Session key distribution method, apparatus and storage medium

CN118827011BActive Publication Date: 2026-08-14CHINA MOBILE COMM LTD RES INST +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-19
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

其核心思想相同,即用量子密钥存储介质中预先充注的量子密钥作为密钥加密密钥(Key Encryption Key,KEK),保护量子会话密钥的下发,然而,在两个设备的信息交互过程中,可能会存在中间人对消息进行篡改或重放,使两个设备获取到不同的密钥,对信息安全造成威胁

Benefits of technology

[0028]本申请实施例所提供的会话密钥分发方法,通过量子密钥设备生成消息验证码,用于发送设备对量子密钥管理设备发送的消息进行完整性验证,发送设备根据对接收到的参数进行验证,防止中间人的攻击,保证信息交互的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827011B_ABST
    Figure CN118827011B_ABST
Patent Text Reader

Abstract

This application discloses a session key distribution method, a key management device, a sending device, a receiving device, an electronic device, a chip, and a computer-readable storage medium. The method, applied to a key management device, includes: receiving a first session key request message sent by a sending device; generating a session key and a session identifier; encrypting the session key using a first key; performing a MAC operation on the sending device identifier, the receiving device identifier, a first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key to generate a first message verification code MAC1; and sending a first session key request response message to the sending device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a session key distribution method, key management device, sending device, receiving device, electronic device, chip, and computer-readable storage medium. Background Technology

[0002] When two devices initiate quantum session key distribution / negotiation, the quantum secure communication application service system provides quantum secure communication application services to upper-layer users over a wide area. The core idea is the same: using a quantum key pre-loaded in a quantum key storage medium as the key encryption key (KEK) to protect the distribution of the quantum session key. However, during the information exchange between the two devices, there is a possibility of a man-in-the-middle attack that tampers with or replays the message, causing the two devices to obtain different keys, posing a threat to information security. Summary of the Invention

[0003] This application provides a session key distribution method, a key management device, a sending device, a receiving device, an electronic device, a chip, and a computer-readable storage medium.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] In a first aspect, embodiments of this application provide a session key distribution method, applied to a key management device, comprising:

[0006] Receive a first session key request message sent by a sending device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number;

[0007] Generate session key and session identifier;

[0008] The session key is encrypted using a first key; the first key is a key that the sending device has not used before.

[0009] A first message verification code MAC1 is generated by performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key.

[0010] Send a first session key request response message to the sending device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and the MAC1.

[0011] Secondly, embodiments of this application provide a session key distribution method, applied to a sending device, comprising:

[0012] Send a first session key request message to the key management device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number;

[0013] The system receives a first session key request response message from the key management device. This message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and MAC1. MAC1 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key. The first key is a key that the sending device has not used.

[0014] Thirdly, embodiments of this application provide a session key distribution method, applied to a receiving device, comprising:

[0015] The device receives a communication request message from a key management device. The communication request message includes: a sending device identifier, a receiving device identifier, a key management device identifier, a first timestamp, a session identifier, a key index corresponding to a second key, a session key encrypted with the second key, and MAC2. MAC2 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key. The second key is a key that the receiving device has not used. The first timestamp is generated by the key management device based on its local time.

[0016] Fourthly, embodiments of this application provide a key management device, including:

[0017] First receiving unit: used to receive a first session key request message sent by the sending device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number;

[0018] First processing unit: used to generate a session key and a session identifier; encrypt the session key using a first key; the first key is a key that the sending device has not used before; perform MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key to generate a first message verification code MAC1;

[0019] First sending unit: used to send a first session key request response message to the sending device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and the MAC1.

[0020] Fifthly, embodiments of this application provide a transmitting device, including:

[0021] The second sending unit is used to send a first session key request message to the key management device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number;

[0022] The second receiving unit is used to receive a first session key request response message sent by the key management device. The first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and MAC1. The MAC1 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key. The first key is a key that the sending device has not used.

[0023] Sixthly, embodiments of this application provide a receiving device, including:

[0024] The third receiving unit is used to receive a communication request message sent by the key management device. The communication request message includes: a sending device identifier, a receiving device identifier, a key management device identifier, a first timestamp, a session identifier, a key index corresponding to a second key, a session key encrypted with the second key, and MAC2. MAC2 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key. The second key is a key that the receiving device has not used. The first timestamp is generated by the key management device based on the local time of the key management device.

[0025] In a seventh aspect, this application provides an electronic device, including: a processor and a memory, the memory being used to store a computer program, and the processor being used to call and run the computer program stored in the memory to execute any of the session key distribution methods provided in the embodiments of this application.

[0026] Eighthly, this application provides a chip, including: a processor, configured to call and run a computer program from a memory, causing a device equipped with the chip to execute any of the session key distribution methods provided in the embodiments of this application.

[0027] Ninthly, this application provides a computer-readable storage medium for storing a computer program that causes a computer to execute any of the session key distribution methods provided in the embodiments of this application.

[0028] The session key distribution method provided in this application generates a message verification code through a quantum key device. This code is used by the sending device to verify the integrity of messages sent by the quantum key management device. The sending device verifies the received parameters to prevent man-in-the-middle attacks and ensure the security of information exchange. Attached Figure Description

[0029] Figure 1 A schematic diagram of the quantum session key distribution process in related technologies. Figure 1 ;

[0030] Figure 2 Schematic diagram of the implementation process of the session key distribution method provided in the embodiments of this application Figure 1 ;

[0031] Figure 3 Schematic diagram of the implementation process of the session key distribution method provided in the embodiments of this application Figure 2 ;

[0032] Figure 4 Schematic diagram of the implementation process of the session key distribution method provided in the embodiments of this application Figure 3 ;

[0033] Figure 5 A schematic diagram of the quantum session key distribution process provided in this application embodiment. Figure 2 ;

[0034] Figure 6 This is a schematic diagram of the key management device 600 provided in an embodiment of this application;

[0035] Figure 7 This is a schematic diagram of the structure of the transmitting device 700 provided in an embodiment of this application;

[0036] Figure 8 This is a schematic diagram of the structure of the receiving device 800 provided in the embodiments of this application;

[0037] Figure 9 A schematic structural diagram of an electronic device provided in the embodiments of this application;

[0038] Figure 10 This is a schematic structural diagram of the chip provided in an embodiment of this application. Detailed Implementation

[0039] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0040] It should be noted that, in the embodiments of this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, in the embodiments of this application, the character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0041] In the description of the embodiments of this application, the term "correspondence" may indicate that there is a direct or indirect correspondence between two things, or that there is an association between two things, or that there is a relationship of instruction and being instructed, configuration and being configured, etc.

[0042] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0043] refer to Figure 1 , Figure 1 A schematic diagram of the quantum session key distribution process in related technologies. Figure 1 ,like Figure 1 As shown, the quantum cryptography application (initiator) requests a new session from the quantum key management device and requests a quantum session key. Upon receiving the request, the quantum key management device creates the session, extracts the quantum session key, encrypts the quantum session key using a KEK, and returns the session ID, the ciphertext of the quantum session key, and the KEK index to the quantum cryptography application (initiator). The quantum cryptography application (initiator) finds the KEK corresponding to the KEK index in its local quantum key storage medium and decrypts the ciphertext of the quantum session key to obtain the session key. The quantum cryptography application (initiator) synchronizes the session ID with the quantum cryptography application (passive party). The quantum cryptography application (initiator) requests the quantum key management device to query the quantum session key corresponding to the session ID. The quantum key management device queries the quantum session key corresponding to the session ID in the key library, encrypts the quantum session key using a key encryption key (KEK), and returns the ciphertext of the quantum session key and the KEK index to the quantum cryptography application (passive party). The quantum cryptography application (passive party) finds the KEK corresponding to the KEK index in its local quantum key storage medium and decrypts the ciphertext of the quantum session key to obtain the quantum session key.

[0044] In the aforementioned technical solutions, the quantum key service center binds the sender and receiver using session IDs, and the quantum session key is transmitted using KEK encryption. However, this solution lacks integrity protection and replay protection mechanisms for all messages. Therefore, it is vulnerable to man-in-the-middle attacks, meaning an attacker can tamper with and replay messages, preventing the communicating parties from negotiating the same quantum session key. Messages between the initiator and the quantum key management device lack integrity protection; an attacker can modify the KEK index to give the initiator an incorrect quantum session key, or replay previous messages to give the initiator a previously used quantum session key. Messages between the initiator and receiver also lack integrity protection; an attacker can modify the session ID to give the receiver a different key from the sender's key from the quantum key service center. An attacker can also replay previous quantum key identifiers to give the receiver a previously used quantum key. Messages between the quantum key management device and the receiver also lack integrity protection and replay protection mechanisms.

[0045] Figure 2 Schematic diagram of the implementation process of the session key distribution method provided in the embodiments of this application Figure 1 ,like Figure 2 As shown in the figure, this application provides a session key distribution method, applied to a key management device, the method including the following steps:

[0046] Step 201: Receive a first session key request message sent by the sending device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number.

[0047] Step 202: Generate session key and session identifier.

[0048] Step 203: Encrypt the session key using a first key; the first key is a key that the sending device has not used before.

[0049] Step 204: Perform MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key to generate the first message verification code MAC1.

[0050] Step 205: Send a first session key request response message to the sending device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and the MAC1.

[0051] In some alternative implementations, the method further includes: encrypting the session key using a second key; the second key is a key that the receiving device has not used before;

[0052] A second message verification code MAC2 is generated by performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key; the first timestamp is generated based on the local time of the key management device.

[0053] Send communication request information to the receiving device; the communication request information includes: the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, the session key encrypted with the second key, and the MAC2.

[0054] In this way, key distribution can be achieved by sending session key request response messages to the sending device and communication request messages to the receiving device through the key management device. This reduces the information interaction process, lowers the risk of being attacked, and ensures the security of information interaction.

[0055] In some optional implementations, the MAC operation can be performed using the HMAC-SHA256 function. For example, when the first session key request message further includes a first random number, and the first session key request response message further includes the first random number and the first timestamp, MAC1 = HMAC-SHA256(Ka, A‖B‖Na‖Sid‖KEKxa‖[SK]Ka), MAC2 = HAMC-SHA256(Kb, A‖B‖C‖Sid‖TS‖KEKxb‖[SK]Kb), where ‖ represents a string concatenation, Ka represents the first key, A... A represents the sending device identifier, B represents the receiving device identifier, C represents the key management device identifier, Na represents the first random number, Sid represents the session identifier, KEKxa represents the key index corresponding to the first key, [SK]Ka represents the session key encrypted with the first key, Kb represents the second key, TS represents the first timestamp, KEKxb represents the key index corresponding to the second key, and [SK]Kb represents the session key encrypted with the second key. HMAC-SHA256 is the message verification code generation function, but other functions such as CBC-AES can also be used, and this application does not limit this.

[0056] refer to Figure 3 , Figure 3 A schematic diagram of the implementation process of the session key distribution method provided in the embodiments of this application. Figure 2 In this embodiment, the session key distribution method is applied to the sending device, and the method includes the following steps:

[0057] Step 301: Send a first session key request message to the key management device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number.

[0058] Step 302: Receive a first session key request response message sent by the key management device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and MAC1; the MAC1 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key; the first key is a key that the sending device has not used.

[0059] In some alternative implementations, the method further includes:

[0060] The third message verification code MAC3 is generated by performing a MAC operation on the received sending device identifier, receiving device identifier, first random number, session identifier, key index corresponding to the first key, and session key encrypted with the first key using the first key.

[0061] If MAC3 is equal to MAC1, then the session key is obtained by decrypting the session key encrypted with the first key using the first key.

[0062] In some alternative implementations,

[0063] Before decrypting the session key encrypted with the first key to obtain the session key, the method further includes:

[0064] Determine whether the received first random number is the same as the first random number sent to the key management device;

[0065] If they are the same, the session key is obtained by decrypting the session key encrypted with the first key using the first key.

[0066] refer to Figure 4 , Figure 4 A schematic diagram of the implementation process of the session key distribution method provided in the embodiments of this application. Figure 3 In this embodiment, the session key distribution method is applied to a receiving device, and the method includes the following steps:

[0067] Step 401: Receive a communication request message sent by the key management device; the communication request message includes: a sending device identifier, the receiving device identifier, the key management device identifier, a first timestamp, a session identifier, a key index corresponding to the second key, a session key encrypted with the second key, and MAC2; the MAC2 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key; the second key is a key that the receiving device has not used; the first timestamp is generated by the key management device according to the local time of the key management device.

[0068] In some alternative implementations, the method further includes:

[0069] The second key is used to perform a MAC operation on the received sending device identifier, receiving device identifier, key management device identifier, first timestamp, session identifier, key index corresponding to the second key, and session key encrypted with the second key to generate a fourth message verification code MAC4.

[0070] If MAC4 is equal to MAC2, then the session key is obtained by decrypting the session key encrypted with the second key using the second key.

[0071] In some optional implementations, before decrypting the session key encrypted with the second key using the second key to obtain the session key, the method further includes:

[0072] Determine whether the difference between the first timestamp and the local time of the receiving device is within a preset range. If it is within the preset range, then decrypt the session key encrypted with the second key using the second key to obtain the session key.

[0073] refer to Figure 5 , Figure 5 This application provides a schematic diagram of a quantum session key distribution process in an embodiment of the present application. Figure 2 ,like Figure 5 As shown, the method includes the following steps:

[0074] Step 501: The sending end and the receiving end obtain a set of quantum key encryption keys and the key index corresponding to each key from the quantum key management device. For example, this can be done through offline filling.

[0075] Step 502: The sending end sends a session key request message to the quantum key management device. The message contains the sending end identifier A, the receiving end identifier B, and a one-time random number Na. Here, the quantum key management device can be a quantum key service center.

[0076] Step 503: The quantum key management device receives a session key request message. It generates a session key SK and a session identifier Sid for communication between sender A and receiver B. Based on sender identifier A, the quantum key management device finds the unused pre-stored key encryption key Ka and its corresponding key encryption key index KEKxa, and encrypts the session key using key Ka, i.e., [SK]Ka. It further uses key Ka to generate a message verification code MAC1, calculated as follows:

[0077] MAC1=HMAC-SHA256(Ka,A‖B‖Na‖Sid‖KEKxa‖[SK]Ka)

[0078] Here, "‖" represents a string concatenation. HMAC-SHA256 is the message verification code generation function, but it can also be other functions such as HMAC-SHA3.

[0079] The quantum key management device generates a session key request response message and returns it to the sender. The message consists of A, B, Na, Sid, KEKxa, [SK]Ka, and MAC1.

[0080] Step 504: After receiving the session key request response message, the sending end first finds the corresponding key Ka based on KEKxa, and then uses key Ka to perform MAC operations on A, B, Na, Sid, KEKxa, and [SK]Ka to generate MAC3. The received MAC1 is compared with the calculated MAC3. If they are equal, the session key request response message A, B, Na, Sid, KEKxa, and [SK]Ka has not been tampered with by a man-in-the-middle. The sending end then compares the received Na with the Na in the session key request message it sent to the quantum key management device. If they are the same, it can be determined that the session key request response message is not a replay message.

[0081] After confirming that the session key request response message has not been tampered with or replayed, the sender uses the key Ka to decrypt [SK]Ka to obtain the session key SK.

[0082] Step 505: Based on the receiver identifier B, the quantum key management device finds the unused pre-stored key encryption key Kb and its corresponding key encryption key index KEKxb. The quantum key management device generates a timestamp TS based on the local time. It further generates a message verification code MAC2, which is calculated as follows: MAC2 = HAMC-SHA256(Kb, A‖B‖C‖Sid‖TS‖KEKxb‖[SK]Kb), where ‖ represents the string concatenation, C is the quantum key management device identifier, and HMAC-SHA256 is the message verification code generation function, which can also be other functions such as HMAC-SHA3. The quantum key management device generates a communication request message and sends it to the receiver, which consists of A, B, C, TS, Sid, KEKxb, [SK]Kb, and MAC2.

[0083] Step 506: After receiving the communication request message, the receiving end first identifies the sender's identifier A and the quantum key management device identifier C. Then, based on KEKxb, the device finds the corresponding key Kb and uses key Kb to perform a MAC operation on A, B, C, TS, Sid, KEKxb, and [SK]Kb to generate MAC4. The received MAC2 is compared with the calculated MAC4. If they are equal, the communication request message has not been tampered with by a man-in-the-middle. The receiving end then compares the timestamp TS in the message with the local time. If TS is within the system-set threshold range, the communication request message is determined not to be a replay message. The receiving end then uses key Kb to decrypt [SK]Kb to obtain the session key SK.

[0084] Step 507: The receiver and sender use the session key SK for secure communication.

[0085] The session key distribution method provided in this application involves a quantum key management device generating two message verification codes, MAC1 and MAC2. MAC1 is used by the sending end to verify the integrity of messages sent by the quantum key management device, while MAC2 is used by the receiving end to verify the integrity of messages forwarded by the sending end. Anti-replay parameters and anti-tampering message verification codes (MACs) are added to the sent messages. The receiving end verifies whether a message is a replay or has been tampered with by verifying the anti-replay parameters and MACs in the received message, thus preventing man-in-the-middle attacks. The encryption keys (Ka, Kb) are used not only to encrypt the session key but also in the computation of generating the message verification codes. Furthermore, the quantum key management device includes a timestamp TS in the session key request response message sent to the sending end, which is forwarded to the receiving end by the sending end in the communication request message. The receiving end uses the TS to determine whether the communication request message is a replay, preventing man-in-the-middle attacks and preventing attackers from tampering with and replaying messages, thereby increasing security.

[0086] In addition, this application improves the quantum session distribution process, reduces the interaction process between devices, and further increases the security of information exchange.

[0087] refer to Figure 6 , Figure 6 This is a schematic diagram of the key management device 600 provided in the embodiments of this application, as shown below. Figure 6 As shown, the key management device 600 includes:

[0088] First receiving unit 610: used to receive a first session key request message sent by a sending device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number;

[0089] First processing unit 620: used to generate a session key and a session identifier; encrypt the session key using a first key; the first key is a key that the sending device has not used before; perform MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key to generate a first message verification code MAC1;

[0090] First sending unit 630: configured to send a first session key request response message to the sending device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and the MAC1.

[0091] In this embodiment, the first processing unit 620 is further configured to encrypt the session key using a second key; the second key is a key that the receiving device has not used before; and to perform a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key to generate a second message verification code MAC2; the first timestamp is generated based on the local time of the key management device; the first sending unit 630 is further configured to send communication request information to the receiving device; the communication request information includes: the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, the session key encrypted with the second key, and the MAC2.

[0092] Those skilled in the art should understand that Figure 6 The functions of each unit in the key management device shown can be understood by referring to the relevant descriptions of the aforementioned methods. Figure 6 The functions of each unit in the key management device shown can be implemented by a program running on a processor or by specific logic circuits.

[0093] refer to Figure 7 , Figure 7 This is a schematic diagram of the structure of the transmitting device 700 provided in the embodiments of this application, as shown below. Figure 7 As shown, the transmitting device 700 includes:

[0094] The second sending unit 710 is used to send a first session key request message to the key management device; the session key request message includes: a sending device identifier, a receiving device identifier, and a first random number;

[0095] The second receiving unit 720 is configured to receive a first session key request response message sent by the key management device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and MAC1; the MAC1 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key; the first key is a key that the sending device has not used.

[0096] In this embodiment of the application, the transmitting device 700 further includes: a second processing unit, configured to perform MAC operation on the received transmitting device identifier, receiving device identifier, first random number, session identifier, key index corresponding to the first key, and session key encrypted with the first key using the first key to generate a third message verification code MAC3; and further configured to, if the MAC3 is equal to the MAC1, decrypt the session key encrypted with the first key using the first key to obtain the session key.

[0097] In this embodiment of the application, the first session key request message further includes: before decrypting the session key encrypted with the first key to obtain the session key, the second processing unit is further configured to determine whether the received first random number is the same as the first random number sent to the key management device; if they are the same, then decrypting the session key encrypted with the first key to obtain the session key.

[0098] Those skilled in the art should understand that Figure 7 The functions of each unit in the transmitting device shown can be understood by referring to the relevant descriptions of the aforementioned method. Figure 7 The functions of each unit in the transmitting device shown can be implemented by a program running on a processor or by specific logic circuits.

[0099] refer to Figure 8 , Figure 8 This is a schematic diagram of the structure of the receiving device 800 provided in the embodiments of this application, as shown below. Figure 8 As shown, the receiving device 800 includes:

[0100] The third receiving unit 810 is used to receive a communication request message sent by the key management device. The communication request message includes: a sending device identifier, the receiving device identifier, the key management device identifier, a first timestamp, a session identifier, a key index corresponding to a second key, a session key encrypted with the second key, and MAC2. MAC2 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key. The second key is a key that the receiving device has not used. The first timestamp is generated by the key management device according to the local time of the key management device.

[0101] In this embodiment of the application, the receiving device 800 further includes: a third processing unit: configured to perform MAC operation on the received sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted by the second key using the second key, to generate a fourth message verification code MAC4; if the MAC4 is equal to the MAC2, then the session key encrypted by the second key is decrypted using the second key to obtain the session key.

[0102] In this embodiment of the application, before decrypting the session key encrypted with the second key using the second key to obtain the session key, the third processing unit is further configured to: determine whether the difference between the first timestamp and the local time of the receiving device is within a preset range; if it is within the preset range, then decrypt the session key encrypted with the second key using the second key to obtain the session key.

[0103] Those skilled in the art should understand that Figure 8 The functions of each unit in the receiving device shown can be understood by referring to the relevant descriptions of the aforementioned method. Figure 8 The functions of each unit in the receiving device shown can be implemented by a program running on a processor or by specific logic circuits.

[0104] Figure 9 This is a schematic structural diagram of an electronic device 900 provided in an embodiment of this application. Figure 9 The illustrated electronic device 900 includes a processor 910, which can call and run computer programs from memory to implement the methods in the embodiments of this application.

[0105] Optionally, such as Figure 9As shown, the electronic device 900 may further include a memory 920. The processor 910 can retrieve and run computer programs from the memory 920 to implement the methods described in the embodiments of this application.

[0106] The memory 920 can be a separate device independent of the processor 910, or it can be integrated into the processor 910.

[0107] Optionally, such as Figure 9 As shown, the electronic device 900 may also include a transceiver 930, which the processor 910 can control to communicate with other devices. Specifically, it can send information or data to other devices or receive information or data sent by other devices.

[0108] The transceiver 930 may include a transmitter and a receiver. The transceiver 930 may further include antennas, and the number of antennas may be one or more.

[0109] The electronic device 900 may specifically be a key management device, a transmitting device, or a receiving device in the embodiments of this application. The electronic device 900 can implement the corresponding processes implemented by the key management device, the transmitting device, and the receiving device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0110] Figure 10 This is a schematic structural diagram of the chip according to an embodiment of this application. Figure 10 The chip 1000 shown includes a processor 1010, which can call and run computer programs from memory to implement the methods in the embodiments of this application.

[0111] Optionally, such as Figure 10 As shown, chip 1000 may further include memory 1020. Processor 1010 can retrieve and run computer programs from memory 1020 to implement the methods described in this embodiment.

[0112] The memory 1020 can be a separate device independent of the processor 1010, or it can be integrated into the processor 1010.

[0113] Optionally, the chip 1000 may also include an input interface 1030. The processor 1010 can control the input interface 1030 to communicate with other devices or chips, specifically, to acquire information or data sent by other devices or chips.

[0114] Optionally, the chip 1000 may also include an output interface 1040. The processor 1010 can control the output interface 1040 to communicate with other devices or chips, specifically, to output information or data to other devices or chips.

[0115] This chip can be applied to the key management device, transmitting device, and receiving device in the embodiments of this application, and the chip can implement the corresponding processes implemented by the key management device, transmitting device, and receiving device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0116] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0117] It should be understood that the processor in the embodiments of this application may be an integrated circuit chip with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor described above can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0118] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0119] It should be understood that the above-described memory is exemplary and not a limiting description. For example, the memory in the embodiments of this application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DR RAM), etc. That is to say, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.

[0120] This application also provides a computer-readable storage medium for storing a computer program. This computer-readable storage medium can be applied to the key management device, transmitting device, and receiving device in the embodiments of this application, and the computer program causes the computer to execute the corresponding processes implemented by the key management device, transmitting device, and receiving device in the various methods of the embodiments of this application. For simplicity, further details are omitted here.

[0121] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0122] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0123] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0124] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0125] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0126] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or key management device, sending device, receiving device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0127] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A session key distribution method, applied to a key management device, characterized in that, include: Receive the first session key request message sent by the transmitting device; The session key request message includes: a sending device identifier, a receiving device identifier, and a first random number; Generate session key and session identifier; The session key is encrypted using a first key; the first key is a key that the sending device has not used before. A first message verification code MAC1 is generated by performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key. Send a first session key request response message to the sending device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and the MAC1.

2. The session key distribution method according to claim 1, characterized in that, Also includes: The session key is encrypted using a second key; the second key is a key that the receiving device has not used before. A second message verification code MAC2 is generated by performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key. The first timestamp is generated based on the local time of the key management device; Send communication request information to the receiving device; The communication request information includes: the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, the session key encrypted with the second key, and the MAC2.

3. A session key distribution method, applied to a sending device, characterized in that, include: Send a first session key request message to the key management device; The session key request message includes: a sending device identifier, a receiving device identifier, and a first random number; The system receives a first session key request response message from the key management device. This message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and MAC1. MAC1 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key. The first key is a key that the sending device has not used.

4. The session key distribution method according to claim 3, characterized in that, Also includes: The third message verification code MAC3 is generated by performing a MAC operation on the received sending device identifier, receiving device identifier, first random number, session identifier, key index corresponding to the first key, and session key encrypted with the first key using the first key. If MAC3 is equal to MAC1, then the session key is obtained by decrypting the session key encrypted with the first key using the first key.

5. The session key distribution method according to claim 4, characterized in that, Before decrypting the session key encrypted with the first key to obtain the session key, the method further includes: Determine whether the received first random number is the same as the first random number sent to the key management device; If they are the same, the session key is obtained by decrypting the session key encrypted with the first key using the first key.

6. A session key distribution method, applied to a receiving device, characterized in that, include: Receive communication request messages sent by the key management device; The communication request message includes: a sending device identifier, a receiving device identifier, a key management device identifier, a first timestamp, a session identifier, a key index corresponding to a second key, a session key encrypted with the second key, and MAC2; MAC2 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key; the second key is a key that the receiving device has not used; the first timestamp is generated by the key management device according to the local time of the key management device.

7. The session key distribution method according to claim 6, characterized in that, Also includes: The second key is used to perform a MAC operation on the received sending device identifier, receiving device identifier, key management device identifier, first timestamp, session identifier, key index corresponding to the second key, and session key encrypted with the second key to generate a fourth message verification code MAC4. If MAC4 is equal to MAC2, then the session key is obtained by decrypting the session key encrypted with the second key using the second key.

8. The session key distribution method according to claim 7, characterized in that, Before decrypting the session key encrypted with the second key using the second key to obtain the session key, the method further includes: Determine whether the difference between the first timestamp and the local time of the receiving device is within a preset range. If it is within the preset range, then decrypt the session key encrypted with the second key using the second key to obtain the session key.

9. A key management device, characterized in that, include: First receiving unit: used to receive the first session key request message sent by the sending device; The session key request message includes: a sending device identifier, a receiving device identifier, and a first random number; First processing unit: used to generate a session key and a session identifier; encrypt the session key using a first key; the first key is a key that the sending device has not used before; perform MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key to generate a first message verification code MAC1; First sending unit: used to send a first session key request response message to the sending device; the first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and the MAC1.

10. A transmitting device, characterized in that, include: Second sending unit: used to send a first session key request message to the key management device; The session key request message includes: a sending device identifier, a receiving device identifier, and a first random number; The second receiving unit is used to receive a first session key request response message sent by the key management device. The first session key request response message includes: the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, the session key encrypted with the first key, and MAC1. The MAC1 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the first random number, the session identifier, the key index corresponding to the first key, and the session key encrypted with the first key using the first key. The first key is a key that the sending device has not used.

11. A receiving device, characterized in that, include: The third receiving unit is used to receive communication request messages sent by the key management device. The communication request message includes: a sending device identifier, a receiving device identifier, a key management device identifier, a first timestamp, a session identifier, a key index corresponding to a second key, a session key encrypted with the second key, and MAC2; MAC2 is obtained by the key management device performing a MAC operation on the sending device identifier, the receiving device identifier, the key management device identifier, the first timestamp, the session identifier, the key index corresponding to the second key, and the session key encrypted with the second key using the second key; the second key is a key that the receiving device has not used; the first timestamp is generated by the key management device according to the local time of the key management device.

12. An electronic device, characterized in that, include: A processor and a memory, the memory for storing a computer program, the processor for calling and running the computer program stored in the memory to perform the session key distribution method as described in any one of claims 1-2, 3-5, and 6-8.

13. A chip, characterized in that, include: A processor for retrieving and running a computer program from memory, causing a device with the chip installed to perform the session key distribution method according to any one of claims 1-2, 3-5, or 6-8.

14. A computer-readable storage medium, characterized in that, Used to store a computer program that causes a computer to perform the session key distribution method as described in any one of claims 1-2, 3-5, and 6-8.

Citation Information

Patent Citations

  • Cryptogram-key distribution system

    CN102804676A

  • Data access method and device, computer equipment and storage medium

    CN112260997A

  • Key exchange method and device

    CN113872755A

  • Satellite terminal key distribution method, device and system

    CN115334497A