Device authentication method, system, apparatus, and non-transitory storage medium
By routing messages through the Border Gateway Protocol to carry quantum keys and device identification information, combined with hash message authentication code operations, the problem of low efficiency of multi-point to multi-point authentication in existing device authentication protocols is solved, and efficient two-way authentication and security improvement between devices are achieved.
Patent Information
- Application Number
- CN202411357398.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-09-26
AI Technical Summary
Existing device authentication protocols such as IEEE802.1X and tacacs are difficult to implement bidirectional authentication between multi-point devices, resulting in low negotiation efficiency, multiple network protocols, complex operation and maintenance, and high costs.
The border gateway protocol is used to route messages carrying quantum keys and device identification information, and two-way authentication between devices is achieved through hash message authentication code operations. The quantum key service layer and software-defined network controller are used to transmit and verify authentication information.
It realizes multi-point to multi-point two-way authentication between devices, simplifies the authentication protocol, improves authentication efficiency, reduces costs and enhances security.
Smart Images

Figure CN119299101B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and more specifically, to a device authentication method, system, apparatus, and non-volatile storage medium. Background Art
[0002] Authentication is a prerequisite for network security and is used to ensure the legitimacy of device identities. Common device authentication protocols include IEEE802.1X and TACACS. However, these authentication protocols are generally point-to-point between the client and the server, making it difficult to implement bidirectional authentication between multiple devices. This leads to problems such as low negotiation efficiency, multiple network protocols, complex operations and maintenance, and high costs.
[0003] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0004] The embodiments of the present application provide a device authentication method, system, apparatus, and non-volatile storage medium to at least solve the technical problems of high device authentication cost and low security caused by low negotiation efficiency of traditional authentication methods.
[0005] According to one aspect of an embodiment of the present application, a device authentication method is provided, comprising: a first device publishing a first message of a border gateway protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network, and identification information of the quantum key, and the first message carries the device identification information of the first device and the identification information of the quantum key; receiving a second message generated by the second device based on the first message, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the second device; after receiving the second message, generating a second random number. The first device receives a random number, a second random number, and a quantum key, and performs a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code; sends a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is used to verify the first message authentication code, and performs a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is a border gateway protocol routing message; receives a fourth message carrying the second message authentication code sent by the second device, and authenticates the second message authentication code, wherein the message type of the fourth message is a border gateway protocol routing message.
[0006] Optionally, the first device comprises a communication device, the second device comprises a communication device or a soft-defined gateway controller of a quantum service platform, the quantum service platform comprises a quantum key service layer, a network operation control layer and a network forwarding layer, wherein the quantum key service layer is connected with a quantum key distribution network; the network operation control layer comprises the soft-defined gateway controller and a routing transmitter; the network forwarding layer comprises a router device, wherein the router device is configured to receive a border gateway protocol routing information, extract authentication information from the border gateway protocol routing information, and send the authentication information of the router device.
[0007] Optionally, a neighbor relationship is established between the first device and the second device through the routing transmitter, and packet interaction is performed through the routing transmitter.
[0008] Optionally, the border gateway protocol routing packet comprises a custom security community attribute field, and the custom security community attribute field comprises a high-bit field and a low-bit field, wherein the high-bit field comprises a first character indicating a packet type, a second character indicating a packet serial number, and a third character representing a link flag bit; and the low-bit field comprises authentication information.
[0009] Optionally, the first message authentication code is obtained by performing a hash message authentication code operation on the first random number, the second random number and the quantum key, comprising: splicing the first random number and the second random number to obtain a first splicing result, wherein the first random number is located in the first half of the first splicing result, and the second random number is located in the second half of the first splicing result; and performing a hash message authentication code operation on the first splicing result and the quantum key to obtain the first message authentication code.
[0010] Optionally, the second message authentication code is determined by: splicing the second random number and the first random number to obtain a second splicing result, wherein the second random number is located in the first half of the second splicing result, and the first random number is located in the second half of the second splicing result; and performing a hash message authentication code operation on the second splicing result and the quantum key to obtain the second message authentication code.
[0011] Optionally, the first device and the second device further store an authentication state matrix for recording an authentication session and a session state, wherein a field in the authentication state matrix comprises at least one of the following: an authentication session identifier, a session initiator identifier, a session receiver identifier, a session serial number, and a session corresponding extended community attribute word.
[0012] Optionally, the identification information of the quantum key comprises a zone number of a zone where the quantum key is located, and a key number of the quantum key.
[0013] According to another aspect of the embodiment of the present application, a device authentication method is also provided, including: a second device receives a first message published by a first device, the message type of which is a border gateway protocol routing message, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network, and identification information of the quantum key, and the first message carries the device identification information of the first device and the identification information of the quantum key; sends a second message generated based on the first message to the first device, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the second device; receives a message sent by the first device carrying the first random number; A third message containing a message authentication code and a second random number, wherein the first device is configured to, after receiving the second message, generate a second random number, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code, and the message type of the third message is a border gateway protocol routing message; verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code; and send a fourth message carrying the second message authentication code to the first device, wherein the first device is configured to authenticate the second message authentication code, and the message type of the fourth message is a border gateway protocol routing message.
[0014] According to another aspect of an embodiment of the present application, a device authentication system is also provided, including a quantum service platform and multiple communication devices, wherein the quantum service platform includes a quantum key service layer, a network operation control layer and a network forwarding layer, the quantum key service layer is connected to the quantum key distribution network, the network operation control layer includes a soft-defined gateway controller and a routing transmitter, the network forwarding layer includes a router device, the router device is used to receive border gateway protocol routing information, extract authentication information from the border gateway protocol routing information, and send authentication information of the router device; a first device among the multiple communication devices is used to publish a first message of a border gateway protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by the quantum key distribution network, and identification information of the quantum key, the first message carries device identification information of the first device and identification information of the quantum key, the first device is any device among the multiple communication devices, and the second device is Any device in the communication device except the first device, or a soft-defined gateway controller; receiving a second message generated by the second device based on the first message, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the second device; after receiving the second message, generating a second random number, and performing a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain a first message authentication code; sending a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is used to verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain a second message authentication code, and the message type of the third message is a border gateway protocol routing message; receiving a fourth message carrying the second message authentication code sent by the second device, and authenticating the second message authentication code, wherein the message type of the fourth message is a border gateway protocol routing message.
[0015] According to another aspect of an embodiment of the present application, a device authentication apparatus is further provided, which is applicable to an authentication initiating device, and includes: a first processing module, configured to publish a first message of a border gateway protocol routing message to a receiving device, wherein the authentication initiating device is pre-filled with a quantum key distributed to the authentication initiating device by a quantum key distribution network, and identification information of the quantum key, and the first message carries device identification information of the authentication initiating device and identification information of the quantum key; a second processing module, configured to receive a second message generated by the receiving device based on the first message, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the receiving device; and a third processing module, configured to receive a first message of a border gateway protocol routing message. After receiving the second message, a second random number is generated, and a hash message authentication code operation is performed on the first random number, the second random number, and the quantum key to obtain a first message authentication code; a fourth processing module is used to send a third message carrying the first message authentication code and the second random number to the receiving device, wherein the receiving device is used to verify the first message authentication code and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is a border gateway protocol routing message; a fifth processing module is used to receive a fourth message carrying the second message authentication code sent by the receiving device, and authenticate the second message authentication code, wherein the message type of the fourth message is a border gateway protocol routing message.
[0016] According to another aspect of an embodiment of the present application, a non-volatile storage medium is provided, in which a program is stored. When the program is running, a device where the non-volatile storage medium is located is controlled to execute a device authentication method.
[0017] According to another aspect of an embodiment of the present application, an electronic device is provided, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the device authentication method is executed when the program is run.
[0018] According to another aspect of an embodiment of the present application, a computer program product is further provided, including a computer program, which implements a device authentication method when executed by a processor.
[0019] In an embodiment of the present application, a first device is used to publish a first message of a border gateway protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network, and identification information of the quantum key, and the first message carries device identification information of the first device and identification information of the quantum key; a second message generated by the second device based on the first message is received, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the second device; after receiving the second message, a second random number is generated, and a hash message authentication code operation is performed on the first random number, the second random number and the quantum key to obtain a first message authentication code; and a message carrying the first message authentication code and the second random number is sent to the second device. A third message, wherein the second device is used to verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain the second message authentication code, and the message type of the third message is a border gateway protocol routing message; a fourth message carrying the second message authentication code sent by the second device is received, and the second message authentication code is authenticated, wherein the message type of the fourth message is a border gateway protocol routing message, and the authentication message is transmitted through group attributes and combined with the pre-injected quantum key for authentication, thereby achieving the purpose of simplifying the authentication protocol and improving the authentication efficiency, thereby realizing the technical effect of multi-point to multi-point two-way authentication between devices, and thus solving the technical problems of high device authentication cost and low security caused by low negotiation efficiency of traditional authentication methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0021] Figure 1 is a schematic diagram of a device authentication system architecture provided according to an embodiment of the present application;
[0022] Figure 2 This is a schematic diagram of the structure of a computer terminal (mobile device) provided according to an embodiment of the present application;
[0023] Figure 3 This is a flow chart of a device authentication method provided according to an embodiment of the present application;
[0024] Figure 4 is a schematic diagram of a key storage data structure provided according to an embodiment of the present application;
[0025] Figure 5 is a schematic diagram of an interaction process between a first device and a second device provided according to an embodiment of the present application;
[0026] Figure 6 This is a schematic diagram of a data structure of group attributes provided according to an embodiment of the present application;
[0027] Figure 7 It is a structural diagram of a device authentication apparatus provided according to an embodiment of the present invention. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0030] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are explained as follows:
[0031] BGP (Border Gateway Protocol) is an inter-autonomous system routing protocol that exchanges network reachability information between ASs (Autonomous Systems).
[0032] BGP Community Attribute: The Community attribute is a mechanism used in BGP to classify and label routes. It is an optional, transparent attribute of any length that enables specific route processing by attaching one or more labels to a route. Community attributes are divided into custom community attributes and recognized community attributes.
[0033] IEEE802.1X: A user authentication technology used in LAN switches and wireless LAN access points.
[0034] QKD (quantum key distribution): Quantum technology has advanced rapidly in recent years, garnering widespread attention. Quantum security technology has broad application prospects in finance, government affairs, transportation, and other fields. Quantum-secure cryptography uses the principles of quantum physics to achieve the goals of classical cryptography. The most representative and practical of these technologies is quantum key distribution (QKD), which leverages the properties of quantum mechanics to ensure secure communications. It enables communicating parties to generate and share a random, secure key to encrypt and decrypt messages.
[0035] QKD Quantum Key Distribution Network (QKD): A network consisting of multiple quantum key distribution nodes connected by quantum key distribution links. The communicating parties can generate and share a random, secure key for encrypting and decrypting messages.
[0036] RR (Route Reflector): A special router that serves as a central point for storing and forwarding routing entries for the entire network and redistributes routing information to other routers.
[0037] SDN (Software Defined Networking): A network management approach that supports dynamic, programmable network configuration, improving network performance and management efficiency, and enabling flexible customization of network services similar to cloud computing. SDN decouples the forwarding and control planes of network devices, allowing a controller to manage network devices, orchestrate network services, and schedule service traffic. This approach offers advantages such as low cost, centralized management, and flexible scheduling.
[0038] HMAC (Hash-based Message Authentication Code) is a security mechanism that uses a secret key and a hash function (such as MD5, SHA-1, or SHA-256) to generate a fixed-length digest for verifying data integrity and origin. HMAC combines the characteristics of hash functions with the advantages of symmetric encryption, providing stronger security than simple hash functions because it requires a secret key for calculation, preventing message tampering and forgery.
[0039] Authentication is a prerequisite for network security and the foundation before quantum key distribution. It is a necessary condition for devices to obtain keys and ensures the legitimacy of device identity.
[0040] Common device authentication protocols include IEEE802.1X and tacacs. The main issues with this type of authentication are as follows:
[0041] 1. Using dedicated protocols such as IEEE802.1X and TACACS for authentication requires adding new protocols or configurations to the router network, which has poor security.
[0042] 2. Traditional authentication methods are generally point-to-point authentication between the client and the server, which makes it difficult to achieve two-way authentication between multi-point to multi-point devices.
[0043] In order to solve the above problems, relevant solutions are provided in the embodiments of the present application, which are described in detail below.
[0044] According to an embodiment of the present application, an embodiment of a method for device authentication is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0045] The present application embodiment provides a device authentication system, the architecture of which is as follows: Figure 1As shown, it includes a quantum service platform and multiple communication devices, wherein the quantum service platform includes a quantum key service layer, a network operation control layer and a network forwarding layer, the quantum key service layer is connected to the quantum key distribution network, the network operation control layer includes a soft-defined gateway controller and a routing transmitter, the network forwarding layer includes a router device, the router device is used to receive border gateway protocol routing information, extract authentication information from the border gateway protocol routing information, and send authentication information of the router device; a first device among the multiple communication devices is used to publish a first message of a border gateway protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by the quantum key distribution network, and identification information of the quantum key, the first message carries device identification information of the first device and identification information of the quantum key, the first device is any device among the multiple communication devices, and the second device is a communication device other than the first device. Any device, or a soft-defined gateway controller; receiving a second message generated by a second device based on the first message, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the second device; after receiving the second message, generating a second random number, and performing a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain a first message authentication code; sending a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is used to verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain a second message authentication code, and the message type of the third message is a border gateway protocol routing message; receiving a fourth message carrying the second message authentication code sent by the second device, and authenticating the second message authentication code, wherein the message type of the fourth message is a border gateway protocol routing message.
[0046] Optionally, the quantum key service layer generates physical true random numbers using a quantum key distribution network (QKD). The quantum key service platform provides authentication and key services for the operation network. The network operation control layer consists of the SDN controller and RR router transmitters. The RR acts as a router transmitter and also reflects authentication information. The SDN controller acts as an authentication agent for the key service platform. The network forwarding layer consists of routers. Routers receive BGP routing information, extract authentication information, authenticate the platform and other devices, and transmit their own authentication information.
[0047] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 2 FIG1 shows a hardware structure block diagram of a computer terminal (or mobile device) for implementing a device authentication method. Figure 2As shown, the computer terminal 20 (or mobile device 20) may include one or more (shown as 202a, 202b, ..., 202n in the figure) processors 202 (the processor 202 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 204 for storing data, and a transmission module 206 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 2 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 2 More or fewer components than shown, or with Figure 2 Different configurations shown.
[0048] It should be noted that the one or more processors 202 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 20 (or mobile device). As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0049] The memory 204 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the device authentication method in the embodiment of the present application. The processor 202 executes various functional applications and data processing by running the software programs and modules stored in the memory 204, that is, implementing the device authentication method of the above-mentioned application. The memory 204 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 204 may further include a memory remotely located relative to the processor 202, and these remote memories may be connected to the computer terminal 20 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0050] Transmission device 206 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of computer terminal 20. In one embodiment, transmission device 206 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, transmission device 206 may be a radio frequency (RF) module configured to communicate with the Internet wirelessly.
[0051] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 20 (or mobile device).
[0052] In the above operating environment, the embodiment of the present application provides a device authentication method, such as Figure 3 As shown, the method includes the following steps:
[0053] Step S302: The first device sends a first message of a Border Gateway Protocol routing message to the second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network and identification information of the quantum key, and the first message carries the device identification information of the first device and the identification information of the quantum key;
[0054] In some embodiments of the present application, the R1 device (i.e., the first device) initiates an authentication request and publishes a routing update message through BGP (Border Gateway Protocol). This message contains specific extended attributes. These extended attributes are additional information outside the BGP standard and are used for specific purposes, including the R1 device SN number (i.e., the device identification information of the first device), the pre-filled quantum key area ID (i.e., the identification information of the quantum key), the type of the sent message (i.e., the first message) is registration authentication, the message subtype is 1, and the pre-filled quantum key area ID is the identifier of the key storage area pre-allocated to the device in the quantum key distribution network. The key storage data structure is as follows: Figure 4 As shown, it includes the pre-fill key ID and the pre-fill key.
[0055] Optionally, in the key, the pre-filled key area ID is used to identify the unique identifier of the key storage area. In a quantum key distribution network, there may be multiple key areas, each of which contains several pre-filled quantum keys. The key area ID helps devices and systems locate the correct key area for use during authentication or key distribution. The pre-filled key ID is used to number the quantum keys in a certain order or rule within each key area. The pre-filled key ID is a unique number used to identify a specific quantum key. During the authentication process, the pre-filled key ID is used to index and select the correct key for HMAC calculation to ensure the security and accuracy of the authentication process. The pre-filled key is a real random key generated by the quantum key distribution network, which is pre-stored in the key storage area of the device or system. The pre-filled key is used to calculate the HMAC value for authentication when communicating between devices or when the device communicates with the cryptographic service platform.
[0056] Step S304: receiving a second message generated by the second device based on the first message, wherein the message type of the second message is a Border Gateway Protocol routing message, and the community attribute of the second message is a first random number generated by the second device;
[0057] In some embodiments of the present application, the second device is another network device that interacts with the device that initiates the authentication request (e.g., R1 device) during the device authentication process. The second device can be an SDN controller, other router devices, etc. Figure 5 An interaction process between a first device and a second device is shown. Figure 5 As shown, the first device R1 can interact with other devices (such as another communication device R2) through a route reflector, or with an SDN controller through a route reflector. The second device is used to receive the authentication request from device R1, parse the information contained therein, extract the pre-charge key area ID, retrieve the corresponding charge key sequence ID, generate a random number a or c as the community attribute, and publish the BGP route. The message type is registration authentication, and the message subtype is 1.
[0058] Specifically, the BGP community attribute is a mechanism for classifying and labeling routes. It is an optional, transparent attribute of arbitrary length. By attaching one or more labels to a route, specific route processing is implemented. Community attributes are divided into custom community attributes and well-known community attributes. Each autonomous system (AS) can freely define and use community attributes to meet its specific needs. The community attribute format consists of a 32-bit number, typically composed of two 16-bit numbers, called the high-order and low-order bits. The high-order bit typically represents the autonomous system number (ASN), while the low-order bit represents the custom community value. ASN:Value represents a specific community value. A route can carry multiple community attributes simultaneously, separated by commas. Each community attribute can have different meanings and functions. When processing and matching community attributes, logical operators can be used to combine them. Common logical operators include AND, OR, and NOT. By flexibly combining and matching community attributes, more complex routing policies and controls can be implemented. Up to 32 community attributes can be configured in a single command. RFC 1997 specifies that the community attribute consists of two 16-bit numbers, called the high bit and the low bit. The high bit represents the AS number, and the low bit represents the community attribute value. The format is AA:NN. This format is optional and can be defined by each organization.
[0059] Optionally, a customized extended group attribute (security group attribute) is used to record data. The data structure of the group attribute is as follows: Figure 6 As shown, the security community attribute uses TLV format to identify information, with the upper 12 bits and the lower 20 bits. The first 8 bits of the upper 12 bits represent the message type: bits 6, 7, and 8 represent the registration and authentication type, with bit 6 representing the registration and authentication type, and bits 7 and 8 representing the message sequence number (subtype). One bit represents the link flag, 1 indicates the presence of the next community attribute, and three bits represent the message length. The lower 20 bits are the payload, which contains authentication information. In registration and authentication messages, there are four message types: 00000100, 00000101, 00000110, and 00000111. These represent four session sequence IDs, respectively. Multiple community values are separated by commas to form a list, conveying a group of information. The community attribute is a transferable attribute and can be transmitted to any neighbor (i.e., the second device). After obtaining this attribute, the router identifies the message type and extracts the payload. For messages used for registration and authentication, the corresponding community attribute can carry authentication information for authentication.
[0060] Optionally, when the second device is an SDN controller, a random number a is generated; and when the second device is other communication device, a random number c is generated.
[0061] Step S306: After receiving the second message, generate a second random number, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code;
[0062] In some embodiments of the present application, after the first device receives a message with a message subtype of 1, it generates a random number b by itself, uses the injection key corresponding to the injection sequence ID to calculate HMAC (a+b, the injection key corresponding to the injection ID), concatenates the random numbers a and b, and performs a hash message authentication code operation together with the injection key corresponding to the injection ID, and synchronously sends the calculated message to the BGP route. The community word in the message carries the calculated MAC value and the random number b. The message type is registration authentication, and the message subtype is 2.
[0063] Step S308: Send a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is configured to verify the first message authentication code and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code. The message type of the third message is a Border Gateway Protocol routing message.
[0064] In some embodiments of the present application, after receiving the third message, the SDN controller or other device parses the message content, verifies the HMAC (a+b or c+b, the charging ID corresponds to the charging key) value, and uses the charging key corresponding to the charging sequence ID to perform an HMAC (b+a or b+c, the charging ID corresponds to the charging key) value operation, and synchronously sends the calculated HMAC value to R1 for synchronization verification calculation. The message type is registration authentication, and the message subtype is 3.
[0065] Step S310: Receive a fourth message carrying a second message authentication code sent by the second device, and authenticate the second message authentication code, wherein the message type of the fourth message is a Border Gateway Protocol routing message.
[0066] In some embodiments of the present application, after receiving the fourth message, R1 calculates HMAC to verify whether the authentication is successful.
[0067] In some optional embodiments of the present application, each device records authentication sessions and session status with other devices. The authentication status matrix includes at least fields such as authentication session ID, initiator router ID, receiver router ID, session sequence ID, and extended community attribute.
[0068] Alternatively, assuming N devices require authentication, device R1 will need to record (N-1) authentication sessions, each with four messages. For a network with N devices, there are N*(N-1) session connections. BGP authentication routes can use a dedicated routing prefix (for example, specifying 10.0.0.0 / 8 as the routing endpoint between devices through data configuration) or use a default service route as the authentication route to speed up authentication.
[0069] Optionally, the device authentication process can be triggered when the device is restarted, newly connected to the network, the authentication counter is reset to zero, the route is revoked, etc.
[0070] Through the above steps, device authentication based on pre-filled quantum keys can be achieved, and the registration and authentication of network devices on the quantum secret service platform can be completed, which can ensure the legitimacy of the device, prevent counterfeit devices from entering the network, and prepare for key distribution and encrypted transmission. This application uses the BGP protocol to extend group attributes to transmit authentication messages, combined with pre-filled quantum keys and SDN controllers, to achieve simultaneous two-way authentication between devices and secret service platforms, and between devices, solving the problem of low efficiency of multi-point to multi-point networking service authentication.
[0071] Specifically, this application has the following advantages:
[0072] 1. Simplified protocol: Leverage the extensibility of the BGP protocol to implement device authentication. BGP's Update message carries routing update (deletion, addition) information. At the same time, BGP extended community words are used to carry authentication information. Authentication information is obtained while routing updates are being implemented. Routing control and key negotiation control use the same protocol, simplifying the control plane and unifying the authentication and routing release control architectures. This simplifies the protocol, facilitates operation and maintenance for operators and Internet companies, reduces costs, and improves network management efficiency.
[0073] 2. High Efficiency: Using BGP RR route transmitters, bidirectional authentication can be achieved between the platform and the device, between devices, and between different customer sites. Each route or VPN can be authenticated separately, allowing for mutual authentication between different users. This provides wide adaptability, high authentication efficiency, and improved security.
[0074] The embodiment of the present application provides a device authentication method, comprising: a second device receiving a first message of a message type of a border gateway protocol routing message issued by a first device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network and identification information of the quantum key, and the first message carries device identification information of the first device and the identification information of the quantum key; sending a second message generated according to the first message to the first device, wherein the message type of the second message is the border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the second device; receiving a third message carrying a first message authentication code and a second random number sent by the first device, wherein the first device is used to generate the second random number after receiving the second message, and perform a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain the first message authentication code, and the message type of the third message is the border gateway protocol routing message; verifying the first message authentication code, and performing a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain a second message authentication code; and sending a fourth message carrying the second message authentication code to the first device, wherein the first device is used to authenticate the second message authentication code, and the message type of the fourth message is the border gateway protocol routing message.
[0075] The embodiment of the present application provides a data storage device, Figure 7 is a structural schematic diagram of the device, as Figure 7 shown, the device comprises: a first processing module 70, used for issuing a first message of a message type of a border gateway protocol routing message to a receiving device, wherein the authentication initiator device is pre-filled with a quantum key distributed to the authentication initiator device by a quantum key distribution network and identification information of the quantum key, and the first message carries device identification information of the authentication initiator device and the identification information of the quantum key; a second processing module 72, used for receiving a second message generated by the receiving device according to the first message, wherein the message type of the second message is the border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the receiving device; a third processing module 74, used for generating a second random number after receiving the second message, and performing a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain a first message authentication code; a fourth processing module 76, used for sending a third message carrying the first message authentication code and the second random number to the receiving device, wherein the receiving device is used to verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number and the quantum key to obtain a second message authentication code, and the message type of the third message is the border gateway protocol routing message; and a fifth processing module 78, used for receiving a fourth message carrying the second message authentication code sent by the receiving device and authenticating the second message authentication code, wherein the message type of the fourth message is the border gateway protocol routing message.
[0076] In some embodiments of the present application, the first device includes a communication device, the second device includes a soft-defined gateway controller of the communication device or a quantum service platform, the quantum service platform includes a quantum key service layer, a network operation control layer and a network forwarding layer, wherein the quantum key service layer is connected to the quantum key distribution network; the network operation control layer includes a soft-defined gateway controller and a routing transmitter; the network forwarding layer includes a router device, wherein the router device is used to receive border gateway protocol routing information, extract authentication information from the border gateway protocol routing information, and send authentication information of the router device.
[0077] In some embodiments of the present application, a neighbor relationship is established between the first device and the second device through a routing transmitter, and messages are exchanged through the routing transmitter.
[0078] In some embodiments of the present application, the border gateway protocol routing message includes a custom security group attribute field, and the custom security group attribute field includes a high-order field and a low-order field, wherein the high-order field includes a first character for indicating the message type, a second character for indicating the message sequence number, and a third character representing a link flag; the low-order field includes authentication information.
[0079] In some embodiments of the present application, performing a hash message authentication code operation on a first random number, a second random number, and a quantum key to obtain a first message authentication code includes: concatenating the first random number and the second random number to obtain a first concatenation result, wherein the first random number is located in the first half of the first concatenation result and the second random number is located in the second half of the first concatenation result; and performing a hash message authentication code operation on the first concatenation result and the quantum key to obtain the first message authentication code.
[0080] In some embodiments of the present application, the second message authentication code is determined by: splicing the second random number and the first random number to obtain a second splicing result, wherein the second random number is located in the first half of the second splicing result, and the first random number is located in the second half of the second splicing result; performing a hash message authentication code operation on the second splicing result and the quantum key to obtain the second message authentication code.
[0081] In some embodiments of the present application, the first device and the second device also store an authentication status matrix for recording authentication sessions and session status, wherein the fields in the authentication status matrix include at least one of the following: authentication session identifier, session initiator identifier, session receiver identifier, session serial number, and extended group attribute word corresponding to the session.
[0082] In some embodiments of the present application, the identification information of the quantum key includes the zone number of the zone where the quantum key is located and the key number of the quantum key.
[0083] It should be noted that the various modules in the above-mentioned device authentication device can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.
[0084] An embodiment of the present application provides a non-volatile storage medium, wherein a program is stored in the non-volatile storage medium, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the following device authentication method: a first device sends a first message of a border gateway protocol routing message type to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network, and identification information of the quantum key, and the first message carries the device identification information of the first device and the identification information of the quantum key; and a second message generated by the second device based on the first message is received, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is generated by the second device. a first random number; after receiving the second message, generating a second random number, and performing a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code; sending a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is used to verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is a border gateway protocol routing message; receiving a fourth message carrying the second message authentication code sent by the second device, and authenticating the second message authentication code, wherein the message type of the fourth message is a border gateway protocol routing message.
[0085] An embodiment of the present application provides an electronic device, comprising: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the following device authentication method is executed when the program is run: a first device publishes a first message of a border gateway protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network, and identification information of the quantum key, and the first message carries the device identification information of the first device and the identification information of the quantum key; and a second message generated by the second device based on the first message is received, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is the first message generated by the second device. a random number; after receiving the second message, generating a second random number, and performing a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code; sending a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is used to verify the first message authentication code, and performing a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is a border gateway protocol routing message; receiving a fourth message carrying the second message authentication code sent by the second device, and authenticating the second message authentication code, wherein the message type of the fourth message is a border gateway protocol routing message.
[0086] An embodiment of the present application provides a computer program product, including a computer program. When the computer program is executed by a processor, the computer program implements the following device authentication method: a first device publishes a first message of a border gateway protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network, and identification information of the quantum key, and the first message carries the device identification information of the first device and the identification information of the quantum key; a second message generated by the second device based on the first message is received, wherein the message type of the second message is a border gateway protocol routing message, and the group attribute of the second message is a first random number generated by the second device; and the receiving After receiving the second message, a second random number is generated, and a hash message authentication code operation is performed on the first random number, the second random number, and the quantum key to obtain a first message authentication code; a third message carrying the first message authentication code and the second random number is sent to the second device, wherein the second device is used to verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is a border gateway protocol routing message; a fourth message carrying the second message authentication code sent by the second device is received, and the second message authentication code is authenticated, wherein the message type of the fourth message is a border gateway protocol routing message.
[0087] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0088] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0089] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0090] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0091] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0092] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the relevant technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0093] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A device authentication method, characterized in that: include: A first device publishes a first message of a Border Gateway Protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network and identification information of the quantum key, and the first message carries device identification information of the first device and identification information of the quantum key; receiving a second message generated by the second device based on the first message, wherein the message type of the second message is the Border Gateway Protocol routing message, and the community attribute of the second message is a first random number generated by the second device; After receiving the second message, generating a second random number, and performing a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code; Sending a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is configured to verify the first message authentication code and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is the Border Gateway Protocol routing message; Receive a fourth message carrying the second message authentication code sent by the second device, and authenticate the second message authentication code, wherein the message type of the fourth message is the Border Gateway Protocol routing message.
2. The device authentication method according to claim 1, wherein: The first device includes a communication device, the second device includes a communication device or a soft-defined gateway controller of a quantum service platform, and the quantum service platform includes a quantum key service layer, a network operation control layer, and a network forwarding layer, wherein: The quantum key service layer is connected to the quantum key distribution network; The network operation control layer includes a soft-defined gateway controller and a routing transmitter; The network forwarding layer includes a router device, wherein the router device is used to receive border gateway protocol routing information, extract authentication information from the border gateway protocol routing information, and send the authentication information of the router device.
3. The device authentication method according to claim 2, wherein: The first device and the second device establish a neighbor relationship through the routing transmitter, and perform message exchange through the routing transmitter.
4. The device authentication method according to claim 1, wherein: The border gateway protocol routing message includes a custom security community attribute field, and the custom security community attribute field includes a high-order field and a low-order field, wherein: The high-order field includes a first character for indicating a message type, a second character for indicating a message sequence number, and a third character representing a link flag bit; The low-order field includes authentication information.
5. The device authentication method according to claim 1, wherein: Performing a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code includes: Splicing the first random number and the second random number to obtain a first splicing result, wherein the first random number is located in the first half of the first splicing result, and the second random number is located in the second half of the first splicing result; Perform a hash message authentication code operation on the first splicing result and the quantum key to obtain the first message authentication code.
6. The device authentication method according to claim 1, wherein: The second message authentication code is determined by: Splicing the second random number and the first random number to obtain a second splicing result, wherein the second random number is located in the first half of the second splicing result, and the first random number is located in the second half of the second splicing result; Perform a hash message authentication code operation on the second splicing result and the quantum key to obtain the second message authentication code.
7. The device authentication method according to claim 1, wherein: The first device and the second device also store an authentication status matrix for recording authentication sessions and session status, wherein the fields in the authentication status matrix include at least one of the following: authentication session identifier, session initiator identifier, session receiver identifier, session serial number, and extended community attribute word corresponding to the session.
8. The device authentication method according to claim 1, wherein: The identification information of the quantum key includes the zone number of the zone where the quantum key is located and the key number of the quantum key.
9. A device authentication method, characterized in that: include: The second device receives a first message published by the first device, the message type of which is a Border Gateway Protocol routing message, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network and identification information of the quantum key, and the first message carries the device identification information of the first device and the identification information of the quantum key; Sending a second message generated based on the first message to the first device, wherein the message type of the second message is the Border Gateway Protocol routing message, and the community attribute of the second message is a first random number generated by the second device; receiving a third message sent by the first device and carrying a first message authentication code and a second random number, wherein the first device is configured to, after receiving the second message, generate the second random number, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain the first message authentication code, and the message type of the third message is the Border Gateway Protocol routing message; verifying the first message authentication code, and performing a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code; A fourth message carrying the second message authentication code is sent to the first device, wherein the first device is used to authenticate the second message authentication code, and the message type of the fourth message is the Border Gateway Protocol routing message.
10. A device authentication system, characterized in that: Including quantum service platform, multiple communication equipment, among which, The quantum service platform includes a quantum key service layer, a network operation control layer, and a network forwarding layer. The quantum key service layer is connected to the quantum key distribution network. The network operation control layer includes a soft-defined gateway controller and a routing transmitter. The network forwarding layer includes a router device. The router device is used to receive border gateway protocol routing information, extract authentication information from the border gateway protocol routing information, and send the authentication information of the router device. The first device among the multiple communication devices is configured to publish a first message of a border gateway protocol routing message to a second device, wherein the first device is pre-filled with a quantum key distributed to the first device by a quantum key distribution network, and identification information of the quantum key, the first message carries device identification information of the first device and identification information of the quantum key, the first device is any device among the multiple communication devices, the second device is any device among the communication devices except the first device, or the soft-defined gateway controller; and receive a second message generated by the second device according to the first message, wherein the message type of the second message is the border gateway protocol routing message, and the group attribute of the second message is the first message generated by the second device. random number; after receiving the second message, generate a second random number, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code; send a third message carrying the first message authentication code and the second random number to the second device, wherein the second device is used to verify the first message authentication code, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is the Border Gateway Protocol routing message; receive a fourth message carrying the second message authentication code sent by the second device, and authenticate the second message authentication code, wherein the message type of the fourth message is the Border Gateway Protocol routing message.
11. A device authentication apparatus, suitable for use in an authentication initiating device, characterized in that: include: a first processing module, configured to publish a first message of a Border Gateway Protocol routing message to a receiving device, wherein the authentication initiating device is pre-filled with a quantum key distributed to the authentication initiating device by a quantum key distribution network and identification information of the quantum key, and the first message carries device identification information of the authentication initiating device and identification information of the quantum key; a second processing module, configured to receive a second message generated by the receiving device based on the first message, wherein the message type of the second message is the Border Gateway Protocol routing message, and the community attribute of the second message is a first random number generated by the receiving device; a third processing module, configured to, after receiving the second message, generate a second random number, and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a first message authentication code; a fourth processing module, configured to send a third message carrying the first message authentication code and the second random number to the receiving device, wherein the receiving device is configured to verify the first message authentication code and perform a hash message authentication code operation on the first random number, the second random number, and the quantum key to obtain a second message authentication code, and the message type of the third message is the Border Gateway Protocol routing message; The fifth processing module is used to receive a fourth message carrying the second message authentication code sent by the receiving device, and authenticate the second message authentication code, wherein the message type of the fourth message is the Border Gateway Protocol routing message.
12. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the device authentication method according to any one of claims 1 to 8 or claim 9.
13. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the program, when running, executes the device authentication method according to any one of claims 1 to 8 or claim 9.
14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the device authentication method according to any one of claims 1 to 8 or claim 9 are implemented.
Citation Information
Patent Citations
Metropolitan area network system for realizing quantum security encryption
CN112235318A
Information verification method and related equipment
CN118174967A