A key distribution method, device, communication device and storage medium
By using an attribute encryption algorithm to generate a key in a digital twin network, and performing encryption based on the public key of the physical device and the data access control structure, the latency and storage load problems caused by traditional encryption mechanisms are solved, achieving efficient data transmission and security control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-14
- Publication Date
- 2026-03-24
AI Technical Summary
In digital twin networks, the multiple encryption and decryption processes caused by traditional encryption mechanisms increase the latency of terminal data processing. Furthermore, when a large number of devices are connected, the network storage and load become too heavy, posing a risk of data leakage.
An attribute encryption algorithm is adopted, which generates a key based on the public key of the physical device and the data access control structure. The key is then encrypted once through a twin management network element to avoid repeated encryption. Only twin instances that meet the access control structure are allowed to decrypt the key.
It reduces data processing latency in digital twin networks, provides fine-grained access control, avoids the risk of data leakage, and improves network processing efficiency.
Smart Images

Figure CN118827081B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and specifically to a key distribution method, apparatus, communication device, and storage medium. Background Technology
[0002] In the application scenarios of Digital Twin Networks (DTN), a single physical device may have multiple twin instances. Data collection in a DTN requires storage in a shared data repository. DTN involves massive amounts of data storage and usage, thus leveraging distributed technologies such as cloud storage and cloud computing. However, storing data in plaintext poses a risk of data leakage. If traditional encryption mechanisms are used, the physical device needs to encrypt network data using keys from different instances to generate multiple ciphertexts, which are then sent to the twin instances in the DTN to achieve state synchronization between the twin devices and the physical devices. Digital twin networks are characterized by high real-time requirements; multiple encryption and decryption operations increase processing latency for terminal data. Furthermore, when a large number of devices connect to the network, it poses significant challenges to network storage and load. Summary of the Invention
[0003] To address the existing technical problems, embodiments of the present invention provide a key distribution method, apparatus, communication device, and storage medium.
[0004] To achieve the above objectives, the technical solution of this invention is implemented as follows:
[0005] In a first aspect, embodiments of the present invention provide a key distribution method, the method being applied to a first network element of a digital twin network, the method comprising:
[0006] The system receives a first message sent by a second network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device.
[0007] Based on the stored first information, the first public key and the first data access control structure corresponding to the first identifier are queried. An attribute encryption algorithm is used to encrypt the first key using the first public key and the first data access control structure to obtain the second key. The first information includes at least one set of associations between the identifier, public key and data access control structure representing the identity of the physical device. The first key comes from a third network element.
[0008] The second message corresponding to the first message is sent to the second network element. The second message includes at least the second key, so that the second network element can issue the second key to the twin instance, which is associated with the first physical device.
[0009] In the above scheme, before receiving the first message sent by the second network element, the method further includes:
[0010] The third message sent by the third network element is received. The third message is used to request anchoring or storing the first key. The third message includes at least the first key and the first identifier. The first key is generated by the third network element based on relevant information in the authentication process with the terminal device.
[0011] Store the first key and the first identifier.
[0012] In the above scheme, before receiving the first message sent by the second network element, the method further includes:
[0013] The system receives a fourth message sent by the first physical device, the fourth message being used to request the subscription of twin services; the fourth message includes at least the first public key and the first identifier;
[0014] The first public key and the first identifier, which are associated, are stored in the first information.
[0015] In the above scheme, the fourth message also includes the first data access control structure;
[0016] The step of storing the associated first public key and first identifier in the first information includes: storing the associated first public key, first identifier, and first data access control structure in the first information.
[0017] In the above scheme, the method further includes: receiving a fifth message sent by the first physical device, the fifth message being used to request an update to the digital twin access structure; the fifth message includes at least the first identifier and the updated first data access control structure;
[0018] The data access control structure corresponding to the first identifier stored in the first information is updated to the updated first data access control structure.
[0019] In the above scheme, the second message also includes the validity period of the first key; and / or,
[0020] The third message also includes the validity period of the first key.
[0021] In the above scheme, the physical device includes terminal equipment or network element.
[0022] Secondly, embodiments of the present invention also provide a key distribution method, the method being applied to a second network element of a digital twin network, the method comprising:
[0023] Send a first message to the first network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device;
[0024] The first network element receives a second message, which includes at least a second key. The second key is obtained by the first network element using an attribute-based encryption algorithm, a first public key corresponding to the stored first identifier, and a first data access control structure to encrypt the first key.
[0025] A sixth message is sent to the twin instance, the sixth message including the second key, the twin instance being associated with the first physical device.
[0026] In the above scheme, both the second message and the sixth message also include the validity period of the first key.
[0027] Thirdly, embodiments of the present invention also provide a key distribution method, the method being applied to a twin instance of a digital twin network, the method comprising:
[0028] The system receives a sixth message sent by a second network element, the sixth message including a second key, the second key being obtained from a first network element; the second key is obtained by the first network element using an attribute encryption algorithm, a first public key corresponding to a stored first identifier representing the identity of a first physical device, and encryption of the first key based on a first data access control structure; the twin instance is associated with the first physical device;
[0029] The second key is decrypted using the first private key corresponding to the first public key to obtain the first key.
[0030] In the above scheme, the sixth message also includes the validity period of the first key.
[0031] Fourthly, embodiments of the present invention also provide a key distribution method, the method being applied to a third network element of a digital twin network, the method comprising:
[0032] Generate a first key associated with the first physical device;
[0033] A third message is sent to the first network element, the third message being used to request anchoring or storing the first key; the third message includes at least the first key and a first identifier representing the identity of the first physical device.
[0034] In the above scheme, the third message also includes the validity period of the first key.
[0035] In the above scheme, generating the first key associated with the first device or the first network element includes:
[0036] The first key is generated based on relevant information from the authentication process of the first physical device.
[0037] In the above scheme, the first physical device includes a first terminal device or a network element.
[0038] Fifthly, embodiments of the present invention also provide a key distribution device, which is applied to a first network element of a digital twin network; the device includes: a first communication unit and a first processing unit; wherein,
[0039] The first communication unit is configured to receive a first message sent by the second network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device;
[0040] The first processing unit is configured to query the first public key and the first data access control structure corresponding to the first identifier based on the stored first information, and use the first public key and the first data access control structure to encrypt the first key to obtain the second key using an attribute encryption algorithm; wherein, the first information includes at least one set of association relationships between the identifier, public key and data access control structure representing the identity of the physical device; the first key comes from a third network element;
[0041] The first communication unit is further configured to send a second message corresponding to the first message to the second network element, the second message including at least the second key, so that the second network element can issue the second key to the twin instance, the twin instance being associated with the first physical device.
[0042] In a sixth aspect, embodiments of the present invention also provide a key distribution device, the device being applied to a second network element in a digital twin network, the device comprising: a second communication unit, configured to send a first message to a first network element, the first message being used to request a first key; the first message including at least a first identifier representing the identity of a first physical device; further configured to receive a second message sent by the first network element, the second message including at least a second key, the second key being obtained by the first network element based on an attribute encryption algorithm, using a stored first public key corresponding to the first identifier, and encrypting the first key based on a first data access control structure; and further configured to send a sixth message to a twin instance, the sixth message including the second key, the twin instance being associated with the first physical device.
[0043] In a seventh aspect, embodiments of the present invention also provide a key distribution device, the device being applied to a twin instance of a digital twin network, the device comprising a third communication unit and a second processing unit; wherein,
[0044] The third communication unit is used to receive a sixth message sent by the second network element. The sixth message includes a second key, which comes from the first network element. The second key is obtained by the first network element using an attribute encryption algorithm, a first public key corresponding to a stored first identifier representing the identity of the first physical device, and encryption of the first key based on a first data access control structure. The twin instance is associated with the first physical device.
[0045] The second processing unit is used to decrypt the second key using the first private key corresponding to the first public key to obtain the first key.
[0046] Eighthly, embodiments of the present invention also provide a key distribution device, which is applied to a third network element of a digital twin network. The device includes: a third processing unit and a fourth communication unit; wherein...
[0047] The third processing unit is used to generate a first key associated with the first physical device;
[0048] The fourth communication unit is used to send a third message to the first network element, the third message being used to request anchoring or storing the first key; the third message includes at least the first key and a first identifier representing the identity of the first physical device.
[0049] In a ninth aspect, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the key distribution method described in any one of the first to fourth aspects of embodiments of the present invention.
[0050] In a tenth aspect, embodiments of the present invention also provide a communication device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the key distribution method described in any one of the first to fourth aspects of the embodiments of the present invention.
[0051] The present invention provides a key distribution method, apparatus, communication device, and storage medium. The method includes: a first network element of a digital twin network receiving a first message sent by a second network element, the first message being used to request a first key; the first message including at least a first identifier representing the identity of a first physical device; querying a first public key and a first data access control structure corresponding to the first identifier based on stored first information; encrypting the first key using the first public key and the first data access control structure based on an attribute encryption algorithm to obtain a second key; wherein the first information includes at least one set of association relationships between the identifier, public key, and data access control structure representing the identity of the physical device; the first key originating from a third network element; sending a second message corresponding to the first message to the second network element, the second message including at least the second key, so that the second network element distributes the second key to a digital twin instance; the digital twin instance decrypting the second key using a first private key corresponding to the first public key to obtain the first key; the digital twin instance being associated with the first physical device. The technical solution of this invention avoids repeated encryption of the same data by encrypting the data once through the first network element of the physical layer; and the use of a symmetric encryption key does not increase the processing latency of the network; in addition, this invention adopts an attribute-based encryption method, which can only decrypt the session key by a twin instance that satisfies the data access control structure, thus providing fine-grained access control capabilities. Attached Figure Description
[0052] Figure 1 A schematic diagram of a digital twin network architecture;
[0053] Figure 2 A schematic diagram illustrating the mapping between physical devices and twin instances in digital twin application scenarios;
[0054] Figure 3 This is a schematic diagram of the system architecture for the key distribution method according to an embodiment of the present invention;
[0055] Figure 4 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 1 ;
[0056] Figure 5 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 2 ;
[0057] Figure 6 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 3 ;
[0058] Figure 7 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 4 ;
[0059] Figure 8 This is a schematic diagram of the interaction flow of the key distribution method according to an embodiment of the present invention. Figure 1 ;
[0060] Figure 9 This is a schematic diagram of the interaction flow of the key distribution method according to an embodiment of the present invention. Figure 2 ;
[0061] Figure 10 This is a schematic diagram of the interaction flow of the key distribution method according to an embodiment of the present invention. Figure 3 ;
[0062] Figure 11 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 1 ;
[0063] Figure 12 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 2 ;
[0064] Figure 13 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 3 ;
[0065] Figure 14 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 4 ;
[0066] Figure 15 This is a schematic diagram of the hardware composition structure of a communication device according to an embodiment of the present invention. Detailed Implementation
[0067] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.
[0068] The technical solutions of this invention can be applied to various communication systems, such as GSM (Global System of Mobile communication), LTE (Long Term Evolution), or 5G systems. Optionally, a 5G system or 5G network can also be referred to as a New Radio (NR) system or NR network.
[0069] For example, the communication system used in this embodiment of the invention may include network devices and terminal devices (also referred to as terminals, communication terminals, etc.); the network device may be a device that communicates with the terminal device. The network device can provide communication coverage within a certain area and can communicate with terminals located within that area. Optionally, the network device may be a base station in various communication systems, such as an evolved Node B (eNB) in an LTE system, or a gNB in a 5G or NR system.
[0070] It should be understood that devices with communication functions in the network / system of this application embodiment can be referred to as communication devices. Communication devices may include network devices and terminals with communication functions. Network devices and terminal devices can be the specific devices described above, which will not be repeated here. Communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities. This embodiment of the present invention does not limit these.
[0071] It should be understood that the terms "system" and "network" are often used interchangeably in this document. The term "and / or" in this document merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Furthermore, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0072] The terms “first,” “second,” etc., used in the specification and claims of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0073] Before providing a detailed description of the technical solutions of the embodiments of the present invention, a brief explanation of digital twin networks will be given first.
[0074] A Digital Twin Network (DTN) is a network system with physical entities and virtual twins that can interact and map in real time. Digital twins are real-time mirror images of physical entities in the digital world and are becoming a new focus of global information technology development and industrial digital transformation. In the future, with the continuous development of technologies such as cloud computing, big data, and artificial intelligence, and the ubiquity of information, digital twin technology will be widely used in fields such as intelligent manufacturing, smart cities, and scientific research, leading society towards a "digital twin" world that combines the virtual and the real. Currently, the digital twin network project is under discussion at the International Telecommunication Union (ITU), and the overall network framework design has been completed. However, how to achieve interaction between network entities within the digital twin network has not yet been specifically defined.
[0075] The architecture of digital twin networks can be referenced. Figure 1 As shown, a digital twin network can be designed as a "three-layer, three-domain, dual-closed-loop" architecture. The three layers refer to the physical network layer, the twin network layer, and the network application layer that constitute the digital twin network. The three domains refer to the data domain, model domain, and management domain of the twin network layer, which correspond to the three subsystems of data sharing warehouse, service mapping model, and network twin management, respectively. The "dual closed loop" refers to the "inner closed loop" simulation and optimization based on the service mapping model within the twin network layer, and the "outer closed loop" control, feedback, and optimization of network applications based on the three-layer architecture.
[0076] The core of a digital twin network is data-driven modeling, providing data model instances for various network applications to maximize the agility and programmability of network services. The service mapping model of the twin network layer consists of two parts: a basic model and a functional model. The basic model refers to the device and topology models of the twin network entity corresponding to the physical network, built based on information such as the basic configuration of physical devices, environmental information, operating status, and link topology, achieving a real-time and accurate description of the physical network. The functional model refers to various data models for network analysis, simulation, diagnosis, prediction, and assurance, built by fully utilizing network data in the data warehouse for specific application scenarios.
[0077] like Figure 2 As shown, in multiple twin application scenarios, at the twin network layer, one physical device will correspond to multiple twin instances. Combined with... Figure 1As shown, in a digital twin network, data needs to be collected and stored in a shared data warehouse. Digital twin networks involve massive amounts of data storage and usage, thus utilizing distributed technologies such as cloud storage and cloud computing. Storing data in plaintext poses a risk of data leakage. If traditional encryption mechanisms are used, physical devices need to encrypt network data using keys from different instances to generate multiple ciphertexts, which are then sent to the twin instances in the twin network to achieve state synchronization between the twin devices and the physical devices. Digital twin networks are characterized by high real-time requirements; multiple encryption and decryption operations increase the processing latency of terminal data, and when a large number of devices connect to the network, it poses a significant challenge to network storage and load.
[0078] Twin instances refer to the digital models of devices in a twin network, which may vary depending on the application.
[0079] Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is an attribute-based encryption mechanism that embeds the policy into the ciphertext and the attributes into the user key. The ciphertext corresponds to an access structure, and the key corresponds to a set of attributes. Decryption occurs if and only if the attributes in the attribute set satisfy the access structure. CP-ABE uses cryptographic mechanisms to protect data, allowing the data owner to define the policy for accessing the ciphertext and associate the attribute set with the accessed resource. Data users can access ciphertext information based on their authorized attributes.
[0080] The public-private key generated by the CP-ABE algorithm based on attribute encryption enables secure one-to-many data transmission. This method requires a trusted twin center to generate public and private keys based on the CP-ABE algorithm. The model instance's attributes are embedded in the private key and sent to the twin instance, while the public key is sent to the physical device. If the terminal has subscribed to a digital twin service, the trusted twin center generates {PK,MK} = Setup() using the CP-ABE initialization algorithm, where PK is used as the device's public key, and MK is stored in the trusted center as a master key for generating the private key. When the twin layer generates a new twin instance, it requests a twin private key SK from the trusted twin center. The trusted twin center generates the key SK = KeyGen(MK,S) using the CP-ABE private key generation algorithm, where S is the set of attributes of the twin instance. This public-key encryption mechanism has relatively low encryption efficiency. Digital twin networks have high requirements for network real-time performance; directly using the public and private keys generated by CP-ABE to encrypt and decrypt data will increase data processing latency.
[0081] Based on this, the following embodiments of the present invention are proposed.
[0082] Figure 3This is a schematic diagram of the system architecture for the key distribution method according to an embodiment of the present invention; as shown below. Figure 3 As shown, this embodiment adds a twin management network element to the existing physical devices and authentication network elements of the physical layer of the digital twin network. This twin management network element is responsible for providing secure transmission keys between the physical devices and the twin instances of the twin layer. In other optional embodiments, the twin management network element can also be called the first network element, management network element, etc., as long as it can achieve the corresponding function. This embodiment does not limit the name of the network element. In practical applications, the first network element (or twin management network element) can be implemented through an independent physical entity, or it can be co-located with other network functions on a single physical entity through network functions. This embodiment does not limit this.
[0083] This invention provides a key distribution method, which is applied to the first network element of a digital twin network. Figure 4 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 1 ,like Figure 4 As shown, the method includes:
[0084] Step 101: Receive a first message sent by the second network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device;
[0085] Step 102: Based on the stored first information, query the first public key and the first data access control structure corresponding to the first identifier; use the first public key and the first data access control structure to encrypt the first key using the attribute encryption algorithm to obtain the second key; wherein, the first information includes at least one set of association relationships between the identifier, public key and data access control structure representing the identity of the physical device; the first key comes from the third network element;
[0086] Step 103: Send a second message corresponding to the first message to the second network element. The second message includes at least the second key, so that the second network element can issue the second key to the twin instance, which is associated with the first physical device.
[0087] In this embodiment, the first network element can be as follows: Figure 3 The illustrated twin management network element. The second network element can be a data sharing warehouse of the digital twin network, as shown in the reference. Figure 1As shown, the data sharing warehouse has functions such as data management, data service, data storage, and data collection. In other optional embodiments, the second network element can also be other network elements in the digital twin network that specifically perform the above functions. This embodiment does not limit the name of the network element. The third network element can be a network element used to authenticate physical devices, and can be called an authentication network element, or a device authentication network element, etc. This embodiment does not limit the name of the network element.
[0088] In this embodiment, the physical device includes a terminal device or a network element. The network element can be, for example, a core network element, an access network element, etc. In this embodiment, any physical device capable of using digital twin services, that is, a device corresponding to one or more twin instances, can be referred to as a network element.
[0089] In this embodiment, the second network element sends a key request (i.e., a first message) to the first network element. The key request (i.e., the first message) may carry a first identifier (such as a device ID) of the first physical device corresponding to or associated with the twin instance. Upon receiving the key request (i.e., the first message), the first network element can determine the first public key and the first data access control structure corresponding to the first identifier based on pre-stored first information. The first information includes at least one set of associations between the identifier, public key, and data access control structure representing the physical device's identity. By searching the first information using the first identifier, the first public key and the first data access control structure corresponding to the first identifier can be obtained. Furthermore, the first network element can use an attribute-based encryption algorithm, utilizing the first public key and the first data access control structure to encrypt the first key, thereby obtaining the second key. The attribute-based encryption algorithm may be the CP_ABE algorithm; however, this embodiment is not limited to using the CP_ABE algorithm, and other attribute-based encryption algorithms are also within the scope of this embodiment.
[0090] As an example, the above encryption process can satisfy: K ET =K_en(K PK ,K AT ,H);
[0091] Where K_en represents the CP_ABE encryption algorithm; K PK H represents the first public key; H represents the first data access control structure; K represents the first public key. AT Indicates the first key; K ET This indicates the second key.
[0092] In this embodiment, the first network element sends the second key to the second network element through a key response (i.e., the second message), so that the second network element can send the second key to the twin instance.
[0093] In some optional embodiments, the second message further includes the validity period of the first key; in other embodiments, the second message further includes the validity period of the second key, which is equivalent to the validity period of the first key.
[0094] In some optional embodiments of the present invention, before receiving the first message sent by the second network element, the method further includes: receiving a third message sent by the third network element, the third message being used to request anchoring or storing the first key; the third message including at least the first key and the first identifier; the first key being generated by the third network element based on relevant information in the authentication process with the terminal device; and storing the first key and the first identifier.
[0095] In this embodiment, the third network element acts as an authentication network element. During the authentication process with the first physical device, it generates a first key based on the relevant information of the authentication process and sends the first key and the first identifier of the first physical device to the first network element through a key anchoring request (i.e., the third message). The key anchoring request (i.e., the third message) is used to request the first network element to store the first key and the first identifier.
[0096] In some alternative embodiments, the third message further includes the validity period of the first key. In other embodiments, the third message further includes the validity period of the second key, which is equivalent to the validity period of the first key.
[0097] In some optional embodiments of the present invention, before receiving the first message sent by the second network element, the method further includes: receiving a fourth message sent by the first physical device, the fourth message being used to request the subscription of twin services; the fourth message including at least the first public key and the first identifier; and storing the associated first public key and the first identifier in the first information.
[0098] In this embodiment, before requesting the key, the first physical device first completes the digital twin service subscription process. In practical applications, each physical device (such as the first physical device) has a direct communication interface with the first network element, through which they can directly interact. In other embodiments, the information exchanged between the first physical device and the first network element can also be forwarded through other network elements, such as through a third network element (such as an authentication network element). This embodiment does not limit this.
[0099] In this embodiment, the first physical device requests to subscribe to a digital twin service (or twin service) from the first network element via a fourth message; the fourth message includes at least the first public key and the first identifier; after receiving the fourth message, the first network element stores the associated first public key and the first identifier in the first information.
[0100] In some optional embodiments, the fourth message further includes the first data access control structure; storing the associated first public key and the first identifier in the first information includes: storing the associated first public key, the first identifier, and the first data access control structure in the first information.
[0101] In some optional embodiments of the present invention, the method further includes: receiving a fifth message sent by the first physical device, the fifth message being used to request an update of the digital twin access structure; the fifth message including at least the first identifier and an updated first data access control structure; and updating the data access control structure stored in the first information corresponding to the first identifier to the updated first data access control structure.
[0102] In this embodiment, the first physical device requests the first network element to update the digital twin access structure via a fifth message, that is, to update the data access control structure corresponding to the first identifier; the fifth message includes the first identifier and the updated first data access control structure; after receiving the fifth message, the first network element can look up the first information based on the first identifier, obtain the association relationship related to the first identifier stored in the first information, and further update the data access control structure corresponding to the first identifier stored in the first information to the updated first data access control structure.
[0103] Based on the above embodiments, this invention provides a key distribution method, which is applied to the second network element of a digital twin network. Figure 5 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 2 ,like Figure 5 As shown, the method includes:
[0104] Step 201: Send a first message to the first network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device;
[0105] Step 202: Receive a second message sent by the first network element. The second message includes at least a second key. The second key is obtained by the first network element using an attribute encryption algorithm, a first public key corresponding to the stored first identifier, and encryption of the first key based on a first data access control structure.
[0106] Step 203: Send a sixth message to the twin instance, the sixth message including the second key, the twin instance being associated with the first physical device.
[0107] In this embodiment, the second network element can be a data sharing warehouse of a digital twin network, referring to... Figure 1 As shown, the data sharing warehouse has functions such as data management, data service, data storage, and data collection. In other optional embodiments, the second network element can also be other network elements with the above-mentioned functions in the digital twin network. This embodiment does not limit the name of the network element.
[0108] In this embodiment, the second network element sends a key request (i.e., a first message) to the first network element. The key request (i.e., the first message) may carry a first identifier (such as a device ID) of the first physical device corresponding to or associated with the twin instance. Upon receiving the key request (i.e., the first message), the first network element can determine the first public key and the first data access control structure corresponding to the first identifier based on pre-stored first information. The first information includes at least one set of associations between the identifier, public key, and data access control structure representing the physical device identity. By searching the first information using the first identifier, the first public key and the first data access control structure corresponding to the first identifier can be obtained. Furthermore, the first network element can use an attribute-based encryption algorithm, utilizing the first public key and based on the first data access control structure, to encrypt the first key to obtain a second key. Further, the first network element sends the second key to the second network element via a key response (i.e., a second message); the second network element then sends the second key to the twin instance via a key sending message (i.e., a sixth message).
[0109] In some optional embodiments, both the second message and the sixth message further include the validity period of the first key. In other embodiments, the second message further includes the validity period of the second key, which is equivalent to the validity period of the first key; and / or, the sixth message further includes the validity period of the second key, which is equivalent to the validity period of the first key.
[0110] This invention provides a key distribution method, which is applied to a twin instance of a digital twin network. Figure 6 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 3 ,like Figure 6 As shown, the method includes:
[0111] Step 301: Receive a sixth message sent by the second network element, the sixth message including a second key, the second key coming from the first network element; the second key is obtained by the first network element based on an attribute encryption algorithm, using a stored first public key corresponding to a first identifier representing the identity of the first physical device, and encrypting the first key based on a first data access control structure; the twin instance is associated with the first physical device;
[0112] Step 302: Decrypt the second key using the first private key corresponding to the first public key to obtain the first key.
[0113] In this embodiment, the twin instance receives the second key issued by the second network element through the sixth message, and decrypts the second key using the first private key corresponding to the first public key to obtain the first key. For example, the above decryption process can satisfy: K AT = = K_de(K ET ,K SK );
[0114] Among them, K AT Indicates the first key; K ET K represents the second key; K_de represents the CP_ABE decryption algorithm; K SK This represents the first private key corresponding to the first public key.
[0115] In various embodiments of the present invention, the first key is used to establish secure communication between the first physical device and the twin instance, that is, the first physical device and the twin instance establish secure communication based on the first key.
[0116] In some alternative embodiments, the sixth message further includes the validity period of the first key. In other embodiments, the sixth message further includes the validity period of the second key, which is equivalent to the validity period of the first key.
[0117] In other alternative embodiments, the method of this embodiment can also be applied to a device with a twin instance, or it can also be called a twin device, communication device, etc.; the second network element interacts with the device to realize the interaction between the twin instance.
[0118] This invention provides a key distribution method, which is applied to a third network element in a digital twin network. Figure 7 This is a flowchart illustrating the key distribution method according to an embodiment of the present invention. Figure 4 ,like Figure 7 As shown, the method includes:
[0119] Step 401: Generate a first key associated with the first physical device;
[0120] Step 402: Send a third message to the first network element, the third message being used to request anchoring or storing the first key; the third message includes at least the first key and a first identifier representing the identity of the first physical device.
[0121] In this embodiment, the third network element can be a network element used to authenticate physical devices, and can be called an authentication network element, or a device authentication network element, etc. This embodiment does not limit the name of the network element.
[0122] In this embodiment, the physical device includes a terminal device or a network element; that is, the first physical device includes a first terminal device or a network element (first terminal device / network element). The network element may be, for example, a core network element, an access network element, etc. In this embodiment, any physical device capable of using digital twin services, that is, a device corresponding to one or more twin instances, can be referred to as a network element.
[0123] In this embodiment, the third network element can send the first key and the first identifier of the first physical device to the first network element through a key anchoring request (i.e., a third message); the key anchoring request (i.e., the third message) is used to request the first network element to store the first key and the first identifier.
[0124] In some alternative embodiments, generating the first key associated with the first device or the first network element includes: generating the first key based on relevant information in the authentication process of the first physical device.
[0125] In this embodiment, the third network element acts as the authentication network element. During the authentication process with the first physical device, it generates the first key based on relevant information from the authentication process. This relevant information may include relevant keys and / or vectors from the authentication process, and the first key is derived from these relevant keys and / or vectors.
[0126] In addition, during the authentication process between the third network element and the first physical device, the first physical device can also generate the first key based on the relevant information in the authentication process.
[0127] In some alternative embodiments, the third message further includes the validity period of the first key. In other embodiments, the third message further includes the validity period of the second key, which is equivalent to the validity period of the first key.
[0128] The key distribution method of this invention will be described in detail below with specific examples. In the following examples, the first network element is a twin management network element, the second network element is a data sharing warehouse, the third network element is an authentication network element, and the physical device is a physical terminal / network element.
[0129] Example 1
[0130] Figure 8 This is a schematic diagram of the interaction flow of the key distribution method according to an embodiment of the present invention. Figure 1 ;like Figure 8 As shown, the method includes:
[0131] Step 501: The physical terminal / network element performs a device authentication process with the authentication network element; after completing the device authentication, a key K is derived based on the relevant information (such as relevant keys and vectors) in the authentication process. AT .
[0132] Here, key K AT This is equivalent to the first key mentioned above.
[0133] Step 502: The authentication network element sends a twin key anchoring request to the twin management network element, the key anchoring request carrying key K. AT Device ID and key validity period; twin management network element stores K AT .
[0134] Here, the device ID represents the identity of the physical terminal / network element, equivalent to the identity identifier of the physical terminal / network element. The twin key anchoring request is equivalent to the third message in the above embodiment.
[0135] Step 503: The data sharing warehouse sends a key request to the twin management network element, and the key request carries the device ID.
[0136] Here, the key request is equivalent to the first message in the above embodiment.
[0137] Steps 504 to 505: The twin management network element queries the twin public key K corresponding to the device based on the device ID. PK and data access control structure H; using twin public key K PK Based on the data access structure H, the symmetric session key K is encrypted. AT Get K ET .
[0138] Here, K ET =K_en(K PK ,K AT K_en is the CP_ABE encryption algorithm, which can only be decrypted if the twin instance attributes satisfy the data access control structure H. ET .
[0139] Step 506: The twin management network element sends a twin key response to the data sharing warehouse, the twin key response carrying K ET and key validity period.
[0140] Here, the twin key response is equivalent to the second message in the above embodiment.
[0141] Step 507: The data sharing repository distributes the key to one or more twin instances corresponding to the physical device. Among them, the key carrying the K... ET and key validity period.
[0142] Step 508: Decrypt K using the twin instance's private key ET Obtain key K AT .
[0143] Here, K AT ==K_de(K ET ,K SK ), where K_de is the CP_ABE decryption algorithm, K SK It is the private key of the twin instance, and also the twin's public key K. PK The corresponding private key.
[0144] Step 509: Communication between the physical terminal / network element and the twin instance based on key K AT Establish secure communication.
[0145] Example 2
[0146] This example illustrates a digital twin service subscription / access structure update scheme within a key distribution method. Figure 9 This is a schematic diagram of the interaction flow of the key distribution method according to an embodiment of the present invention. Figure 2 ;like Figure 9 As shown, the method includes:
[0147] Step 601: The physical terminal / network element sends a twin service subscription request to the twin management network element; wherein the twin service subscription request carries the twin public key K. PK Data access structure H and device ID.
[0148] Here, the twin service subscription request can be equivalent to the fourth message in the above embodiments.
[0149] Step 602: After receiving the request, the twin management element saves the K. PK The system accesses the data structure H and the device ID, and returns a response message indicating that the digital twin service subscription is complete.
[0150] Step 603: The physical terminal / network element sends a digital twin access structure update request to the twin management network element; wherein, the digital twin access structure update request carries a new data access control structure H' and a device ID. After receiving the request, the twin management network element updates the digital access control structure corresponding to or associated with the device ID to the new data access control structure H'.
[0151] Here, the digital twin access structure update request can be equivalent to the fifth message in the above embodiments.
[0152] Step 604: The twin management network element returns a response message to the physical terminal / network element indicating that the digital twin access structure update is complete.
[0153] Example 3
[0154] This example illustrates a digital twin service subscription scheme within a key distribution method. Figure 10 This is a schematic diagram of the interaction flow of the key distribution method according to an embodiment of the present invention. Figure 3 ;like Figure 10 As shown, the method includes:
[0155] Step 701: The physical terminal / network element sends a twin service subscription request to the twin management network element; wherein the twin service subscription request carries the twin public key K. PK and device ID.
[0156] Here, the twin service subscription request can be equivalent to the fourth message in the above embodiments.
[0157] Step 702: After receiving the request, the twin management element saves the K. PK The system retrieves the device ID and returns a response message indicating that the digital twin service subscription is complete.
[0158] Based on the above embodiments, this invention also provides a key distribution device, which is applied to a first network element of a digital twin network. Figure 11 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 1 ;like Figure 11 As shown, the device includes: a first communication unit 11 and a first processing unit 12; wherein,
[0159] The first communication unit 11 is used to receive a first message sent by the second network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device;
[0160] The first processing unit 12 is configured to query the first public key and the first data access control structure corresponding to the first identifier based on the stored first information, and use the first public key and the first data access control structure to encrypt the first key to obtain the second key using an attribute encryption algorithm; wherein, the first information includes at least one set of association relationships between the identifier, public key and data access control structure representing the identity of the physical device; the first key comes from a third network element;
[0161] The first communication unit 11 is further configured to send a second message corresponding to the first message to the second network element, the second message including at least the second key, so that the second network element can issue the second key to the twin instance, the twin instance being associated with the first physical device.
[0162] In some optional embodiments of the present invention, the device further includes a storage unit;
[0163] The first communication unit 11 is further configured to receive a third message sent by the third network element before receiving the first message sent by the second network element, the third message being used to request anchoring or storing the first key; the third message includes at least the first key and the first identifier; the first key is generated by the third network element based on relevant information in the authentication process with the terminal device;
[0164] The storage unit is used to store the first key and the first identifier.
[0165] In some optional embodiments of the present invention, the first communication unit 11 is further configured to receive a fourth message sent by the first physical device before receiving the first message sent by the second network element, the fourth message being used to request to subscribe to twin services; the fourth message includes at least the first public key and the first identifier;
[0166] The first processing unit 12 is further configured to store the first public key and the first identifier, which are associated, in the first information.
[0167] In some optional embodiments of the present invention, the fourth message further includes the first data access control structure;
[0168] The first processing unit 12 is further configured to store the associated first public key, the first identifier, and the first data access control structure in the first information.
[0169] In some optional embodiments of the present invention, the first communication unit 11 is further configured to receive a fifth message sent by the first physical device, the fifth message being used to request an update to the digital twin access structure; the fifth message includes at least the first identifier and an updated first data access control structure;
[0170] The first processing unit 12 is further configured to update the data access control structure stored in the first information corresponding to the first identifier to the updated first data access control structure.
[0171] In some optional embodiments of the present invention, the second message may further include the validity period of the first key; and / or, the third message may further include the validity period of the first key.
[0172] In some alternative embodiments of the present invention, the physical device includes a terminal device or a network element.
[0173] In this embodiment of the invention, the first processing unit 12 in the device can be implemented by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU), or a field-programmable gate array (FPGA) in practical applications; the first communication unit 11 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in practical applications.
[0174] This invention also provides a key distribution device, which is applied to a second network element of a digital twin network. Figure 12 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 2 ;like Figure 12 As shown, the device includes: a second communication unit 21, configured to send a first message to a first network element, the first message being used to request a first key; the first message including at least a first identifier representing the identity of a first physical device; further configured to receive a second message sent by the first network element, the second message including at least a second key, the second key being obtained by the first network element based on an attribute encryption algorithm, using a stored first public key corresponding to the first identifier, and encrypting the first key based on a first data access control structure; further configured to send a sixth message to a twin instance, the sixth message including the second key, the twin instance being associated with the first physical device.
[0175] In some optional embodiments of the present invention, both the second message and the sixth message further include the validity period of the first key.
[0176] In this embodiment of the invention, the second communication unit 21 in the device can be implemented in practical applications through a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna.
[0177] This invention also provides a key distribution device, which is applied to a twin instance of a digital twin network. Figure 13 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 3 ;like Figure 13As shown, the device includes a third communication unit 31 and a second processing unit 32; wherein,
[0178] The third communication unit 31 is used to receive a sixth message sent by the second network element. The sixth message includes a second key, which comes from the first network element. The second key is obtained by the first network element based on an attribute encryption algorithm, using a first public key corresponding to a stored first identifier representing the identity of the first physical device, and encrypting the first key based on a first data access control structure. The twin instance is associated with the first physical device.
[0179] The second processing unit 32 is used to decrypt the second key using the first private key corresponding to the first public key to obtain the first key.
[0180] In some optional embodiments of the present invention, the sixth message may also include the validity period of the first key.
[0181] In this embodiment of the invention, the second processing unit 32 in the device can be implemented by a CPU, DSP, MCU or FPGA in practical applications; the third communication unit 31 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and transceiver antenna in practical applications.
[0182] This invention also provides a key distribution device, which is applied to a third network element in a digital twin network. Figure 14 This is a schematic diagram of the composition of the key distribution device according to an embodiment of the present invention. Figure 4 ;like Figure 14 As shown, the device includes: a third processing unit 41 and a fourth communication unit 42; wherein,
[0183] The third processing unit 41 is used to generate a first key associated with the first physical device;
[0184] The fourth communication unit 42 is used to send a third message to the first network element. The third message is used to request anchoring or storing the first key. The third message includes at least the first key and a first identifier representing the identity of the first physical device.
[0185] In some optional embodiments of the present invention, the third message may also include the validity period of the first key.
[0186] In some alternative embodiments of the present invention, the third processing unit 41 is configured to generate the first key based on relevant information in the authentication process of the first physical device.
[0187] In some alternative embodiments of the present invention, the first physical device includes a first terminal device or a network element.
[0188] In this embodiment of the invention, the third processing unit 41 in the device can be implemented by a CPU, DSP, MCU or FPGA in practical applications; the fourth communication unit 42 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and transceiver antenna in practical applications.
[0189] This invention also provides a communication device, which may specifically be a first network element, a second network element, a twin instance, or a third network element of a digital twin network. Figure 15 This is a schematic diagram of the hardware composition structure of the communication device according to an embodiment of the present invention, such as... Figure 15 As shown, the communication device includes a memory 52, a processor 51, and a computer program stored in the memory 52 and executable on the processor 51. When the processor 51 executes the program, it implements the steps of a key distribution method applied to a first network element, a second network element, a twin instance, or a third network element in a digital twin network.
[0190] Optionally, the communication device also includes at least one network interface 53. The various components of the communication device are coupled together via a bus system 54. It is understood that the bus system 54 is used to implement communication between these components. In addition to a data bus, the bus system 54 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 15 The general labeled all buses as Bus System 54.
[0191] It is understood that memory 52 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 52 described in this embodiment of the invention is intended to include, but is not limited to, these and any other suitable types of memory.
[0192] The methods disclosed in the above embodiments of the present invention can be applied to processor 51, or implemented by processor 51. Processor 51 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in processor 51 or by instructions in the form of software. The processor 51 may be a general-purpose processor, DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 51 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present invention can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in memory 52. Processor 51 reads the information in memory 52 and completes the steps of the aforementioned method in combination with its hardware.
[0193] In an exemplary embodiment, the communication device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.
[0194] In an exemplary embodiment, the present invention also provides a computer-readable storage medium, such as a memory 52 including a computer program, which can be executed by a processor 51 of a communication device to perform the steps described in the foregoing method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM; or it may be various devices including one or any combination of the above-mentioned memories.
[0195] The computer-readable storage medium provided in the embodiments of the present invention stores a computer program thereon, which, when executed by a processor, implements the steps of the key distribution method of the first network element, second network element, twin instance or third network element of the digital twin network according to the embodiments of the present invention.
[0196] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0197] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0198] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.
[0199] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.
[0200] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.
[0201] In addition, in the various embodiments of the present invention, each functional unit can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0202] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.
[0203] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.
[0204] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A key distribution method, characterized in that, The method is applied to a first network element of a digital twin network, and the method includes: The system receives a first message sent by a second network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device. Based on the stored first information, the first public key and the first data access control structure corresponding to the first identifier are queried. An attribute encryption algorithm is used to encrypt the first key using the first public key and the first data access control structure to obtain the second key. The first information includes at least one set of associations between the identifier, public key and data access control structure representing the identity of the physical device. The first key comes from a third network element. The second message corresponding to the first message is sent to the second network element. The second message includes at least the second key, so that the second network element issues the second key to the twin instance, which is associated with the first physical device.
2. The method according to claim 1, characterized in that, Before receiving the first message sent by the second network element, the method further includes: The third message sent by the third network element is received. The third message is used to request anchoring or storing the first key. The third message includes at least the first key and the first identifier. The first key is generated by the third network element based on relevant information in the authentication process with the terminal device. Store the first key and the first identifier.
3. The method according to claim 1, characterized in that, Before receiving the first message sent by the second network element, the method further includes: The system receives a fourth message sent by the first physical device, the fourth message being used to request the subscription of twin services; the fourth message includes at least the first public key and the first identifier; The first public key and the first identifier, which are associated, are stored in the first information.
4. The method according to claim 3, characterized in that, The fourth message also includes the first data access control structure; The step of storing the associated first public key and first identifier in the first information includes: The first public key, the first identifier, and the first data access control structure that are associated are stored in the first information.
5. The method according to claim 4, characterized in that, The method further includes: The system receives a fifth message sent by the first physical device, the fifth message being used to request an update to the digital twin access structure; the fifth message includes at least the first identifier and the updated first data access control structure; The data access control structure corresponding to the first identifier stored in the first information is updated to the updated first data access control structure.
6. The method according to claim 2, characterized in that, The second message also includes the validity period of the first key; and / or, The third message also includes the validity period of the first key.
7. The method according to claim 1, characterized in that, The physical devices include terminal devices or network elements.
8. A key distribution method, characterized in that, The method is applied to a second network element of a digital twin network, and the method includes: Send a first message to the first network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device; The first network element receives a second message, which includes at least a second key. The second key is obtained by the first network element using an attribute-based encryption algorithm, a first public key corresponding to the stored first identifier, and a first data access control structure to encrypt the first key. A sixth message is sent to the twin instance, the sixth message including the second key, the twin instance being associated with the first physical device.
9. The method according to claim 8, characterized in that, Both the second message and the sixth message also include the validity period of the first key.
10. A key distribution method, characterized in that, The method is applied to a twin instance of a digital twin network, and the method includes: The system receives a sixth message sent by a second network element, the sixth message including a second key, the second key being obtained from a first network element; the second key is obtained by the first network element using an attribute encryption algorithm, a first public key corresponding to a stored first identifier representing the identity of a first physical device, and encryption of the first key based on a first data access control structure; the twin instance is associated with the first physical device; The second key is decrypted using the first private key corresponding to the first public key to obtain the first key.
11. The method according to claim 10, characterized in that, The sixth message also includes the validity period of the first key.
12. A key distribution method, characterized in that, The method is applied to a third network element in a digital twin network, and the method includes: Generate a first key associated with the first physical device; A third message is sent to the first network element, the third message being used to request anchoring or storing the first key; the third message includes at least the first key and a first identifier representing the identity of the first physical device; the first key is used by the first network element to encrypt a second key using a first public key based on an attribute encryption algorithm and based on a first data access control structure; the second key is used by the first network element to send the second key to the second network element via a second message, so that the second network element can distribute it to the twin instance.
13. The method according to claim 12, characterized in that, The third message also includes the validity period of the first key.
14. The method according to claim 12, characterized in that, The generation of the first key associated with the first device or the first network element includes: The first key is generated based on relevant information from the authentication process of the first physical device.
15. The method according to claim 12, characterized in that, The first physical device includes a first terminal device or a network element.
16. A key distribution device, characterized in that, The device is applied to a first network element of a digital twin network; the device includes: a first communication unit and a first processing unit; wherein... The first communication unit is configured to receive a first message sent by the second network element, the first message being used to request a first key; the first message includes at least a first identifier representing the identity of the first physical device; The first processing unit is configured to query the first public key and the first data access control structure corresponding to the first identifier based on the stored first information, and use the first public key and the first data access control structure to encrypt the first key to obtain the second key using an attribute encryption algorithm; wherein, the first information includes at least one set of association relationships between the identifier, public key and data access control structure representing the identity of the physical device; the first key comes from a third network element; The first communication unit is further configured to send a second message corresponding to the first message to the second network element, the second message including at least the second key, so that the second network element can issue the second key to the twin instance, the twin instance being associated with the first physical device.
17. A key distribution device, characterized in that, The device is applied to a second network element in a digital twin network. The device includes: a second communication unit, configured to send a first message to a first network element, the first message being used to request a first key; the first message including at least a first identifier representing the identity of a first physical device; further configured to receive a second message sent by the first network element, the second message including at least a second key, the second key being obtained by the first network element based on an attribute encryption algorithm, using a stored first public key corresponding to the first identifier, and encrypting the first key based on a first data access control structure; and further configured to send a sixth message to a twin instance, the sixth message including the second key, the twin instance being associated with the first physical device.
18. A key distribution device, characterized in that, The device is applied to a twin instance of a digital twin network, and the device includes a third communication unit and a second processing unit; wherein, The third communication unit is used to receive a sixth message sent by the second network element. The sixth message includes a second key, which comes from the first network element. The second key is obtained by the first network element using an attribute encryption algorithm, a first public key corresponding to a stored first identifier representing the identity of the first physical device, and encryption of the first key based on a first data access control structure. The twin instance is associated with the first physical device. The second processing unit is used to decrypt the second key using the first private key corresponding to the first public key to obtain the first key.
19. A key distribution device, characterized in that, The device is applied to a third network element in a digital twin network, and the device includes: a third processing unit and a fourth communication unit; wherein, The third processing unit is used to generate a first key associated with the first physical device; The fourth communication unit is used to send a third message to the first network element. The third message is used to request anchoring or storing the first key. The third message includes at least the first key and a first identifier representing the identity of the first physical device. The first key is used by the first network element to encrypt the first key using an attribute encryption algorithm based on the first public key and based on the first data access control structure to obtain a second key. The second key is used by the first network element to send the second key to the second network element through the second message, so that the second network element can distribute it to the twin instance.
20. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the steps of the method according to any one of claims 1 to 7; or... When executed by a processor, the program implements the steps of the method described in claim 8 or 9; or... When executed by a processor, the program implements the steps of the method described in claim 10 or 11; or... When executed by a processor, the program performs the steps of the method according to any one of claims 12 to 15.
21. A communication device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 7; or... When the processor executes the program, it implements the steps of the method of claim 8 or 9; or... When the processor executes the program, it implements the steps of the method of claim 10 or 11; or... When the processor executes the program, it implements the steps of the method according to any one of claims 12 to 15.
Citation Information
Patent Citations
Strategy authentication method and device and communication equipment
CN116347444A