier to the second communication device;

[0009] The second communication device is further configured to generate first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device, authenticate the first communication device based on the first authentication comparison data and the first authentication data, and if the authentication is successful, generate second authentication data based on the second target key obtained from the second key device, and send the second authentication data and the second target key identifier to the first communication device.

[0010] The first communication device is further configured to generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and to authenticate the second communication device based on the second authentication comparison data and the second authentication data.

[0011] Secondly, this application provides a two-way authentication method based on any one of the above-described systems, the method being applied to a first communication device, the method comprising:

[0012] A first key request is sent to a first key device, the first key request carrying a first communication device identifier and a second key device identifier corresponding to the second communication device; key distribution is then performed between the first key device and the second key device corresponding to the second key device identifier to generate at least one target key;

[0013] The system receives a first target key and a first target key identifier sent by the first key device; generates first authentication data based on the first target key, and sends the first authentication data and the first target key identifier to the second communication device; the second communication device generates first authentication comparison data based on the key of the first target key identifier obtained from the second key device, and authenticates the first communication device based on the first authentication comparison data and the first authentication data; if the authentication is successful, the second communication device generates second authentication data based on the second target key obtained from the second key device, and sends the second authentication data and the second target key identifier to the first communication device.

[0014] The system receives second authentication data and a second target key identifier sent by the second communication device, generates second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and authenticates the second communication device based on the second authentication comparison data and the second authentication data.

[0015] Thirdly, this application discloses a two-way authentication method based on any one of the above-described systems, the method being applied to a second communication device, the method comprising:

[0016] Based on the key corresponding to the first target key identifier obtained from the second key device, first authentication comparison data is generated. Based on the first authentication comparison data and the first authentication data received from the first communication device, the first communication device is authenticated.

[0017] If authentication is successful, second authentication data is generated based on the second target key obtained from the second key device, and the second authentication data and the second target key identifier are sent to the first communication device; the first communication device generates second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and the first communication device authenticates the second communication device based on the second authentication comparison data and the second authentication data.

[0018] Fourthly, this application discloses a two-way authentication method based on any one of the above-described systems, the method being applied to a first key device, the method comprising:

[0019] Receive a first key request sent by a first communication device, wherein the first key request carries the identifier of the first communication device and the identifier of the second key device corresponding to the second communication device;

[0020] Key distribution is performed between the key device and the second key device corresponding to the second key device identifier to generate at least one target key;

[0021] Based on the first communication device identifier, any first target key and the first target key identifier are sent to the first communication device.

[0022] Fifthly, this application discloses a two-way authentication method based on any one of the above-described systems, the method being applied to a second key device, the method comprising:

[0023] Receive a second key request sent by a second communication device, wherein the second key request carries a first key authorization code, a first target key identifier, and a second communication device identifier;

[0024] Based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm, a first key authorization comparison code is generated. If the first key authorization comparison code is consistent with the first key authorization code, and the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key application, then the first target key identifier and the first target key are sent to the second communication device corresponding to the second communication device identifier.

[0025] Sixthly, this application provides a two-way authentication device based on any one of the above-described systems, the device being applied to a first communication device, the device comprising:

[0026] A first sending module is configured to send a first key request to a first key device, the first key request carrying a first communication device identifier and a second key device identifier corresponding to the second communication device; to enable key distribution between the first key device and the second key device corresponding to the second key device identifier, and generate at least one target key;

[0027] A first receiving module is configured to receive a first target key and a first target key identifier sent by the first key device; generate first authentication data based on the first target key; send the first authentication data and the first target key identifier to the second communication device; enable the second communication device to generate first authentication comparison data based on the key of the first target key identifier obtained from the second key device; and enable the second communication device to authenticate the first communication device based on the first authentication comparison data and the first authentication data; if the authentication is successful, enable the second communication device to generate second authentication data based on the second target key obtained from the second key device; and send the second authentication data and the second target key identifier to the first communication device.

[0028] The first authentication module is configured to receive second authentication data and a second target key identifier sent by the second communication device, generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and authenticate the second communication device based on the second authentication comparison data and the second authentication data.

[0029] Seventhly, this application discloses a two-way authentication device based on any one of the preceding claims, the device being applied to a second communication device, the device comprising:

[0030] The second authentication module is used to generate first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device, and to authenticate the first communication device based on the first authentication comparison data and the first authentication data received from the first communication device.

[0031] The second sending module is configured to, if authentication is successful, generate second authentication data based on the second target key obtained from the second key device, and send the second authentication data and the second target key identifier to the first communication device; enable the first communication device to generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and enable the first communication device to authenticate the second communication device based on the second authentication comparison data and the second authentication data.

[0032] Eighthly, this application discloses a two-way authentication device based on any one of the preceding claims, the device being applied to a first key device, the device comprising:

[0033] The second receiving module is used to receive a first key request sent by the first communication device, wherein the first key request carries the identifier of the first communication device and the second key device identifier corresponding to the second communication device.

[0034] A key generation module is used to perform key distribution with a second key device corresponding to the second key device identifier, and generate at least one target key;

[0035] The third sending module is used to send any first target key and the first target key identifier to the first communication device based on the first communication device identifier.

[0036] Ninthly, this application discloses a two-way authentication device based on any one of the preceding claims, the device being applied to a second key device, the device comprising:

[0037] The second receiving module is used to receive a second key request sent by the second communication device, wherein the second key request carries a first key authorization code, a first target key identifier, and a second communication device identifier.

[0038] The comparison module is used to generate a first key authorization comparison code based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm. If the first key authorization comparison code is consistent with the first key authorization code, and the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key application, then the first target key identifier and the first target key are sent to the second communication device corresponding to the second communication device identifier.

[0039] In a tenth aspect, this application provides an electronic device comprising at least a processor and a memory, the processor being configured to execute a computer program stored in the memory to implement the steps of any of the methods described above.

[0040] In one aspect, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the methods described above.

[0041] Because this application allows the first and second communication devices to send key requests to the corresponding key device only each time two-way authentication is required, and the corresponding key device then generates and distributes the key, the two communicating parties (such as the first and second communication devices) do not need to share keys in advance or pre-share keys with trusted third parties. Therefore, it achieves fast, efficient, and secure two-way authentication. Furthermore, this application uses a newly generated (or newly requested) key for authentication each time two-way authentication is required, achieving "one authentication, one key." Compared to using a fixed key for a long period, this application can prevent attackers from stealing key information and has higher security. Attached Figure Description

[0042] To more clearly illustrate the implementation methods in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.

[0043] Figure 1 The diagram illustrates a two-way authentication system provided by some embodiments;

[0044] Figure 2 A schematic diagram of a first type of two-way authentication process provided by some embodiments is shown;

[0045] Figure 3 A schematic diagram of a second two-way authentication process provided by some embodiments is shown;

[0046] Figure 4 A schematic diagram of a third two-way authentication process provided by some embodiments is shown;

[0047] Figure 5 A schematic diagram of a fourth two-way authentication process provided in some embodiments is shown;

[0048] Figure 6 A schematic diagram of a fifth two-way authentication process provided in some embodiments is shown;

[0049] Figure 7 A schematic diagram of a sixth two-way authentication process provided in some embodiments is shown;

[0050] Figure 8 A schematic diagram of a seventh two-way authentication process provided in some embodiments is shown;

[0051] Figure 9 A schematic diagram of an eighth two-way authentication process provided in some embodiments is shown;

[0052] Figure 10 A schematic diagram of a first type of two-way authentication device provided in some embodiments is shown;

[0053] Figure 11 A schematic diagram of a second two-way authentication device provided in some embodiments is shown;

[0054] Figure 12 A schematic diagram of a third two-way authentication device provided in some embodiments is shown;

[0055] Figure 13 A schematic diagram of a fourth two-way authentication device provided in some embodiments is shown;

[0056] Figure 14 A schematic diagram of an electronic device structure provided by some embodiments is shown. Detailed Implementation

[0057] To enable fast, efficient, and secure two-way authentication, this application provides a two-way authentication system, method, apparatus, equipment, and medium.

[0058] To make the objectives and implementation methods of this application clearer, the exemplary implementation methods of this application will be clearly and completely described below with reference to the accompanying drawings of the exemplary embodiments of this application. Obviously, the exemplary embodiments described are only some embodiments of this application, and not all embodiments.

[0059] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.

[0060] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.

[0061] The terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclude inclusion, for example, a product or device that includes a range of components is not necessarily limited to all of the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.

[0062] The term "module" refers to any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.

[0063] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0064] Example 1:

[0065] Figure 1 The diagram illustrates a two-way authentication system provided by some embodiments, such as... Figure 1 As shown, the system includes:

[0066] The first communication device 11 is used to send a first key request to the first key device 12, wherein the first key request carries the identifier of the first communication device and the identifier of the second key device corresponding to the second communication device obtained;

[0067] The first key device 12 is used to perform key distribution with the second key device 14 corresponding to the second key device identifier, generate at least one target key, and send any first target key and the first target key identifier to the first communication device 11 based on the first communication device identifier;

[0068] The first communication device 11 is further configured to generate first authentication data based on the first target key, and send the first authentication data and the first target key identifier to the second communication device 13;

[0069] The second communication device 13 is further configured to generate first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device 14, authenticate the first communication device 11 based on the first authentication comparison data and the first authentication data, and if the authentication is successful, generate second authentication data based on the second target key obtained from the second key device 14, and send the second authentication data and the second target key identifier to the first communication device 11.

[0070] The first communication device 11 is further configured to generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device 12, and to authenticate the second communication device 13 based on the second authentication comparison data and the second authentication data.

[0071] In one possible implementation, the devices requiring two-way authentication are referred to as a first communication device 11 (e.g., communication device-A) and a second communication device 13 (e.g., communication device-B). For fast, efficient, and secure two-way authentication, the first communication device 11 corresponds to a first key device 12 (e.g., QKD device-X), and the second communication device 13 corresponds to a second key device 14 (e.g., QKD device-Y). Optionally, the first communication device and the first key device can be directly connected via a dedicated line, located within the same security domain, which can effectively improve communication security. Similarly, the second communication device and the second key device can also be directly connected via a dedicated line, located within the same security domain. The communication devices and key devices can pre-trust and exchange relevant communication device information, key device information, information transmission protocols, encryption / decryption algorithms, initial keys, and key update strategies, ensuring that keys such as quantum keys are not transmitted in plaintext. Optionally, considering that public-key cryptography algorithms may be affected by quantum computing, in order to improve the security of the authentication process, the key devices (first key device 12 and second key device 14) in this application can be quantum key distribution (QKD) devices.

[0072] When two-way authentication is required between the first communication device 11 (communication device-A) and the second communication device 13 (communication device-B), the first communication device 11 can first send an authentication request to the second communication device 13. This authentication request can carry the identifier of the first communication device (first communication device identifier, such as ID). A The communication equipment identifier can be flexibly set according to requirements, and this application does not impose specific limitations on it.

[0073] After receiving the authentication request sent by the first communication device 11, the second communication device 13 can return a challenge message to the first communication device 11. This challenge message may contain the identifier of the second communication device 13 itself (second communication device identifier, such as ID). B ) and the second key device identifier (such as ID) corresponding to the second communication device 13. Y ).

[0074] After receiving the challenge information returned by the second communication device 13, the first communication device 11 can send a first key request to the first key device 12 (such as QKD device-X) with which a pre-established connection has been established. The first key request may carry the identifier of the first communication device (such as ID). A ) and the second key device identifier (such as ID) Y ).

[0075] After receiving the first key request, the first key device 12 (such as QKD device-X) and the second key device 14 can perform key distribution, such as a quantum key distribution process, to generate at least one target key, for example, several quantum keys. The key distribution process between the first key device 12 and the second key device 14 can employ existing technology and will not be elaborated further here. Both the first key device 12 and the second key device 14 can store these target keys.

[0076] The first key device 12 (e.g., QKD device-X) can generate any one of several target keys (for ease of description, referred to as the first target key, such as QK1) and the identifier corresponding to the first target key (first target key identifier, such as ID). QK1 The first target key is sent to the first communication device 11. To ensure key security, the first key device 12 can use a pre-defined first encryption algorithm to secure the first target key QK1 and the first target key identifier ID. QK1 Encryption is performed, and the encrypted first target key QK1 and the first target key identifier ID are used. QK1 Send to the first communication device 11.

[0077] After receiving the first target key and the first target key identifier encrypted using the first encryption algorithm, the first communication device 11 can use the first decryption algorithm corresponding to the first encryption algorithm to decrypt the first target key QK1 and the first target key identifier ID. QK1 After decryption, the decrypted first target key QK1 and the first target key identifier ID are obtained. QK1 The first communication device 11 can generate first authentication data based on a first target key. Optionally, the first communication device 11 can generate first authentication data based on the first target key and a set authentication data encryption algorithm. For example, the first communication device 11 can identify the first communication device ID based on the first target key QK1 and the set authentication data encryption algorithm. A (Local Communication Device Identifier), Secondary Communication Device Identifier ID B Encryption calculations are performed on the (peer communication device identifier) ​​to generate the first authentication data. The cryptographic encryption algorithm used in the authentication data encryption algorithm can be a keyed-hash message authentication code (HMAC), block cipher, stream cipher, or other verifiable encryption techniques. The cryptographic encryption algorithm is denoted by E, and can be used to encrypt the first communication device identifier ID based on the first target key QK1 and the set authentication data encryption algorithm E. A Second communication device identifier ID BPerform encrypted calculations to generate the first authentication data: Token1 = E QK1 (ID A ||ID B When the cryptographic encryption algorithm is HMAC, the first communication device identifier ID can be determined based on the first target key QK1 and HMAC. A Second communication device identifier ID B Perform encrypted calculations to obtain the first authentication data: Token1 = HMAC(QK1, ID) A ||ID B Other methods can also be used to obtain the first authentication data, which will not be elaborated here but will be described in detail in subsequent embodiments.

[0078] Optionally, after generating the first authentication data Token1, the first communication device 11 can transmit the first authentication data and the first target key identifier ID. QK1 Send to the second communication device 13.

[0079] Optionally, after receiving the first authentication data and the first target key identifier, the second communication device 13 can send a key request to the second key device 14 to obtain the key corresponding to the first target key identifier. The second key device 14 can use a pre-defined second encryption algorithm to encrypt the key corresponding to the first target key identifier and send the encrypted key to the second communication device 13. The second communication device 13 can also obtain the key of the first target key identifier from the second key device 14 in other ways, which will not be elaborated here but will be described in detail in subsequent embodiments.

[0080] The second communication device 13 can use a second decryption algorithm corresponding to the second encryption algorithm to decrypt the key corresponding to the first target key identifier after encryption by the second encryption algorithm, thereby obtaining the key corresponding to the first target key identifier (the first target key). The second communication device 13 can generate first authentication comparison data based on the first target key. For example, similar to the process of the first communication device 11 generating first authentication data, the second communication device 13 can generate first authentication comparison data based on the first target key and a set authentication data encryption algorithm. For example, the second communication device 13 can encrypt the first communication device identifier ID based on the first target key QK1 and the set authentication data encryption algorithm. A Second communication device identifier ID B Perform encrypted calculations to generate the first authentication comparison data. For example, the first authentication comparison data can be represented as: E QK1 (ID A ||ID B ), or HMAC(QK1, ID A||ID B Other methods, such as [list of methods], will not be elaborated upon here. Additionally, the second communication device 13 can also obtain the first authentication comparison data through other means, which will not be detailed here but will be described in detail in subsequent embodiments.

[0081] The second communication device 13 generates the first authentication comparison data (such as HMAC(QK1, ID)). A ||ID B After that, the first authentication comparison data can be compared with the received first authentication data (Token1 = HMAC(QK1, ID)). A ||ID B A comparison is performed, and the first communication device 11 is authenticated based on the comparison result. Specifically, if the comparison result shows that the two are consistent, the first communication device 11 can be considered a secure device, and the authentication of the first communication device 11 can be passed. If the comparison result shows that the two are inconsistent, the first communication device 11 can be considered insecure, and the authentication of the first communication device 11 can fail. For example, an authentication failure prompt message can be sent to the first communication device 11.

[0082] Optionally, after the second communication device 13 authenticates the first communication device 11, the second communication device 13 can generate second authentication data, thereby enabling the first communication device 11 to authenticate the second communication device 13 based on the second authentication data. Specifically, the second communication device 13 can generate the second authentication data based on the target key obtained from the second key device 14. The target key used by the second communication device 13 to generate the second authentication data can be the same as the first target key, or it can be two different keys. For ease of description, the target key used by the second communication device 13 to generate the second authentication data is called the second target key. When the second target key and the first target key are the same key, the second target key is represented by QK1; when the second target key and the first target key are two different keys, the second target key is represented by QK2. When the second target key and the first target key are the same key, the second communication device 13 can directly generate the second authentication data based on the key QK1 already obtained from the second key device 14. When the second target key and the first target key are two different keys, the second communication device 13 can send a key acquisition request to the second key device 14 again. The second key device 14 can then send the second communication device 13 a target key QK2 and the key identifier ID of that target key. QK2 .

[0083] Optionally, after generating the second authentication data, the second communication device 13 can send the second authentication data and the second target key identifier to the first communication device 11. The first communication device 11 can generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device 12. The process of generating the second authentication comparison data is similar to the process of generating the first authentication data; for example, it can generate the second authentication comparison data based on the key (second target key) corresponding to the second target key identifier obtained from the first key device 12. For example, the first communication device 11 can generate the second authentication comparison data based on the second target key and a set authentication data encryption algorithm. For example, the first communication device 11 can identify the second communication device ID based on the second target key and a set authentication data encryption algorithm. B (Peer communication device identifier), First communication device identifier ID A (The local communication device identifier) ​​is used for encryption calculation to generate second authentication comparison data. For example, when the second target key is the same as the first target key, the second authentication comparison data can be E. QK1 (ID B ||ID A ), or, HMAC(QK1, ID B ||ID A When the second target key is different from the first target key, the second authentication comparison data can be E. QK2 (ID B ||ID A ), or, HMAC(QK2, ID B ||ID A Other methods can also be used to obtain the second authentication comparison data, which will not be elaborated here but will be described in detail in subsequent embodiments.

[0084] The first communication device 11 can compare the second authentication comparison data with the second authentication data, and authenticate the second communication device 13 based on the comparison result. Optionally, when the comparison result is consistent, the second communication device 13 can be authenticated; when the comparison result is inconsistent, the second communication device 13 can be unauthenticated.

[0085] Because this application allows the first and second communication devices to send a key request to the corresponding key device only each time two-way authentication is required, and the corresponding key device then generates and distributes the key, the two communicating parties (the first and second communication devices) do not need to share keys in advance or pre-share keys with trusted third parties. Therefore, it achieves fast, efficient, and secure two-way authentication. Furthermore, this application uses a newly generated (or newly requested) key for authentication each time two-way authentication is required, achieving "one-time authentication, one-key." Compared to using a fixed key for a long period, this application can prevent attackers from stealing key information and has higher security.

[0086] Example 2:

[0087] To improve security, based on the above embodiments, in this application embodiment, the second communication device 13 is further configured to send the obtained first random factor to the first communication device 11;

[0088] The first communication device 11 is specifically used to generate first authentication data based on the first target key, the first random factor, and the set authentication data encryption algorithm;

[0089] The second communication device 13 is specifically used to generate first authentication comparison data based on the first random factor, the set authentication data encryption algorithm, and the key corresponding to the first target key identifier obtained from the second key device 14.

[0090] In one possible implementation, after receiving the authentication request sent by the first communication device 11, when the second communication device 13 returns challenge information to the first communication device 11, the challenge information may include, in addition to the second communication device identifier (ID), B ) and the second key device identifier (such as ID) corresponding to the second communication device 13. Y In addition to the first random number R, the second communication device 13 may also include a first random factor, that is, the second communication device 13 may also send the first random factor to the first communication device 11. The first random factor may be a random number R, a counter currently generated by the counter, a timestamp, or other information that can be shared, etc., and this application does not specifically limit it.

[0091] Optionally, the first communication device 11 receives a data containing a first random factor and a second communication device identifier (ID). B ) and the second key device identifier (such as ID) corresponding to the second communication device 13. YAfter receiving the challenge information, the first key device 12 can send a first key request to the first key device 12. After receiving the first key request, the first key device 12 can perform key distribution with the second key device 14 corresponding to the second key device identifier to generate at least one target key; and can send the first target key encrypted with the first encryption algorithm and the first target key identifier to the first communication device 11, which will not be elaborated here.

[0092] Optionally, to improve security, after receiving the first target key, the first communication device 11 can generate the first authentication data based on the first target key, a first random factor, and a set authentication data encryption algorithm. For example, taking the first random factor as a random number R1, the first authentication data can be generated by encrypting the first random factor, the first communication device identifier, and the second communication device identifier based on the first target key and the set authentication data encryption algorithm. For example, the first authentication data Token1 can be represented as: HMAC(QK1, R1||ID) A ||ID B Alternatively, Token1 can also be represented as: E QK1 (R1||ID A ||ID B (This will not be elaborated upon here.)

[0093] For another example, taking the counter generated by the first random factor as counter1, the first authentication data Token1 can be represented as: HMAC(QK1, counter1||ID) A ||ID B Alternatively, Token1 can also be identified as: E QK1 (counter1||ID A ||ID B For another example, taking the first random factor as the timestamp (timestamp1), the first authentication data Token1 can be represented as: HMAC(QK1, timestamp1||ID) A ||ID B Alternatively, Token1 can also be represented as: E QK1 (timestamp1||ID A ||ID B ).

[0094] Optionally, when generating the first authentication comparison data, the second communication device 13 may also generate the first authentication comparison data based on a first random factor (such as R1), a set authentication data encryption algorithm, and the key corresponding to the first target key identifier (first target key) obtained from the second key device 14. The process of generating the first authentication comparison data is similar to the process of generating the first authentication data. For example, the first authentication comparison data can be represented as: HMAC(QK1, R1||ID) A ||ID B E QK1 (R1||ID A ||ID B HMAC(QK1, counter1||ID) A ||ID B E QK1 (counter1||ID A ||ID B HMAC(QK1, timestamp1||ID) A ||ID B ), or E QK1 (timestamp1||ID A ||ID B (etc.) will not be elaborated here.

[0095] After generating the first authentication comparison data, the second communication device 13 can compare the first authentication comparison data with the first authentication data to authenticate the first communication device 11. The process of authenticating the first communication device 11 is the same as in the above embodiment and will not be described again here.

[0096] Since this application can generate first authentication data and first authentication comparison data based on a first random factor, the security of the authentication process can be further improved.

[0097] Example 4:

[0098] To improve the security of the authentication process, based on the above embodiments, in this embodiment of the application, the first communication device 11 is further configured to send the obtained second random factor to the second communication device 13;

[0099] The second communication device 13 is specifically used to generate second authentication data based on the second random factor, the set authentication data encryption algorithm, and the second target key obtained from the second key device 14;

[0100] The first communication device 11 is specifically used to generate second authentication comparison data based on the second random factor, the set authentication data encryption algorithm, and the key corresponding to the second target key identifier obtained from the first key device 12.

[0101] In one possible implementation, the first communication device 11 can send not only the first authentication data and the first target key identifier to the second communication device 13, but also the obtained second random factor. For example, the first communication device 11 can send the generated second random factor to the second communication device 13 simultaneously with the first authentication data and the first target key identifier. The second random factor can be a random number R, a counter generated by a counter, a timestamp, or other shareable information; this application does not specifically limit its application in this regard.

[0102] Optionally, to improve security, after receiving the second random factor, the second communication device 13 can generate the second authentication data based on the second target key, the second random factor, and a set authentication data encryption algorithm when generating the second authentication data. For example, taking the second random factor as a random number R2, the second authentication data can be generated by encrypting the second random factor, the second communication device identifier, and the first communication device identifier based on the second target key and the set authentication data encryption algorithm. For example, when the second target key is the same as the first target key, the second authentication data Token2 can be: HMAC(QK1, R2||ID) B ||ID A E QK1 (R2||ID B ||ID A HMAC(QK1, counter2||ID) B ||ID A E QK1 (counter2||ID B ||ID A HMAC(QK1, timestamp2||ID) B ||ID A E QK1 (timestamp2||ID B ||ID A )wait.

[0103] For another example, when the second target key is different from the first target key, the second authentication data Token2 can be: HMAC(QK2, R2||ID) B ||IDA E QK2 (R2||ID B ||ID A HMAC(QK2, counter2||ID) B ||ID A E QK2 (counter2||ID B ||ID A HMAC(QK2, timestamp2||ID) B ||ID A E QK2 (timestamp2||ID B ||ID A )wait.

[0104] Optionally, when generating the second authentication comparison data, the first communication device 11 may also generate the second authentication comparison data based on a second random factor (such as R2), a set authentication data encryption algorithm, and the key corresponding to the second target key identifier (the second target key) obtained from the first key device 12. The process of generating the second authentication comparison data is similar to the process of generating the second authentication data. For example, the second authentication comparison data can be: HMAC(QK1, R2||ID) B ||ID A (etc.) will not be elaborated here.

[0105] The process of generating the second authentication comparison data and then comparing it with the second authentication data to authenticate the second communication device 13 is the same as in the above embodiment, and will not be repeated here.

[0106] Since this application can generate second authentication data and second authentication comparison data based on a second random factor, the security of the authentication process can be further improved.

[0107] To facilitate understanding, the two-way authentication process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 2 , Figure 2 The diagram illustrates a first type of two-way authentication process provided by some embodiments, which includes the following steps:

[0108] S201: The first communication device (communication device-A) sends an authentication request to the second communication device (communication device-B), the authentication request carrying the identifier ID of the first communication device. A .

[0109] S202: The second communication device receives the authentication request and returns challenge information to the first communication device, the challenge information containing the second communication device's identifier ID.B The second key device identifier ID corresponding to the second communication device Y The first random factor R1.

[0110] S203: The first communication device sends a first key request to the first key device (QKD device-X), the first key request carrying the identification ID of the first communication device. A and the second key device identifier ID corresponding to the second communication device obtained Y .

[0111] S204: The first key device (QKD device-X) and the second key device (QKD device-Y) with the corresponding second key device identifier perform key distribution to generate at least one target key.

[0112] S205: The first key device (QKD device-X) uses the first communication device identifier to encrypt the first target key QK1 and the first target key identifier ID using the first encryption algorithm. QK1 Send to the first communication device.

[0113] S206: The first communication device uses a first decryption algorithm corresponding to the first encryption algorithm to encrypt the first target key QK1 and the first target key identifier ID. QK1 Decryption is performed to obtain the decrypted first target key QK1 and the first target key identifier ID. QK1 Based on the first target key, the first random factor, and the set authentication data encryption algorithm, the first authentication data Token1 is generated (e.g., HMAC(QK1, R1||ID)). A ||ID B The first authentication data Token1, the second random factor R2, and the first target key identifier ID are used. QK1 Send to the second communication device.

[0114] S207: The second communication device generates first authentication comparison data based on the key (QK1) corresponding to the first target key identifier obtained from the second key device, and compares the first authentication comparison data with the first authentication data. If they match, the first communication device is authenticated. Then, based on the second random factor, the set authentication data encryption algorithm, and the second target key obtained from the second key device, it generates second authentication data Token2 (e.g., HMAC(QK2, R2||ID)). B ||ID A The second authentication data and the second target key identifier ID will be used. QK2 Send to the first communication device.

[0115] S208: The first communication device generates second authentication comparison data based on the key QK2 corresponding to the second target key identifier obtained from the first key device, and compares whether the second authentication comparison data is consistent with the second authentication data. If they are consistent, the second communication device is authenticated.

[0116] Example 5:

[0117] To improve security, based on the above embodiments, in this application embodiment, the first communication device 11 is further configured to generate a first key authorization code based on the first target key, the second communication device identifier and the set key authorization code encryption algorithm, and send the first key authorization code to the second communication device 13;

[0118] The second communication device 13 is also used to send a second key request to the second key device 14, wherein the second key request carries the first key authorization code, the first target key identifier, and the second communication device identifier;

[0119] The second key device 14 is further configured to receive the second key application, generate a first key authorization comparison code based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm, and if the first key authorization comparison code is consistent with the first key authorization code, and the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key application, then the first target key identifier and the first target key are sent to the second communication device 13 corresponding to the second communication device identifier.

[0120] In one possible implementation, considering that the same key device may serve multiple communication devices simultaneously—for example, QKD device-Y can serve communication device B while also serving other communication devices, such as communication device-C—to prevent other communication devices, such as communication device-C, from obtaining the first target key QK1 from QKD device-Y and to ensure the security of the authentication process, the first communication device 11 can also base its authentication on the first target key QK1 and the second communication device identifier ID. B The system sets up a key authorization code encryption algorithm, generates a first key authorization code, and sends the first key authorization code to the second communication device 13. This allows the second communication device 13 to send the first key authorization code to the second key device 14 when requesting the first key. The second key device 14 then verifies the second communication device 13 based on the first key authorization code. Only after successful verification is the first target key sent to the second communication device 13, thus ensuring the security of the authentication process.

[0121] Specifically, when generating the first key authorization code, the first key authorization code can be generated by encrypting the second communication device identifier based on the first target key and the set key authorization code encryption algorithm. For example, the first key authorization code KeyAuth1 can be: HMAC(QK1, ID) B Optionally, the encryption algorithm used in the key authorization code encryption algorithm can be HMAC, or it can be a block cipher such as Advanced Encryption Standard (AES) or SM4, or a stream cipher such as ZUC or RC4, or a verifiable encryption technology such as AES-CCM (Counter with CBC-MAC), AES-GCM (Galois / Counter Mode), SM4-CCM, or SM4-GCM. Similar to the authentication data and authentication comparison data in the above embodiments, the first key authorization code KeyAuth1 can also be represented as: E QK1 (ID B (This will not be elaborated further here.) Additionally, when generating the first key authorization code, the second communication device identifier ID can also be included. B The first key authorization code is generated by encrypting the first target key and the set key authorization code encryption algorithm together with the corresponding session identifier and other obtainable information. This application does not specify the generation method of the key authorization code or the information contained therein.

[0122] Optionally, after generating the first key authorization code, the first communication device 11 can send the first key authorization code to the second communication device 13. For example, the first communication device 11 can send a first target key identifier ID to the second communication device 13. QK1 When the first authentication data Token1 and the second random factor R2 are received, the first key authorization code KeyAuth1 is sent to the second communication device 13.

[0123] After receiving the first key authorization code, the second communication device 13 can send a second key request to the second key device 14. The second key request may carry the first key authorization code KeyAuth1 and the first target key identifier ID. QK1 and the second communication device identifier ID B .

[0124] Optionally, after receiving the second key request, the second key device 14 can obtain the second communication device identifier ID carried in the second key request. B The second key device 14 can be based on the key QK1 corresponding to the first target key identifier and the second communication device identifier ID. BThe system uses a predefined key authorization code encryption algorithm to generate a first key authorization comparison code. The process of generating the key authorization comparison code is similar to that of generating the key authorization code, and will not be repeated here. For example, the first key authorization comparison code can be represented as HMAC(QK1, ID). B ) or E QK1 (ID B ).

[0125] Optionally, after generating the first key authorization comparison code, the second key device 14 can compare the generated first key authorization comparison code with the received first key authorization code. If the generated first key authorization code is consistent with the received first key authorization code, in order to ensure security, the second key device 14 can further determine whether the communication device identifier used to generate the first key authorization code is the same as the identifier of the communication device that sent the second key application to it. If the communication device identifier used to generate the first key authorization code is the same as the identifier of the communication device that sent the second key application to it, it can be considered that the communication device corresponding to the second communication device identifier is indeed a secure device that requires the first target key, and the first target key and the corresponding first target key identifier can be sent to the second communication device 13 together.

[0126] For ease of understanding, the two-way authentication process provided in this application will be explained and illustrated below through a specific embodiment. In this embodiment, the first target key and the second target key are the same key, and for ease of description, both are referred to as the target key. Figure 3 The diagram illustrates a second two-way authentication process provided by some embodiments. Figure 4 A schematic diagram of a third two-way authentication process provided by some embodiments is shown below. Figure 3 and Figure 4 The process includes the following steps:

[0127] S300: The first communication device (communication device-A) sends a QKD service registration request to the first key device (QKD device-X). In response to the QKD service registration request, the first key device (QKD device-X) registers the first communication device for QKD service. Similarly, the second communication device (communication device-B) sends a QKD service registration request to the first key device (QKD device-Y). In response to the QKD service registration request, the second key device (QKD device-Y) registers the second communication device for QKD service.

[0128] The first communication device and the first key device can be directly connected via a dedicated line, located within the same security domain, which effectively enhances communication security. Similarly, the second communication device and the second key device can also be directly connected via a dedicated line, located within the same security domain. During QKD service registration for the communication devices, the communication devices and key devices can mutually trust and exchange relevant communication device information, key device information, information transmission protocols, encryption / decryption algorithms, initial keys, and key update strategies, ensuring that quantum keys and other keys are not transmitted in plaintext. The QKD service registration process can utilize existing technologies and will not be elaborated upon here.

[0129] S301: The first communication device (communication device-A) sends an authentication request to the second communication device (communication device-B), the authentication request carrying the first communication device identifier ID. A .

[0130] S302: The second communication device (communication device-B) receives the authentication request and returns challenge information to the first communication device, the challenge information containing the second communication device identifier ID. B The first random factor R1 and the second key device identifier ID corresponding to the second communication device. Y .

[0131] S303: The first communication device (communication device-A) sends a first key request to the first key device (QKD device-X) to request a quantum key. The first key request carries the identification ID of the first communication device. A and the second key device identifier ID corresponding to the second communication device obtained Y .

[0132] S304: The first key device (QKD device-X) performs key distribution (such as quantum key distribution) with the second key device (QKD device-Y) corresponding to the second key device identifier, and generates the target key.

[0133] S305: The first key device (QKD device-X) uses the first communication device identifier to encrypt the target key QK and the target key identifier ID using the first encryption algorithm. QK Send to the first communication device (communication device-A).

[0134] S305 can also be referred to as the quantum key distribution process.

[0135] S306: The first communication device (communication device-A) uses the first decryption algorithm to encrypt the target key QK and the target key identifier ID. QK Decryption is performed to obtain the decrypted target key QK and target key identifier ID. QKThe first communication device generates first authentication data Token1 (e.g., HMAC(QK, R1||ID)) based on the target key QK, the first random factor R1, and the set authentication data encryption algorithm. A ||ID B Simultaneously, the first communication device can generate a first key authorization code KeyAuth1 (e.g., HMAC(QK, ID)) based on the target key, the second communication device identifier, and a set key authorization code encryption algorithm. B The first communication device will send the first key authorization code KeyAuth1, the first authentication data Token1, the second random factor R2, and the target key identifier (quantum key identifier) ​​ID. QK Send (response) to the second communication device (communication device-B).

[0136] S307: The second communication device (communication device-B) sends a request to the second key device (QKD device-Y) to obtain the second key. The second key request carries the first key authorization code KeyAuth1 and the target key identifier ID. QK Second communication device identifier ID B .

[0137] S308: The second key device (QKD device-Y) receives the second key request, verifies the validity of the first authorization code, and if the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key request, it will use the second encryption algorithm to encrypt the target key identifier ID. QK The target key QK is sent to the second communication device.

[0138] The process of verifying the validity of the first authorization code is as follows: the second key device generates a first key authorization comparison code based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm. If the generated first key authorization comparison code is consistent with the first key authorization code, then the first authorization code is determined to be valid.

[0139] Understandably, if the generated key authorization comparison code does not match the first key authorization code, then verifying the first key authorization code is invalid, and the target key identifier ID does not need to be set. QK The target key QK is sent to the second communication device.

[0140] S308 can also be referred to as the quantum key distribution process.

[0141] S309: The second communication device (communication device-B) uses the second decryption algorithm to identify the ID of the encrypted target key. QK Decrypt the target key QK to obtain the decrypted target key identifier ID. QKThe second communication device generates first authentication comparison data based on the key QK corresponding to the target key identifier, the first random factor R1, and the set authentication data encryption algorithm. The first authentication comparison data is compared with the first authentication data. If the first authentication comparison data and the first authentication data are consistent, the first communication device is authenticated, that is, the authentication result is passed.

[0142] S310: The second communication device (communication device-B) generates second authentication data Token2 (e.g., HMAC(QK, R2||ID)) based on the target key QK, the second random factor R2, and the set authentication data encryption algorithm. B ||ID A )) , will include the second authentication data Token2 and the target key identifier ID QK Send (response) to the first communication device.

[0143] S311: The first communication device (communication device-A) generates second authentication comparison data based on the key QK corresponding to the target key identifier, the second random factor R2, and the set authentication data encryption algorithm. The second authentication comparison data is compared with the received second authentication data Token2. If the second authentication comparison data is consistent with the received second authentication data Token2, the second communication device is authenticated, that is, the authentication result is passed.

[0144] Please refer to it again. Figure 4 The communication device may include a key authorization code generation module, a QKD service registration module, and a quantum key request module. The key authorization code generation module can generate a key authorization code. The QKD service registration module sends a QKD service registration request to the key device, completing the initial mutual trust and communication between the communication device and the QKD device. The quantum key request module sends a key request to the key device, etc., which will not be elaborated here. The key device (such as a QKD device) may include a key authorization code verification module. The key authorization code generation module can verify the validity of the key authorization code, etc., which will not be elaborated here.

[0145] The cryptographic encryption algorithm used in the authentication data encryption algorithm of this application is not limited to a keyed hash function (HMAC), nor does it require pre-sharing of keys between communication devices. Communication devices do not need to have QKD capabilities; instead, they use QKD services through QKD devices, requiring minimal modification to the communication devices and applicable to a wide range of scenarios.

[0146] In this application, the quantum key (target key) can be used for encryption and decryption, or it can be used as a symmetric key when generating authentication data by requesting a new real-time quantum key from the QKD device each time two-way authentication is required. In this application, the target key can be deleted after one two-way authentication is completed and is only used for one two-way authentication, achieving "one authentication, one key". This can prevent attackers from stealing key information and has higher security than using the same key for a long time.

[0147] Furthermore, since the communicating parties in this application do not need to share keys in advance, or pre-share keys with trusted third parties respectively, but instead obtain a consistent real-time target key (such as a quantum key) from their respective corresponding key devices (QKD devices), the difficulty of key management is not affected even if the number of communicating devices increases. The two-way authentication method of this application can be applied to two-way authentication between communication devices such as data centers and high-security leased line nodes.

[0148] For ease of understanding, the two-way authentication process provided in this application will be explained below through a specific embodiment. In this embodiment, the first target key and the second target key are different keys. (See also...) Figure 5 , Figure 5 The diagram illustrates a fourth two-way authentication process provided by some embodiments, which includes the following steps:

[0149] S500: The first communication device (communication device-A) sends a QKD service registration request to the first key device (QKD device-X). In response to the QKD service registration request, the first key device (QKD device-X) registers the first communication device for QKD service. Similarly, the second communication device (communication device-B) sends a QKD service registration request to the first key device (QKD device-Y). In response to the QKD service registration request, the second key device (QKD device-Y) registers the second communication device for QKD service.

[0150] S501: The first communication device (communication device-A) sends an authentication request to the second communication device (communication device-B), the authentication request carrying the first communication device identifier ID. A .

[0151] S502: The second communication device (communication device-B) receives the authentication request and returns challenge information to the first communication device, the challenge information containing the second communication device identifier ID. B The first random factor R1 and the second key device identifier ID corresponding to the second communication device. Y .

[0152] S503: The first communication device (communication device-A) sends a first key request to the first key device (QKD device-X) to request a quantum key. The first key request carries the identification ID of the first communication device. A and the second key device identifier ID corresponding to the second communication device obtained Y .

[0153] S504: The first key device (QKD device-X) and the second key device (QKD device-Y) corresponding to the second key device identifier perform key distribution to generate at least one target key.

[0154] S505: The first key device (QKD device-X) uses the first communication device identifier to encrypt the first target key QK1 and the first target key identifier ID using the first encryption algorithm. QK1 Send to the first communication device (communication device-A).

[0155] S506: The first communication device (communication device-A) receives the first target key QK1 and the first target key identifier ID encrypted using the set first encryption algorithm. QK1 Then, the first decryption algorithm corresponding to the first encryption algorithm can be used to decrypt the first target key QK1 and the first target key identifier ID. QK1 After decryption, the decrypted first target key QK1 and the first target key identifier ID are obtained. QK1 The first communication device generates first authentication data Token1 (e.g., HMAC(QK1, R1||ID)) based on the first target key QK1, the first random factor R1, and the set authentication data encryption algorithm. A ||ID B Simultaneously, the first communication device can generate a first key authorization code KeyAuth1 (e.g., HMAC(QK1, ID)) based on the first target key, the second communication device identifier, and a set key authorization code encryption algorithm. B The first communication device will send the first key authorization code KeyAuth1, the first authentication data Token1, the second random factor R2, and the target key identifier ID. QK Send to the second communication device (communication device-B).

[0156] S507: The second communication device (communication device-B) sends a second key request to the second key device (QKD device-Y), the second key request carrying the first key authorization code KeyAuth1 and the first target key identifier ID. QK1 Second communication device identifier ID B .

[0157] The second communication device can use a pre-defined second encryption algorithm to authenticate the first key authorization code KeyAuth1 and the first target key identifier ID. QK1 Second communication device identifier ID B Encryption is performed, and the encrypted first key authorization code KeyAuth1 and the first target key identifier ID are used. QK1 Second communication device identifier ID B Send to the second key device.

[0158] S508: The second key device (QKD device-Y) receives the second key request, verifies the validity of the first authorization code, and if the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key request, it will use the second encryption algorithm to encrypt the first target key identifier ID. QK1 The first target key QK1 is sent to the second communication device. Simultaneously, the second target key identifier ID, encrypted using the second encryption algorithm, can also be sent. QK2 The second target key QK2 is sent together to the second communication device.

[0159] The second key device can employ a second decryption algorithm corresponding to the second encryption algorithm to decrypt the first key authorization code KeyAuth1 and the first target key identifier ID encrypted using the second encryption algorithm. QK1 Second communication device identifier ID B Decryption is performed to obtain the decrypted first key authorization code KeyAuth1 and the first target key identifier ID. QK1 Second communication device identifier ID B .

[0160] S509: The second communication device (communication device-B) uses the second decryption algorithm to identify the ID of the encrypted first target key. QK1 First target key QK1, second target key identifier ID QK2 The second target key QK2 is decrypted to obtain the decrypted first target key identifier ID. QK1 First target key QK1, second target key identifier ID QK2 The second target key QK2. The second communication device generates first authentication comparison data based on the key QK1 corresponding to the first target key identifier, the first random factor R1, and the set authentication data encryption algorithm. The first authentication comparison data is compared with the first authentication data. If the first authentication comparison data and the first authentication data are consistent, the first communication device is authenticated.

[0161] S510: The second communication device (communication device-B) generates second authentication data Token2 (e.g., HMAC(QK2, R2||ID) based on the second target key QK2, the second random factor R2, and the set authentication data encryption algorithm. B ||ID A Simultaneously, the second communication device can generate a second key authorization code KeyAuth2 (e.g., HMAC(QK2, ID)) based on the second target key, the first communication device identifier, and a set key authorization code encryption algorithm. A The second key authorization code KeyAuth2, the second authentication data Token2, and the second target key identifier ID are used. QK2 Send to the first communication device.

[0162] S511: The first communication device (communication device-A) sends a third key request to the first key device (QKD device-X), the third key request carrying the second key authorization code KeyAuth2 and the second target key identifier ID. QK2 First communication device identifier ID A .

[0163] The first communication device may use a first encryption algorithm to encrypt the second key authorization code KeyAuth2 and the second target key identifier ID. QK2 First communication device identifier ID A Encryption is performed, and the encrypted second key authorization code KeyAuth2 and the second target key identifier ID are used. QK2 First communication device identifier ID A Send to the first key device.

[0164] S512: The first key device (QKD device-X) receives the third key request, verifies the validity of the second authorization code, and if the communication device identifier used to generate the second key authorization comparison code is the same as the identifier of the communication device that sent the third key request, it will use the second target key identifier ID encrypted with the first encryption algorithm. QK2 The second target key QK2 is sent to the first communication device.

[0165] The process of verifying the validity of the second key authorization code is as follows: The first key device generates a second key authorization comparison code based on the key corresponding to the second target key identifier, the first communication device identifier, and the set key authorization code encryption algorithm. If the generated second key authorization comparison code matches the second key authorization code, then the second key authorization code is determined to be valid. The process of verifying the validity of the second key authorization code is similar to the process of verifying the validity of the first key authorization code, and will not be described in detail here.

[0166] The first key device can use a first decryption algorithm corresponding to the first encryption algorithm to decrypt the second key authorization code KeyAuth2 and the second target key identifier ID, which are encrypted using the first encryption algorithm. QK2 First communication device identifier ID A Decrypt to obtain the decrypted second key authorization code KeyAuth2 and the second target key identifier ID. QK2 First communication device identifier ID A .

[0167] S513: The first communication device (communication device-A) may use a first decryption algorithm corresponding to the first encryption algorithm to identify the second target key ID for encryption. QK2 The second target key QK2 is decrypted to obtain the decrypted second target key identifier ID. QK2 The second target key QK2. The first communication device generates second authentication comparison data based on the key QK2 corresponding to the second target key identifier, the second random factor R2, and the set authentication data encryption algorithm. The second authentication comparison data is compared with the received second authentication data Token2. If the second authentication comparison data matches the received second authentication data Token2, the second communication device is authenticated.

[0168] Example 6:

[0169] Based on the same technical concept, this application provides a two-way authentication method based on any of the above-described systems, the method being applied to a first communication device, see reference. Figure 6 , Figure 6 The diagram illustrates a fifth two-way authentication process provided by some embodiments, which includes the following steps:

[0170] S601: Send a first key request to the first key device, the first key request carrying a first communication device identifier and a second key device identifier corresponding to the second communication device; cause the first key device to perform key distribution with the second key device corresponding to the second key device identifier, and generate at least one target key.

[0171] S602: Receive a first target key and a first target key identifier sent by the first key device; generate first authentication data based on the first target key, and send the first authentication data and the first target key identifier to the second communication device; cause the second communication device to generate first authentication comparison data based on the key of the first target key identifier obtained from the second key device, and cause the second communication device to authenticate the first communication device based on the first authentication comparison data and the first authentication data; if the authentication is successful, cause the second communication device to generate second authentication data based on the second target key obtained from the second key device, and send the second authentication data and the second target key identifier to the first communication device.

[0172] S603: Receive the second authentication data and the second target key identifier sent by the second communication device, generate the second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and authenticate the second communication device based on the second authentication comparison data and the second authentication data.

[0173] In one possible implementation, before sending the first key request to the first key device, the method further includes:

[0174] Send an authentication request to the second communication device, the authentication request carrying the identifier of the first communication device.

[0175] In one possible implementation, generating the first authentication data based on the first target key includes:

[0176] First authentication data is generated based on the first target key, the first random factor received from the second communication device, and the set authentication data encryption algorithm.

[0177] In one possible implementation, after receiving the first target key and the first target key identifier sent by the first key device and before receiving the second authentication data and the second target key identifier sent by the second communication device, the method further includes:

[0178] The obtained second random factor is sent to the second communication device;

[0179] The step of generating second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device includes:

[0180] Based on the second random factor, the set authentication data encryption algorithm, and the key corresponding to the second target key identifier obtained from the first key device, second authentication comparison data is generated.

[0181] In one possible implementation, after receiving the first target key and the first target key identifier sent by the first key device and before receiving the second authentication data and the second target key identifier sent by the second communication device, the method further includes:

[0182] Based on the first target key, the second communication device identifier, and the set key authorization code encryption algorithm, a first key authorization code is generated and sent to the second communication device.

[0183] In one possible implementation, after receiving the second authentication data and the second target key identifier sent by the second communication device, the method further includes generating second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device.

[0184] If the first target key and the second target key are different keys, a third key request is sent to the first key device. The third key request carries the second target key identifier, the first communication device identifier, and the second key authorization code received from the second communication device.

[0185] In one possible implementation, after receiving the target key and target key identifier sent by the first key device, the method further includes:

[0186] If the target key and target key identifier encrypted with the first encryption algorithm are received from the first key device, the first decryption algorithm corresponding to the first encryption algorithm is used to decrypt the encrypted target key and target key identifier to obtain the decrypted target key and target key identifier.

[0187] Based on the same technical concept, this application provides a two-way authentication method based on any of the above-described systems, wherein the method is applied to a second communication device, see reference. Figure 7 , Figure 7 A schematic diagram of a sixth two-way authentication process provided by some embodiments is shown, which includes the following steps:

[0188] S701: Generate first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device, and authenticate the first communication device based on the first authentication comparison data and the first authentication data received from the first communication device.

[0189] S702: If authentication is successful, second authentication data is generated based on the second target key obtained from the second key device, and the second authentication data and the second target key identifier are sent to the first communication device; the first communication device generates second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and the first communication device authenticates the second communication device based on the second authentication comparison data and the second authentication data.

[0190] In one possible implementation, before generating the first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device, the method further includes:

[0191] Receive an authentication request sent by the first communication device, wherein the authentication request carries the identifier of the first communication device;

[0192] The challenge information is returned to the first communication device, and the challenge information includes the identifier of the second communication device and the identifier of the second key device corresponding to the second communication device.

[0193] In one possible implementation, the challenge information includes a second communication device identifier, a second key device identifier corresponding to the second communication device, and a first random factor;

[0194] The step of generating first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device includes:

[0195] First authentication comparison data is generated based on the first random factor, the set authentication data encryption algorithm, and the key corresponding to the first target key identifier obtained from the second key device.

[0196] In one possible implementation, generating the second authentication data based on the second target key obtained from the second key device includes:

[0197] The second authentication data is generated based on the second target key obtained from the second key device, the second random factor received from the first communication device, and the set authentication data encryption algorithm.

[0198] In one possible implementation, before generating the first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device, the method further includes:

[0199] Send a second key request to the second key device. The second key request carries the first key authorization code, the first target key identifier, and the second communication device identifier.

[0200] In one possible implementation, after the authentication is successful, the method further includes:

[0201] If the first target key and the second target key are different keys, then based on the second target key, the first communication device identifier and the set key authorization code encryption algorithm, a second key authorization code is generated and sent to the first communication device.

[0202] Based on the same technical concept, this application provides a two-way authentication method based on any of the above-described systems, wherein the method is applied to a first key device, see reference. Figure 8 , Figure 8 A schematic diagram of a seventh two-way authentication process provided by some embodiments is shown, which includes the following steps:

[0203] S801: Receive a first key request sent by a first communication device, wherein the first key request carries a first communication device identifier and a second key device identifier corresponding to a second communication device.

[0204] S802: Perform key distribution with the second key device corresponding to the second key device identifier to generate at least one target key.

[0205] S803: Based on the first communication device identifier, send any first target key and the first target key identifier to the first communication device.

[0206] In one possible implementation, the method further includes:

[0207] Receive a third key request sent by a first communication device, wherein the third key request carries a second key authorization code, a second target key identifier, and a first communication device identifier;

[0208] Based on the key corresponding to the second target key identifier, the first communication device identifier, and the set key authorization code encryption algorithm, a second key authorization comparison code is generated. If the second key authorization comparison code is consistent with the second key authorization code, and the communication device identifier used to generate the second key authorization comparison code is the same as the identifier of the communication device that sent the third key application, then the second target key identifier and the second target key are sent to the first communication device corresponding to the first communication device identifier.

[0209] In one possible implementation, sending the target key identifier and the target key to the first communication device includes:

[0210] The target key and the target key identifier are encrypted using the first encryption algorithm, and the encrypted target key and the target key identifier are sent to the first communication device.

[0211] Based on the same technical concept, this application provides a two-way authentication method based on any of the above-described systems, wherein the method is applied to a second key device, see reference. Figure 9 , Figure 9 The diagram illustrates an eighth two-way authentication process provided in some embodiments, which includes the following steps:

[0212] S901: Receive a second key request sent by a second communication device, wherein the second key request carries a first key authorization code, a first target key identifier, and a second communication device identifier.

[0213] S902: Based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm, generate a first key authorization comparison code. If the generated first key authorization comparison code is consistent with the first key authorization code, and the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key application, then send the first target key identifier and the first target key to the second communication device corresponding to the second communication device identifier.

[0214] Example 7:

[0215] Based on the same technical concept, this application provides a two-way authentication device based on any of the above-described systems, the device being applied to a first communication device, see reference. Figure 10 , Figure 10 A schematic diagram of a first type of two-way authentication device provided in some embodiments is shown, the process including the following steps:

[0216] The first sending module 101 is used to send a first key request to a first key device, wherein the first key request carries a first communication device identifier and a second key device identifier corresponding to the second communication device; and enables the first key device to perform key distribution with the second key device corresponding to the second key device identifier to generate at least one target key.

[0217] The first receiving module 102 is configured to receive a first target key and a first target key identifier sent by the first key device; generate first authentication data based on the first target key; send the first authentication data and the first target key identifier to the second communication device; enable the second communication device to generate first authentication comparison data based on the key of the first target key identifier obtained from the second key device; and enable the second communication device to authenticate the first communication device based on the first authentication comparison data and the first authentication data; if the authentication is successful, enable the second communication device to generate second authentication data based on the second target key obtained from the second key device; and send the second authentication data and the second target key identifier to the first communication device.

[0218] The first authentication module 103 is used to receive second authentication data and a second target key identifier sent by the second communication device, generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and authenticate the second communication device based on the second authentication comparison data and the second authentication data.

[0219] In one possible implementation, the first sending module 101 is further configured to send an authentication request to the second communication device, the authentication request carrying the identifier of the first communication device.

[0220] In one possible implementation, the first receiving module 102 is specifically used to generate first authentication data based on the first target key, the first random factor received from the second communication device, and the set authentication data encryption algorithm.

[0221] In one possible implementation, the first authentication module 103 is further configured to send the obtained second random factor to the second communication device;

[0222] Based on the second random factor, the set authentication data encryption algorithm, and the key corresponding to the second target key identifier obtained from the first key device, second authentication comparison data is generated.

[0223] In one possible implementation, the first authentication module 103 is further configured to generate a first key authorization code based on the first target key, the second communication device identifier, and a set key authorization code encryption algorithm, and send the first key authorization code to the second communication device.

[0224] Based on the same technical concept, this application provides a two-way authentication device based on any of the above-described systems, the device being applied to a second communication device, see reference. Figure 11 , Figure 11A schematic diagram of a second two-way authentication device provided in some embodiments is shown, the process including the following steps:

[0225] The second authentication module 111 is used to generate first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device, and to authenticate the first communication device based on the first authentication comparison data and the first authentication data received from the first communication device.

[0226] The second sending module 112 is configured to, if authentication is successful, generate second authentication data based on the second target key obtained from the second key device, and send the second authentication data and the second target key identifier to the first communication device; enable the first communication device to generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and enable the first communication device to authenticate the second communication device based on the second authentication comparison data and the second authentication data.

[0227] In one possible implementation, the second authentication module 111 is further configured to receive an authentication request sent by the first communication device, the authentication request carrying the identifier of the first communication device;

[0228] The challenge information is returned to the first communication device, and the challenge information includes the identifier of the second communication device and the identifier of the second key device corresponding to the second communication device.

[0229] In one possible implementation, the second authentication module 111 is specifically used to generate first authentication comparison data based on the first random factor, the set authentication data encryption algorithm, and the key corresponding to the first target key identifier obtained from the second key device if the challenge information includes a second communication device identifier, a second key device identifier corresponding to the second communication device, and a first random factor.

[0230] In one possible implementation, the second sending module 112 is specifically used to generate second authentication data based on the second target key obtained from the second key device, the second random factor received from the first communication device, and the set authentication data encryption algorithm.

[0231] In one possible implementation, the second authentication module 111 is further configured to send a second key application to the second key device, wherein the second key application carries the first key authorization code, the first target key identifier, and the second communication device identifier.

[0232] Based on the same technical concept, this application provides a two-way authentication device based on any of the above-described systems, the device being applied to a first key device, see reference. Figure 12 , Figure 12 A schematic diagram of a third two-way authentication device provided in some embodiments is shown, the process including the following steps:

[0233] The second receiving module 121 is used to receive a first key application sent by the first communication device, wherein the first key application carries the identifier of the first communication device and the second key device identifier corresponding to the second communication device.

[0234] The key generation module 122 is used to perform key distribution with the second key device corresponding to the second key device identifier and generate at least one target key;

[0235] The third sending module 123 is used to send any first target key and the first target key identifier to the first communication device based on the first communication device identifier.

[0236] Based on the same technical concept, this application provides a two-way authentication device based on any of the above-described systems, wherein the device is applied to a second key device, see reference. Figure 13 , Figure 13 A schematic diagram of a fourth two-way authentication device provided in some embodiments is shown, the process including the following steps:

[0237] The second receiving module 131 is used to receive a second key application sent by the second communication device, wherein the second key application carries a first key authorization code, a first target key identifier, and a second communication device identifier.

[0238] The comparison module 132 is used to generate a first key authorization comparison code based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm. If the generated first key authorization comparison code is consistent with the first key authorization code, and the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key application, then the first target key identifier and the first target key are sent to the second communication device corresponding to the second communication device identifier.

[0239] Example 8:

[0240] Based on the same technical concept, this application also provides an electronic device. Figure 14 The diagram illustrates a schematic representation of an electronic device structure provided in some embodiments, such as... Figure 14 As shown, the electronic device includes: a processor 141, a communication interface 142, a memory 143, and a communication bus 144, wherein the processor 141, the communication interface 142, and the memory 143 communicate with each other through the communication bus 144.

[0241] The memory 143 stores a computer program. When the program is executed by the processor 141, the processor 141 executes the computer program stored in the memory to implement the steps of any of the two-way authentication methods described above, which will not be repeated here.

[0242] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0243] Communication interface 142 is used for communication between the above-mentioned electronic device and other devices.

[0244] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0245] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0246] Example 9:

[0247] Based on the same technical concept, embodiments of this application provide a computer-readable storage medium storing a computer program executable by an electronic device. When the program is run on the electronic device, the electronic device executes the steps of the two-way authentication method as described in any of the above method embodiments, which will not be repeated here.

[0248] The aforementioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in an electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs), etc.

[0249] Based on the same technical concept, this application provides a computer program product, which includes: computer program code, which, when run on a computer, causes the computer to implement the steps of the two-way authentication evaluation method described in any of the method embodiments applied to electronic devices, which will not be repeated here.

[0250] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof, or in whole or in part, as a computer program product. The computer program product includes one or more computer instructions, which, when loaded and executed on a computer, generate, in whole or in part, the processes or functions described in the embodiments of this application.

[0251] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0252] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0253] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0254] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0255] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A two-way authentication system, characterized in that, The system includes: A first communication device is used to send a first key request to a first key device, wherein the first key request carries a first communication device identifier and a second key device identifier corresponding to the second communication device obtained therefrom. The first key device is configured to perform key distribution with a second key device corresponding to the second key device identifier, generate at least one target key, and send any first target key and a first target key identifier to the first communication device based on the first communication device identifier. The first communication device is further configured to generate first authentication data based on the first target key, and send the first authentication data and the first target key identifier to the second communication device; The second communication device is further configured to generate first authentication comparison data based on the key corresponding to the first target key identifier obtained from the second key device, authenticate the first communication device based on the first authentication comparison data and the first authentication data, and if the authentication is successful, generate second authentication data based on the second target key obtained from the second key device, and send the second authentication data and the second target key identifier to the first communication device. The first communication device is further configured to generate second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and to authenticate the second communication device based on the second authentication comparison data and the second authentication data; The first communication device is further configured to generate a first key authorization code and send the first key authorization code to the second communication device; The second communication device is further configured to send a second key request to the second key device, wherein the second key request carries the first key authorization code, the first target key identifier, and the second communication device identifier; The second key device is further configured to receive the second key application, generate a first key authorization comparison code, and if the first key authorization comparison code matches the first key authorization code, send the first target key identifier and the first target key to the second communication device corresponding to the second communication device identifier.

2. The system according to claim 1, characterized in that, The first communication device is further configured to send an authentication request to the second communication device, wherein the authentication request carries the identifier of the first communication device; The second communication device is further configured to receive the authentication request and return challenge information to the first communication device, the challenge information including the identifier of the second communication device and the identifier of the second key device corresponding to the second communication device.

3. The system according to claim 1 or 2, characterized in that, The second communication device is further configured to send the obtained first random factor to the first communication device; The first communication device is specifically used to generate first authentication data based on the first target key, the first random factor, and the set authentication data encryption algorithm; The second communication device is specifically used to generate first authentication comparison data based on the first random factor, the set authentication data encryption algorithm, and the key corresponding to the first target key identifier obtained from the second key device.

4. The system according to claim 1 or 2, characterized in that, The first communication device is further configured to send the obtained second random factor to the second communication device; The second communication device is specifically used to generate second authentication data based on the second random factor, the set authentication data encryption algorithm, and the second target key obtained from the second key device; The first communication device is specifically used to generate second authentication comparison data based on the second random factor, the set authentication data encryption algorithm, and the key corresponding to the second target key identifier obtained from the first key device.

5. The system according to claim 1, characterized in that, The first communication device is specifically used to generate a first key authorization code based on the first target key, the second communication device identifier, and a set key authorization code encryption algorithm; The second key device is specifically used to generate a first key authorization comparison code based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm. If the first key authorization comparison code is consistent with the first key authorization code, and the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key application, then the first target key identifier and the first target key are sent to the second communication device corresponding to the second communication device identifier.

6. The system according to claim 1, characterized in that, The first target key and the second target key are the same key; or, the first target key and the second target key are different keys.

7. The system according to claim 6, characterized in that, If the first target key and the second target key are different keys, the second communication device is further configured to generate a second key authorization code based on the second target key, the first communication device identifier and the set key authorization code encryption algorithm, and send the second key authorization code to the first communication device; The first communication device is further configured to send a third key request to the first key device, wherein the third key request carries the second key authorization code, the second target key identifier, and the first communication device identifier; The first key device is further configured to receive the third key application, generate a second key authorization comparison code based on the key corresponding to the second target key identifier, the first communication device identifier, and the set key authorization code encryption algorithm, and if the second key authorization comparison code is consistent with the second key authorization code, and the communication device identifier used to generate the second key authorization comparison code is the same as the identifier of the communication device that sent the third key application, then the second target key identifier and the second target key are sent to the first communication device corresponding to the first communication device identifier.

8. The system according to claim 1 or 6, characterized in that, The first key device is specifically used to encrypt the target key and the target key identifier using a set first encryption algorithm, and send the encrypted target key and the target key identifier to the first communication device. The first communication device is further configured to receive the encrypted target key and target key identifier, and use a first decryption algorithm corresponding to the first encryption algorithm to decrypt the encrypted target key and target key identifier to obtain the decrypted target key and target key identifier.

9. A two-way authentication method based on the system according to any one of claims 1-8, characterized in that, The method is applied to a first communication device, and the method includes: A first key request is sent to a first key device, the first key request carrying a first communication device identifier and a second key device identifier corresponding to the second communication device; key distribution is then performed between the first key device and the second key device corresponding to the second key device identifier to generate at least one target key; The system receives a first target key and a first target key identifier sent by the first key device; generates first authentication data based on the first target key, and sends the first authentication data and the first target key identifier to the second communication device; the second communication device generates first authentication comparison data based on the key of the first target key identifier obtained from the second key device, and authenticates the first communication device based on the first authentication comparison data and the first authentication data; if the authentication is successful, the second communication device generates second authentication data based on the second target key obtained from the second key device, and sends the second authentication data and the second target key identifier to the first communication device. The system receives second authentication data and a second target key identifier sent by the second communication device, generates second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and authenticates the second communication device based on the second authentication comparison data and the second authentication data.

10. A two-way authentication method based on the system according to any one of claims 1-8, characterized in that, The method is applied to a second communication device, and the method includes: Based on the key corresponding to the first target key identifier obtained from the second key device, first authentication comparison data is generated. Based on the first authentication comparison data and the first authentication data received from the first communication device, the first communication device is authenticated. If authentication is successful, second authentication data is generated based on the second target key obtained from the second key device, and the second authentication data and the second target key identifier are sent to the first communication device; the first communication device generates second authentication comparison data based on the key corresponding to the second target key identifier obtained from the first key device, and the first communication device authenticates the second communication device based on the second authentication comparison data and the second authentication data.

11. A two-way authentication method based on the system according to any one of claims 1-8, characterized in that, The method is applied to a first key device, and the method includes: Receive a first key request sent by a first communication device, wherein the first key request carries the identifier of the first communication device and the identifier of the second key device corresponding to the second communication device; Key distribution is performed between the key device and the second key device corresponding to the second key device identifier to generate at least one target key; Based on the first communication device identifier, any first target key and the first target key identifier are sent to the first communication device.

12. A two-way authentication method based on the system according to any one of claims 1-8, characterized in that, The method is applied to a second key device, and the method includes: Receive a second key request sent by a second communication device, wherein the second key request carries a first key authorization code, a first target key identifier, and a second communication device identifier; Based on the key corresponding to the first target key identifier, the second communication device identifier, and the set key authorization code encryption algorithm, a first key authorization comparison code is generated. If the first key authorization comparison code is consistent with the first key authorization code, and the communication device identifier used to generate the first key authorization comparison code is the same as the identifier of the communication device that sent the second key application, then the first target key identifier and the first target key are sent to the second communication device corresponding to the second communication device identifier.

Citation Information

Patent Citations

  • Bidirectional identity authentication method and device

    CN108282329A

  • Encrypted communication based on quantum key

    WO2020260751A1