Information transmission method and device, equipment and storage medium
By employing an encrypted authentication mechanism for random numbers, device identifiers, and optical module identifiers, the problem of unverifiable optical module legitimacy in existing technologies is solved, thereby enhancing the security of Ethernet communication.
Patent Information
- Application Number
- CN202310868916.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-14
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2043-07-14
AI Technical Summary
Existing Ethernet authentication methods cannot verify the legitimacy of optical modules, posing a security risk.
First information is generated by encrypting the first random number, the second random number, the identifier of the first device, and the identifier of the first optical module, and then sent to the second device for authentication. At the same time, the identifier of the optical module is decrypted and its legitimacy is judged using a pre-configured shared key.
This ensures the legitimacy of the equipment and optical modules, enhances the security of Ethernet communication, and prevents network attacks.
Smart Images

Figure CN118827010B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of wireless communication, and particularly relates to an information transmission method and device, equipment and a storage medium. BACKGROUND
[0002] At present, any device connected to an Ethernet can receive transmitted data, resulting in that network attacks are more likely to occur in the Ethernet. Measures such as data encryption, secure communication protocols and physical security enhancement can be taken to prevent network attacks. Existing network encryption mechanisms include a Transport Layer Security (TLS) protocol, an Internet Protocol Security (IPSec) protocol and a Media Access Control Security (MACSec) protocol of a link layer, which are respectively used to provide security services at different network layers. A Physical Security (PHYSec) protocol is a security encryption technology working at the physical layer of the Ethernet, and performs encryption and decryption on a bit stream of the physical layer. The PHYSec can protect all upper layer protocols and data, and hide traffic characteristics, and has extremely high security. In the related art, the legality of an optical module cannot be confirmed in the process of authenticating a device in the Ethernet, and there is a certain security risk. SUMMARY
[0003] Therefore, the embodiments of the present application aim to provide an information transmission method, device, equipment and storage medium.
[0004] The technical scheme of the embodiments of the present application is implemented as follows.
[0005] The embodiments of the present application provide an information transmission method applied to a first device, and the method comprises the following steps.
[0006] Encrypt a first random number, a second random number, an identifier of the first device and an identifier of a first optical module in the first device to obtain first information;
[0007] Send the first information to a second device, wherein the first information is used for the second device to authenticate the first device.
[0008] In addition, according to at least one embodiment of the present application, the method further comprises the following steps.
[0009] Read the identifier of the first optical module from a memory of the first optical module in the first device.
[0010] In addition, according to at least one of the embodiments of the present application, the encryption of the first random number, the second random number, the identifier of the first device, and the identifier of the first optical module in the first device comprises:
[0011] obtaining a pre-configured shared key;
[0012] encrypting the first random number, the second random number, the identifier of the first device, and the identifier of the first optical module in the first device by using the shared key.
[0013] In addition, according to at least one of the embodiments of the present application, the method further comprises:
[0014] receiving second information; the second information is obtained by encrypting the first random number, the identifier of the second device, and the identifier of the second optical module in the second device by using the pre-configured shared key by the second device;
[0015] authenticating the second device based on the second information.
[0016] In addition, according to at least one of the embodiments of the present application, the authentication of the second device based on the second information comprises:
[0017] decrypting the first random number, the identifier of the second device, and the identifier of the second optical module in the second device in the second information by using the pre-configured shared key to obtain the identifier of the second optical module;
[0018] judging whether the second optical module is legal according to the identifier of the second optical module;
[0019] in the case where it is determined that the second optical module is legal, encrypting the first random number, the identifier of the second device, and the decrypted identifier of the second optical module by using the pre-configured shared key to obtain third information;
[0020] comparing the third information with the second information to obtain a comparison result;
[0021] in the case where the comparison result represents that the third information is the same as the second information, determining that the second device is a legal device.
[0022] In addition, according to at least one of the embodiments of the present application, the method further comprises:
[0023] interchangeably transmitting first messages with the second device;
[0024] if the first message transmitted by the second device is not received within a preset time length, closing the current secure port.
[0025] Further, according to at least one of the embodiments of the present application, the method further comprises:
[0026] After the authentication of the second device is passed, a physical layer link state is acquired;
[0027] If the physical layer link state is a disconnected state, the authentication of the legality of the second device is failed;
[0028] After the authentication of the second device is failed, the physical layer link state is acquired again;
[0029] If the physical layer link state is a connected state, the legality of the second device is re-authenticated.
[0030] Further, according to at least one of the embodiments of the present application, the method further comprises:
[0031] After the authentication of the second device is passed, a physical layer link state is acquired;
[0032] If the physical layer link state is a disconnected state, a timing window is started, and the legality of the second device is not re-authenticated in the timing window;
[0033] After the timing window is ended, the physical layer link state is acquired again;
[0034] If the physical layer link state acquired again is a connected state, the legality of the second device is re-authenticated, and the timing window is ended;
[0035] If the physical layer link state acquired again is a disconnected state, the authentication of the legality of the second device is failed, and a next timing window is started.
[0036] An information transmission method is provided in the embodiments of the present application, and the method is applied to a second device, and the method comprises the following steps:
[0037] Receiving first information; the first information is obtained by encrypting a first random number, a second random number, an identifier of the first device and an identifier of a first optical module in the first device by the first device;
[0038] Based on the first information, the first device is authenticated.
[0039] Further, according to at least one of the embodiments of the present application, the authentication of the first device based on the first information comprises:
[0040] decrypt the first random number, the second random number, the identity of the first device and the identity of the first optical module in the first device in the first information by using the pre-configured shared key to obtain the identity of the first optical module;
[0041] determine whether the first optical module is legal according to the second identity;
[0042] encrypt the first random number, the second random number, the identity of the first device and the identity of the first optical module obtained by decryption by using the pre-configured shared key to obtain fourth information in a case where it is determined that the first optical module is legal;
[0043] compare the fourth information with the first information to obtain a comparison result;
[0044] determine that the first device is a legal device in a case where the comparison result represents that the fourth information is the same as the first information.
[0045] In addition, according to at least one embodiment of the present application, the method further comprises:
[0046] obtaining a pre-configured shared key;
[0047] encrypting the first random number, the identity of the second device and the identity of the second optical module in the second device by using the shared key to obtain second information;
[0048] sending the second information to the first device; wherein the second information is used for the first device to authenticate the second device.
[0049] In addition, according to at least one embodiment of the present application, the method further comprises:
[0050] reading the identity of the second optical module from the memory of the second optical module in the second device.
[0051] In addition, according to at least one embodiment of the present application, the method further comprises:
[0052] interchangeably sending a first packet with the first device;
[0053] if the first packet sent by the first device is not received within a preset time length, closing the current secure port.
[0054] In addition, according to at least one embodiment of the present application, the method further comprises:
[0055] obtaining a physical layer link state after the first device passes the authentication;
[0056] if the physical layer link state is the disconnected state, the authentication of the legality of the first device is invalidated;
[0057] after the authentication of the first device is invalidated, the physical layer link state is obtained again;
[0058] if the physical layer link state is the connected state, the re-authentication of the legality of the first device is performed.
[0059] In addition, according to at least one embodiment of the present application, the method further comprises:
[0060] after the authentication of the first device is invalidated, the physical layer link state is obtained again;
[0061] if the physical layer link state is the disconnected state, a timing window is started, and the re-authentication of the legality of the first device is not performed in the timing window;
[0062] after the timing window ends, the physical layer link state is obtained again;
[0063] if the physical layer link state obtained again is the connected state, the re-authentication of the legality of the first device is performed, and the timing of the timing window ends;
[0064] if the physical layer link state obtained again is the disconnected state, the authentication of the legality of the first device is invalidated, and the next timing window is started.
[0065] An information transmission apparatus is provided in an embodiment of the present application, and the apparatus comprises:
[0066] a first processing module configured to encrypt a first random number, a second random number, an identifier of the first device, and an identifier of a first optical module in the first device to obtain first information;
[0067] a sending module configured to send the first information to a second device, wherein the first information is used by the second device to authenticate the first device.
[0068] An information transmission apparatus is provided in an embodiment of the present application, and the apparatus comprises:
[0069] a receiving module configured to receive first information; the first information is obtained by the second device by encrypting a first random number, a second random number, an identifier of the first device, and an identifier of a first optical module in the first device;
[0070] a second processing module configured to authenticate the first device based on the first information.
[0071] At least one embodiment of the present application provides a first device, comprising a processor and a memory for storing a computer program capable of running on the processor,
[0072] Wherein, the processor is configured to execute the steps of any of the methods on the first device side when running the computer program.
[0073] At least one embodiment of the present application provides a second device, comprising a processor and a memory for storing a computer program capable of running on the processor,
[0074] Wherein, the processor is configured to execute the steps of any of the methods on the second device side when running the computer program.
[0075] The information transmission method, device and equipment and storage medium provided by the embodiments of the present application encrypt the first random number, the second random number, the identifier of the first device and the identifier of the first optical module in the first device to obtain first information; and send the first information to a second device, wherein the first information is used for the second device to authenticate the first device.
[0076] The technical scheme provided by the embodiments of the present application adds the unique identifier of the first optical module of the first device to the authentication process in addition to adding the identifier of the first device to the authentication process, and ensures the legality of the device and the optical module. BRIEF DESCRIPTION OF DRAWINGS
[0077] Figure 1 is an implementation flow diagram of the information transmission method of the embodiments of the present application Figure 1 ;
[0078] Figure 2 is an implementation flow diagram of the information transmission method of the embodiments of the present application Figure 2 ;
[0079] Figure 3 is a system architecture diagram of the application of the information transmission method of the embodiments of the present application;
[0080] Figure 4 is a specific implementation flow diagram of the information transmission method of the embodiments of the present application;
[0081] Figure 5 is a diagram for judging whether the opposite end is online through the physical layer link state according to the embodiments of the present application;
[0082] Figure 6 is a composition structure diagram of the information transmission device according to the embodiments of the present application Figure 1 ;
[0083] Figure 7is a schematic diagram of a component structure of an information transmission device according to an embodiment of the present application Figure 2 ;
[0084] Figure 8 is a schematic diagram of a component structure of a first device according to an embodiment of the present application
[0085] Figure 9 is a schematic diagram of a component structure of a second device according to an embodiment of the present application DETAILED DESCRIPTION
[0086] Before the technical solutions of the embodiments of the present application are introduced, the related technologies are introduced.
[0087] At present, Ethernet is widely used in data centers, operator networks, industrial Internet, Internet of Things, vehicle-mounted Ethernet and other scenarios, and its security is directly related to the business production of key industries such as telecommunications, energy, transportation, electricity, finance, and even threatens personnel life and national security. Since Ethernet is a shared communication link, any device connected to the Ethernet can receive transmitted data, resulting in network attacks more likely to occur in Ethernet. With the emergence of 800Gbps and 1.6Tbps Ethernet, the amount of data transmitted by Ethernet links has increased dramatically, and the damage and impact caused by network attacks are also more significant.
[0088] Therefore, measures such as data encryption, secure communication protocols, and physical security enhancements are needed to prevent eavesdropping attacks.
[0089] Existing network encryption mechanisms include transport layer TLS, network layer IPSec, and link layer MACSec, which provide security services at different network levels. Physical layer security (PHYSec) is a security encryption technology that works at the physical layer of Ethernet and encrypts and decrypts the bit stream of the physical layer. The identity authentication mechanism of PHYSec mainly ensures that the two ends of the communication are legal Ethernet devices. The traditional Ethernet authentication method is a port authentication method based on the link layer device (such as a switch), such as 802.1X, MAC address authentication, etc.
[0090] PHYSec is a security encryption technology that works at the physical layer of Ethernet and encrypts and decrypts the bit stream of the physical layer. The Ethernet frame header of the data link layer and the IP header of the network layer both belong to the payload of the physical layer bit stream, therefore, PHYSec can protect all upper layer protocols and data, mask the traffic characteristics, and has extremely high security.
[0091] In the related art, the identity authentication of PHYSec only uses the information of the communication device in the authentication process, and does not use the information of the optical module on the interface, so the legality of the optical module cannot be confirmed, and there is a certain security risk.
[0092] Based on this, in the embodiments of the present application, the first random number, the second random number, the identifier of the first device and the identifier of the first optical module in the first device are encrypted to obtain first information; the first information is sent to the second device, wherein the first information is used for the second device to authenticate the first device.
[0093] Referring to Figure 1 , Figure 1 is a flowchart of an implementation of an information transmission method of the embodiments of the present application, applied to a first device, the method comprising steps 101 to 102:
[0094] Step 101: encrypting the first random number, the second random number, the identifier of the first device and the identifier of the first optical module in the first device to obtain first information.
[0095] As an example, the first random number is generated by the first device.
[0096] As an example, the second random number is generated by the second device.
[0097] As an example, before the first device determines the first information, the second device can send the generated second random number to the first device.
[0098] As an example, the first random number and the second random number can be generated by a random function. Wherein, the random function can be RAND().
[0099] As an example, the identifier of the first device can be obtained from the local memory of the first device.
[0100] In some embodiments, the method further comprises:
[0101] reading the identifier of the first optical module from the memory of the first optical module in the first device.
[0102] As an example, the memory can be Electrically-Erasable Programmable Read-Only Memory (EEPROM), but includes but is not limited to EEPROM.
[0103] As an example, the first optical module is a core device in a communication network. The first optical module supports hot plug and can be inserted into the first device for use.
[0104] As an example, the first device can read the identifier of the first optical module stored in the EEPROM of the first optical module into the device through the IIC interface.
[0105] Step 102: sending the first information to a second device, wherein the first information is used for the second device to authenticate the first device.
[0106] In some embodiments, the encrypting the first random number, the second random number, the identity of the first device, and the identity of the first optical module in the first device comprises:
[0107] obtaining a pre-configured shared key;
[0108] encrypting the first random number, the second random number, the identity of the first device, and the identity of the first optical module in the first device by using the shared key.
[0109] As an example, the pre-configured shared key can refer to a PSK.
[0110] As an example, the first device can send a first request to a server, the first request being used for requesting to obtain a pre-configured shared key; the server authenticates the first device in response to the first request, and configures the shared key to the first device after the first device passes the authentication.
[0111] The server can generate the shared key by using a random number generator, and the server can obtain the identity of the first device, and determine that the first device passes the authentication when the identity of the first device is stored in a local database.
[0112] In some embodiments, the method further comprises:
[0113] receiving second information; the second information being obtained by the second device by encrypting the first random number, the identity of the second device, and the identity of the second optical module in the second device by using a pre-configured shared key; the first random number being generated by the first device;
[0114] authenticating the second device based on the second information.
[0115] As an example, before the first device receives the second information sent by the second device, the first device can send the first random number to the second device.
[0116] As an example, the first information sent by the first device to the second device is encrypted by a first random number, a second random number, an identity of the first device and an identity of a first optical module in the first device, and the second information sent by the second device to the first device is encrypted by the first random number, an identity of the second device and an identity of a second optical module in the second device. In this way, other devices are prevented from impersonating the second device to send authentication information to the first device in the case of network attacks.
[0117] As an example, the second device can also encrypt the second random number, the identity of the second device and the identity of the second optical module in the second device by using a pre-configured shared key.
[0118] As an example, the second device can obtain the identity of the second device from a local memory of the second device and send it to the first device.
[0119] As an example, the second device can read the identity of the second optical module from a memory of the second optical module in the second device.
[0120] As an example, the memory can refer to an EEPROM, but is not limited to an EEPROM.
[0121] As an example, the second optical module is a core device in a communication network. The second optical module supports hot plugging and can be inserted into the second device for use.
[0122] In some embodiments, the authentication of the second device based on the second information comprises:
[0123] decrypting the first random number, the identity of the second device and the identity of the second optical module in the second device in the second information by using the pre-configured shared key to obtain the identity of the second optical module;
[0124] determining whether the second optical module is legal according to the identity of the second optical module;
[0125] in the case of determining that the second optical module is legal, encrypting the first random number, the identity of the second device and the decrypted identity of the second optical module by using the pre-configured shared key to obtain third information;
[0126] comparing the third information with the second information to obtain a comparison result;
[0127] in the case of the comparison result representing that the third information is the same as the second information, determining that the second device is a legal device.
[0128] As an example, the first device can locally store a serial number of the second optical module in the second device, after the first device decodes the second information to obtain the identification of the second optical module, the first device compares the decoded identification of the second optical module with the locally stored serial number of the second optical module, if they are the same, it is determined that the second optical module is legal; otherwise, it is determined that the second optical module is illegal.
[0129] As an example, a database can be stored in the server, the database stores the serial number of the second optical module in the second device, after the first device decodes the second information to obtain the identification of the second optical module, the first device can obtain the database from the server and query whether the decoded identification of the second optical module is contained in the database, if the decoded identification of the second optical module is contained in the database, it is determined that the second optical module is legal; otherwise, it is determined that the second optical module is illegal.
[0130] As an example, after the first device decodes the second information to obtain the identification of the second optical module, the decoded identification of the second optical module can also be sent to the server, and the server queries whether the decoded identification of the second optical module is contained in the database, if the decoded identification of the second optical module is contained in the database, the server sends indication information to the first device, the indication information is used to indicate that the second optical module is legal; otherwise, the server sends indication information to the first device, the indication information is used to indicate that the second optical module is illegal.
[0131] As an example, the first information and the second information can be two sequences in particular, the sequence can be a sequence composed of 0 and 1, in the case of two sequences being the same, it is determined that the second device is a legal device. Further, the two sequences can be converted into corresponding strings respectively, in the case of two strings being the same, it is determined that the second device is a legal device.
[0132] Here, the encryption algorithm is not limited, and it only needs to meet the security requirements, and can be based on the AES (Advanced Encrypted Standard)-CMAC (Cipher-base Message Authentication Code) algorithm of the AES (Advanced Encrypted Standard).
[0133] It should be noted that, in the authentication process of the first device to the second device, in addition to adding the identification of the second device to the authentication process, the unique identification of the second optical module of the second device is also added to the authentication process, so as to ensure the legality of the second device and the second optical module.
[0134] In some embodiments, the method further comprises:
[0135] interchanging a first message with the second device;
[0136] if the first message sent by the second device is not received within a preset time period, closing the current secure port.
[0137] In some embodiments, the method further comprises:
[0138] after the second device is authenticated, obtaining a physical layer link state;
[0139] if the physical layer link state is a disconnected state, the authentication of the legality of the second device is invalidated;
[0140] after the authentication of the second device is invalidated, the physical layer link state is obtained again;
[0141] if the physical layer link state is a connected state, the legality of the second device is re-authenticated.
[0142] As an example, the physical layer link state includes a connected state (up) and a disconnected state (down).
[0143] In some embodiments, the method further comprises:
[0144] after the second device is authenticated, obtaining a physical layer link state;
[0145] if the physical layer link state is a disconnected state, a timing window is opened, and the legality of the second device is not re-authenticated within the timing window;
[0146] after the timing window ends, the physical layer link state is obtained again;
[0147] if the physical layer link state obtained again is a connected state, the legality of the second device is re-authenticated, and the timing of the timing window ends;
[0148] if the physical layer link state obtained again is a disconnected state, the authentication of the legality of the second device is invalidated, and a next timing window is opened.
[0149] In the embodiments of the present application, the following advantages are provided:
[0150] (1) In the process of authenticating the first device, in addition to adding the identity of the first device to the authentication process, the unique identity of the first optical module of the first device is also added to the authentication process, and the legality of the device and the optical module is ensured.
[0151] (2) The identity authentication mechanism technology based on the optical module identification is one of the key technologies for implementing the PHYSec scheme. The authentication mechanism of the PHYSec integrates the unique identity identification (ID) of the optical module into the authentication process, ensuring that the device and the optical module are both legitimate.
[0152] Referring to Figure 2 , Figure 2 is a flowchart of an implementation process of an information transmission method of an embodiment of the present application, applied to a second device. The method comprises steps 201 to 202:
[0153] Step 201: receiving first information; the first information is obtained by encrypting a first random number, a second random number, an identification of the first device, and an identification of a first optical module in the first device by the first device.
[0154] As an example, the first random number is generated by the first device.
[0155] As an example, the second random number is generated by the second device.
[0156] As an example, in the process of determining the first information by the first device, the second device can send the generated second random number to the first device.
[0157] As an example, the first random number and the second random number can be generated by a random function. The random function can be RAND().
[0158] As an example, the identification of the first device can be obtained by the first device from a local memory of the first device.
[0159] As an example, the first device can read the identification of the first optical module from a memory of the first optical module in the first device.
[0160] As an example, the memory can refer to an EEPROM, but is not limited to an EEPROM.
[0161] As an example, the first optical module is a core device in a communication network. The first optical module supports hot plugging and can be inserted into the first device for use.
[0162] As an example, the first device can read the identification of the first optical module stored in the EEPROM of the first optical module into the device through an IIC interface.
[0163] As an example, the first device can obtain a pre-configured shared key, and encrypt the first random number, the second random number, the identity of the first device, and the identity of the first optical module in the first device by using the pre-configured shared key to obtain the first information.
[0164] As an example, the pre-configured shared key can refer to a PSK.
[0165] As an example, the first device can send a first request to a server, the first request being used to request to obtain a pre-configured shared key; the server responds to the first request to authenticate the first device, and configures the shared key to the first device after the first device passes the authentication.
[0166] The server can generate the shared key by using a random number generator, and the server can obtain the identity of the first device, and determine that the first device passes the authentication when the identity of the first device is stored in a local database.
[0167] Step 202: authenticating the first device based on the first information.
[0168] In some embodiments, the authentication of the first device based on the first information comprises:
[0169] decrypting the first random number, the second random number, the identity of the first device, and the identity of the first optical module in the first device in the first information by using the pre-configured shared key to obtain the identity of the first optical module;
[0170] determining whether the first optical module is legal according to the second identity;
[0171] in a case where it is determined that the first optical module is legal, encrypting the first random number, the second random number, the identity of the first device, and the decrypted identity of the first optical module by using the pre-configured shared key to obtain fourth information;
[0172] comparing the fourth information with the first information to obtain a comparison result;
[0173] in a case where the comparison result represents that the fourth information is the same as the first information, determining that the first device is a legal device.
[0174] As an example, the second device can locally store a serial number of the first optical module in the first device, after the second device decodes the first information to obtain the identification of the first optical module, the second device compares the decoded identification of the first optical module with the locally stored serial number of the first optical module, if the two are the same, it is determined that the first optical module is legal; otherwise, it is determined that the first optical module is illegal.
[0175] As an example, a database can be stored in the server, the database stores a serial number of the first optical module in the first device, after the second device decodes the first information to obtain the identification of the first optical module, the second device can obtain the database from the server and query whether the database contains the decoded identification of the first optical module, if the database contains the decoded identification of the first optical module, it is determined that the first optical module is legal; otherwise, it is determined that the first optical module is illegal.
[0176] As an example, after the second device decodes the first information to obtain the identification of the first optical module, the second device can also send the decoded identification of the first optical module to the server, and the server queries whether the database contains the decoded identification of the first optical module, if the database contains the decoded identification of the first optical module, the server sends indication information to the second device, the indication information is used to indicate that the first optical module is legal; otherwise, the server sends indication information to the second device, the indication information is used to indicate that the first optical module is illegal.
[0177] Here, the encryption algorithm is not limited, which meets the security requirements, and can be based on the AES-CMAC algorithm of AES.
[0178] It should be noted that, in the authentication process of the second device to the first device, in addition to adding the identification of the first device to the authentication process, the unique identification of the first optical module of the first device is also added to the authentication process, so as to ensure the legality of the first device and the first optical module.
[0179] In some embodiments, the method further comprises:
[0180] obtaining a preconfigured shared key;
[0181] encrypting the first random number, the identification of the second device and the identification of the second optical module in the second device by using the shared key to obtain second information; the first random number is generated by the first device;
[0182] sending the second information to the first device; wherein the second information is used for the first device to authenticate the second device.
[0183] As an example, the first device can send the first random number to the second device before the first device receives the second information sent by the second device.
[0184] As an example, the second device can obtain the identity of the second device from a local memory of the second device and send to the first device.
[0185] As an example, the second optical module is a core device in a communication network. The second optical module supports hot plug and can be inserted into the second device for use.
[0186] In some embodiments, the method further comprises:
[0187] reading the identity of the second optical module from a memory of the second optical module in the second device.
[0188] As an example, the memory can refer to an EEPROM, but includes but is not limited to an EEPROM.
[0189] In some embodiments, the method further comprises:
[0190] interchangeably sending a first packet with the first device;
[0191] if the first packet sent by the first device is not received within a preset time length, closing the current secure port.
[0192] In some embodiments, the method further comprises:
[0193] after the first device passes the authentication, obtaining a physical layer link state;
[0194] if the physical layer link state is a disconnected state, the authentication of the legality of the first device is invalid;
[0195] after the authentication of the first device is invalid, obtaining the physical layer link state again;
[0196] if the physical layer link state is a connected state, re-authenticating the legality of the first device.
[0197] As an example, the physical layer link state includes a connected state (up) and a disconnected state (down).
[0198] In some embodiments, the method further comprises:
[0199] after the first device passes the authentication, obtaining a physical layer link state;
[0200] if the physical layer link state is the disconnected state, a timing window is started, and the first device is not re-authenticated during the timing window;
[0201] after the timing window ends, the physical layer link state is obtained again;
[0202] if the physical layer link state obtained again is the connected state, the first device is re-authenticated, and the timing window ends;
[0203] if the physical layer link state obtained again is the disconnected state, the authentication of the first device is invalidated, and the next timing window is started.
[0204] In the embodiments of the present application, the following advantages are achieved:
[0205] (1) In the process of authenticating the first device, the unique identifier of the first optical module of the first device is added to the authentication process in addition to the identifier of the first device, and the legality of the device and the optical module is ensured.
[0206] (2) The identity authentication mechanism technology based on the optical module identifier is one of the key technologies for implementing the PHYSec scheme. The authentication mechanism of the PHYSec integrates the unique identity identifier (ID) of the optical module into the authentication process, and ensures that the device and the optical module are both legal.
[0207] Referring to Figure 3 , Figure 3 is a system architecture diagram for the information transmission method of the embodiments of the present application, and the system comprises:
[0208] a management system, configured to obtain a pre-configured shared key by the first device and the second device.
[0209] the first device, configured to obtain a pre-configured shared key; encrypt the first random number, the second random number, the identifier of the first device, and the identifier of the first optical module in the first device by using the shared key to obtain first information; and send the first information to the second device.
[0210] the second device, configured to receive the first information; and authenticate the first device based on the first information.
[0211] the second device, further configured to obtain a pre-configured shared key; encrypt the first random number, the identifier of the second device, and the identifier of the second optical module in the second device by using the shared key to obtain second information; and send the second information to the first device.
[0212] The first device is further configured to receive the second information and, based on the second information, authenticate the second device.
[0213] See Figure 4 , Figure 4 This is a schematic diagram illustrating the specific implementation flow of the information transmission method according to an embodiment of this application. The method includes steps 401 to 410:
[0214] Step 401: The administrator pre-configures a shared key PSK for the two communication devices through the management system.
[0215] Step 402: The first device, Bob, receives the second random number.
[0216] Here, the second device Alice generates a second random number and sends it to the first device Bob.
[0217] Here, the second random number can have 256 bits.
[0218] Here, the second random number is represented by random number A.
[0219] Step 403: After receiving the second random number, the first device Bob generates the first random number locally.
[0220] Here, the first random number can be 256 bits.
[0221] Here, the first random number is represented by the random value B.
[0222] Step 404: The first device Bob reads the identifier of the first optical module from the EEPROM of the first optical module and obtains the identifier of the first device Bob from the local memory.
[0223] Step 405: The first device Bob uses the pre-configured shared key PSK to perform encryption operations on the first random number, the second random number, the identifier of the first device Bob, and the identifier of the first optical module to obtain the first information.
[0224] Here, the first random number is represented by the random value B.
[0225] Here, the second random number is represented by random number A.
[0226] Here, the identifier of the first device is used. express.
[0227] Here, the identifier of the first optical module is used... express.
[0228] Here, the first information is used express.
[0229] Step 406: The first device Bob sends the first random number, the identity of the first device Bob, and the first information to the second device Alice.
[0230] Step 407: The second device Alice receives the first random number, the identity of the first device Bob, and the first information, and authenticates the first device Bob based on the first random number, the identity of the first device Bob, and the first information.
[0231] Here, the authentication of the first device Bob by the second device Alice includes:
[0232] First, after receiving the first information, the second device Alice decrypts the first information using the pre-configured shared key PSK to obtain the identity of the first optical module.
[0233] Here, the first information is represented by .
[0234] Here, the identity of the first optical module is represented by .
[0235] Second, based on the identity of the first optical module, it is determined whether the first optical module is legitimate.
[0236] Here, the process of determining whether the first optical module is legitimate has been described above and will not be repeated here.
[0237] Here, the first optical module is represented by optical module B.
[0238] Third, if the first optical module is legitimate, the first random number, the second random number, the identity of the first device Bob, and the decrypted identity of the first optical module are encrypted using the pre-configured shared key to obtain fourth information.
[0239] Here, the fourth information is represented by .
[0240] Here, the encryption algorithm is not limited and can meet the security requirements, and the AES-CMAC algorithm based on AES is recommended.
[0241] Finally, the fourth information is compared with the first information to obtain a comparison result.
[0242] Here, the comparison is between the received If they are not consistent, the authentication of the first device Bob fails and the authentication process is terminated; if they are consistent, the authentication of the first device Bob is successful.
[0243] Step 408: After the second device Alice succeeds in authenticating the first device Bob, the second device Alice performs an encryption operation on the first random number, the identity of the second device Alice, and the identity of the second optical module using the preconfigured shared key PSK to obtain second information.
[0244] Here, the first random number is denoted by a random value B, which is generated by the first device Bob and sent to the second device Alice.
[0245] Here, the identity of the second device is denoted by .
[0246] Here, the identity of the second optical module is denoted by .
[0247] Here, the second information is denoted by .
[0248] Here, the encryption algorithm is not limited and only needs to meet the security requirements. The AES-CMAC algorithm based on AES is recommended.
[0249] Step 409: The second device Alice sends the identity of the second device Alice and the second information to the first device Bob.
[0250] Step 410: The first device Bob receives the identity of the second device Alice and the second information, and authenticates the second device Alice based on the identity of the second device Alice and the second information.
[0251] Here, the first device Bob authenticates the second device Alice, including:
[0252] First, after receiving the second information, the first device Bob decrypts the second information using the preconfigured shared key PSK to obtain the identity of the second optical module.
[0253] Here, the second information is denoted by .
[0254] Here, the identity of the second optical module is denoted by .
[0255] Second, based on the identity of the second optical module, it is determined whether the second optical module is legitimate.
[0256] Here, the second optical module is denoted by optical module A.
[0257] Third, if the second optical module is legitimate, the first random number, the identity of the second device and the decrypted identity of the second optical module are encrypted using a pre-configured shared key to obtain third information.
[0258] Here, the third information is represented by .
[0259] Here, the encryption algorithm is not limited, and the security requirement is met, and the AES-CMAC algorithm based on AES is recommended.
[0260] Finally, the third information is compared with the second information to obtain a comparison result.
[0261] Here, the comparison is performed between the received If the two are inconsistent, the authentication of the second device Alice fails, and the authentication process is terminated; if the two are consistent, the authentication of the second device Alice is successful, and the bilateral authentication is successful.
[0262] Referring to Figure 5 , Figure 5 is a schematic diagram of determining whether the opposite end is online by the physical layer link state of the embodiment of the present application, as shown in Figure 5 , after the bilateral authentication between the first device and the second device is completed, whether the opposite end is online is determined by the physical layer link state.
[0263] Here, the physical layer link state includes a connection state (up) and a disconnection state (down).
[0264] Here, according to the security requirement of the user, the mode of determining whether the opposite end is online based on the physical layer link state can provide two modes for the customer to choose flexibly.
[0265] First, high security mode: after the bilateral authentication of the two-end devices is completed, if the device physical layer detects that the link state is the disconnection (down) state, it means that the link is interrupted at this time due to some reasons, and the current authentication is invalidated immediately. If the device physical layer detects again that the link is in the connection state (up) state, the two-end devices need to perform the bilateral authentication again.
[0266] The second, high usability mode: design a timing window, the window period is T, and the initial state is connected (up). After the two-end device completes the mutual authentication, when the device detects that the physical layer link state is disconnected (down), the timer starts to count. In a window period, no re-authentication is performed. After the end of a window period T, the physical layer link state is checked. If the physical layer link state is still disconnected (down), a new round of window timing is started, the current authentication is invalid, but the service is not blocked, and the re-authentication is initiated as soon as the physical layer link state is detected to be connected (up); if the physical layer link state is connected (up), the re-authentication is initiated, the timer stops counting, and the timer is cleared. The window period T can be configured.
[0267] Here, the authentication protocol can be based on Ethernet frame bearer (EAPoL) or physical layer channel bearer. If the Ethernet frame bearer is adopted, after the authentication succeeds, the device port needs to maintain a certain timer, and sends a handshake message to the opposite end every fixed time (such as 30 seconds) to perform port authentication keep-alive. If the handshake message sent by the opposite end is not received within the specified time (such as 90 seconds), the device will close the current secure port.
[0268] Here, in the mode of the authentication protocol based on the physical layer channel bearer, the physical layer link state (up / down) can be directly used to quickly judge whether the opposite end is offline after the authentication succeeds, so as to avoid the mechanism that the handshake message is sent by the two ends every fixed time to inform the opposite end that the local end is still online after the authentication succeeds.
[0269] In this example, the following advantages are provided:
[0270] (1) By pre-configuring the shared key PSK for the two communication devices in advance, the device reads the optical module identifier stored in the EEPROM of the optical module into the device through the IIC interface, and the two devices perform mutual identity authentication based on the EAP authentication framework through the interaction of authentication information. The authentication information can be ciphertext obtained by performing encryption operation on the device ID, optical module ID and security random number using the shared key PSK.
[0271] (2) The identity authentication mechanism of the optical module identifier is proposed, the unique identity identifier (ID) of the optical module is integrated into the authentication process, and the identifier of the optical module participates in the encryption and decryption operation, thereby ensuring the legality of the optical module as well as the legality of the device.
[0272] (3) The mode of judging the online state of the opposite end based on the physical layer link state can provide multiple modes for the customer to choose flexibly.
[0273] High security mode, if the device physical layer detects that the physical layer link state is down state, the current authentication is invalidated immediately. If the device physical layer detects that the link state is up again, the devices at both ends of the link need to re-authenticate bidirectionally.
[0274] High usability mode: design timing window, multiple flash breaks, only re-authenticate once, and do not block business.
[0275] (4) Based on the physical layer channel bearing authentication protocol mode, whether the physical layer state is connected (up) or disconnected (down) can be directly used to quickly judge whether the opposite end is offline after successful authentication, and the mechanism of sending handshake messages to notify the opposite end that the end is still online every fixed time after successful authentication is eliminated.
[0276] To implement the information transmission method of the embodiment of the application, an information transmission device is further provided in the embodiment of the application. Figure 6 As shown in the component structure schematic diagram of the information transmission device of the embodiment of the application, Figure 6 the device comprises:
[0277] The first processing module 61 is configured to encrypt the first random number, the second random number, the identifier of the first device, and the identifier of the first optical module in the first device to obtain first information.
[0278] The sending module 62 is configured to send the first information to a second device, wherein the first information is used for the second device to authenticate the first device.
[0279] In an embodiment, the device is further configured to:
[0280] read the identifier of the first optical module from the memory of the first optical module in the first device.
[0281] In addition, according to at least one embodiment of the application, the encryption of the first random number, the second random number, the identifier of the first device, and the identifier of the first optical module in the first device comprises:
[0282] obtaining a preconfigured shared key;
[0283] encrypting the first random number, the second random number, the identifier of the first device, and the identifier of the first optical module in the first device by using the shared key.
[0284] In an embodiment, the device is further configured to:
[0285] receive second information; the second information is obtained by encrypting the first random number, an identity of the second device and an identity of a second optical module in the second device by the second device using a preconfigured shared key; the first random number is generated by the first device;
[0286] authenticate the second device based on the second information.
[0287] In an embodiment, the apparatus is further configured to:
[0288] decrypt the first random number, the identity of the second device and the identity of the second optical module in the second device in the second information using the preconfigured shared key to obtain the identity of the second optical module;
[0289] determine whether the second optical module is legal according to the identity of the second optical module;
[0290] encrypt the first random number, the identity of the second device and the decrypted identity of the second optical module using the preconfigured shared key to obtain third information in a case where it is determined that the second optical module is legal;
[0291] compare the third information with the second information to obtain a comparison result;
[0292] determine that the second device is a legal device in a case where the comparison result represents that the third information is identical to the second information.
[0293] In an embodiment, the apparatus is further configured to:
[0294] interchange first messages with the second device;
[0295] close a current secure port in a case where the first message sent by the second device is not received within a preset time length.
[0296] In an embodiment, the apparatus is further configured to:
[0297] obtain a physical layer link state after the second device is authenticated;
[0298] invalidate authentication of the legality of the second device in a case where the physical layer link state is a disconnected state;
[0299] obtain the physical layer link state again after the authentication of the second device is invalidated;
[0300] reauthenticate the legality of the second device in a case where the physical layer link state is a connected state.
[0301] In an embodiment, the apparatus is further configured to:
[0302] After the second device is authenticated, a physical layer link state is acquired;
[0303] If the physical layer link state is a disconnected state, a timing window is started, and the validity of the second device is not re-authenticated in the timing window;
[0304] After the timing window ends, the physical layer link state is acquired again;
[0305] If the physical layer link state acquired again is a connected state, the validity of the second device is re-authenticated, and the timing window ends;
[0306] If the physical layer link state acquired again is a disconnected state, the authentication of the validity of the second device is invalid, and the next timing window is started.
[0307] In actual application, the sending unit 62 can be implemented by a communication interface in the information transmission apparatus; and the first processing unit 61 can be implemented by a processor in the information transmission apparatus.
[0308] It should be noted that the information transmission apparatus provided in the above embodiments is only used for example to illustrate the division of the above program modules, and in actual application, the above processing can be completed by different program modules according to needs, that is, the internal structure of the apparatus is divided into different program modules to complete all or part of the above processing. In addition, the information transmission apparatus and the information transmission method provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.
[0309] To implement the information transmission method in the embodiments of the present application, an information transmission apparatus in the embodiments of the present application is further provided, which is arranged in a second device. Figure 7 As shown in FIG. 6, the apparatus includes: Figure 7
[0310] A receiving module 71 is configured to receive first information, wherein the first information is obtained by encrypting a first random number, a second random number, an identifier of the first device and an identifier of a first optical module in the first device by the second device;
[0311] A second processing module 72 is configured to authenticate the first device based on the first information.
[0312] In an embodiment, the second processing module 72 is configured to:
[0313] decrypt the first random number, the second random number, the identity of the first device and the identity of the first optical module in the first device in the first information by using the pre-configured shared key to obtain the identity of the first optical module;
[0314] determine whether the first optical module is legal according to the second identity;
[0315] encrypt the first random number, the second random number, the identity of the first device and the identity of the first optical module obtained by decryption by using the pre-configured shared key to obtain fourth information in the case of determining that the first optical module is legal;
[0316] compare the fourth information with the first information to obtain a comparison result;
[0317] determine that the first device is a legal device in the case of the comparison result representing that the fourth information is the same as the first information.
[0318] In an embodiment, the apparatus is further configured to:
[0319] obtain a pre-configured shared key;
[0320] encrypt the first random number, the identity of the second device and the identity of the second optical module in the second device by using the shared key to obtain second information; the first random number is generated by the first device;
[0321] send the second information to the first device; wherein the second information is used for the first device to authenticate the second device.
[0322] In an embodiment, the apparatus is further configured to:
[0323] read the identity of the second optical module from the memory of the second optical module in the second device.
[0324] In an embodiment, the method further comprises:
[0325] interchange first packets with the first device;
[0326] if the first packet sent by the first device is not received within a preset time length, close the current security port.
[0327] In an embodiment, the apparatus is further configured to:
[0328] obtain a physical layer link state after the first device passes the authentication;
[0329] if the physical layer link state is the disconnected state, the authentication of the legality of the first device is failed;
[0330] after the authentication of the first device is failed, the physical layer link state is acquired again;
[0331] if the physical layer link state is the connected state, the re-authentication of the legality of the first device is performed.
[0332] In an embodiment, the apparatus is further configured to:
[0333] after the authentication of the first device is passed, the physical layer link state is acquired;
[0334] if the physical layer link state is the disconnected state, a timing window is started, and the re-authentication of the legality of the first device is not performed in the timing window;
[0335] after the timing window is ended, the physical layer link state is acquired again;
[0336] if the physical layer link state acquired again is the connected state, the re-authentication of the legality of the first device is performed, and the timing window is ended;
[0337] if the physical layer link state acquired again is the disconnected state, the authentication of the legality of the first device is failed, and the next timing window is started.
[0338] In practical application, the receiving unit 71 can be implemented by a communication interface in the information transmission apparatus; and the second processing unit 72 can be implemented by a processor in the information transmission apparatus.
[0339] It should be noted that the information transmission apparatus provided in the above embodiments is only used for example to illustrate the division of the above program modules, and in practical application, the above processing can be completed by different program modules according to the needs, that is, the internal structure of the apparatus is divided into different program modules to complete all or part of the above processing. In addition, the information transmission apparatus and the information transmission method provided in the above embodiments belong to the same concept, and the specific implementation process is described in the method embodiments, which will not be repeated here.
[0340] The present application also provides a first device, as shown in the following table: Figure 8 The first device includes:
[0341] a first communication interface 81, which is capable of information interaction with other first devices;
[0342] The first processor 82 is connected with the first communication interface 81, and is configured to execute a computer program to implement the method provided in the one or more technical solutions of the first device.
[0343] It should be noted that the specific processing procedures of the first processor 82 and the first communication interface 81 are described in the method embodiments, which will not be repeated here.
[0344] Of course, in actual application, various components in the first device 80 are coupled together through a bus system 84. It can be understood that the bus system 84 is used to realize the connection and communication between the components. The bus system 84 includes not only a data bus, but also a power supply bus, a control bus and a status signal bus. However, in order to clearly illustrate the present application, all kinds of buses are marked as the bus system 84 in the Figure 8 .
[0345] The first memory 83 in the embodiment of the present application is used to store various types of data to support the operation of the first device 80. Examples of these data include any computer programs used for operation on the first device 80.
[0346] The method disclosed in the above embodiment of the present application can be applied to or implemented by the first processor 82. The first processor 82 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits or instructions in the form of software in the first processor 82. The first processor 82 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The first processor 82 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the above steps, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in a storage medium, which is located in the first memory 83, and the first processor 82 reads the information in the first memory 83 and combines the hardware to complete the steps of the above method.
[0347] The embodiment of the present application further provides a second device, as shown in Figure 9 , comprising:
[0348] The second communication interface 91 can interact with other first devices.
[0349] The second processor 92 is connected with the second communication interface 91, and is configured to execute a computer program to implement the method provided in the one or more technical solutions of the second device.
[0350] It should be noted that the specific processing procedures of the second processor 92 and the second communication interface 91 are described in the method embodiments, which will not be repeated here.
[0351] Of course, in actual application, various components in the second device 90 are coupled together through a bus system 94. It can be understood that the bus system 94 is used to realize the connection and communication between the components. The bus system 94 includes not only a data bus, but also a power supply bus, a control bus and a status signal bus. However, in order to clearly illustrate the application, all kinds of buses are marked as the bus system 94 in the description. Figure 9
[0352] The second memory 93 in the embodiment of the present application is used to store various types of data to support the operation of the second device 90. Examples of the data include any computer programs used for operation on the second device 90.
[0353] The method disclosed in the above embodiments of the present application can be applied to or implemented by the second processor 92. The second processor 92 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits or instructions in the form of software in the second processor 92. The second processor 92 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 92 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps, or the hardware and software modules in the decoding processor can be combined to execute the steps. The software module can be located in a storage medium, which is located in the second memory 93, and the second processor 92 reads the information in the second memory 93 and combines the hardware to complete the steps of the above method.
[0354] In exemplary embodiments, the first device 80, the second device 90 can be implemented by one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs), Field-Programmable Gate Arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors (Microprocessors), or other electronic elements for performing the aforementioned methods.
[0355] It can be understood that the memory (the first memory 83 and the second memory 93) of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both the volatile memory and the non-volatile memory. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as a static random access memory (SRAM), a synchronous static random access memory (SSRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a sync link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
[0356] In the example embodiments, the embodiments of the present application also provide a storage medium, i.e. a computer storage medium, specifically a computer readable storage medium, such as a memory storing a computer program, which can be executed by the first processor 82 of the first device 80 to complete the steps of the aforementioned first device side method. The computer readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0357] It should be noted that "first", "second", etc. are used to distinguish similar objects, and do not necessarily mean a specific order or sequence.
[0358] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0359] The above is only a preferred embodiment of the present application, and is not intended to limit the protection scope of the present application.
Claims
1. A method of information transmission, characterized in that, Applied to a first device, the method comprises: encrypting a first random number, a second random number, an identifier of the first device and an identifier of a first optical module in the first device to obtain first information; wherein the first random number is generated by the first device, and the second random number is generated by a second device and sent to the first device; sending the first random number, the identifier of the first device and the first information to the second device, wherein the first random number, the identifier of the first device and the first information are used for the second device to authenticate the first device; wherein the second device authenticates the first device based on the first random number, the identifier of the first device and the first information, comprising: using a pre-configured shared key to decrypt the first random number, the second random number, the identifier of the first device and the identifier of the first optical module in the first information in the first information to obtain the identifier of the first optical module; determining whether the first optical module is legal according to the identifier of the first optical module; in the case of determining that the first optical module is legal, using the pre-configured shared key to encrypt the first random number, the second random number, the identifier of the first device and the decrypted identifier of the first optical module to obtain fourth information; comparing the fourth information with the first information to obtain a comparison result; in the case that the comparison result represents that the fourth information is the same as the first information, determining that the first device is a legal device.
2. The method of claim 1, wherein, The method further comprises: reading the identifier of the first optical module from the memory of the first optical module in the first device.
3. The method of claim 1, wherein the encryption of the first random number, the second random number, the identifier of the first device and the identifier of the first optical module in the first device comprises: obtaining a pre-configured shared key; using the shared key to encrypt the first random number, the second random number, the identifier of the first device and the identifier of the first optical module in the first device.
4. The method of claim 1, wherein, The method further comprises: receiving an identifier of the second device and second information; the second information is obtained by the second device using a pre-configured shared key to encrypt the first random number, the identifier of the second device and the identifier of a second optical module in the second device; authenticating the second device based on the identifier of the second device and the second information.
5. The method of claim 4, wherein the authentication of the second device based on the identifier of the second device and the second information comprises: using the pre-configured shared key to decrypt the first random number, the identifier of the second device and the identifier of the second optical module in the second device in the second information to obtain the identifier of the second optical module; determining whether the second optical module is legal according to the identifier of the second optical module; encrypt the first random number, the identity of the second device, and the decrypted identity of the second optical module using the preconfigured shared key to obtain third information; compare the third information with the second information to obtain a comparison result; in a case where the comparison result indicates that the third information is identical to the second information, determine that the second device is a legitimate device.
6. The method of claim 5, wherein, The method further comprises: interchangeably transmitting a first message with the second device; if the first message transmitted by the second device is not received within a preset time length, close the current secure port.
7. The method of claim 5, wherein, The method further comprises: after the authentication of the second device is passed, obtaining a physical layer link state; if the physical layer link state is a disconnected state, the authentication of the legitimacy of the second device is invalidated; after the authentication of the second device is invalidated, obtaining the physical layer link state again; if the physical layer link state is a connected state, re-authenticating the legitimacy of the second device.
8. The method of claim 5, wherein, The method further comprises: after the authentication of the second device is passed, obtaining a physical layer link state; if the physical layer link state is a disconnected state, opening a timing window, and not re-authenticating the legitimacy of the second device within the timing window; after the timing window ends, obtaining the physical layer link state again; if the physical layer link state obtained again is a connected state, re-authenticating the legitimacy of the second device, and the timing of the timing window ends; if the physical layer link state obtained again is a disconnected state, the authentication of the legitimacy of the second device is invalidated, and the next timing window is opened.
9. An information transmission method, characterized by, Applied to a second device, the method comprises: receiving a first random number, an identity of a first device, and first information; the first information is obtained by encrypting the first random number, a second random number, the identity of the first device, and an identity of a first optical module in the first device by the first device; wherein the first random number is generated by the first device, and the second random number is generated by the second device and sent to the first device; authenticating the first device based on the first random number, the identity of the first device, and the first information; wherein authenticating the first device based on the first random number, the identity of the first device, and the first information comprises: decrypting the first random number, the second random number, the identity of the first device, and the identity of the first optical module in the first device in the first information using the preconfigured shared key to obtain the identity of the first optical module; determining whether the first optical module is legitimate according to the identity of the first optical module; in a case where the first optical module is determined to be legitimate, encrypting the first random number, the second random number, the identity of the first device, and the decrypted identity of the first optical module using the preconfigured shared key to obtain fourth information; comparing the fourth information with the first information to obtain a comparison result; In a case where the comparison result indicates that the fourth information is identical to the first information, the first device is determined as a legal device.
10. The method of claim 9, wherein, The method further comprises: obtaining a preconfigured shared key; encrypting the first random number, the identity of the second device and the identity of the second optical module in the second device by using the shared key to obtain second information; sending the identity of the second device and the second information to the first device, wherein the identity of the second device and the second information are used for the first device to authenticate the second device.
11. The method of claim 9, wherein, The method further comprises: reading the identity of the second optical module from a memory of the second optical module in the second device.
12. The method of claim 9, wherein, The method further comprises: interchanging first messages with the first device; if the first message sent by the first device is not received within a preset time length, closing the current secure port.
13. The method of claim 9, wherein, The method further comprises: after the authentication of the first device is passed, obtaining a physical layer link state; if the physical layer link state is a disconnected state, the authentication of the legality of the first device is failed; after the authentication of the first device is failed, obtaining the physical layer link state again; if the physical layer link state is a connected state, re-authenticating the legality of the first device.
14. The method of claim 9, wherein, The method further comprises: after the authentication of the first device is passed, obtaining a physical layer link state; if the physical layer link state is a disconnected state, starting a timing window, and not re-authenticating the legality of the first device within the timing window; after the timing window is ended, obtaining the physical layer link state again; if the physical layer link state obtained again is a connected state, re-authenticating the legality of the first device, and the timing of the timing window is ended; if the physical layer link state obtained again is a disconnected state, the authentication of the legality of the first device is failed, and a next timing window is started.
15. An information transmission apparatus characterized by comprising: comprises: a first processing module configured to encrypt a first random number, a second random number, an identity of a first device and an identity of a first optical module in the first device to obtain first information, wherein the first random number is generated by the first device, and the second random number is generated by a second device and sent to the first device; a sending module configured to send the first random number, the identity of the first device and the first information to the second device, wherein the first random number, the identity of the first device and the first information are used for the second device to authenticate the first device; and a receiving module configured to receive a second information sent by the second device, wherein the second information is used for the first device to authenticate the second device. The second device authenticates the first device based on the first random number, the identity of the first device, and the first information, including: using a pre-configured shared key to decrypt the first random number, the second random number, the identity of the first device, and the identity of a first optical module in the first device in the first information to obtain the identity of the first optical module; determining whether the first optical module is legal according to the identity of the first optical module; in a case where it is determined that the first optical module is legal, using the pre-configured shared key to encrypt the first random number, the second random number, the identity of the first device, and the decrypted identity of the first optical module to obtain fourth information; comparing the fourth information with the first information to obtain a comparison result; and in a case where the comparison result indicates that the fourth information is the same as the first information, determining that the first device is a legal device.
16. An information transmission apparatus characterized by comprising: Comprising: a receiving module configured to receive a first random number, an identity of a first device, and first information; the first information is obtained by encrypting, by a second device, the first random number, a second random number, the identity of the first device, and an identity of a first optical module in the first device; the first random number is generated by the first device, and the second random number is generated by the second device and sent to the first device; a second processing module configured to authenticate the first device based on the first random number, the identity of the first device, and the first information; wherein authenticating the first device based on the first random number, the identity of the first device, and the first information includes: decrypting, using a pre-configured shared key, the first random number, the second random number, the identity of the first device, and the identity of the first optical module in the first information to obtain the identity of the first optical module; determining whether the first optical module is legal according to the identity of the first optical module; in a case where it is determined that the first optical module is legal, encrypting, using the pre-configured shared key, the first random number, the second random number, the identity of the first device, and the decrypted identity of the first optical module to obtain fourth information; comparing the fourth information with the first information to obtain a comparison result; in a case where the comparison result indicates that the fourth information is the same as the first information, determining that the first device is a legal device.
17. A first device, comprising: comprising a processor and a memory for storing a computer program capable of running on the processor, wherein the processor is configured to execute the steps of the method of any one of claims 1 to 8 when running the computer program.
18. A second device, comprising: comprising a processor and a memory for storing a computer program capable of running on the processor, wherein the processor is configured to execute the steps of the method of any one of claims 9 to 14 when running the computer program.
19. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 8, or to implement the steps of the method of any one of claims 9 to 14.
Citation Information
Patent Citations
Optical module authentication method and device
CN105577380A
Interface authentication method and system based on SE chip and storage medium
CN110166453A