Secure communication method, apparatus, related device, and storage medium

By establishing an encrypted communication channel between IoT terminals and network devices, and using identity identification and encryption algorithms for two-way authentication and key negotiation, the high cost and resource consumption of secure communication in IoT terminal devices are solved, and encrypted communication capabilities for low-configuration terminals are realized.

CN118827105BActive Publication Date: 2026-04-24CHINA MOBILE COMM LTD RES INST +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2023-11-29
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing technologies for providing secure communication in IoT terminal devices suffer from high costs, high resource consumption, and weakened security capabilities, making them difficult to widely apply to low-configuration terminals.

Method used

By establishing an encrypted communication channel between the terminal and network devices, and using identity identification and encryption algorithms for two-way authentication and key negotiation, encrypted data transmission is achieved, and security is enhanced by adopting an extremely lightweight software implementation.

Benefits of technology

Without increasing hardware costs, it improves the data storage and transmission security of low-configuration IoT terminals and enables extensive encrypted communication capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827105B_ABST
    Figure CN118827105B_ABST
Patent Text Reader

Abstract

The application discloses a secure communication method and device, related equipment and a storage medium. The method comprises the following steps: sending a first request to a first network device; the first request is used for the first network device to encrypt first data by using first storage information of the first network device; receiving first response information of the first network device based on the first request; the first response information carries second data obtained by encrypting the first data; sending the second data to a second terminal; the second data is used for the second terminal to send a second request to a second network device; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when a secure communication is constructed between the first terminal and the second terminal; and the second request is used for the second network device to decrypt the second data by using second storage information of the second network device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to a secure communication method, apparatus, related equipment and storage medium. Background Technology

[0002] In related technologies, one approach is to provide secure boot capabilities and basic encryption for IoT terminals by embedding lightweight cryptographic hardware units into the chip hardware. However, this technology requires systematic modifications to the IoT terminal, from the underlying hardware and firmware to the operating system, making it complex, costly, and difficult to widely apply to various weak IoT terminal devices. Another approach is to provide basic encryption capabilities for IoT terminals by lightweightly optimizing cryptographic algorithms. However, lightweight cryptographic software components still consume significant computing, storage, and energy resources from the IoT terminal, making widespread application difficult in various weak IoT terminal devices. Furthermore, the cryptographic security capabilities provided by lightweight cryptographic software components are weakened. Additionally, some cryptographic components suitable for Internet client / server (C / S) communication are not suitable for point-to-point communication between IoT terminal devices. Currently, there is no effective solution to this problem. Summary of the Invention

[0003] To address the related technical problems, embodiments of this application provide a secure communication method, apparatus, related devices, and storage medium.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] This application provides a secure communication method applied to a first terminal, including:

[0006] A first request is sent to a first network device; the first request carries the first identity identifier of the first terminal, the first communication registration identifier, and the first data to be encrypted and transmitted; the first request is used by the first network device to encrypt the first data using its own first storage information;

[0007] Receive first response information from the first network device based on the first request; the first response information carries second data encrypted with the first data;

[0008] The second data is sent to the second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information.

[0009] In the above scheme, the first stored information includes at least one of the following:

[0010] At least one identification identifier for the first terminal;

[0011] The first encryption algorithm corresponding to the first communication registration identifier;

[0012] The first key corresponding to the first encryption algorithm.

[0013] In the above scheme, before sending the first request to the first network device, the method further includes:

[0014] A third request is sent to the second terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal;

[0015] The system receives a third response sent by the second terminal based on the third request; the third response carries the second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication encryption registration identifier.

[0016] A fourth request is sent to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm, and the second communication encryption registration identifier; the fourth request is used to register the second terminal for communication encryption.

[0017] If the second terminal successfully registers for communication encryption, it receives a fourth response sent by the first network device based on the fourth request; the fourth response carries a first cryptographic algorithm table and a first communication encryption registration identifier determined by the first network device.

[0018] Wherein, the first communication encryption registration identifier is used by the first terminal to call the first cryptographic algorithm and the first key in the first network device to encrypt and transmit the data to be communicated; the second communication encryption registration identifier is used by the second terminal to call the second cryptographic algorithm and the second key in the second network device to decrypt the data to be communicated.

[0019] In the above scheme, before receiving the third response sent by the second terminal based on the third request, the method further includes:

[0020] Receive first authentication information sent by the second network device based on the first identity identifier;

[0021] If the first authentication information is successfully authenticated, the first public key of the first terminal is sent to the second network device; the first public key is used by the second network device to generate the second communication encryption registration identifier.

[0022] In the above scheme, after receiving the fourth response sent by the first network device based on the fourth request, the method further includes:

[0023] The second terminal sends verification information for encrypted communication; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key; the verification information is used by the second terminal to send a verification request for encrypted communication to the second network device; the verification request is used by the second network device to verify the verification information.

[0024] If the second network device successfully verifies the verification information, it receives a verification response sent by the second terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0025] This application also provides a secure communication method applied to a second terminal, including:

[0026] Receive the second data sent by the first terminal;

[0027] A second request is sent to a second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information;

[0028] The device receives the first data after the second network device has decrypted the second data using its own second stored information.

[0029] In the above scheme, the second stored information includes at least one of the following:

[0030] At least one second terminal's identity identifier;

[0031] The second encryption algorithm corresponding to the second communication registration identifier;

[0032] The second key corresponding to the second encryption algorithm.

[0033] In the above scheme, after sending the second request to the second network device, the method further includes:

[0034] Send a first registration request with encrypted communication to the second network device; the first registration request carries the second identity identifier and the first communication address of the first terminal; the second identity identifier and the first communication address are used by the first terminal to authenticate the identity of the first terminal;

[0035] If the first terminal successfully authenticates its identity, it receives a first registration application response sent by the second network device based on the first registration application request; the first registration application response carries a first communication registration identifier, a first cryptographic algorithm table, and a first identity identifier; the first communication registration identifier is generated based on the first public key of the first terminal.

[0036] The method in the above scheme further includes:

[0037] Receive the second authentication information sent by the first network device;

[0038] If the second authentication information is successfully authenticated, the second public key of the second terminal is sent to the first network device; the second public key is used by the first network device to generate the first communication encryption registration identifier.

[0039] The method in the above scheme further includes:

[0040] The system receives verification information for encrypted communication sent by the first terminal; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key.

[0041] Based on the verification information, an encrypted communication verification request is sent to the second network device; the verification request is used by the second network device to verify the verification information.

[0042] If the second network device successfully verifies the verification information, it sends a verification response to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0043] This application provides a secure communication method applied to a second network device, including:

[0044] The system receives a second request sent by a second terminal; the second request carries a second identity identifier, a second communication registration identifier, and second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication.

[0045] Based on the second request, the second data is decrypted using its own second stored information.

[0046] In the above scheme, the second stored information includes at least one of the following:

[0047] At least one second terminal's identity identifier;

[0048] The second encryption algorithm corresponding to the second communication registration identifier;

[0049] The second key corresponding to the second encryption algorithm.

[0050] In the above scheme, before receiving the second request sent by the second terminal, the method further includes:

[0051] Receives a first registration request sent by a second terminal with encrypted communication; the first registration request carries the second identity identifier and the first communication address of the first terminal;

[0052] First authentication information is sent to the first terminal based on the second identity identifier and the first communication address; the first authentication information is used to authenticate the identity of the first terminal.

[0053] If the first terminal successfully authenticates its identity, the first public key sent by the first terminal is received, and a first communication encryption registration identifier is generated based on the first public key.

[0054] Send a first registration request response to the first terminal; the first registration request response carries a first communication registration identifier, a first cryptographic algorithm table, and a second identity identifier.

[0055] In the above scheme, generating the first communication encryption registration identifier based on the first public key includes:

[0056] The first parameter is generated based on the cryptographic service component in the second network device;

[0057] The first parameter is encrypted using the first public key to obtain the first communication encryption registration identifier.

[0058] The method in the above scheme further includes:

[0059] Receive a verification request for encrypted communication sent by the second terminal; verify the verification information based on the verification request;

[0060] If the verification information is successfully verified, a verification response is sent to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0061] This application also provides a secure communication method applied to a first network device, including:

[0062] Receive a first request sent by a first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; encrypt the first data using its own first storage information based on the first request.

[0063] In the above scheme, the first stored information includes at least one of the following:

[0064] At least one identification identifier for the first terminal;

[0065] The first encryption algorithm corresponding to the first communication registration identifier;

[0066] The first key corresponding to the first encryption algorithm.

[0067] The method in the above scheme further includes:

[0068] The system receives a second registration request sent by the first terminal, which is encrypted with communication. The second registration request carries the second identity identifier and the second communication address of the second terminal.

[0069] The second authentication information is sent to the second terminal based on the second identity identifier and the second communication address; the second authentication information is used to authenticate the identity of the second terminal.

[0070] If the second terminal successfully authenticates its identity, it receives the second public key sent by the first terminal and generates a second communication encryption registration identifier based on the second public key.

[0071] Send a second registration request response to the first terminal; the second registration request response carries a second communication registration identifier, a second cryptographic algorithm table, and a second identity identifier.

[0072] In the above scheme, generating the second communication encryption registration identifier based on the second public key includes:

[0073] The second parameter is generated based on the cryptographic service component in the first network device;

[0074] The second parameter is encrypted using the second public key to obtain the second communication encryption registration identifier.

[0075] The method in the above scheme further includes:

[0076] The system receives verification information for encrypted communication sent by the first terminal; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key.

[0077] Based on the verification information, an encrypted communication verification request is sent to the second network device; the verification request is used by the second network device to verify the verification information.

[0078] If the second network device successfully verifies the verification information, it sends a verification response to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0079] This application embodiment also provides a secure communication device, disposed in a first terminal, including:

[0080] The first sending unit is configured to send a first request to a first network device; the first request carries a first identity identifier of the first terminal, a first communication registration identifier, and first data to be encrypted and transmitted; the first request is used by the first network device to encrypt the first data using its own first storage information.

[0081] The first receiving unit is configured to receive first response information from the first network device based on the first request; the first response information carries second data encrypted with the first data;

[0082] The first sending unit is further configured to send the second data to the second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information.

[0083] This application embodiment also provides a secure communication device, disposed on a second terminal, including:

[0084] The second receiving unit is used to receive the second data sent by the first terminal;

[0085] The second sending unit is configured to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information.

[0086] The second receiving unit is further configured to receive first data after the second network device has decrypted the second data using its own second stored information.

[0087] This application embodiment also provides a secure communication device, disposed in a second network device, including:

[0088] The third receiving unit is used to receive a second request sent by the second terminal; the second request carries the second identity identifier, the second communication registration identifier, and second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication.

[0089] The decryption unit is used to decrypt the second data using its own second stored information based on the second request.

[0090] This application embodiment also provides a secure communication device, disposed on a first network device, including:

[0091] The fourth receiving unit is configured to receive a first request sent by the first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; and encrypts the first data using its own first storage information based on the first request.

[0092] This application embodiment also provides a first terminal, including: a first processor and a first communication interface; wherein,

[0093] The first communication interface is used to send a first request to a first network device; the first request carries a first identity identifier, a first communication registration identifier, and first data to be encrypted and transmitted from the first terminal; the first request is used by the first network device to encrypt the first data using its own first storage information; and to receive first response information from the first network device based on the first request; the first response information carries second data encrypted with the first data; and to send the second data to a second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries a second identity identifier, a second communication registration identifier, and the second data from the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when establishing secure communication between the first terminal and the second terminal; the second request is used by the second network device to decrypt the second data using its own second storage information.

[0094] This application also provides a second terminal, including: a second communication interface and a second processor; wherein,

[0095] The second communication interface is used to receive second data sent by the first terminal; and to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information; and to receive the first data after the second network device has decrypted the second data using its own second storage information.

[0096] This application also provides a second network device, including: a third processor and a third communication interface; wherein,

[0097] The third communication interface is used to receive a second request sent by the second terminal; the second request carries the second identity identifier, the second communication registration identifier, and second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication.

[0098] The third processor is used to decrypt the second data using its own second stored information based on the second request.

[0099] This application also provides a first network device, including: a fourth communication interface and a fourth processor; wherein,

[0100] The fourth communication interface is used to receive a first request sent by the first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; and the first data is encrypted using its own first storage information based on the first request.

[0101] This application also provides a first terminal, including: a first processor and a first memory for storing a computer program capable of running on the processor.

[0102] Wherein, when the first processor is used to run the computer program, it executes the steps of any of the methods described above for the first terminal side.

[0103] This application also provides a second terminal, including: a second processor and a second memory for storing computer programs capable of running on the processor.

[0104] Wherein, when the second processor is used to run the computer program, it executes the steps of any of the methods described above for the second terminal side.

[0105] This application also provides a second network device, including: a third processor and a third memory for storing computer programs capable of running on the processor.

[0106] When the third processor runs the computer program, it executes any of the steps of the second network device side method described above.

[0107] This application also provides a first network device, including: a fourth processor and a fourth memory for storing computer programs capable of running on the processor.

[0108] Wherein, when the first processor is used to run the computer program, it executes the steps of any of the methods described above on the first network device side.

[0109] This application embodiment also provides a storage medium storing a computer program thereon, wherein when the computer program is executed by a processor, it implements the steps of any of the methods described above for the first terminal side, or implements the steps of any of the methods described above for the second terminal side, or implements the steps of any of the methods described above for the first network device side, or implements the steps of any of the methods described above for the second network device.

[0110] The secure communication method, apparatus, related devices, and storage medium provided in this application embodiment include: a first terminal sending a first request to a first network device; the first request carrying the first terminal's first identity identifier, first communication registration identifier, and first data to be encrypted and transmitted; the first request being used by the first network device to encrypt the first data using its own first storage information; receiving first response information from the first network device based on the first request; the first response information carrying second data encrypted with the first data; sending the second data to a second terminal; the second data being used by the second terminal to send a second request to the second network device; the second request carrying the second terminal's second identity identifier, second communication registration identifier, and the second data; the first and second communication registration identifiers being registration identifiers obtained when establishing secure communication between the first and second terminals; the second request being used by the second network device to decrypt the second data using its own second storage information. For IoT networks, through the establishment of an encrypted communication channel between two terminals and the support of two network devices, combined with the two-way authentication process of terminal identity identifiers, a secure negotiation and verification process of encryption keys is completed, enabling encrypted data transmission between the two terminals, thereby enabling widely used IoT terminals with weak security capabilities to have encrypted communication capabilities. Attached Figure Description

[0111] Figure 1 This is a flowchart illustrating the secure communication method according to an embodiment of this application;

[0112] Figure 2 This is another flowchart illustrating the secure communication method according to an embodiment of this application;

[0113] Figure 3 This is another flowchart illustrating the secure communication method according to an embodiment of this application;

[0114] Figure 4 This is another flowchart illustrating the secure communication method according to an embodiment of this application;

[0115] Figure 5 This is a schematic diagram of a related technical architecture;

[0116] Figure 6 This is a schematic diagram of an Internet of Things (IoT) technology architecture in an embodiment of this application;

[0117] Figure 7 A schematic diagram illustrating the process of establishing an encrypted communication channel between the first terminal and the second terminal;

[0118] Figure 8 This is a schematic diagram of the encrypted communication process between IoT terminal (A) and IoT terminal (B).

[0119] Figure 9 This is a schematic diagram of a secure communication device according to an embodiment of this application;

[0120] Figure 10 This is a schematic diagram of yet another device for secure communication according to an embodiment of this application;

[0121] Figure 11 This is a schematic diagram of yet another device for secure communication according to an embodiment of this application;

[0122] Figure 12 This is a schematic diagram of yet another device for secure communication according to an embodiment of this application;

[0123] Figure 13 This is a schematic diagram of the structure of the first terminal in the embodiment of this application;

[0124] Figure 14 This is a schematic diagram of the structure of the second terminal in an embodiment of this application;

[0125] Figure 15 This is a schematic diagram of the structure of the second network device according to an embodiment of this application;

[0126] Figure 16 This is a schematic diagram of the structure of the first network device according to an embodiment of this application;

[0127] Figure 17 This is a schematic diagram of the secure communication system structure according to an embodiment of this application. Detailed Implementation

[0128] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0129] In the sensing and control domain of IoT systems, most sensing terminals and control terminals are typically inexpensive and lack built-in security or cryptographic chips. Their computing power, storage capacity, and battery life are generally weak, and they do not support complex encryption and decryption operations or secure key storage. Therefore, they are usually unable to encrypt and securely transmit the data they generate. To enable these weak IoT terminals to possess basic encrypted computing capabilities, the industry is currently attempting efforts in two technical directions. One direction is to optimize from a hardware perspective by combining the underlying processor chip and firmware design, providing the terminal with lightweight embedded cryptographic hardware units. For example, the Armv8-M architecture series processors have cryptographic units such as Secure Hash Algorithm (SHA) and Advanced Encryption Standard (AES) within their secure zone, as well as secure storage units, supporting the Arm Trustzone function. Another technological direction is to optimize cryptographic algorithms from a software perspective by comprehensively considering factors such as terminal storage requirements, data throughput, energy consumption, and hardware implementation efficiency, and to provide terminals with lightweight embedded cryptographic software components, such as the mbed Transport Layer Security (mbed TLS) algorithm library, block cipher (CLEFIA), and PRESENT.

[0130] The first technical direction mentioned above provides secure boot capabilities and basic encryption capabilities to IoT terminals by embedding lightweight cryptographic hardware units in the chip hardware. However, the application of this technology requires a systematic transformation of the IoT terminal from the underlying hardware and device firmware to the operating system. The technology is complex, costly, and difficult to widely apply in various weak IoT terminal devices.

[0131] The second technological direction mentioned above provides basic encryption capabilities for IoT terminals through lightweight optimization of cryptographic algorithms. However, lightweight cryptographic software components still consume significant computing, storage, and energy resources from IoT terminals, making them difficult to widely apply in various weak IoT terminal devices. Furthermore, the cryptographic security capabilities provided by lightweight cryptographic software components are weakened. In addition, some cryptographic components suitable for internet client / server communication are not suitable for point-to-point communication between IoT terminal devices.

[0132] Based on this, this application improves the security of data storage and transmission of IoT terminal devices, especially low-configuration and low-cost IoT terminal devices, through a very lightweight software implementation without increasing the hardware cost of the devices.

[0133] This application provides a secure communication method applied to a first terminal. Figure 1This is a flowchart illustrating the secure communication method according to an embodiment of this application; as shown Figure 1 As shown, the method includes:

[0134] Step 101: Send a first request to the first network device; the first request carries the first identity identifier of the first terminal, the first communication registration identifier, and the first data to be encrypted and transmitted; the first request is used by the first network device to encrypt the first data using its own first storage information.

[0135] Step 102: Receive first response information from the first network device based on the first request; the first response information carries second data after encrypting the first data.

[0136] Step 103: Send the second data to the second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information.

[0137] It should be noted that the first terminal can be determined according to the actual situation, and no limitation is made here. As an example, the first terminal can be an Internet of Things (IoT) terminal, which can act as the initiator of encrypted communication, and this IoT terminal can be denoted as A.

[0138] In step 101, the first network device can be determined according to the actual situation, and is not limited here. As an example, the first network device can be a gateway or a router, specifically a cryptographic service engine in that gateway or router. In practical applications, the first network device can be the cryptographic service engine in the gateway or router corresponding to A, and the first network device can be denoted as A.

[0139] The first request carries the first identity identifier of the first terminal, the first communication registration identifier, and the first data to be encrypted and transmitted. The first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted can all be determined according to actual circumstances and are not limited here. As an example, the first identity identifier can be a security identity identifier, which can be denoted as SecurityID_A; the first communication registration identifier can be understood as the registration number obtained when applying for encrypted communication, which can be denoted as EncryptedRegID_A; and the first data to be encrypted and transmitted can be understood as the data to be encrypted, which can be denoted as Data. In practical applications, the cryptographic interface module of the IoT terminal (A) sends its own security identity identifier SecurityID_A, the registration number EncryptedRegID_A obtained when establishing an encrypted communication application with the IoT terminal (B), and the data to be encrypted Data to the cryptographic service engine in the smart gateway / router (A), requesting encryption of the data Data.

[0140] The first request is used by the first network device to encrypt the first data using its own first stored information; wherein, both the first request and the first stored information can be determined according to actual conditions, and are not limited here. As an example, the first request can be a data encryption request; the first stored information may include a saved encryption key list; the encryption key list includes symmetric encryption keys, symmetric encryption algorithms, etc.

[0141] In step 102, the first response information carries second data encrypted with the first data; wherein, the second data can be determined according to the actual situation and is not limited here. As an example, the second data can be denoted as EncryptedData. In practical applications, the cryptographic service engine in the smart gateway / router (A) finds the corresponding symmetric encryption key CryptKey and symmetric encryption algorithm CryptAlgSelected from the saved encryption key list based on SecurityID_A and EncryptedRegID_A, and then uses them to encrypt the data Data to obtain the encrypted data EncryptedData and returns it to the IoT terminal (A).

[0142] In step 103, the second terminal can be determined according to the actual situation, and is not limited here. As an example, the first terminal can be an Internet of Things (IoT) terminal, which can act as the sender of encrypted communication, and this IoT terminal can be denoted as B.

[0143] The second data is used by the second terminal to send a second request to the second network device; wherein, the second network device can be determined according to the actual situation, and is not limited here. As an example, the second network device can be a gateway or a router, specifically a cryptographic service engine in the gateway or router. In practical applications, the second network device can be the cryptographic service engine in the gateway or router corresponding to B, and the second network device can be referred to as B. The second request can be determined according to the actual situation, and is not limited here. As an example, the second request can be a data decryption request.

[0144] The second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; wherein the second identity identifier, the second communication registration identifier, and the second data can be determined according to the actual situation, and are not limited here. As an example, the second identity identifier can be a security identity identifier, which can be denoted as SecurityID_B; the second communication registration identifier can be understood as the registration number obtained when applying for encrypted communication, which can be denoted as EncryptedRegID_B; the second data can be understood as the data to be decrypted, which can be denoted as EncryptedData. In practical applications, the cryptographic interface module of the IoT terminal (B) sends its own security identity identifier SecurityID_B, the registration number EncryptedRegID_B obtained when establishing encrypted communication with the IoT terminal (A) in the early stage, and the data to be decrypted EncryptedData to the cryptographic service engine in the smart gateway / router (B), requesting the decryption of the encrypted data EncryptedData.

[0145] The second request is used by the second network device to decrypt the second data using its own second stored information; wherein, both the second request and the second stored information can be determined according to actual conditions, and are not limited here. As an example, the second request can be a data decryption request; the second stored information may include a saved decryption key list; the decryption key list includes symmetric decryption keys, symmetric decryption algorithms, etc. In practical applications, the cryptographic service engine in the smart gateway / router (B) finds the corresponding symmetric decryption key CryptKey and symmetric decryption algorithm CryptAlgSelected from the saved decryption key list based on SecurityID_B and EncryptedRegID_B, and then uses them to decrypt the encrypted data EncryptedData, obtaining the data Data and returning it to the IoT terminal (B).

[0146] Furthermore, various lifecycle management strategies can be adopted for the CryptKey, which is established during the construction of the encrypted communication channel, such as validity for a single session or validity for a given period. When the CryptKey and the encrypted communication channel become invalid, the above process can be repeated to rebuild the encrypted communication channel.

[0147] In one embodiment, the first stored information includes at least one of the following:

[0148] At least one identification identifier for the first terminal;

[0149] The first encryption algorithm corresponding to the first communication registration identifier;

[0150] The first key corresponding to the first encryption algorithm.

[0151] It should be noted that the identity identifier can be determined according to the actual situation, and is not limited here. As an example, the identity identifier can be a security identity identifier, which can be denoted as SecurityID; in practical applications, the identity identifier of each first terminal can be denoted as SecurityID_A.

[0152] The first encryption algorithm can be determined according to the actual situation, and is not limited here. As an example, the first encryption algorithm can be a symmetric encryption algorithm, which can be denoted as CryptAlgSelected.

[0153] The first key can be determined according to the actual situation, and is not limited here. As an example, the first key can be a symmetric encryption key, which can be denoted as CryptKey.

[0154] In practical applications, the first stored information can be presented in the form of a list. The specific form of the list can be determined according to the actual situation and is not limited here. As an example, the list can be a list of saved encryption keys.

[0155] In one embodiment, before sending the first request to the first network device, the method further includes:

[0156] A third request is sent to the second terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal;

[0157] The system receives a third response sent by the second terminal based on the third request; the third response carries the second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication encryption registration identifier.

[0158] A fourth request is sent to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm, and the second communication encryption registration identifier; the fourth request is used to register the second terminal for communication encryption.

[0159] If the second terminal successfully registers for communication encryption, it receives a fourth response sent by the first network device based on the fourth request; the fourth response carries a first cryptographic algorithm table and a first communication encryption registration identifier determined by the first network device.

[0160] Wherein, the first communication encryption registration identifier is used by the first terminal to call the first cryptographic algorithm and the first key in the first network device to encrypt and transmit the data to be communicated; the second communication encryption registration identifier is used by the second terminal to call the second cryptographic algorithm and the second key in the second network device to decrypt the data to be communicated.

[0161] In this embodiment, the third request is used to encrypt the communication data between the first terminal and the second terminal; the third request can be understood as an encrypted communication request.

[0162] The third request carries the first identity identifier of the first terminal; the first identity identifier can be determined according to the actual situation and is not limited here. As an example, the first identity identifier can be a security identity identifier, which can be denoted as SecurityID; in practical applications, the first identity identifier of the first terminal can be denoted as SecurityID_A.

[0163] As an example, the cryptographic interface module of IoT terminal (A) obtains the security identity identifier SecurityID_A from its own identity client, and then sends an encrypted communication request message to IoT terminal (B) as the SecurityID_A parameter.

[0164] The third response carries the second identity identifier of the second terminal, the second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and the second communication encryption registration identifier. The second identity identifier, the second cryptographic algorithm table, and the second communication encryption registration identifier can all be determined according to actual circumstances and are not limited here. As an example, the second identity identifier can be a security identity identifier, which can be denoted as SecurityID B; the second cryptographic algorithm table can be denoted as CryptAlgList_B; and the second communication encryption registration identifier can be denoted as EncryptedRegID_B.

[0165] In practical applications, the cryptographic interface module of IoT terminal (B) sends an encrypted communication request response message to the cryptographic interface module of IoT terminal (A). The response message carries {SecurityID_B, CryptAlgList_B, EncryptedRegID_B}.

[0166] The fourth request carries the second identity identifier, the second cryptographic algorithm, and the second communication encryption registration identifier; wherein, the second identity identifier, the second cryptographic algorithm table, and the second communication encryption registration identifier can all be determined according to the actual situation, and are not limited here. As an example, the second identity identifier can be a security identity identifier and / or an address identity identifier, which can be denoted as SecurityID B and / or Address_B; the second cryptographic algorithm table can be denoted as CryptAlgList_B; and the second communication encryption registration identifier can be denoted as EncryptedRegID_B.

[0167] In practical applications, the cryptographic interface module of the IoT terminal (A) sends an encrypted communication registration request message to the cryptographic service engine in the smart gateway / router (A). The request message carries {SecurityID_B, Address_B, CryptAlgList_B, EncryptedRegID_B}.

[0168] The fourth response carries a first cryptographic algorithm table and a first communication encryption registration identifier determined by the first network device. Both the first cryptographic algorithm table and the first communication encryption registration identifier can be determined according to actual circumstances and are not limited here. As an example, the first cryptographic algorithm table can be a table composed of selected symmetric cryptographic algorithms (CryptAlgSelected) used by the cryptographic service engine in the smart gateway / router; the first communication encryption registration identifier can be denoted as EncryptedRegID_A.

[0169] In this embodiment, after an encrypted communication channel is successfully established between the two IoT terminals, IoT terminal (A) and IoT terminal (B) can respectively use EncryptedRegID_A and EncryptedRegID_B to call the cryptographic service engine in their respective connected smart gateways / routers to encrypt and decrypt the communication data between the two parties using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey.

[0170] In one embodiment, before receiving the third response sent by the second terminal based on the third request, the method further includes:

[0171] Receive first authentication information sent by the second network device based on the first identity identifier;

[0172] If the first authentication information is successfully authenticated, the first public key of the first terminal is sent to the second network device; the first public key is used by the second network device to generate the second communication encryption registration identifier.

[0173] In this embodiment, receiving the first authentication information sent by the second network device based on the first identity identifier can be understood as the first terminal receiving the first authentication information sent by the second network device based on the first identity identifier; wherein, the first authentication information can be determined according to the actual situation, and is not limited here. As an example, the first authentication information can be identity authenticity authentication information.

[0174] The first public key is used by the second network device to generate the second communication encryption registration identifier; the first public key can be determined according to the actual situation and is not limited here. As an example, the first public key can be the identity public key, denoted as PublicKey_A. If the identity authenticity challenge initiated by the IoT terminal (A) is true, the cryptographic service engine in the smart gateway / router (B) calls the cryptographic hardware and software functions of the smart gateway / router (B) to generate a random number as the registration number: RegID_B = Random(); then, RegID_B is encrypted using PublicKey_A: EncryptedRegID_B = Encrypt(RegID_B, PublicKey_A), and a cryptographic algorithm list CryptAlgList_B is prepared according to the symmetric cryptographic algorithms and parameters supported by the smart gateway / router (B). Finally, the cryptographic service engine in the smart gateway / router (B) returns the encrypted communication registration application result to the cryptographic interface module of the IoT terminal (B). The result information carries {SecurityID_A, CryptAlgList_B, EncryptedRegID_B}. At the end of this stage, the password service engine in the smart gateway / router (B) will clear PublicKey_A, but will retain {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} in its own secure storage space.

[0175] In practical applications, the cryptographic service engine in the smart gateway / router (B) initiates and completes an identity verification challenge to the IoT terminal (A). During the challenge process, the cryptographic service engine in the smart gateway / router (B) can obtain the IoT terminal (A)'s public key, PublicKey_A.

[0176] In one embodiment, after receiving the fourth response sent by the first network device based on the fourth request, the method further includes:

[0177] The second terminal sends verification information for encrypted communication; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key; the verification information is used by the second terminal to send a verification request for encrypted communication to the second network device; the verification request is used by the second network device to verify the verification information.

[0178] If the second network device successfully verifies the verification information, it receives a verification response sent by the second terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0179] In this embodiment, the verification information can be determined according to the actual situation, and is not limited here. As an example, the verification information can be encrypted communication verification information.

[0180] The verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key; the first communication registration identifier, the first cryptographic algorithm table, and the first key can all be determined according to actual circumstances, and are not limited here. As an example, the first communication registration identifier can be denoted as EncryptedRegID_A; the first cryptographic algorithm table can be denoted as CryptAlgSelected; and the first key can be denoted as TestMsg.

[0181] If the second network device successfully verifies the verification information, it can be understood that the encrypted communication verification is successful. The verification response is used to determine that an encrypted communication channel has been established between the first terminal and the second terminal, which can be understood as the two IoT terminals successfully establishing an encrypted communication channel based on the verification response.

[0182] In practical applications, the cryptographic interface module of IoT terminal (B) sends an encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The request message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic interface module of IoT terminal (A) will save {SecurityID_B, EncryptedRegID_A}, and can subsequently use EncryptedRegID_A as a credential to call the cryptographic service engine in smart gateway / router (A) to encrypt communication data between A and B; the cryptographic interface module of IoT terminal (B) sends the encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The application message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic service engine in the smart gateway / router (B) queries its own secure storage space for {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} based on SecurityID_B and EncryptedRegID_B. It then calls the identity identification server to decrypt EncryptedRegID_A using PrivateKey_B to obtain RegID_A: RegID_A = Decrypt(EncryptedRegID_A, PrivateKey_B). A specific common key generation algorithm is used to generate a key for subsequent encrypted communication: CryptKey = KeyGen(RegID_A, RegID_B). Then, TestMsg is decrypted using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey, and the correctness of the decrypted SecurityID_A and SecurityID_B is determined. If correct, it indicates that the encrypted communication channel has been successfully established. The cryptographic service engine in the smart gateway / router (B) saves the CryptAlgSelected contained in TestMsg and then returns the successful result to the cryptographic interface module of the IoT terminal (B). At the end of this stage, the cryptographic service engine in the smart gateway / router (B) will retain only {SecurityID_B, SecurityID_A, EncryptedRegID_B, CryptAlgSelected, CryptKey} in its own secure storage space, while the previously saved RegID_B will be cleared. The cryptographic interface module of the IoT terminal (B) returns the successful result to the IoT terminal (A).After successfully establishing an encrypted communication channel between the two IoT terminals, IoT terminal (A) and IoT terminal (B) can respectively use EncryptedRegID_A and EncryptedRegID_B to call the cryptographic service engine in their respective connected smart gateways / routers to encrypt and decrypt the communication data between the two parties using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey.

[0183] Accordingly, embodiments of this application also provide a data transmission method applied to a second terminal. Figure 2 This is another flowchart illustrating the secure communication method according to an embodiment of this application; as shown Figure 2 As shown, the method includes:

[0184] Step 201: Receive the second data sent by the first terminal.

[0185] Step 202: Send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is the registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information;

[0186] Step 203: Receive the first data after the second network device has decrypted the second data using its own second storage information.

[0187] It should be noted that the second terminal can be determined according to the actual situation, and no limitation is made here. As an example, the second terminal can be an Internet of Things (IoT) terminal, which can act as the receiver of encrypted communication, and this IoT terminal can be denoted as B.

[0188] In step 201, the first terminal can be determined according to the actual situation, and no limitation is made here. As an example, the first terminal can be an Internet of Things (IoT) terminal, which can act as the initiator of encrypted communication, and this IoT terminal can be denoted as A.

[0189] The system receives second data sent by the first terminal; the second data can be determined according to the actual situation and is not limited here. As an example, the second data can be denoted as EncryptedData. In practical applications, the cryptographic service engine in the smart gateway / router (A) finds the corresponding symmetric encryption key CryptKey and symmetric encryption algorithm CryptAlgSelected from the saved encryption key list based on SecurityID_A and EncryptedRegID_A, and then uses them to encrypt the data Data to obtain the encrypted data EncryptedData and returns it to the IoT terminal (A).

[0190] In step 202, the second network device can be determined according to the actual situation, and is not limited here. As an example, the second network device can be a gateway or router, specifically the cryptographic service engine in that gateway or router. In practical applications, the second network device can be the cryptographic service engine in the gateway or router corresponding to B, and the second network device can be referred to as B. The second request can be determined according to the actual situation, and is not limited here. As an example, the second request can be a data decryption request.

[0191] The second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal. The second identity identifier, the second communication registration identifier, and the second data can all be determined according to actual circumstances and are not limited here. As an example, the second identity identifier can be a security identity identifier, which can be denoted as SecurityID_B; the second communication registration identifier can be understood as the registration number obtained when applying for encrypted communication, which can be denoted as EncryptedRegID_B; the second data can be understood as the data to be decrypted, which can be denoted as EncryptedData. In practical applications, the cryptographic interface module of the IoT terminal (B) sends its own security identity identifier SecurityID_B, the registration number EncryptedRegID_B obtained when establishing encrypted communication with the IoT terminal (A) in the early stage, and the data to be decrypted EncryptedData to the cryptographic service engine in the smart gateway / router (B), requesting the decryption of the encrypted data EncryptedData.

[0192] In step 203, the system receives the first data after the second network device has decrypted the second data using its own second storage information. The second request and the second storage information can be determined based on actual circumstances and are not limited here. As an example, the second request can be a data decryption request; the second storage information can include a saved decryption key list; the decryption key list includes symmetric decryption keys, symmetric decryption algorithms, etc. In practical applications, the cryptographic service engine in the smart gateway / router (B) finds the corresponding symmetric decryption key CryptKey and symmetric decryption algorithm CryptAlgSelected from the saved decryption key list based on SecurityID_B and EncryptedRegID_B, and then uses them to decrypt the encrypted data EncryptedData, obtaining the data Data and returning it to the IoT terminal (B).

[0193] Furthermore, various lifecycle management strategies can be adopted for the CryptKey, which is established during the construction of the encrypted communication channel, such as validity for a single session or validity for a given period. When the CryptKey and the encrypted communication channel become invalid, the above process can be repeated to rebuild the encrypted communication channel.

[0194] In one embodiment, the second stored information includes at least one of the following:

[0195] At least one second terminal's identity identifier;

[0196] The second encryption algorithm corresponding to the second communication registration identifier;

[0197] The second key corresponding to the second encryption algorithm.

[0198] It should be noted that the identity identifier can be determined according to the actual situation, and is not limited here. As an example, the identity identifier can be a security identity identifier, which can be denoted as SecurityID; in practical applications, the identity identifier of each second terminal can be denoted as SecurityID_B.

[0199] The second encryption algorithm can be determined based on the actual situation and is not limited here. As an example, the first encryption algorithm can be a symmetric encryption algorithm, which can be denoted as CryptBlgSelected.

[0200] The second key can be determined according to the actual situation, and is not limited here. As an example, the second key can be a symmetric encryption key, which can be denoted as CryptKey.

[0201] In practical applications, the second stored information can be presented in the form of a list. The specific form of the list can be determined according to the actual situation and is not limited here. As an example, the list can be a list of saved encryption keys.

[0202] In one embodiment, after sending the second request to the second network device, the method further includes:

[0203] Send a first registration request with encrypted communication to the second network device; the first registration request carries the second identity identifier and the first communication address of the first terminal; the second identity identifier and the first communication address are used by the first terminal to authenticate the identity of the first terminal;

[0204] If the first terminal successfully authenticates its identity, it receives a first registration application response sent by the second network device based on the first registration application request; the first registration application response carries a first communication registration identifier, a first cryptographic algorithm table, and a first identity identifier; the first communication registration identifier is generated based on the first public key of the first terminal.

[0205] In this embodiment, the first registration request can be determined according to the actual situation, and is not limited here. As an example, the first registration request can be an encrypted communication registration request.

[0206] The first registration application request carries the second identity identifier and the first communication address of the first terminal; wherein, the second identity identifier can be determined according to the actual situation, and is not limited here. As an example, the second identity identifier can be a security identity identifier, which can be denoted as SecurityID_B; the first communication address can be denoted as Address_A.

[0207] The first registration application response carries a first communication registration identifier, a first cryptographic algorithm table, and a first identity identifier; wherein, the first communication registration identifier, the first cryptographic algorithm table, and the first identity identifier can all be determined according to the actual situation, and are not limited here. As an example, the first communication registration identifier can be denoted as EncryptedRegID_B, the first cryptographic algorithm table can be denoted as CryptAlgList_B, and the first identity identifier can be denoted as SecurityID_A.

[0208] The first communication registration identifier is generated based on the first public key of the first terminal; wherein, the first public key can be determined according to the actual situation, and is not limited here. As an example, the first public key can be an identity public key, which can be denoted as PublicKey_A.

[0209] In practical applications, the cryptographic service engine in the smart gateway / router (B) initiates and completes an identity verification challenge to the IoT terminal (A). During the challenge process, the cryptographic service engine in the smart gateway / router (B) obtains the public key of the IoT terminal (A), PublicKey_A. If the identity verification challenge initiated by the IoT terminal (A) is successful, the cryptographic service engine in the smart gateway / router (B) calls the cryptographic hardware and software functions of the smart gateway / router (B) to generate a random number as the registration number: RegID_B = Random(). Then, it uses PublicKey_A to encrypt RegID_B: EncryptedRegID_B = Encrypt(RegID_B, PublicKey_A) and prepares a cryptographic algorithm list, CryptAlgList_B, based on the symmetric cryptographic algorithms and parameters supported by the smart gateway / router (B). Finally, the cryptographic service engine in the smart gateway / router (B) returns the encrypted communication registration application result to the cryptographic interface module of the IoT terminal (B). The result information carries {SecurityID_A, CryptAlgList_B, EncryptedRegID_B}. At the end of this stage, the password service engine in the smart gateway / router (B) will clear PublicKey_A, but will retain {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} in its own secure storage space.

[0210] In one embodiment, the method further includes:

[0211] Receive the second authentication information sent by the first network device;

[0212] If the second authentication information is successfully authenticated, the second public key of the second terminal is sent to the first network device; the second public key is used by the first network device to generate the first communication encryption registration identifier.

[0213] In this embodiment, the second authentication information can be determined according to the actual situation, and is not limited here. As an example, the second authentication information can be identity authenticity authentication information.

[0214] The second public key can be determined according to the actual situation, and is not limited here. As an example, the second public key can be the identity public key, which can be denoted as PublicKey_B;

[0215] The second public key is used by the first network device to generate the first communication encryption registration identifier. This can be understood as the first network device generating a random number as a registration number using its hardware and software cryptographic functions, which can be denoted as RegID_A. Then, PublicKey_B is used to encrypt RegID_A and subsequently decrypt it to generate the first communication encryption registration identifier. The first communication encryption registration identifier can be denoted as EncryptedRegID_A.

[0216] For ease of understanding, an example is provided here: the cryptographic service engine in a smart gateway / router (A) initiates and completes an identity verification challenge to an IoT terminal (B). During the challenge, the cryptographic service engine in the smart gateway / router (A) obtains the IoT terminal's public key, PublicKey_B. If the identity verification challenge initiated against the IoT terminal (B) is successful, the cryptographic service engine in the smart gateway / router (A) uses the cryptographic hardware and software functions of the smart gateway / router (A) to generate a random number as the registration number: RegID_A = Random(). Then, it uses PublicKey_B to encrypt RegID_A: EncryptedRegID_A = Encrypt(RegID_A, PublicKey_B), and selects one symmetric cryptographic algorithm from the algorithm list CryptAlgList_B as CryptAlgSelected based on the symmetric cryptographic algorithms supported by the smart gateway / router (A). The identity server decrypts EncryptedRegID_B using PrivateKey_A to obtain RegID_B: RegID_B = Decrypt(EncryptedRegID_B, PrivateKey_A), and generates a key for subsequent encrypted communication using a specific common key generation algorithm: CryptKey = KeyGen(RegID_A, RegID_B). Then, it encrypts "SecurityID_A + SecurityID_B" using CryptKey: TestMsg = Encrypt(CryptAlgSelected, CryptKey, "SecurityID_A|SecurityID_B"). Finally, the cryptographic service engine in the smart gateway / router (A) returns the encrypted communication registration application result to the cryptographic interface module of the IoT terminal (A). The result information carries {SecurityID_B, CryptAlgSelected, EncryptedRegID_A, TestMsg}.

[0217] In one embodiment, the method further includes:

[0218] The system receives verification information for encrypted communication sent by the first terminal; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key.

[0219] Based on the verification information, an encrypted communication verification request is sent to the second network device; the verification request is used by the second network device to verify the verification information.

[0220] If the second network device successfully verifies the verification information, it sends a verification response to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0221] In this embodiment, the verification information can be determined according to the actual situation, and is not limited here. As an example, the verification information can be encrypted communication verification information.

[0222] The verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key; the first communication registration identifier, the first cryptographic algorithm table, and the first key can all be determined according to actual circumstances, and are not limited here. As an example, the first communication registration identifier can be denoted as EncryptedRegID_A; the first cryptographic algorithm table can be denoted as CryptAlgSelected; and the first key can be denoted as TestMsg.

[0223] If the second network device successfully verifies the verification information, it can be understood that the encrypted communication verification is successful. The verification response is used to determine that an encrypted communication channel has been established between the first terminal and the second terminal, which can be understood as the two IoT terminals successfully establishing an encrypted communication channel based on the verification response.

[0224] In practical applications, the cryptographic interface module of IoT terminal (B) sends an encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The request message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic interface module of IoT terminal (A) will save {SecurityID_B, EncryptedRegID_A}, and can subsequently use EncryptedRegID_A as a credential to call the cryptographic service engine in smart gateway / router (A) to encrypt communication data between A and B; the cryptographic interface module of IoT terminal (B) sends the encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The application message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic service engine in the smart gateway / router (B) queries its own secure storage space for {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} based on SecurityID_B and EncryptedRegID_B. It then calls the identity identification server to decrypt EncryptedRegID_A using PrivateKey_B to obtain RegID_A: RegID_A = Decrypt(EncryptedRegID_A, PrivateKey_B). A specific common key generation algorithm is used to generate a key for subsequent encrypted communication: CryptKey = KeyGen(RegID_A, RegID_B). Then, TestMsg is decrypted using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey, and the correctness of the decrypted SecurityID_A and SecurityID_B is determined. If correct, it indicates that the encrypted communication channel has been successfully established. The cryptographic service engine in the smart gateway / router (B) saves the CryptAlgSelected contained in TestMsg and then returns the successful result to the cryptographic interface module of the IoT terminal (B). At the end of this stage, the cryptographic service engine in the smart gateway / router (B) will retain only {SecurityID_B, SecurityID_A, EncryptedRegID_B, CryptAlgSelected, CryptKey} in its own secure storage space, while the previously saved RegID_B will be cleared. The cryptographic interface module of the IoT terminal (B) returns the successful result to the IoT terminal (A).After successfully establishing an encrypted communication channel between the two IoT terminals, IoT terminal (A) and IoT terminal (B) can respectively use EncryptedRegID_A and EncryptedRegID_B to call the cryptographic service engine in their respective connected smart gateways / routers to encrypt and decrypt the communication data between the two parties using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey.

[0225] Accordingly, embodiments of this application also provide a data transmission method applied to a second network device. Figure 3 This is another flowchart illustrating the secure communication method according to an embodiment of this application; as shown Figure 3 As shown, the method includes:

[0226] Step 301: Receive a second request sent by the second terminal; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication.

[0227] Step 302: Based on the second request, decrypt the second data using its own second stored information.

[0228] It should be noted that the second network device can be determined based on the actual situation and is not limited here. As an example, the second network device can be a gateway or router, specifically the cryptographic service engine within that gateway or router. In practical applications, the second network device can be the cryptographic service engine within the gateway or router corresponding to B, and the second network device can be denoted as B.

[0229] In step 301, the second terminal can be determined according to the actual situation, and is not limited here. As an example, the second terminal can be an Internet of Things (IoT) terminal, which can act as the receiver of encrypted communication, and this IoT terminal can be denoted as B.

[0230] The second request can be determined according to the actual situation and is not limited here. As an example, the second request can be a data decryption request. The second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; wherein, the second identity identifier, the second communication registration identifier, and the second data can all be determined according to the actual situation and are not limited here. As an example, the second identity identifier can be a security identity identifier, which can be denoted as SecurityID_B; the second communication registration identifier can be understood as the registration number obtained when applying for encrypted communication, which can be denoted as EncryptedRegID_B; the second data can be understood as the data to be decrypted, which can be denoted as EncryptedData. In practical applications, the cryptographic interface module of the IoT terminal (B) sends its own security identity identifier SecurityID_B, the registration number EncryptedRegID_B obtained when establishing encrypted communication with the IoT terminal (A) in the early stage, and the data to be decrypted EncryptedData to the cryptographic service engine in the smart gateway / router (B) to apply for decryption of the encrypted data EncryptedData.

[0231] In step 302, the second data is decrypted using its own second stored information based on the second request. Both the second request and the second stored information can be determined according to actual circumstances and are not limited here. As an example, the second request can be a data decryption request; the second stored information can include a saved decryption key list; the decryption key list includes symmetric decryption keys, symmetric decryption algorithms, etc. In practical applications, the cryptographic service engine in the smart gateway / router (B) finds the corresponding symmetric decryption key CryptKey and symmetric decryption algorithm CryptAlgSelected from the saved decryption key list based on SecurityID_B and EncryptedRegID_B, and then uses them to decrypt the encrypted data EncryptedData, obtaining the data Data and returning it to the IoT terminal (B).

[0232] Furthermore, various lifecycle management strategies can be adopted for the CryptKey, which is established during the construction of the encrypted communication channel, such as validity for a single session or validity for a given period. When the CryptKey and the encrypted communication channel become invalid, the above process can be repeated to rebuild the encrypted communication channel.

[0233] In one embodiment, the second stored information includes at least one of the following:

[0234] At least one second terminal's identity identifier;

[0235] The second encryption algorithm corresponding to the second communication registration identifier;

[0236] The second key corresponding to the second encryption algorithm.

[0237] It should be noted that the identity identifier can be determined according to the actual situation, and is not limited here. As an example, the identity identifier can be a security identity identifier, which can be denoted as SecurityID; in practical applications, the identity identifier of each second terminal can be denoted as SecurityID_B.

[0238] The second encryption algorithm can be determined based on the actual situation and is not limited here. As an example, the second encryption algorithm can be a symmetric encryption algorithm, which can be denoted as CryptBlgSelected.

[0239] The second key can be determined according to the actual situation, and is not limited here. As an example, the second key can be a symmetric encryption key, which can be denoted as CryptKey.

[0240] In practical applications, the second stored information can be presented in the form of a list. The specific form of the list can be determined according to the actual situation and is not limited here. As an example, the list can be a list of saved encryption keys.

[0241] In one embodiment, before receiving the second request sent by the second terminal, the method further includes:

[0242] Receives a first registration request sent by a second terminal with encrypted communication; the first registration request carries the second identity identifier and the first communication address of the first terminal;

[0243] First authentication information is sent to the first terminal based on the second identity identifier and the first communication address; the first authentication information is used to authenticate the identity of the first terminal.

[0244] If the first terminal successfully authenticates its identity, the first public key sent by the first terminal is received, and a first communication encryption registration identifier is generated based on the first public key.

[0245] Send a first registration request response to the first terminal; the first registration request response carries a first communication registration identifier, a first cryptographic algorithm table, and a second identity identifier.

[0246] In this embodiment, the first registration request can be determined according to the actual situation, and is not limited here. As an example, the first registration request can be an encrypted communication registration request.

[0247] The first registration application request carries the second identity identifier and the first communication address of the first terminal; wherein, the second identity identifier can be determined according to the actual situation, and is not limited here. As an example, the second identity identifier can be a security identity identifier, which can be denoted as SecurityID_B; the first communication address can be denoted as Address_A.

[0248] The first registration application response carries a first communication registration identifier, a first cryptographic algorithm table, and a first identity identifier; wherein, the first communication registration identifier, the first cryptographic algorithm table, and the first identity identifier can all be determined according to the actual situation, and are not limited here. As an example, the first communication registration identifier can be denoted as EncryptedRegID_B, the first cryptographic algorithm table can be denoted as CryptAlgList_B, and the first identity identifier can be denoted as SecurityID_A.

[0249] A first communication encryption registration identifier is generated based on the first public key; wherein, the first public key can be determined according to the actual situation, and is not limited here. As an example, the first public key can be an identity public key, which can be denoted as PublicKey_A.

[0250] In practical applications, the cryptographic service engine in the smart gateway / router (B) initiates and completes an identity verification challenge to the IoT terminal (A). During the challenge process, the cryptographic service engine in the smart gateway / router (B) obtains the public key of the IoT terminal (A), PublicKey_A. If the identity verification challenge initiated by the IoT terminal (A) is successful, the cryptographic service engine in the smart gateway / router (B) calls the cryptographic hardware and software functions of the smart gateway / router (B) to generate a random number as the registration number: RegID_B = Random(). Then, it uses PublicKey_A to encrypt RegID_B: EncryptedRegID_B = Encrypt(RegID_B, PublicKey_A) and prepares a cryptographic algorithm list, CryptAlgList_B, based on the symmetric cryptographic algorithms and parameters supported by the smart gateway / router (B). Finally, the cryptographic service engine in the smart gateway / router (B) returns the encrypted communication registration application result to the cryptographic interface module of the IoT terminal (B). The result information carries {SecurityID_A, CryptAlgList_B, EncryptedRegID_B}. At the end of this stage, the password service engine in the smart gateway / router (B) will clear PublicKey_A, but will retain {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} in its own secure storage space.

[0251] In one embodiment, generating the first communication encryption registration identifier based on the first public key includes:

[0252] The first parameter is generated based on the cryptographic service component in the second network device;

[0253] The first parameter is encrypted using the first public key to obtain the first communication encryption registration identifier.

[0254] In this embodiment, the cryptographic service component can be determined according to the actual situation, and is not limited here. As an example, the cryptographic service component can be any cryptographic hardware or software component.

[0255] The first parameter generated based on the cryptographic service component in the second network device can be a random number generated by the cryptographic service component in the second network device, and this random number can be used as the first parameter. This random number can be denoted as Random(); the first parameter can be denoted as RegID_B; that is, RegID_B = Random();

[0256] The first public key can be determined according to the actual situation, and is not limited here. As an example, the first public key can be an identity public key, which can be denoted as PublicKey__A;

[0257] The first parameter is encrypted using the first public key to obtain the first communication encryption registration identifier. This first communication encryption registration identifier can be denoted as EncryptedRegID_B.

[0258] For ease of understanding, here is an example: the password service engine in the smart gateway / router (B) calls the password software and hardware functions of the smart gateway / router (B) to generate a random number as the registration number:

[0259] RegID_B = Random();

[0260] Then use PublicKey_A to encrypt RegID_B:

[0261] EncryptedRegID_B=Encrypt(RegID_B, PublicKey_A).

[0262] In one embodiment, the method further includes:

[0263] Receive a verification request for encrypted communication sent by the second terminal; verify the verification information based on the verification request;

[0264] If the verification information is successfully verified, a verification response is sent to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0265] In this embodiment, the verification information can be determined according to the actual situation, and is not limited here. As an example, the verification information can be encrypted communication verification information.

[0266] Successful verification of the verification information can be interpreted as successful encrypted communication verification. The verification response, used to determine the establishment of an encrypted communication channel between the first terminal and the second terminal, can be understood as a successful establishment of an encrypted communication channel between the two IoT terminals based on the verification response.

[0267] In practical applications, the cryptographic interface module of IoT terminal (B) sends an encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The request message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic interface module of IoT terminal (A) will save {SecurityID_B, EncryptedRegID_A}, and can subsequently use EncryptedRegID_A as a credential to call the cryptographic service engine in smart gateway / router (A) to encrypt communication data between A and B; the cryptographic interface module of IoT terminal (B) sends the encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The application message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic service engine in the smart gateway / router (B) queries its own secure storage space for {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} based on SecurityID_B and EncryptedRegID_B. It then calls the identity identification server to decrypt EncryptedRegID_A using PrivateKey_B to obtain RegID_A: RegID_A = Decrypt(EncryptedRegID_A, PrivateKey_B). A specific common key generation algorithm is used to generate a key for subsequent encrypted communication: CryptKey = KeyGen(RegID_A, RegID_B). Then, TestMsg is decrypted using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey, and the correctness of the decrypted SecurityID_A and SecurityID_B is determined. If correct, it indicates that the encrypted communication channel has been successfully established. The cryptographic service engine in the smart gateway / router (B) saves the CryptAlgSelected contained in TestMsg and then returns the successful result to the cryptographic interface module of the IoT terminal (B). At the end of this stage, the cryptographic service engine in the smart gateway / router (B) will retain only {SecurityID_B, SecurityID_A, EncryptedRegID_B, CryptAlgSelected, CryptKey} in its own secure storage space, while the previously saved RegID_B will be cleared. The cryptographic interface module of the IoT terminal (B) returns the successful result to the IoT terminal (A).After successfully establishing an encrypted communication channel between the two IoT terminals, IoT terminal (A) and IoT terminal (B) can respectively use EncryptedRegID_A and EncryptedRegID_B to call the cryptographic service engine in their respective connected smart gateways / routers to encrypt and decrypt the communication data between the two parties using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey.

[0268] Accordingly, embodiments of this application also provide a data transmission method applied to a first network device. Figure 4 This is another flowchart illustrating the secure communication method according to an embodiment of this application; as shown Figure 4 As shown, the method includes:

[0269] Step 401: Receive a first request sent by the first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; encrypt the first data using its own first storage information based on the first request.

[0270] It should be noted that the first network device can be determined based on the actual situation and is not limited here. As an example, the second network device can be a gateway or router, specifically the cryptographic service engine within that gateway or router. In practical applications, the first network device can be the cryptographic service engine within the gateway or router corresponding to A, and the second network device can be denoted as A.

[0271] In step 401, the first terminal can be determined according to the actual situation, and no limitation is made here. As an example, the first terminal can be an Internet of Things (IoT) terminal, which can act as the sender of encrypted communication, and this IoT terminal can be denoted as A.

[0272] The first request carries the first identity identifier of the first terminal, the first communication registration identifier, and the first data to be encrypted and transmitted. The first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted can all be determined according to actual circumstances and are not limited here. As an example, the first identity identifier can be a security identity identifier, which can be denoted as SecurityID_A; the first communication registration identifier can be understood as the registration number obtained when applying for encrypted communication, which can be denoted as EncryptedRegID_A; and the first data to be encrypted and transmitted can be understood as the data to be encrypted, which can be denoted as Data. In practical applications, the cryptographic interface module of the IoT terminal (A) sends its own security identity identifier SecurityID_A, the registration number EncryptedRegID_A obtained when establishing an encrypted communication application with the IoT terminal (B), and the data to be encrypted Data to the cryptographic service engine in the smart gateway / router (A), requesting encryption of the data Data.

[0273] Based on the first request, the first data is encrypted using its own first stored information; wherein, both the first request and the first stored information can be determined according to the actual situation, and are not limited here. As an example, the first request can be a data encryption request; the first stored information may include a saved encryption key list; the encryption key list includes symmetric encryption keys, symmetric encryption algorithms, etc.

[0274] In one embodiment, the first stored information includes at least one of the following:

[0275] At least one identification identifier for the first terminal;

[0276] The first encryption algorithm corresponding to the first communication registration identifier;

[0277] The first key corresponding to the first encryption algorithm.

[0278] It should be noted that the identity identifier can be determined according to the actual situation and is not limited here. As an example, the identity identifier can be a security identity identifier, which can be denoted as SecurityID; in practical applications, the identity identifier of each first terminal can be denoted as SecurityID_A.

[0279] The first encryption algorithm can be determined according to the actual situation, and is not limited here. As an example, the first encryption algorithm can be a symmetric encryption algorithm, which can be denoted as CryptAlgSelected.

[0280] The first key can be determined according to the actual situation, and is not limited here. As an example, the first key can be a symmetric encryption key, which can be denoted as CryptKey.

[0281] In practical applications, the first stored information can be presented in the form of a list. The specific form of the list can be determined according to the actual situation and is not limited here. As an example, the list can be a list of saved encryption keys.

[0282] In one embodiment, the method further includes:

[0283] The system receives a second registration request sent by the first terminal, which is encrypted with communication. The second registration request carries the second identity identifier and the second communication address of the second terminal.

[0284] The second authentication information is sent to the second terminal based on the second identity identifier and the second communication address; the second authentication information is used to authenticate the identity of the second terminal.

[0285] If the second terminal successfully authenticates its identity, it receives the second public key sent by the first terminal and generates a second communication encryption registration identifier based on the second public key.

[0286] Send a second registration request response to the first terminal; the second registration request response carries a second communication registration identifier, a second cryptographic algorithm table, and a second identity identifier.

[0287] In this embodiment, the second registration request can be determined according to the actual situation, and is not limited here. As an example, the second registration request can be an encrypted communication registration request.

[0288] The second registration application request carries the second identity identifier and the second communication address of the second terminal; wherein, the second identity identifier can be determined according to the actual situation, and is not limited here. As an example, the second identity identifier can be a security identity identifier, which can be denoted as SecurityID_B; the second communication address can be denoted as Address_B.

[0289] In this embodiment, the second authentication information can be determined according to the actual situation, and is not limited here. As an example, the second authentication information can be identity authenticity authentication information.

[0290] The second public key can be determined according to the actual situation, and is not limited here. As an example, the second public key can be the identity public key, which can be denoted as PublicKey_B;

[0291] Generating a second communication encryption registration identifier based on the second public key can be understood as follows: the cryptographic hardware and software cryptographic functions of the second network device generate a random number as a registration number, which can be denoted as RegID_A; then, PublicKey_B is used to encrypt RegID_A and subsequently decrypt it to generate the first communication encryption registration identifier. The first communication encryption registration identifier can be denoted as EncryptedRegID_A.

[0292] For ease of understanding, an example is provided here: the cryptographic service engine in a smart gateway / router (A) initiates and completes an identity verification challenge to an IoT terminal (B). During the challenge, the cryptographic service engine in the smart gateway / router (A) obtains the IoT terminal's public key, PublicKey_B. If the identity verification challenge initiated against the IoT terminal (B) is successful, the cryptographic service engine in the smart gateway / router (A) uses the cryptographic hardware and software functions of the smart gateway / router (A) to generate a random number as the registration number: RegID_A = Random(). Then, it uses PublicKey_B to encrypt RegID_A: EncryptedRegID_A = Encrypt(RegID_A, PublicKey_B), and selects one symmetric cryptographic algorithm from the algorithm list CryptAlgList_B as CryptAlgSelected based on the symmetric cryptographic algorithms supported by the smart gateway / router (A). The identity server decrypts EncryptedRegID_B using PrivateKey_A to obtain RegID_B: RegID_B = Decrypt(EncryptedRegID_B, PrivateKey_A), and generates a key for subsequent encrypted communication using a specific common key generation algorithm: CryptKey = KeyGen(RegID_A, RegID_B). Then, it encrypts "SecurityID_A + SecurityID_B" using CryptKey: TestMsg = Encrypt(CryptAlgSelected, CryptKey, "SecurityID_A|SecurityID_B"). Finally, the cryptographic service engine in the smart gateway / router (A) returns the encrypted communication registration application result to the cryptographic interface module of the IoT terminal (A). The result information carries {SecurityID_B, CryptAlgSelected, EncryptedRegID_A, TestMsg}.

[0293] In one embodiment, generating the second communication encryption registration identifier based on the second public key includes:

[0294] The second parameter is generated based on the cryptographic service component in the first network device;

[0295] The second parameter is encrypted using the second public key to obtain the second communication encryption registration identifier.

[0296] In this embodiment, the cryptographic service component can be determined according to the actual situation, and is not limited here. As an example, the cryptographic service component can be any cryptographic hardware or software component.

[0297] The second parameter can be generated based on the cryptographic service component in the first network device. This second parameter can be generated as a random number by the cryptographic service component in the first network device, and the random number can be used as the first parameter. The random number can be denoted as Random(); the first parameter can be denoted as RegID_A; that is, RegID_A = Random().

[0298] The first public key can be determined according to the actual situation, and is not limited here. As an example, the second public key can be the identity public key, which can be denoted as PublicKey_B;

[0299] The first parameter is encrypted using the first public key to obtain the first communication encryption registration identifier. This first communication encryption registration identifier can be denoted as EncryptedRegID_A.

[0300] For ease of understanding, here is an example: the password service engine in the smart gateway / router (A) calls the password software and hardware functions of the smart gateway / router (A) to generate a random number as the registration number:

[0301] RegID_A = Random();

[0302] Then, PublicKey_B is used to encrypt RegID_A:

[0303] EncryptedRegID_A=Encrypt(RegID_A, PublicKey_B).

[0304] In one embodiment, the method further includes:

[0305] Receive a verification request for encrypted communication sent by the second terminal; verify the verification information based on the verification request;

[0306] If the verification information is successfully verified, a verification response is sent to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0307] In this embodiment, the verification information can be determined according to the actual situation, and is not limited here. As an example, the verification information can be encrypted communication verification information.

[0308] Successful verification of the verification information can be interpreted as successful encrypted communication verification. The verification response, used to determine the establishment of an encrypted communication channel between the first terminal and the second terminal, can be understood as a successful establishment of an encrypted communication channel between the two IoT terminals based on the verification response.

[0309] In practical applications, the cryptographic interface module of IoT terminal (B) sends an encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The request message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic interface module of IoT terminal (A) will save {SecurityID_B, EncryptedRegID_A}, and can subsequently use EncryptedRegID_A as a credential to call the cryptographic service engine in smart gateway / router (A) to encrypt communication data between A and B; the cryptographic interface module of IoT terminal (B) sends the encrypted communication verification request to the cryptographic service engine in smart gateway / router (B). The application message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg}. The cryptographic service engine in the smart gateway / router (B) queries its own secure storage space for {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} based on SecurityID_B and EncryptedRegID_B. It then calls the identity identification server to decrypt EncryptedRegID_A using PrivateKey_B to obtain RegID_A: RegID_A = Decrypt(EncryptedRegID_A, PrivateKey_B). A specific common key generation algorithm is used to generate a key for subsequent encrypted communication: CryptKey = KeyGen(RegID_A, RegID_B). Then, TestMsg is decrypted using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey, and the correctness of the decrypted SecurityID_A and SecurityID_B is determined. If correct, it indicates that the encrypted communication channel has been successfully established. The cryptographic service engine in the smart gateway / router (B) saves the CryptAlgSelected contained in TestMsg and then returns the successful result to the cryptographic interface module of the IoT terminal (B). At the end of this stage, the cryptographic service engine in the smart gateway / router (B) will retain only {SecurityID_B, SecurityID_A, EncryptedRegID_B, CryptAlgSelected, CryptKey} in its own secure storage space, while the previously saved RegID_B will be cleared. The cryptographic interface module of the IoT terminal (B) returns the successful result to the IoT terminal (A).After successfully establishing an encrypted communication channel between the two IoT terminals, IoT terminal (A) and IoT terminal (B) can respectively use EncryptedRegID_A and EncryptedRegID_B to call the cryptographic service engine in their respective connected smart gateways / routers to encrypt and decrypt the communication data between the two parties using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey.

[0310] This application, targeting Internet of Things (IoT) networks, establishes an encrypted communication channel between two terminals and, with the support of two network devices, combines a two-way authentication process for terminal identity to complete the secure negotiation and verification of encryption keys, thereby enabling encrypted data transmission between the two terminals. This allows IoT terminals with weak security capabilities to possess encrypted communication capabilities.

[0311] For ease of understanding, the example secure communication method here specifically refers to a device encrypted communication method. Taking the first terminal as IoT terminal (A) as the initiator of encrypted communication and the second terminal as IoT terminal (B) as the receiver, with the first network device being a smart gateway / router (A) and the second network device being a smart gateway / router (B), this application, by embedding a lightweight cryptographic interface module within the IoT terminal operating system and a lightweight cryptographic service engine within the smart gateway / router, can combine... Figure 5 To understand, Figure 5 This is a schematic diagram of a related technical architecture.

[0312] Figure 6 This is a schematic diagram of an Internet of Things (IoT) technology architecture in an embodiment of this application. Figure 6 In this context, the main functions of the cryptographic interface module built into an IoT terminal include:

[0313] 1. Provide password service call interfaces for other programs in IoT terminals;

[0314] 2. By comprehensively calling the relevant functions of the identity identification client built into the IoT terminal and the password service engine built into the smart gateway / router, the authentication and encrypted communication negotiation between the IoT terminal and the remote IoT terminal are completed.

[0315] 3. Data encryption and decryption are performed by calling the built-in password service engine in the smart gateway / router.

[0316] The main functions of the cryptographic service engine built into the security zone / trusted zone of a smart gateway / router include:

[0317] 1. By calling the relevant functions of the identity identification server built into the smart gateway / router and other cryptographic suites integrated into the smart gateway / router, the cryptographic interface module built into the IoT terminal is supported to complete the identity authentication and encrypted communication negotiation with the remote IoT terminal.

[0318] 2. Encrypt and decrypt data from IoT terminals by calling the cryptographic suite integrated in the smart gateway / router.

[0319] Taking an IoT terminal (A) as the initiator of encrypted communication and an IoT terminal (B) as the receiver of encrypted communication as an example, the process of establishing an encrypted communication channel between the two parties is as follows: Figure 7 As shown, Figure 7 A schematic diagram illustrating the process of establishing an encrypted communication channel between the first terminal and the second terminal;

[0320] The specific process is described below:

[0321] S1. The cryptographic interface module of the IoT terminal (A) obtains the security identity identifier SecurityID_A from its own identity identifier client, and then sends an encrypted communication request message to the IoT terminal (B) as the SecurityID_A parameter.

[0322] S2. After receiving the encrypted communication request from IoT terminal (A), IoT terminal (B) sends an encrypted communication registration application to the cryptographic service engine in smart gateway / router (B) through its cryptographic interface module. SecurityID_A and Address_A are used as parameters, where Address_A is the network communication address of IoT terminal (A).

[0323] S3. The cryptographic service engine in the smart gateway / router (B) initiates and completes an identity verification challenge to the IoT terminal (A). During the challenge, the cryptographic service engine in the smart gateway / router (B) can obtain the public key of the IoT terminal (A), PublicKey_A.

[0324] S4. If the identity verification challenge initiated by the IoT terminal (A) is successful, the cryptographic service engine in the smart gateway / router (B) calls the cryptographic hardware and software functions of the smart gateway / router (B) to generate a random number as the registration number:

[0325] RegID_B = Random();

[0326] Then use PublicKey_A to encrypt RegID_B:

[0327] EncryptedRegID_B=Encrypt(RegID_B, PublicKey_A)

[0328] Prepare a list of cryptographic algorithms, CryptAlgList_B, based on the symmetric cryptographic algorithms and parameters supported by the smart gateway / router (B).

[0329] Finally, the cryptographic service engine in the smart gateway / router (B) returns the encrypted communication registration application result to the cryptographic interface module of the IoT terminal (B). The result information carries {SecurityID_A, CryptAlgList_B, EncryptedRegID_B}.

[0330] At the end of this stage, the password service engine in the smart gateway / router (B) will clear PublicKey_A, but will retain {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} in its own secure storage space.

[0331] S5. The cryptographic interface module of IoT terminal (B) sends an encrypted communication request response message to the cryptographic interface module of IoT terminal (A). The response message carries {SecurityID_B, CryptAlgList_B, EncryptedRegID_B}.

[0332] The password interface module of the IoT terminal (B) will store {SecurityID_A, EncryptedRegID_B}, and can subsequently use EncryptedRegID_B as a credential to call the password service engine in the smart gateway / router (B) to encrypt the communication data between A and B;

[0333] S6. The cryptographic interface module of the IoT terminal (A) sends an encrypted communication registration request message to the cryptographic service engine in the smart gateway / router (A). The request message carries {SecurityID_B, Address_B, CryptAlgList_B, EncryptedRegID_B};

[0334] S7. The cryptographic service engine in the smart gateway / router (A) initiates and completes an identity verification challenge to the IoT terminal (B) (see the secure identity verification process in YF2106087 / CN115884169A). During the challenge, the cryptographic service engine in the smart gateway / router (A) can obtain the IoT terminal's (B) public key PublicKey_B;

[0335] S8. If the identity verification challenge initiated by the IoT terminal (B) is successful, the cryptographic service engine in the smart gateway / router (A) calls the cryptographic software and hardware functions of the smart gateway / router (A) to generate a random number as the registration number:

[0336] RegID_A = Random();

[0337] Then, PublicKey_B is used to encrypt RegID_A:

[0338] EncryptedRegID_A=Encrypt(RegID_A, PublicKey_B)

[0339] And select one symmetric cryptographic algorithm from the algorithm list CryptAlgList_B as CryptAlgSelected based on the symmetric cryptographic algorithms supported by the smart gateway / router (A).

[0340] RegID_B is obtained by decrypting EncryptedRegID_B using PrivateKey_A on the identity server:

[0341] RegID_B=Decrypt(EncryptedRegID_B, PrivateKey_A)

[0342] And a specific common key generation algorithm is used to generate keys for subsequent encrypted communication:

[0343] CryptKey=KeyGen(RegID_A, RegID_B)

[0344] Then, use CryptKey to encrypt "SecurityID_A+SecurityID_B":

[0345] TestMsg=Encrypt(CryptAlgSelected, CryptKey, "SecurityID_A|SecurityID_B")

[0346] Finally, the cryptographic service engine in the smart gateway / router (A) returns the encrypted communication registration application result to the cryptographic interface module of the IoT terminal (A). The result information carries {SecurityID_B, CryptAlgSelected, EncryptedRegID_A, TestMsg}.

[0347] At the end of this stage, the password service engine in the smart gateway / router (A) will clear PublicKey_B, but will retain {SecurityID_A, SecurityID_B, EncryptedRegID_A, CryptAlgSelected, CryptKey} in its own secure storage space.

[0348] S9. The cryptographic interface module of IoT terminal (A) sends an encrypted communication verification message to the cryptographic interface module of IoT terminal (B). The verification message carries {EncryptedRegID_A, CryptAlgSelected, TestMsg}.

[0349] The password interface module of the IoT terminal (A) will store {SecurityID_B, EncryptedRegID_A}, and can subsequently use EncryptedRegID_A as a credential to call the password service engine in the smart gateway / router (A) to encrypt the communication data between A and B;

[0350] S10. The cryptographic interface module of the IoT terminal (B) sends an encrypted communication verification request to the cryptographic service engine in the smart gateway / router (B). The request message carries {EncryptedRegID_B, EncryptedRegID_A, CryptAlgSelected, TestMsg};

[0351] S11. The cryptographic service engine in the smart gateway / router (B) queries its own secure storage space for {SecurityID_B, SecurityID_A, EncryptedRegID_B, RegID_B} based on SecurityID_B and EncryptedRegID_B.

[0352] RegID_A is obtained by decrypting EncryptedRegID_A using PrivateKey_B by calling the identity server.

[0353] RegID_A=Decrypt(EncryptedRegID_A, PrivateKey_B)

[0354] And a specific common key generation algorithm is used to generate keys for subsequent encrypted communication:

[0355] CryptKey=KeyGen(RegID_A, RegID_B)

[0356] Then, the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey are used to decrypt TestMsg, and the correctness of the decrypted SecurityID_A and SecurityID_B is determined. If correct, it indicates that the encrypted communication channel has been successfully established. The cryptographic service engine in the smart gateway / router (B) saves the CryptAlgSelected contained in TestMsg and then returns the successful result to the cryptographic interface module of the IoT terminal (B).

[0357] At the end of this stage, the password service engine in the smart gateway / router (B) will retain only {SecurityID_B, SecurityID_A, EncryptedRegID_B, CryptAlgSelected, CryptKey} in its own secure storage space, while the previously saved RegID_B will be cleared.

[0358] S12. The cryptographic interface module of the IoT terminal (B) returns the successful result to the IoT terminal (A).

[0359] After successfully establishing an encrypted communication channel between the two IoT terminals, IoT terminal (A) and IoT terminal (B) can respectively use EncryptedRegID_A and EncryptedRegID_B to call the cryptographic service engine in their respective connected smart gateways / routers to encrypt and decrypt the communication data between them using the selected symmetric cryptographic algorithm CryptAlgSelected and the key CryptKey. Taking IoT terminal (A) as the sender of encrypted data and IoT terminal (B) as the receiver of encrypted data as an example, the encrypted communication process between the two parties is as follows: Figure 8 As shown, Figure 8 This is a schematic diagram of the encrypted communication process between IoT terminal (A) and IoT terminal (B).

[0360] The specific process is described below:

[0361] S1. The cryptographic interface module of IoT terminal (A) sends its own security identity identifier SecurityID_A, the registration number EncryptedRegID_A obtained when establishing encrypted communication with IoT terminal (B) in the early stage, and the data to be encrypted Data to the cryptographic service engine in the smart gateway / router (A) to request encryption of the data Data.

[0362] S2. The cryptographic service engine in the smart gateway / router (A) finds the corresponding symmetric encryption key CryptKey and symmetric encryption algorithm CryptAlgSelected from the saved encryption key list based on SecurityID_A and EncryptedRegID_A, and then uses them to encrypt the data Data to obtain encrypted data EncryptedData and returns it to the IoT terminal (A).

[0363] S3. IoT terminal (A) sends its own security identity identifier SecurityID_A and encrypted data EncryptedData to IoT terminal (B);

[0364] S4. The cryptographic interface module of the IoT terminal (B) sends its own security identity identifier SecurityID_B, the registration number EncryptedRegID_B obtained when establishing encrypted communication with the IoT terminal (A) in the early stage, and the data to be decrypted EncryptedData to the cryptographic service engine in the smart gateway / router (B) to request the decryption of the encrypted data EncryptedData.

[0365] S5. The cryptographic service engine in the smart gateway / router (B) finds the corresponding symmetric encryption key CryptKey and symmetric encryption algorithm CryptAlgSelected from the saved encryption key list based on SecurityID_B and EncryptedRegID_B, and then uses them to encrypt the encrypted data EncryptedData to obtain the data Data and return it to the IoT terminal (B).

[0366] Various lifecycle management strategies can be adopted for the CryptKey, which is established during the construction of the encrypted communication channel, such as validity for a single session or validity for a given period. When the CryptKey and the encrypted communication channel become invalid, the above process can be repeated to rebuild the encrypted communication channel.

[0367] This application proposes an encrypted communication method for IoT terminal devices. This method involves building a lightweight cryptographic interface module into the IoT terminal operating system and a lightweight cryptographic service engine into the smart gateway / router, working in conjunction with a trusted identity client proposed in related technologies. This provides encrypted communication capabilities for a wide range of weakly encrypted IoT terminal devices, ensuring secure data transmission. This method requires no hardware modification or upgrade of the IoT terminal device, no integration of any cryptographic components, and no construction of a secure storage area to store encrypted information. It only requires adding a lightweight cryptographic interface module to the IoT terminal device, making it easily applicable to newly manufactured IoT devices and also applicable to existing IoT terminal devices through software upgrades. The main points to be protected in this application include:

[0368] 1. Overall technical methods and system framework for implementing encrypted communication in IoT terminals. This mainly includes the cryptographic interface module and its functions built into the IoT terminal operating system, the cryptographic service engine and its functions built into the smart gateway / router, and the mechanisms and methods for working together with the trusted identity client and trusted identity server proposed in related technologies;

[0369] 2. The process of establishing an encrypted communication channel between two IoT terminals mainly includes the process of completing the secure negotiation and verification of encryption keys in conjunction with the two-way authentication process of IoT terminal identity, with the support of the cryptographic interface module and cryptographic service engine.

[0370] The method described in this application has the following advantages compared to related technologies:

[0371] 1. Only one cryptographic interface module needs to be added to the IoT terminal device. No special cryptographic hardware support (such as read-only memory chip, cryptographic chip / trusted chip, etc.) or complex cryptographic software suite support is required, making deployment and application convenient;

[0372] 2. The cryptographic interface module in IoT terminal devices has a simple function. It primarily works with the cryptographic service engine built into smart gateways / routers to build encrypted communication channels and provides encryption / decryption call interfaces for other applications in the IoT terminal. The cryptographic interface module does not require any cryptographic algorithm support or secure storage support. Therefore, the cryptographic interface module is small in size and has low computational load, making it easy to apply in low-configuration, low-cost IoT terminal devices.

[0373] 3. The encrypted communication channel constructed by the method of this application for IoT terminal devices is superimposed on two-way identity authentication, which improves the security of key negotiation while simplifying the key negotiation process, and can reduce the traffic consumption and energy consumption of IoT terminal devices.

[0374] 4. The method described in this application does not require configuring any certificates or issuing any keys in IoT terminals and smart gateways / routers, which reduces the complexity of system maintenance and configuration, and makes encrypted communication between IoT terminals more flexible and convenient.

[0375] The terminal encrypted communication method proposed in this application can be widely used in IoT terminal devices, IoT gateway devices, and other IoT devices by integrating it into IoT operating systems. It can also be applied to various complex devices without physical trusted module support, such as cloud computing servers, storage devices, network devices, and security devices. This method can be applied to newly manufactured devices or to existing devices through software upgrades. The technical method of this application is convenient to use, low in cost, and can significantly improve the security, flexibility, and convenience of encrypted data transmission between devices, thus possessing high commercial value.

[0376] To implement the method of this application embodiment, this application embodiment also provides a secure communication device, which is installed on a first terminal. Figure 9 This is a schematic diagram of a secure communication device according to an embodiment of this application; as shown Figure 9 As shown, it includes:

[0377] The first sending unit 901 is configured to send a first request to a first network device; the first request carries a first identity identifier of the first terminal, a first communication registration identifier, and first data to be encrypted and transmitted; the first request is used by the first network device to encrypt the first data using its own first storage information.

[0378] The first receiving unit 902 is configured to receive first response information from the first network device based on the first request; the first response information carries second data after encrypting the first data.

[0379] The first sending unit 901 is further configured to send the second data to the second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information.

[0380] In one embodiment, the first stored information includes at least one of the following:

[0381] At least one identification identifier for the first terminal;

[0382] The first encryption algorithm corresponding to the first communication registration identifier;

[0383] The first key corresponding to the first encryption algorithm.

[0384] In one embodiment, before sending the first request to the first network device, the first sending unit 901 is further configured to send a third request to the second terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal;

[0385] The first receiving unit 902 is further configured to receive a third response sent by the second terminal based on the third request; the third response carries a second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication encryption registration identifier;

[0386] The first sending unit 901 is further configured to send a fourth request to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm, and the second communication encryption registration identifier; the fourth request is used to perform communication encryption registration for the second terminal;

[0387] The first receiving unit 902 is further configured to receive a fourth response sent by the first network device based on the fourth request when the second terminal successfully completes the communication encryption registration; the fourth response carries a first cryptographic algorithm table and a first communication encryption registration identifier determined by the first network device; wherein, the first communication encryption registration identifier is used by the first terminal to call the first cryptographic algorithm and the first key in the first network device to encrypt and transmit the data to be communicated; the second communication encryption registration identifier is used by the second terminal to call the second cryptographic algorithm and the second key in the second network device to decrypt the data to be communicated.

[0388] In one embodiment, before receiving the third response sent by the second terminal based on the third request, the first receiving unit 902 is further configured to receive first authentication information sent by the second network device based on the first identity identifier;

[0389] The first sending unit 901 is further configured to send the first public key of the first terminal to the second network device when the first authentication information is successfully authenticated; the first public key is used by the second network device to generate the second communication encryption registration identifier.

[0390] In one embodiment, after receiving the fourth response sent by the first network device based on the fourth request, the first sending unit 901 is further configured to send verification information for encrypted communication to the second terminal; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key; the verification information is used by the second terminal to send a verification request for encrypted communication to the second network device; the verification request is used by the second network device to verify the verification information;

[0391] The first receiving unit 902 is further configured to receive a verification response sent by the second terminal based on the verification information when the second network device successfully verifies the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0392] To implement the terminal-side method of this application embodiment, this application embodiment also provides a secure communication device, which is installed on a second terminal. Figure 10 This is a schematic diagram of another device for secure communication according to an embodiment of this application; as shown Figure 10 As shown, the device 1000 includes:

[0393] The second receiving unit 1001 is used to receive the second data sent by the first terminal;

[0394] The second sending unit 1002 is used to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information.

[0395] The second receiving unit 1001 is further configured to receive the first data after the second network device has decrypted the second data using its own second stored information.

[0396] In one embodiment, the second stored information includes at least one of the following:

[0397] At least one second terminal's identity identifier;

[0398] The second encryption algorithm corresponding to the second communication registration identifier;

[0399] The second key corresponding to the second encryption algorithm.

[0400] In one embodiment, after sending the second request to the second network device, the second sending unit 1002 is further configured to send a communication-encrypted first registration application request to the second network device; the first registration application request carries the second identity identifier and the first communication address of the first terminal; the second identity identifier and the first communication address are used by the first terminal to authenticate the identity of the first terminal;

[0401] The second receiving unit 1001 is further configured to receive a first registration application response sent by the second network device based on the first registration application request when the identity authentication of the first terminal is successful; the first registration application response carries a first communication registration identifier, a first cryptographic algorithm table, and a first identity identifier; the first communication registration identifier is generated based on the first public key of the first terminal.

[0402] In one embodiment, the second receiving unit 1001 is further configured to receive second authentication information sent by the first network device;

[0403] The second sending unit 1002 is further configured to send the second public key of the second terminal to the first network device when the second authentication information is successfully authenticated; the second public key is used by the first network device to generate the first communication encryption registration identifier.

[0404] In one embodiment, the second receiving unit 1001 is further configured to receive verification information of encrypted communication sent by the first terminal; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key;

[0405] The second sending unit 1002 is further configured to send an encrypted communication verification request to the second network device based on the verification information; the verification request is used by the second network device to verify the verification information;

[0406] If the second network device successfully verifies the verification information, it sends a verification response to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0407] To implement the terminal-side method of this application embodiment, this application embodiment also provides a secure communication device, which is disposed on a second network device. Figure 11 This is a schematic diagram of another device for secure communication according to an embodiment of this application; as shown Figure 11 As shown, the device 1100 includes:

[0408] The third receiving unit 1101 is used to receive a second request sent by the second terminal; the second request carries the second identity identifier, the second communication registration identifier, and second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication.

[0409] The decryption unit 1102 is used to decrypt the second data using its own second stored information based on the second request.

[0410] In one embodiment, the second stored information includes at least one of the following:

[0411] At least one second terminal's identity identifier;

[0412] The second encryption algorithm corresponding to the second communication registration identifier;

[0413] The second key corresponding to the second encryption algorithm.

[0414] In one embodiment, the device 1100 further includes a third sending unit; before receiving the second request sent by the second terminal; the third receiving unit 1101 is further configured to receive a first registration application request with communication encryption sent by the second terminal; the first registration application request carries the second identity identifier and the first communication address of the first terminal;

[0415] The third sending unit is configured to send first authentication information to the first terminal based on the second identity identifier and the first communication address; the first authentication information is used to authenticate the identity of the first terminal.

[0416] The third receiving unit 1101 is further configured to receive the first public key sent by the first terminal when the first terminal's identity authentication is successful, and generate a first communication encryption registration identifier based on the first public key;

[0417] The third sending unit is further configured to send a first registration application response to the first terminal; the first registration application response carries a first communication registration identifier, a first cryptographic algorithm table, and a second identity identifier.

[0418] In one embodiment, the third receiving unit 1101 is further configured to generate a first parameter based on the cryptographic service component in the second network device; and encrypt the first parameter using the first public key to obtain the first communication encryption registration identifier.

[0419] Here, in one embodiment, the third receiving unit 1101 is further configured to receive a verification request for encrypted communication sent by the second terminal; and verify the verification information based on the verification request;

[0420] The third sending unit is further configured to send a verification response to the first terminal based on the verification information if the verification information is successfully verified; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

[0421] To implement the terminal-side method of this application embodiment, this application embodiment also provides a secure communication device, which is installed on a first network device. Figure 12 This is a schematic diagram of another device for secure communication according to an embodiment of this application; as shown Figure 12 As shown, the device 1200 includes:

[0422] The fourth receiving unit 1201 is used to receive a first request sent by the first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; and encrypts the first data using its own first storage information based on the first request.

[0423] In one embodiment, the first stored information includes at least one of the following:

[0424] At least one identification identifier for the first terminal;

[0425] The first encryption algorithm corresponding to the first communication registration identifier;

[0426] The first key corresponding to the first encryption algorithm.

[0427] In one embodiment, the device 1200 further includes a fourth transmitting unit; wherein,

[0428] The fourth receiving unit 1201 is further configured to receive a second registration application request with encrypted communication sent by the first terminal; the second registration application request carries the second identity identifier and the second communication address of the second terminal;

[0429] The fourth sending unit is configured to send second authentication information to the second terminal based on the second identity identifier and the second communication address; the second authentication information is used to authenticate the identity of the second terminal.

[0430] The fourth receiving unit 1201 is further configured to receive the second public key sent by the first terminal when the identity authentication of the second terminal is successful, and generate a second communication encryption registration identifier based on the second public key;

[0431] The fourth sending unit is further configured to send a second registration application response to the first terminal; the second registration application response carries a second communication registration identifier, a second cryptographic algorithm table, and a second identity identifier.

[0432] In one embodiment, the fourth receiving unit 1201 is further configured to generate a second parameter based on the cryptographic service component in the first network device; and encrypt the second parameter using the second public key to obtain the second communication encryption registration identifier.

[0433] It should be noted that the secure communication device provided in the above embodiments is only illustrated by the division of the above program modules when performing secure communication. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the secure communication device and secure communication method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0434] Based on the hardware implementation of the above program modules, and in order to implement the method on the first terminal side of the embodiments of this application, the embodiments of this application also provide a first terminal. Figure 13 This is a schematic diagram of the structure of the first terminal in an embodiment of this application; as shown Figure 13 As shown, the first terminal 1300 includes: a first processor 1301 and a first communication interface 1302; wherein,

[0435] The first communication interface 1301 is capable of exchanging information with the second terminal, the first network device, and the second network device.

[0436] The first processor 1302 is connected to the first communication interface 1301 to enable information interaction with the second terminal, the first network device, and the second network device. When running a computer program, it executes the methods provided by one or more technical solutions on the first terminal side. The computer program is stored in the first memory 1303.

[0437] It should be noted that the specific processing procedures of the first communication interface 1301 and the first processor 1302 can be understood by referring to the above method.

[0438] Of course, in practical applications, the various components in the first terminal 1300 are coupled together through the bus system 1304. It can be understood that the bus system 1304 is used to realize the connection and communication between these components. In addition to the information bus, the bus system 1304 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 13 The general designated all buses as Bus System 1304.

[0439] The first memory 1303 in this embodiment is used to store various types of information to support operation of a terminal 1300. Examples of such information include any computer program for operation on a terminal 1300.

[0440] The methods disclosed in the above embodiments of this application can be applied to the first processor 1302, or implemented by the first processor 1302. The first processor 1302 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 1302. The first processor 1302 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 1302 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 1303. The first processor 1302 reads the information in the first memory 1303 and completes the steps of the aforementioned method in combination with its hardware.

[0441] In an exemplary embodiment, the first terminal 1300 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0442] Based on the hardware implementation of the above program modules, and in order to implement the method on the second terminal side of the embodiments of this application, the embodiments of this application also provide a second terminal. Figure 14 This is a schematic diagram of the structure of the second terminal in an embodiment of this application; as shown... Figure 14 As shown, the second terminal 1400 includes:

[0443] The second communication interface 1401 is capable of exchanging information with the first terminal, the first network device, and the second network device;

[0444] The second processor 1402 is connected to the second communication interface 1401 to enable information interaction with network devices and, when running a computer program, executes the methods provided by one or more of the aforementioned terminal-side technical solutions. The computer program is stored in the second memory 1403.

[0445] It should be noted that the specific processing procedures of the second communication interface 1401 and the second processor 1402 can be understood by referring to the above method.

[0446] Of course, in practical applications, the various components in the second terminal 1400 are coupled together through the bus system 1404. It can be understood that the bus system 1404 is used to realize the connection and communication between these components. In addition to the information bus, the bus system 1404 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 14 The general designated all buses as Bus System 1404.

[0447] The second memory 1403 in this embodiment is used to store various types of information to support the operation of the second terminal 1400. Examples of this information include any computer program used to operate on the second terminal 1400.

[0448] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the second processor 1402. The second processor 1402 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the form of software within the second processor 1402. The second processor 1402 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1402 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a second memory 1403. The second processor 1402 reads information from the second memory 1403 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0449] In an exemplary embodiment, the second terminal 1400 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0450] Based on the hardware implementation of the above program modules, and in order to implement the method on the second network device side of the embodiments of this application, the embodiments of this application also provide a second network device. Figure 15 This is a schematic diagram of the structure of the second network device according to an embodiment of this application; as shown Figure 15 As shown, the second network device 1500 includes:

[0451] The third communication interface 1501 is capable of exchanging information with the first terminal, the second terminal, and the first network device;

[0452] The third processor 1502 is connected to the third communication interface 1501 to enable information interaction with the first terminal, the second terminal, and the first network device. When running a computer program, it executes the methods provided by one or more technical solutions on the second network device side. The computer program is stored in the third memory 1503.

[0453] It should be noted that the specific processing procedures of the third processor 1502 and the third communication interface 1501 can be understood by referring to the above method.

[0454] Of course, in practical applications, the various components in the third network device 1500 are coupled together through the bus system 1504. It can be understood that the bus system 1504 is used to implement communication between these components. In addition to the information bus, the bus system 1504 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 15 The general labeled all buses as Bus System 1504.

[0455] The third memory 1503 in this embodiment is used to store various types of information to support the operation of the second network device 1500. Examples of this information include any computer program used to operate on the second network device 1500.

[0456] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the third processor 1502. The third processor 1502 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the software form of the third processor 1502. The third processor 1502 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The third processor 1502 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a third memory 1503. The third processor 1502 reads information from the third memory 1503 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0457] In an exemplary embodiment, the second network device 1500 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0458] Based on the hardware implementation of the above program modules, and in order to implement the method on the first network device side of the embodiments of this application, the embodiments of this application also provide a first network device. Figure 16 This is a schematic diagram of the structure of the first network device according to an embodiment of this application; as shown Figure 16 As shown, the first network device 1600 includes:

[0459] The fourth communication interface 1601 is capable of exchanging information with the first terminal, the second terminal, and the second network device;

[0460] The fourth processor 1602 is connected to the fourth communication interface 1601 to enable information interaction with the first terminal, the second terminal, and the second network device. When running a computer program, it executes the methods provided by one or more technical solutions on the first network device side. The computer program is stored on the fourth memory 1603.

[0461] It should be noted that the specific processing procedures of the fourth communication interface 1601 and the fourth processor 1602 can be understood by referring to the above method.

[0462] Of course, in practical applications, the various components in the first network device 1600 are coupled together via a bus system 1604. It can be understood that the bus system 1604 is used to implement communication between these components. In addition to an information bus, the bus system 1604 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 16 The general labeled all buses as Bus System 1604.

[0463] The fourth memory 1603 in this embodiment is used to store various types of information to support the operation of the first network device 1600. Examples of this information include any computer program used to operate on the first network device 1600.

[0464] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the fourth processor 1602. The fourth processor 1602 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the software form of the fourth processor 1602. The fourth processor 1602 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The fourth processor 1602 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a fourth memory 1603. The fourth processor 1602 reads information from the fourth memory 1603 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0465] In an exemplary embodiment, the first network device 1600 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0466] It is understood that the memories (first memory 1203, second memory 1303, third memory 1403, and fourth memory 1603) in the embodiments of this application can be volatile memory or non-volatile memory, or both. Specifically, the non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); the magnetic surface memory can be disk storage or magnetic tape storage. The volatile memory can be random access memory (RAM), which is used as an external cache.By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM). The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memory.

[0467] To implement the method provided in the embodiments of this application, the embodiments of this application also provide a secure communication system. Figure 17 This is a schematic diagram of the secure communication system structure according to an embodiment of this application; as shown Figure 17 As shown, the system includes: a first terminal 1701, a first network device 1702, a second network device 1703, and a second terminal 1704.

[0468] It should be noted that the specific processing procedures of the first terminal 1701, the first network device 1702, the second network device 1703, and the second terminal 1704 have been detailed above and will not be repeated here.

[0469] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a first memory 1303 storing a computer program, which can be executed by a first processor 1302 of a first terminal 1300 to complete the steps described in the aforementioned first terminal-side method. Another example is a second memory 1403 storing a computer program, which can be executed by a second processor 1402 of a second terminal 1400 to complete the steps described in the aforementioned second terminal-side method. Yet another example is a third memory 1503 storing a computer program, which can be executed by a third processor 1502 of a second network device 1500 to complete the steps described in the aforementioned second network device-side method. Yet another example is a fourth memory 1503 storing a computer program, which can be executed by a fourth processor 1602 of a first network device 1600 to complete the steps described in the aforementioned first network device-side method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0470] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0471] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0472] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. A secure communication method, characterized in that, Applied to the first terminal, including: A first request is sent to a first network device; the first request carries the first identity identifier of the first terminal, the first communication registration identifier, and the first data to be encrypted and transmitted; the first request is used by the first network device to encrypt the first data using its own first storage information; Receive first response information from the first network device based on the first request; the first response information carries second data encrypted with the first data; The second data is sent to the second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information; Before sending the first request to the first network device, the method further includes: A third request is sent to the second terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal; The system receives a third response sent by the second terminal based on the third request; the third response carries the second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication registration identifier. A fourth request is sent to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm table, and the second communication registration identifier; the fourth request is used to register the second terminal for communication encryption. If the second terminal successfully registers for encrypted communication, it receives a fourth response from the first network device based on the fourth request; the fourth response carries a first cryptographic algorithm table and a first communication registration identifier determined by the first network device. The first communication registration identifier is used by the first terminal to encrypt and transmit the data to be communicated by calling the first cryptographic algorithm table and the first key in the first network device; the second communication registration identifier is used by the second terminal to decrypt the data to be communicated by calling the second cryptographic algorithm table and the second key in the second network device.

2. The method according to claim 1, characterized in that, The first stored information includes at least one of the following: At least one identification identifier for the first terminal; The first encryption algorithm corresponding to the first communication registration identifier; The first key corresponding to the first encryption algorithm.

3. The method according to claim 1, characterized in that, Before receiving the third response sent by the second terminal based on the third request, the method further includes: Receive first authentication information sent by the second network device based on the first identity identifier; If the first authentication information is successfully authenticated, the first public key of the first terminal is sent to the second network device; the first public key is used by the second network device to generate the second communication registration identifier.

4. The method according to claim 1, characterized in that, After receiving the fourth response sent by the first network device based on the fourth request, the method further includes: The second terminal sends verification information for encrypted communication; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key; the verification information is used by the second terminal to send a verification request for encrypted communication to the second network device; the verification request is used by the second network device to verify the verification information. If the second network device successfully verifies the verification information, it receives a verification response sent by the second terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

5. An encrypted communication method, characterized in that, Applied to the second terminal, including: Receive the second data sent by the first terminal; A second request is sent to a second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information; Receive the first data after the second network device has decrypted the second data using its own second stored information; Before receiving the second data sent by the first terminal; the method further includes: The system receives a third request sent by a first terminal; the third request carries a first identity identifier of the first terminal; the third request is used to encrypt the data to be communicated between the first terminal and the second terminal. Based on the third request, a third response is sent to the first terminal; the third response carries the second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication registration identifier; the third response is used by the first terminal to send a fourth request to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm table, and the second communication registration identifier; the fourth request is used to perform communication encryption registration for the second terminal; if the communication encryption registration of the second terminal is successful, a fourth response sent by the first network device based on the fourth request is received; the fourth response carries the first cryptographic algorithm table and the first communication registration identifier determined by the first network device; The first communication registration identifier is used by the first terminal to encrypt and transmit the data to be communicated by calling the first cryptographic algorithm table and the first key in the first network device; the second communication registration identifier is used by the second terminal to decrypt the data to be communicated by calling the second cryptographic algorithm table and the second key in the second network device.

6. The method according to claim 5, characterized in that, The second stored information includes at least one of the following: At least one second terminal's identity identifier; The second decryption algorithm corresponding to the second communication registration identifier; The second key corresponding to the second decryption algorithm.

7. The method according to claim 5, characterized in that, After sending the second request to the second network device, the method further includes: Send a first registration request with encrypted communication to the second network device; the first registration request carries the second identity identifier and the first communication address of the first terminal; the second identity identifier and the first communication address are used by the second network device to authenticate the identity of the first terminal; If the first terminal successfully authenticates its identity, it receives a first registration application response sent by the second network device based on the first registration application request; the first registration application response carries a second communication registration identifier, a first cryptographic algorithm table, and a first identity identifier; the second communication registration identifier is generated based on the first public key of the first terminal.

8. The method according to claim 7, characterized in that, The method further includes: Receive the second authentication information sent by the first network device; If the second authentication information is successfully authenticated, the second public key of the second terminal is sent to the first network device; the second public key is used by the first network device to generate the first communication registration identifier.

9. The method according to claim 8, characterized in that, The method further includes: The system receives verification information for encrypted communication sent by the first terminal; the verification information includes at least a first communication registration identifier, a first cryptographic algorithm table, and a first key. Based on the verification information, an encrypted communication verification request is sent to the second network device; the verification request is used by the second network device to verify the verification information. If the second network device successfully verifies the verification information, it sends a verification response to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

10. An encrypted communication method, characterized in that, Applied to second network devices, including: The system receives a second request sent by a second terminal; the second request carries a second identity identifier, a second communication registration identifier, and second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication. Based on the second request, the second data is decrypted using its own second stored information; Before receiving the second request sent by the second terminal, the method further includes: Receives a first registration request sent by a second terminal with encrypted communication; the first registration request carries the second identity identifier and the first communication address of the first terminal; First authentication information is sent to the first terminal based on the second identity identifier and the first communication address; the first authentication information is used to authenticate the identity of the first terminal. If the first terminal successfully authenticates its identity, the system receives the first public key sent by the first terminal and generates a second communication registration identifier based on the first public key. Send a first registration request response to the first terminal; the first registration request response carries a second communication registration identifier, a first cryptographic algorithm table, and a second identity identifier.

11. The method according to claim 10, characterized in that, The second stored information includes at least one of the following: At least one second terminal's identity identifier; The second decryption algorithm corresponding to the second communication registration identifier; The second key corresponding to the second decryption algorithm.

12. The method according to claim 10, characterized in that, The step of generating a second communication registration identifier based on the first public key includes: The first parameter is generated based on the cryptographic service component in the second network device; The first parameter is encrypted using the first public key to obtain the second communication registration identifier.

13. The method according to claim 12, characterized in that, The method further includes: Receive a verification request for encrypted communication sent by the second terminal; verify the verification information based on the verification request; If the verification information is successfully verified, a verification response is sent to the first terminal based on the verification information; the verification response is used to determine that an encrypted communication channel is established between the first terminal and the second terminal.

14. An encrypted communication method, characterized in that, Applied to the first network device, including: Receive a first request sent by a first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; encrypt the first data using its own first storage information based on the first request; Before receiving the first request sent by the first terminal, the method further includes: The system receives a fourth request sent by a first terminal; the fourth request carries a second identity identifier, a second cryptographic algorithm table, and a second communication registration identifier; the fourth request is used to register the second terminal for communication encryption; the fourth request is a third request sent by the first terminal to the second terminal; the third request carries a first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal; the system sends this request after receiving a third response sent by the second terminal based on the third request; the third response carries a second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication registration identifier; If the second terminal successfully registers for encrypted communication, a fourth response is sent to the first terminal based on the fourth request; the fourth response carries the first cryptographic algorithm table and the first communication registration identifier determined by the first network device. The first communication registration identifier is used by the first terminal to call the first cryptographic algorithm table and the first key in the first network device to encrypt and transmit the data to be communicated; the second communication registration identifier is used by the second terminal to call the second cryptographic algorithm table and the second key in the second network device to decrypt the data to be communicated.

15. The method of claim 14, wherein the first stored information comprises at least one of the following: At least one identification identifier for the first terminal; The first encryption algorithm corresponding to the first communication registration identifier; The first key corresponding to the first encryption algorithm.

16. The method according to claim 15, characterized in that, The method further includes: The system receives a second registration request sent by the first terminal, which is encrypted with communication. The second registration request carries a second identity identifier and a second communication address of the second terminal. The second authentication information is sent to the second terminal based on the second identity identifier and the second communication address; the second authentication information is used to authenticate the identity of the second terminal. If the second terminal successfully authenticates its identity, it receives the second public key sent by the first terminal and generates a first communication registration identifier based on the second public key. Send a second registration request response to the first terminal; the second registration request response carries a second communication registration identifier, a second cryptographic algorithm table, and a second identity identifier.

17. The method according to claim 16, characterized in that, The step of generating the first communication registration identifier based on the second public key includes: The second parameter is generated based on the cryptographic service component in the first network device; The second parameter is encrypted using the second public key to obtain the first communication registration identifier.

18. A secure communication device, characterized in that, The first terminal is configured to include: The first sending unit is configured to send a first request to a first network device; the first request carries a first identity identifier of the first terminal, a first communication registration identifier, and first data to be encrypted and transmitted; the first request is used by the first network device to encrypt the first data using its own first storage information. The first receiving unit is configured to receive first response information from the first network device based on the first request; the first response information carries second data encrypted with the first data; The first sending unit is further configured to send the second data to the second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information; Before sending the first request to the first network device, the first sending unit is further configured to send a third request to the second terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal; The first receiving unit is further configured to receive a third response sent by the second terminal based on the third request; the third response carries a second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication registration identifier; The first sending unit is further configured to send a fourth request to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm table, and the second communication registration identifier; the fourth request is used to register the second terminal for communication encryption. The first receiving unit is further configured to receive a fourth response sent by the first network device based on the fourth request when the second terminal successfully completes the communication encryption registration; the fourth response carries a first cryptographic algorithm table and a first communication registration identifier determined by the first network device; The first communication registration identifier is used by the first terminal to encrypt and transmit the data to be communicated by calling the first cryptographic algorithm table and the first key in the first network device; the second communication registration identifier is used by the second terminal to decrypt the data to be communicated by calling the second cryptographic algorithm table and the second key in the second network device.

19. A secure communication device, characterized in that, The second terminal is configured to include: The second receiving unit is used to receive the second data sent by the first terminal; The second sending unit is configured to send a second request to the second network device; the second request carries the second identity identifier, the second communication registration identifier, and the second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information. The second receiving unit is further configured to receive first data after the second network device has decrypted the second data using its own second stored information; Before receiving the second data sent by the first terminal; the second receiving unit is further configured to receive a third request sent by the first terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal; The second sending unit is further configured to send a third response to the first terminal based on the third request; the third response carries a second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication registration identifier; the third response is used by the first terminal to send a fourth request to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm table, and the second communication registration identifier; the fourth request is used to register the second terminal for communication encryption; if the second terminal successfully registers for communication encryption, the unit receives a fourth response sent by the first network device based on the fourth request; the fourth response carries a first cryptographic algorithm table and a first communication registration identifier determined by the first network device; the first communication registration identifier is used by the first terminal to call the first cryptographic algorithm table and the first key in the first network device to encrypt and transmit the data to be communicated; the second communication registration identifier is used by the second terminal to call the second cryptographic algorithm table and the second key in the second network device to decrypt the data to be communicated.

20. A secure communication device, characterized in that, The second network device includes: The third receiving unit is used to receive a second request sent by the second terminal; the second request carries the second identity identifier, the second communication registration identifier, and second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication. The decryption unit is used to decrypt the second data using its own second stored information based on the second request; Before receiving the second request sent by the second terminal, the third receiving unit is configured to receive a first registration application request with encrypted communication sent by the second terminal; the first registration application request carries the second identity identifier and the first communication address of the first terminal; The third sending unit is configured to send first authentication information to the first terminal based on the second identity identifier and the first communication address; the first authentication information is used to authenticate the identity of the first terminal. The third receiving unit is used to receive the first public key sent by the first terminal when the first terminal's identity authentication is successful, and to generate a second communication registration identifier based on the first public key; The third sending unit is used to send a first registration application response to the first terminal; the first registration application response carries a second communication registration identifier, a first cryptographic algorithm table, and a second identity identifier.

21. A secure communication device, characterized in that, Configured on the first network device, including: The fourth receiving unit is configured to receive a first request sent by the first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; and encrypts the first data using its own first storage information based on the first request; Before receiving the first request sent by the first terminal, the fourth receiving unit is further configured to receive a fourth request sent by the first terminal; the fourth request carries a second identity identifier, a second cryptographic algorithm table, and a second communication registration identifier; the fourth request is used to register the second terminal for communication encryption; the fourth request is a third request sent by the first terminal to the second terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal; it is sent after receiving a third response sent by the second terminal based on the third request; the third response carries the second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication registration identifier; The fourth sending unit is configured to send a fourth response to the first terminal based on the fourth request when the second terminal successfully completes the communication encryption registration; the fourth response carries the first cryptographic algorithm table and the first communication registration identifier determined by the first network device. The first communication registration identifier is used by the first terminal to call the first cryptographic algorithm table and the first key in the first network device to encrypt and transmit the data to be communicated; the second communication registration identifier is used by the second terminal to call the second cryptographic algorithm table and the second key in the second network device to decrypt the data to be communicated.

22. A first terminal, characterized in that, include: A first processor and a first communication interface; wherein... The first communication interface is used to send a first request to a first network device; the first request carries a first identity identifier, a first communication registration identifier, and first data to be encrypted and transmitted from the first terminal; the first request is used by the first network device to encrypt the first data using its own first storage information; and to receive first response information from the first network device based on the first request; the first response information carries second data encrypted with the first data; and to send the second data to a second terminal; the second data is used by the second terminal to send a second request to the second network device; the second request carries a second identity identifier, a second communication registration identifier, and the second data from the second terminal; the first communication registration identifier and the second communication registration identifier are registration identifiers obtained when establishing secure communication between the first terminal and the second terminal; the second request is used by the second network device to decrypt the second data using its own second storage information; before sending the first request to the first network device, a third request is sent to the second terminal; the third request carries the first identity identifier of the first terminal; the third... The system requests encryption of communication data between the first terminal and the second terminal; receives a third response from the second terminal based on the third request; the third response carries a second identity identifier of the second terminal, a second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and a second communication registration identifier; sends a fourth request to the first network device corresponding to the first terminal; the fourth request carries the second identity identifier, the second cryptographic algorithm table, and the second communication registration identifier; the fourth request is used to register the second terminal for communication encryption; if the second terminal successfully registers for communication encryption, receives a fourth response from the first network device based on the fourth request; the fourth response carries a first cryptographic algorithm table and a first communication registration identifier determined by the first network device; the first communication registration identifier is used by the first terminal to call the first cryptographic algorithm table and the first key in the first network device to encrypt and transmit the communication data; the second communication registration identifier is used by the second terminal to call the second cryptographic algorithm table and the second key in the second network device to decrypt the communication data.

23. A second terminal, characterized in that, include: A second communication interface and a second processor; wherein... The second communication interface is used to receive second data sent by the first terminal; and to send a second request to the second network device; the second request carries the second identity identifier of the second terminal, a second communication registration identifier, and the second data; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication; the second request is used by the second network device to decrypt the second data using its own second storage information; and to receive first data after the second network device has decrypted the second data using its own second storage information; to receive a third request sent by the first terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the communication data between the first terminal and the second terminal; and to send a third response to the first terminal based on the third request; the third response carries the second identity identifier of the second terminal, and the second network device corresponding to the second terminal determines the first data; The first terminal sends a fourth request to the first network device corresponding to the first terminal, using a second cryptographic algorithm table and a second communication registration identifier. The fourth request carries the second identity identifier, the second cryptographic algorithm table, and the second communication registration identifier. The fourth request is used to register the second terminal for communication encryption. If the second terminal successfully registers for communication encryption, the first terminal receives a fourth response from the first network device based on the fourth request. The fourth response carries a first cryptographic algorithm table and a first communication registration identifier determined by the first network device. The first communication registration identifier is used by the first terminal to call the first cryptographic algorithm table and the first key in the first network device to encrypt and transmit the data to be communicated. The second communication registration identifier is used by the second terminal to call the second cryptographic algorithm table and the second key in the second network device to decrypt the data to be communicated.

24. A second network device, characterized in that, include: A third processor and a third communication interface; wherein... The third communication interface is used to receive a second request sent by the second terminal; the second request carries the second identity identifier, the second communication registration identifier, and second data of the second terminal; the second communication registration identifier is a registration identifier obtained when the first terminal and the second terminal establish secure communication. The third processor is configured to: decrypt the second data using its own second stored information based on the second request; receive a first registration request for communication encryption sent by the second terminal; the first registration request carries the second identity identifier and the first communication address of the first terminal; send first authentication information to the first terminal based on the second identity identifier and the first communication address; the first authentication information is used to authenticate the identity of the first terminal; if the identity authentication of the first terminal is successful, receive a first public key sent by the first terminal, generate a second communication registration identifier based on the first public key; and send a first registration request response to the first terminal; the first registration request response carries the second communication registration identifier, a first cryptographic algorithm table, and the second identity identifier.

25. A first network device, characterized in that, include: The fourth communication interface and the fourth processor; wherein, The fourth communication interface is used to receive a first request sent by the first terminal; the first request carries the first identity identifier, the first communication registration identifier, and the first data to be encrypted and transmitted by the first terminal; encrypts the first data using its own first storage information based on the first request; receives a fourth request sent by the first terminal; the fourth request carries a second identity identifier, a second cryptographic algorithm table, and a second communication registration identifier; the fourth request is used to register the second terminal for communication encryption; the fourth request is a third request sent by the first terminal to the second terminal; the third request carries the first identity identifier of the first terminal; the third request is used to encrypt the data to be communicated between the first terminal and the second terminal; upon receiving the data from the second terminal based on the first terminal's first identity identifier, the fourth request is used to encrypt the data to be communicated between the first terminal and the second terminal; upon receiving the data from the second terminal based on the ... The third response is sent after the third request; the third response carries the second identity identifier of the second terminal, the second cryptographic algorithm table determined by the second network device corresponding to the second terminal, and the second communication registration identifier; if the communication encryption registration of the second terminal is successful, a fourth response is sent to the first terminal based on the fourth request; the fourth response carries the first cryptographic algorithm table and the first communication registration identifier determined by the first network device; the first communication registration identifier is used by the first terminal to call the first cryptographic algorithm table and the first key in the first network device to encrypt and transmit the data to be communicated; the second communication registration identifier is used by the second terminal to call the second cryptographic algorithm table and the second key in the second network device to decrypt the data to be communicated.

26. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4, or the steps of the method according to any one of claims 5 to 9, or the steps of the method according to any one of claims 10 to 13, or the steps of the method according to any one of claims 14 to 17.

Citation Information

Patent Citations

  • Identity label processing method and device, network equipment and storage medium

    CN115884169A

  • Internet of Things communication method, device and system, and storage medium

    CN113556732A

  • Gateway, method for processing information, program, and data encryption terminal

    JP2010178242A