Stealth communication method, sending terminal, receiving terminal and system based on IPv6

By dynamically generating addresses on IPv6 terminals and combining symmetric encryption and asymmetric encryption technologies, the data security problem when the security verification component is not enabled is solved, and the effect of improving IPv6 communication security is achieved without relying on other security components.

CN118174929BActive Publication Date: 2025-05-16北京英迪瑞讯网络科技有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410301543.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-16
Publication Date
2025-05-16
Estimated Expiration
2044-03-16

AI Technical Summary

Technical Problem

When the existing IPv6 terminals do not enable the security of data transmission, there are data security issues. How to improve the security of IPv6 communication without relying on the security verification component is an urgent problem to be solved.

Method used

By dynamically generating source and destination addresses on the sending terminal and receiving terminal, hashing the message plaintext, using a combination of symmetric encryption and asymmetric encryption, and packaging the key ciphertext and message ciphertext into data packets to improve communication security without relying on other security components.

Benefits of technology

Through dynamic address generation and combined with encryption technology, invisible communication between sending and receiving ends is realized, and the integrity of the message plain text is verified through message digest data to prevent tampering, and the security and efficiency of communication are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118174929B_ABST
    Figure CN118174929B_ABST
Patent Text Reader

Abstract

The present application relates to an IPv6-based stealth communication method, a sending terminal, a receiving terminal and a system, and belongs to the field of communication technology. The communication method includes: randomly generating a source address of a sending terminal; dynamically generating a destination address of a receiving terminal; performing hash processing on a message plaintext to be sent to generate message summary data; asymmetrically encrypting a randomly generated symmetric encryption key and message summary data together to obtain a key ciphertext; encrypting a message plaintext to be sent to obtain a message ciphertext, packaging the source address, destination address, key ciphertext, message summary data and message ciphertext to obtain a data packet, and sending the data packet to a receiving terminal. The key ciphertext and the message ciphertext are packaged as a data packet and sent, and the legitimacy of the communication can be verified by the data packet itself, thereby achieving the effect of improving the security of communication between the sending terminal and the receiving terminal without relying on other security components.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to an IPv6-based stealth communication method, a sending terminal, a receiving terminal and a system. Background Art

[0002] IPv6 (Internet Protocol version 6) stealth communication is a technology that achieves anonymous communication by hiding the real IPv6 addresses of the sender and receiver of the communication, thereby protecting the user's privacy and preventing the user's identity from being exposed to a third party.

[0003] In order to improve the security of stealth communication of IPv6 terminals, IPv6 terminals usually need to include security verification components, such as Ipsec (Internet Protocol Security) protocol software, which is a protocol used to provide security and data integrity at the network layer. It uses encryption and authentication mechanisms to protect the transmission of data packets and prevent unauthorized access and tampering to prevent the leakage of user sensitive information. However, since security verification components such as Ipsec protocol software are usually not guaranteed to be forced to be enabled, there are still data security issues when transmitting data when the security component is not enabled. How to improve the security of IPv6 communication without relying on security verification components is a problem that needs to be solved urgently. Summary of the invention

[0004] In order to improve the security of IPv6 communication without relying on security verification components, the present application provides an IPv6-based stealth communication method, a sending terminal, a receiving terminal and a system.

[0005] In the first aspect, the present application provides an IPv6-based stealth communication method, which adopts the following technical solution:

[0006] An IPv6-based stealth communication method, applied to a sending terminal, comprising:

[0007] Randomly generate the source address of the sending terminal;

[0008] Dynamically generate the destination address of the receiving terminal;

[0009] Perform hash processing on the plaintext of the message to be sent to generate message digest data;

[0010] Asymmetrically encrypt the randomly generated symmetric encryption key to obtain the key ciphertext;

[0011] Based on the symmetric encryption key, encrypt the plaintext message to be sent to obtain a ciphertext message;

[0012] The source address, destination address, key ciphertext, message digest data and message ciphertext are packaged to obtain a data packet, and the data packet is sent to a receiving terminal.

[0013] By adopting the above technical solution, by generating a dynamic pair of source addresses and destination addresses, the invisibility of both the sending and receiving ends is achieved. The message plaintext usually has a large amount of data, and the message ciphertext is obtained by using a more efficient symmetric encryption, while the symmetric encryption key used for encrypting the message plaintext uses a more secure asymmetric encryption method to obtain the key ciphertext. The combination of symmetric encryption and asymmetric encryption improves the encryption efficiency and ensures the communication security. In addition, by hashing the message plaintext, the message digest data is generated to verify the integrity of the message plaintext and prevent the message plaintext from being tampered with. Finally, the key ciphertext and the message ciphertext are packaged as a data packet for transmission. The legitimacy of the communication can be verified through the data packet itself, thereby improving the security of the communication between the sending terminal and the receiving terminal without relying on other separate security components.

[0014] Optionally, the randomly generating a source address of the sending terminal specifically includes:

[0015] Obtain the first IPv6 prefix of the sending terminal;

[0016] Based on the current timestamp information and the first IPv6 prefix, a source address of the sending terminal is randomly generated.

[0017] By adopting the above technical solution, the source address is generated using the first IPv6 prefix, so that the source address is also unique, and the first IPv6 prefix facilitates identification of the sending terminal through the source address.

[0018] Optionally, the dynamically generating a destination address of the receiving terminal specifically includes:

[0019] Get the current timestamp information;

[0020] Obtain a preset first unique number of the sending terminal and a second unique number of the receiving terminal, and obtain a second IPv6 prefix of the receiving terminal;

[0021] A linear operation is performed on the source address, the timestamp information, the first unique number, the second unique number, and the second IPv6 prefix to obtain the destination address.

[0022] By adopting the above technical solution, the destination address contains the first unique number and the second unique number. Since the first unique number and the second unique number are not public information, a third party cannot crack the second IPv6 prefix and the source address from the destination address, thereby protecting the sending terminal and the receiving terminal from being easily exposed.

[0023] Optionally, the asymmetrically encrypting the randomly generated symmetric encryption key to obtain the key ciphertext specifically includes:

[0024] The randomly generated symmetric encryption key is signed with the private key of the sender to obtain the initial key ciphertext;

[0025] The initial key ciphertext is encrypted again based on the receiving end public key to obtain the key ciphertext.

[0026] By adopting the above technical solution, since the private key of the sender is only known to the sending terminal, the first asymmetric encryption is achieved by signing with the private key of the sender, and then the second asymmetric encryption is performed using the public key of the receiving terminal, thereby achieving asymmetric encryption of the symmetric encryption key and message digest data.

[0027] Optionally, the data packet is a UDP message; and the step of packing the source address, the destination address, the key ciphertext, the message summary data and the message ciphertext to obtain the data packet specifically includes:

[0028] Get the virtual port of the receiving terminal;

[0029] Load the virtual port, key ciphertext, message digest data and message ciphertext into a preset message template to obtain a protocol message;

[0030] Load the protocol message into the data field of the UDP message template, and load the source address and the destination address into the header field of the UDP message template to obtain a UDP message;

[0031] Send UDP packets to the receiving terminal.

[0032] By adopting the above technical solution, the protocol message is loaded into the UDP message data field, and the UDP message is used as the carrier of the protocol message. UDP is a connectionless transmission protocol and does not require a connection to be established before sending data. The message plaintext has been encrypted in the UDP message, which improves the transmission efficiency while ensuring the transmission security performance.

[0033] In a second aspect, the present application provides a stealth communication method based on IPv6, which adopts the following technical solution:

[0034] An IPv6-based stealth communication method, applied to a receiving terminal, comprising:

[0035] Receive a data packet from a sending terminal; wherein the data packet generates a source address of the sending terminal by randomly generating a destination address of the receiving terminal, performs hash processing on a plain text message to be sent, and generates message digest data; performs asymmetric encryption on a randomly generated symmetric encryption key to obtain a key ciphertext; encrypts the plain text message to be sent based on the symmetric encryption key to obtain a message ciphertext; and packages the source address, the destination address, the key ciphertext, the message digest data, and the message ciphertext to obtain;

[0036] Parse the timestamp information from the header field of the data packet and verify the validity of the data packet based on the timestamp information;

[0037] In response to the validity verification being passed, parsing the key ciphertext, the virtual port, the message digest data and the message ciphertext from the data field of the data packet;

[0038] Perform asymmetric decryption from the key ciphertext to obtain the symmetric encryption key;

[0039] Decrypt the message ciphertext based on the symmetric encryption key to obtain the message plaintext;

[0040] Based on the message digest data, the message plaintext is checked for consistency;

[0041] In response to the plaintext consistency check of the message passing, the plaintext message is forwarded to the corresponding application process according to the virtual port.

[0042] By adopting the above technical solution, the timestamp information is parsed from the header field of the data packet, and the validity is verified based on the timestamp information, ensuring that the received data packet is not expired or the result of a replay attack. The key ciphertext is decrypted by using asymmetric decryption to obtain the symmetric encryption key and message digest data, and then the message ciphertext is decrypted by using the symmetric encryption key to obtain the message plaintext, and the message digest data is used to verify the message plaintext. Unauthorized access and information leakage are prevented, and the legitimacy of data transmission can be identified only by parsing the data packet without relying on a separate security component.

[0043] Optionally, the consistency check of the message plaintext based on the message digest data specifically includes:

[0044] Hash the message plaintext to generate hash data;

[0045] The hash data and the message digest data are compared. If the comparison is consistent, the message plaintext consistency check passes; if the comparison is inconsistent, the message plaintext consistency check fails.

[0046] By adopting the above technical solution, the message summary data obtained by hashing the message plaintext before sending by the sending terminal and the hash data obtained by hashing the message plaintext received by the receiving terminal are compared, thereby realizing the verification of the integrity of the message plaintext.

[0047] In a third aspect, the present application provides a sending terminal, which adopts the following technical solution:

[0048] A sending terminal, comprising:

[0049] A source address generation unit, used to randomly generate a source address of a sending terminal;

[0050] A destination address generating unit, used for dynamically generating a destination address of a receiving terminal;

[0051] A digest generation unit, used for performing hash processing on the plain text of the message to be sent to generate message digest data;

[0052] A key ciphertext generation unit, used for asymmetrically encrypting a randomly generated symmetric encryption key to obtain a key ciphertext;

[0053] A message ciphertext generating unit, used to encrypt the plaintext of the message to be sent based on the symmetric encryption key to obtain the message ciphertext;

[0054] The output unit is used to package the source address, the destination address, the key ciphertext and the message ciphertext to obtain a data packet, and send the data packet to a receiving terminal.

[0055] In a fourth aspect, the present application provides a receiving terminal, which adopts the following technical solution:

[0056] A receiving terminal, comprising:

[0057] A receiving unit, configured to receive a data packet from a sending terminal; wherein the data packet is obtained by randomly generating a source address of the sending terminal, dynamically generating a destination address of the receiving terminal, performing hash processing on a plain text message to be sent, and generating message digest data; asymmetrically encrypting a randomly generated symmetric encryption key to obtain a key ciphertext; encrypting the plain text message to be sent based on the symmetric encryption key to obtain a message ciphertext; and packaging the source address, destination address, key ciphertext, message digest data, and message ciphertext to obtain;

[0058] A validity verification unit, used to parse out timestamp information from the header field of the data packet and verify the validity of the data packet based on the timestamp information;

[0059] A parsing unit, configured to parse the key ciphertext, the virtual port, the message digest data and the message ciphertext from the data field of the data packet in response to the validity verification being passed;

[0060] an asymmetric decryption unit, used for performing asymmetric decryption from a key ciphertext to obtain a symmetric encryption key;

[0061] A symmetric decryption unit, used to decrypt the message ciphertext based on the symmetric encryption key to obtain the message plaintext;

[0062] A consistency check unit, used to perform consistency check on the message plaintext based on the message digest data;

[0063] The forwarding unit is used for forwarding the plain text of the message to the corresponding application process according to the virtual port in response to the plain text consistency check of the message passing.

[0064] In a fifth aspect, the present application provides an IPv6-based stealth communication system, which adopts the following technical solutions:

[0065] An IPv6-based stealth communication system comprises: a sending terminal as described above and a receiving terminal as described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 This is a flowchart of one of the embodiments of the present application for demonstrating the stealth communication method of the sending end.

[0067] Figure 2 This is a flow chart of a method for encrypting key ciphertext, which is one of the embodiments of the present application.

[0068] Figure 3 This is a flow chart of a method for demonstrating data packet transmission according to one embodiment of the present application.

[0069] Figure 4 It is a flowchart of one embodiment of the present application for demonstrating the stealth communication method at the receiving end.

[0070] Figure 5 It is a block diagram of an embodiment of the present application for illustrating a stealth communication system at a transmitting end.

[0071] Figure 6 It is a block diagram of an embodiment of the present application for illustrating a stealth communication system at a receiving end. DETAILED DESCRIPTION

[0072] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0073] First, the terms used in this embodiment are explained.

[0074] Source Address: In IPv6 communication, the source address indicates the IPv6 address of the sender of the data packet.

[0075] Destination Address: In IPv6 communication, the destination address indicates the IPv6 address of the recipient of the data packet.

[0076] Symmetric Encryption: Symmetric encryption is an encryption algorithm that uses the same key for encryption and decryption. Common symmetric encryption algorithms include AES and DES.

[0077] Asymmetric Encryption: Asymmetric encryption is an encryption algorithm that uses different keys for encryption and decryption. Common asymmetric encryption algorithms include RSA and Diffie-Hellman.

[0078] Local Unique Number: A local unique number is a unique identifier for each IPv6 node (device terminal) and is used to distinguish different devices.

[0079] Hash Processing: Hash processing is a process of mapping data of any length to a hash value of fixed length. The hash function converts the input data into a fixed-length binary value. This process is irreversible, that is, the original data cannot be restored from the hash value. Common hash functions include MD5, SHA-1, SHA-256, etc.

[0080] UDP message (User Datagram Protocol Datagram): UDP is a connectionless transport layer protocol used to transmit data in IP networks. UDP messages are data packets encapsulated in the format specified by the UDP protocol, including fields such as source port, destination port, checksum, and data.

[0081] Virtual Port: A virtual port is a port number used in the transport layer protocol to identify an application or service. In a UDP message, a virtual port is used to forward data packets to the correct application process.

[0082] The present application embodiment discloses a stealth communication method based on IPv6. Figure 1 , a stealth communication method based on IPv6, comprising:

[0083] Step S101: randomly generate a source address of a sending terminal;

[0084] Step S102: dynamically generate a destination address of a receiving terminal;

[0085] Step S103: Perform hash processing on the plain text of the message to be sent to generate message digest data.

[0086] It should be understood that since the hash process cannot be restored, the plain text of the message cannot be restored from the message digest data. Moreover, the message digest data obtained by the hash process is a binary value, and the amount of data is much smaller than the plain text of the message.

[0087] Step S104: Asymmetrically encrypt the randomly generated symmetric encryption key to obtain a key ciphertext.

[0088] Step S105: Encrypt the plaintext message to be sent based on the symmetric encryption key to obtain a ciphertext message;

[0089] Step S106: Packing the source address, destination address, key ciphertext, message digest data and message ciphertext to obtain a data packet, and sending the data packet to a receiving terminal.

[0090] In the above implementation, the invisibility of both the sending and receiving ends is achieved by generating a dynamic pair of source addresses and destination addresses. The message plaintext usually has a large amount of data, so the message ciphertext is obtained by using a more efficient symmetric encryption, and the symmetric encryption key used for encrypting the message plaintext uses a more secure asymmetric encryption method to obtain the key ciphertext. The combination of symmetric encryption and asymmetric encryption improves the encryption efficiency and ensures the communication security. In addition, by hashing the message plaintext, the message digest data is generated to verify the integrity of the message plaintext and prevent the message plaintext from being tampered with. Finally, the key ciphertext and the message ciphertext are packaged as a data packet for transmission. The legitimacy of the communication can be verified by the data packet itself, thereby improving the security of the communication between the sending terminal and the receiving terminal without relying on other separate security components.

[0091] As an implementation of step S101, step S101 specifically includes:

[0092] Acquire a first IPv6 prefix of the sending terminal; and randomly generate a source address of the sending terminal based on current timestamp information and the first IPv6 prefix.

[0093] The first IPv6 prefix is ​​the variable part of the IPv6 address of the sending terminal, and is used to identify the address range of the sending terminal network.

[0094] In the above implementation, the source address is generated by using the first IPv6 prefix, so that the source address is also unique, and the first IPv6 prefix facilitates identification of the sending terminal through the source address.

[0095] As an implementation of step S102, step S102 specifically includes:

[0096] Obtain the current timestamp information; obtain the preset first unique number of the sending terminal and the second unique number of the receiving terminal, and obtain the second IPv6 prefix of the receiving terminal; perform linear operations on the source address, timestamp information, the first unique number, the second unique number and the second IPv6 prefix to obtain the destination address.

[0097] The first unique number is a unique identifier used to characterize a sending terminal, and the second unique number is a unique identifier used to characterize a receiving terminal. The first unique number and the second unique number are information known to both the sending terminal and the receiving terminal.

[0098] Among them, linear operations can use linear shuffling technology.

[0099] It should be understood that the known first unique number and second unique number facilitate the determination of the location of the source address and the second IPv6 prefix in the target address, so that the receiving terminal can decipher the source address and the second IPv6 prefix from the target address.

[0100] In the above implementation, the destination address includes a first unique number and a second unique number. Since the first unique number and the second unique number are not public information, a third party cannot crack the second IPv6 prefix and the source address from the destination address, thereby protecting the sending terminal and the receiving terminal from being easily exposed.

[0101] Reference Figure 2 As an implementation of step S104, step S104 specifically includes:

[0102] Step S1041: The randomly generated symmetric encryption key is signed using the private key of the sender to obtain the initial key ciphertext;

[0103] It should be understood that the sender's private key and the sender's public key need to be used in pairs, and the sender's private key is only known to the sending terminal and cannot be known by third parties. The sender's public key is public information. When the sending terminal uses the sender's private key to encrypt data, the receiving terminal needs to use the sender's public key to decrypt it.

[0104] Step S1042: re-encrypt the initial key ciphertext based on the receiving end public key to obtain the key ciphertext.

[0105] Similarly, the receiving end private key and the receiving end public key also need to be used in pairs. When the sending terminal uses the receiving end public key to encrypt, the receiving terminal needs to use the receiving end private key to decrypt. Since different keys are used for encryption and decryption, the above encryption method is asymmetric encryption.

[0106] In the above implementation, since the sender's private key is only known to the sending terminal, the first asymmetric encryption is achieved by signing with the sender's private key, and then the second asymmetric encryption is performed using the receiving terminal's public key, thereby achieving asymmetric encryption of the symmetric encryption key and message digest data.

[0107] Reference Figure 3 As an implementation of step S105, step S105 specifically includes the following steps: the data packet is a UDP message;

[0108] Step S1051: Obtain the virtual port of the receiving terminal;

[0109] Step S1052: loading the virtual port, key ciphertext, message digest data and message ciphertext into a preset message template to obtain a protocol message;

[0110] Step S1053: Load the protocol message into the data field of the UDP message template, and load the source address and the destination address into the header field of the UDP message template to obtain a UDP message;

[0111] Step S1054: Send the UDP message to the receiving terminal.

[0112] In the above implementation, the protocol message is loaded into the UDP message data field, and the UDP message is used as the carrier of the protocol message. UDP is a connectionless transmission protocol and does not require a connection to be established before sending data. The message plaintext has been encrypted in the UDP message, which improves the transmission efficiency while ensuring the transmission security performance.

[0113] Reference Figure 4 This embodiment also discloses a stealth communication method based on IPv6, which is applied to a receiving terminal and includes:

[0114] Step S201: receiving a data packet from a sending terminal;

[0115] The data packet generates a source address of a sending terminal at random, dynamically generates a destination address of a receiving terminal, performs hash processing on a plain text message to be sent, and generates message summary data; performs asymmetric encryption on a randomly generated symmetric encryption key to obtain a key ciphertext; encrypts the plain text message to be sent based on the symmetric encryption key to obtain a message ciphertext; and packages the source address, destination address, key ciphertext, message summary data, and message ciphertext to obtain;

[0116] Step S202: parse the timestamp information from the header field of the data packet, and verify the validity of the data packet based on the timestamp information. If the verification passes, execute step S203; if the verification fails, execute step S208.

[0117] Specifically, validity verification can be performed by setting a valid time. By setting a time window (for example, a data packet can usually be sent within 5 seconds), it is determined whether the timestamp information of the data packet is within the time window. If the timestamp information exceeds the set range, it can be regarded as an illegal data packet.

[0118] Step S203: In response to the validity verification being passed, the key ciphertext, the virtual port, the message digest data and the message ciphertext are parsed from the data field of the data packet;

[0119] Step S204: Perform asymmetric decryption on the key ciphertext to obtain a symmetric encryption key.

[0120] It should be understood that asymmetric decryption means first decrypting with the private key of the receiving end and then decrypting again with the public key of the sending end.

[0121] Step S205: decrypt the message ciphertext based on the symmetric encryption key to obtain the message plaintext;

[0122] Step S206: Based on the message digest data, perform consistency check on the message plaintext; if the consistency check passes, execute step S207; if the verification fails, execute step S208.

[0123] Step S207: in response to the plain text consistency check of the message passing, the plain text of the message is forwarded to the corresponding application process according to the virtual port.

[0124] Step S208: Determine that the data packet is an illegal data packet and discard the data packet.

[0125] In the above implementation, the timestamp information is parsed from the header field of the data packet, and the validity is verified based on the timestamp information, ensuring that the received data packet is not expired or the result of a replay attack. The key ciphertext is decrypted by using asymmetric decryption to obtain the symmetric encryption key and message digest data, and then the message ciphertext is decrypted by using the symmetric encryption key to obtain the message plaintext, and the message digest data is used to verify the message plaintext. Unauthorized access and information leakage are prevented, and the legitimacy of data transmission can be identified only by parsing the data packet without relying on a separate security component.

[0126] As an implementation of step S206, step S206 specifically includes:

[0127] Hash the message plaintext to generate hash data;

[0128] The hash data and the message digest data are compared. If the comparison is consistent, the message plaintext consistency check passes; if the comparison is inconsistent, the message plaintext consistency check fails.

[0129] It should be understood that the hash processing method used by the receiving terminal should be consistent with the hash processing method used by the sending terminal, for example, both use the MD5 algorithm to hash the message plaintext.

[0130] In the above implementation, the message digest data obtained by hashing the message plaintext before sending by the sending terminal and the hash data obtained by hashing the message plaintext received by the receiving terminal are compared, thereby realizing the verification of the integrity of the message plaintext.

[0131] Reference Figure 5 This embodiment also discloses a sending terminal. A sending terminal includes:

[0132] A source address generation unit, used to randomly generate a source address of a sending terminal;

[0133] A destination address generating unit, used for dynamically generating a destination address of a receiving terminal;

[0134] A digest generation unit, used for performing hash processing on the plain text of the message to be sent to generate message digest data;

[0135] A key ciphertext generation unit, used for asymmetrically encrypting a randomly generated symmetric encryption key to obtain a key ciphertext;

[0136] A message ciphertext generating unit, used to encrypt the plaintext of the message to be sent based on the symmetric encryption key to obtain the message ciphertext;

[0137] The output unit is used to package the source address, the destination address, the key ciphertext and the message ciphertext to obtain a data packet, and send the data packet to a receiving terminal.

[0138] Reference Figure 6 This embodiment also discloses a receiving terminal, which includes:

[0139] A receiving unit, configured to receive a data packet from a sending terminal; wherein the data packet is obtained by randomly generating a source address of the sending terminal, dynamically generating a destination address of the receiving terminal, performing hash processing on a plain text message to be sent, and generating message digest data; asymmetrically encrypting a randomly generated symmetric encryption key to obtain a key ciphertext; encrypting the plain text message to be sent based on the symmetric encryption key to obtain a message ciphertext; and packaging the source address, destination address, key ciphertext, message digest data, and message ciphertext to obtain;

[0140] A validity verification unit, used to parse out timestamp information from the header field of the data packet and verify the validity of the data packet based on the timestamp information;

[0141] A parsing unit, configured to parse the key ciphertext, the virtual port, the message digest data and the message ciphertext from the data field of the data packet in response to the validity verification being passed;

[0142] an asymmetric decryption unit, used for performing asymmetric decryption from a key ciphertext to obtain a symmetric encryption key;

[0143] A symmetric decryption unit, used to decrypt the message ciphertext based on the symmetric encryption key to obtain the message plaintext;

[0144] A consistency check unit, used to perform consistency check on the message plaintext based on the message digest data;

[0145] The forwarding unit is used for forwarding the plain text of the message to the corresponding application process according to the virtual port in response to the plain text consistency check of the message passing.

[0146] This embodiment also discloses a stealth communication system based on IPv6. A stealth communication system based on IPv6 includes a sending terminal as described above and a receiving terminal as described above.

[0147] The IPv6-based stealth communication system provided in the present application can implement the above-mentioned IPv6-based stealth communication method, and the specific working process of the IPv6-based stealth communication system can refer to the corresponding process in the above-mentioned method embodiment.

[0148] It should be noted that in the above embodiments, the description of each embodiment has different emphases, and for parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0149] Based on the same technical concept, the present invention also discloses a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program according to any of the above methods.

[0150] The present invention also discloses a computer-readable storage medium, which includes a computer program that can be loaded by a processor and executed as in any of the above methods.

[0151] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.

[0152] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0153] The above are all preferred embodiments of the present application, and are not intended to limit the protection scope of the present application. Any feature disclosed in this specification (including the abstract and drawings), unless otherwise stated, can be replaced by other equivalent or alternative features with similar purposes. That is, unless otherwise stated, each feature is only an example of a series of equivalent or similar features.

Claims

1. A stealth communication method based on IPv6, applied to a sending terminal, characterized in that: include: Randomly generate the source address of the sending terminal; Dynamically generate the destination address of the receiving terminal; Perform hash processing on the plaintext of the message to be sent to generate message digest data; Asymmetrically encrypt the randomly generated symmetric encryption key to obtain the key ciphertext; Based on the symmetric encryption key, encrypt the plaintext message to be sent to obtain a ciphertext message; Packing the source address, destination address, key ciphertext, message digest data and message ciphertext to obtain a data packet, and sending the data packet to a receiving terminal; The randomly generating a source address of the sending terminal specifically includes: Obtain the first IPv6 prefix of the sending terminal; Based on the current timestamp information and the first IPv6 prefix, randomly generate a source address of the sending terminal; wherein the first IPv6 prefix is ​​the variable part of the IPv6 address of the sending terminal, which is used to identify the address range of the sending terminal network; The dynamically generating a destination address of the receiving terminal specifically includes: Get the current timestamp information; Obtain a preset first unique number of the sending terminal and a second unique number of the receiving terminal, and obtain a second IPv6 prefix of the receiving terminal; A linear operation is performed on the source address, the timestamp information, the first unique number, the second unique number, and the second IPv6 prefix to obtain the destination address.

2. The method according to claim 1, characterized in that The randomly generated symmetric encryption key is asymmetrically encrypted to obtain a key ciphertext, specifically including: The randomly generated symmetric encryption key is signed with the private key of the sender to obtain the initial key ciphertext; The initial key ciphertext is encrypted again based on the receiving end public key to obtain the key ciphertext.

3. The method according to claim 1, characterized in that The data packet is a UDP message; the source address, the destination address, the key ciphertext, the message summary data and the message ciphertext are packaged to obtain the data packet, specifically including: Get the virtual port of the receiving terminal; Load the virtual port, key ciphertext, message digest data and message ciphertext into a preset message template to obtain a protocol message; Load the protocol message into the data field of the UDP message template, and load the source address and the destination address into the header field of the UDP message template to obtain a UDP message; Send UDP packets to the receiving terminal.

4. A stealth communication method based on IPv6, applied to a receiving terminal, characterized in that: Receive a data packet from a sending terminal; wherein the method for generating the data packet is configured as follows: by randomly generating a source address of the sending terminal, dynamically generating a destination address of the receiving terminal, performing hash processing on a plain text message to be sent, and generating message summary data; asymmetrically encrypting a randomly generated symmetric encryption key to obtain a key ciphertext; encrypting the plain text message to be sent based on the symmetric encryption key to obtain a message ciphertext; and packaging the source address, the destination address, the key ciphertext, the message summary data, and the message ciphertext to obtain; Parse the timestamp information from the header field of the data packet and verify the validity of the data packet based on the timestamp information; In response to the validity verification being passed, parsing the key ciphertext, the virtual port, the message digest data and the message ciphertext from the data field of the data packet; Perform asymmetric decryption from the key ciphertext to obtain the symmetric encryption key; Decrypt the message ciphertext based on the symmetric encryption key to obtain the message plaintext; Based on the message digest data, the message plaintext is checked for consistency; In response to the plaintext consistency check of the message passing, forwarding the plaintext message to the corresponding application process according to the virtual port; The randomly generating the source address of the sending terminal specifically includes: Obtaining a first IPv6 prefix of the sending terminal; randomly generating a source address of the sending terminal based on the current timestamp information and the first IPv6 prefix; wherein the first IPv6 prefix is ​​the variable part of the IPv6 address of the sending terminal, and is used to identify the address range of the sending terminal network; The dynamically generating a destination address of the receiving terminal specifically includes: Obtain the current timestamp information; obtain the preset first unique number of the sending terminal and the second unique number of the receiving terminal, and obtain the second IPv6 prefix of the receiving terminal; perform linear operations on the source address, timestamp information, the first unique number, the second unique number and the second IPv6 prefix to obtain the destination address.

5. The method according to claim 4, characterized in that The consistency check of the message plaintext based on the message digest data specifically includes: Hash the message plaintext to generate hash data; The hash data and the message digest data are compared. If the comparison is consistent, the message plaintext consistency check passes; if the comparison is inconsistent, the message plaintext consistency check fails.

6. A sending terminal, characterized in that: A stealth communication method based on IPv6 for executing any one of claims 1 to 3, comprising: A source address generation unit, used to randomly generate a source address of a sending terminal; A destination address generating unit, used for dynamically generating a destination address of a receiving terminal; A digest generation unit, used for performing hash processing on the plain text of the message to be sent to generate message digest data; A key ciphertext generation unit, used for asymmetrically encrypting a randomly generated symmetric encryption key to obtain a key ciphertext; A message ciphertext generating unit, used to encrypt the plaintext of the message to be sent based on the symmetric encryption key to obtain the message ciphertext; The output unit is used to package the source address, the destination address, the key ciphertext and the message ciphertext to obtain a data packet, and send the data packet to a receiving terminal.

7. A receiving terminal, characterized in that: A stealth communication method based on IPv6 for executing any one of claims 4 to 5, comprising: A receiving unit, configured to receive a data packet from a sending terminal; wherein the method for generating the data packet is configured as follows: by randomly generating a source address of the sending terminal, dynamically generating a destination address of the receiving terminal, performing hash processing on a plain text message to be sent, and generating message summary data; asymmetrically encrypting a randomly generated symmetric encryption key to obtain a key ciphertext; encrypting the plain text message to be sent based on the symmetric encryption key to obtain a message ciphertext; and packaging the source address, the destination address, the key ciphertext, the message summary data, and the message ciphertext to obtain; A validity verification unit, used to parse out timestamp information from the header field of the data packet and verify the validity of the data packet based on the timestamp information; A parsing unit, configured to parse the key ciphertext, the virtual port, the message digest data and the message ciphertext from the data field of the data packet in response to the validity verification being passed; an asymmetric decryption unit, used for performing asymmetric decryption from a key ciphertext to obtain a symmetric encryption key; A symmetric decryption unit, used to decrypt the message ciphertext based on the symmetric encryption key to obtain the message plaintext; A consistency check unit, used to perform consistency check on the message plaintext based on the message digest data; The forwarding unit is used for forwarding the plain text of the message to the corresponding application process according to the virtual port in response to the plain text consistency check of the message passing.

8. An IPv6-based stealth communication system, characterized in that: include: A transmitting terminal as claimed in claim 6 and a receiving terminal as claimed in claim 7.

Citation Information

Patent Citations

  • Method and system for safety processing of data files

    CN106534079A

  • Address-free IPv6 non-public server, client and communication method

    CN110493367A