Key negotiation method for the initiating end and key negotiation method for the responding end

Through the IPSec VPN technology and digital envelope mechanism of the State Secret IPSec VPN technology and digital envelope mechanism, the identity checksum key protection is used to protect the identity checksum key, which solves the security risks of wireless communication in the rail transit signal system and realizes reliable data transmission and symmetric key negotiation.

CN119316211BActive Publication Date: 2025-07-25CRRC ZHUZHOU ELECTRIC LOCOMOTIVE RESEARCH INSTITUTE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411446265.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-16
Publication Date
2025-07-25
Estimated Expiration
2044-10-16

AI Technical Summary

Technical Problem

The prior art lacks security of wireless communication in rail transit signal systems, especially in data transmission between trains and ground systems, and the existing IPSec VPN negotiation process lacks identity identification and flexibility.

Method used

The National Secret IPSec VPN technology is adopted, and the key negotiation method between the initiator and the response side is used to symmetric and asymmetric encryption using SM1, SM2, SM3, SM4, SM9 algorithms, and digital certificates are generated for identity verification, and the random number of key source is protected through the digital envelope mechanism to establish a secure communication tunnel independent of service.

Benefits of technology

Reliable data transmission in wireless channels is realized, key security and transmission reliability are improved, communication network coupling is reduced and specific services is enhanced, and symmetric key negotiation is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119316211B_ABST
    Figure CN119316211B_ABST
Patent Text Reader

Abstract

The present invention provides a key negotiation method for an initiating party and a key negotiation method for a responding party. The key negotiation method for the initiating party includes the steps of: sending a first data packet including a first random number to the responding party; obtaining a second data packet returned by the responding party including a second random number and the digital certificate of the responding party; generating a first key source random number and a third random number, symmetrically encrypting the first key source random number based on the third random number, and asymmetrically encrypting the third random number based on the public key of the responding party in the digital certificate; sending the digital certificate of the initiating party to the responding party to obtain the encrypted second key source random number and a fourth random number returned by the responding party; determining the fourth random number according to the public key of the initiating party in the digital certificate of the initiating party, and determining the second key source random number according to the fourth random number; and determining a symmetric key between the initiating party and the responding party based on the first random number, the second random number, the first key source random number, and the second key source random number.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of wireless communication, and in particular, to a key negotiation method for an initiating end, a key negotiation system for an initiating end, a computer-readable storage medium, a key negotiation method for a responding end, a key negotiation system for a responding end, and a computer-readable storage medium. Background Art

[0002] The rail transit signal system uses the communication between trains and track equipment for traffic management and infrastructure control, integrating train operation command and train operation control, and is a key system affecting train driving safety and driving efficiency. Due to business needs, it is necessary to transfer data related to train operation and control to on-vehicle train control equipment.

[0003] Traditional manual transfer has problems such as low efficiency and high error probability. Therefore, wireless transfer is increasingly used in more and more scenarios. Figure 1 Fig. shows a schematic diagram of the wireless transfer network topology of a typical train control system, including three parts: an on-vehicle LKJ (Train Operation Monitoring Device) system 110, a wireless communication network 120, and a ground system 130. The on-vehicle LKJ system 110 mainly includes two types: LKJ2000 and LKJ-15. The wireless communication network 120 is a public mobile communication network (3G / 4G / 5G), and encrypts the communication channel of the wireless communication network 120 by establishing a proprietary virtual private network (VPN) based on IPSec (Internet Protocol Security), so as to realize two-way data encrypted transmission between the vehicle and the ground. The ground system 130 consists of a railway security transmission platform, a system server, and each transfer terminal. The data transfer module of the on-vehicle LKJ system 110 communicates with the ground transfer console 131 of the ground system 130 through the communication channel of the wireless communication network 120, thereby realizing the wireless transfer of on-vehicle train control equipment.

[0004] Due to the natural defects of wireless channels, there are security risks such as the theft of replacement data or man-in-the-middle attacks. Existing technologies (for example, Chinese Patent CN220043678U) are mainly used to implement the wireless replacement function on the LKJ, lacking content descriptions of security. The methods provided by existing technologies (for example, Chinese Patent CN115913727A) are mainly used for the mutual recognition and identification of the identities of vehicle-to-ground communication, focusing on the confirmation of the identities of both vehicle and ground parties. When the authentication fails, the access prohibition action is initiated through the ground firewall, lacking the protection of the security of the wireless communication network. Existing technologies (for example, Chinese Patent CN114162190A) use multi-thread technology to transmit LKJ wireless replacement data to the ground server to improve the transmission efficiency, focusing on the transmission efficiency aspect. However, the establishment of the existing security channels for communication has a strong coupling with the service and poor flexibility.

[0005] In addition, traditional RFC-based IPSec VPNs are based on internationally common cryptos such as AES, SHA256, and RSA. These cryptographic algorithms are designed by foreign institutions and lack controllability. Moreover, there are certain security risks in the negotiation process of RFC-based IPSec VPNs. For example, the basis of its main mode key exchange is DH (Diffie-Hellman) key exchange, and the exchange process lacks the authentication of the identities of both communication parties and cannot judge the credibility of the messages. Existing technologies (for example, Chinese Patent CN116647824A) use national cryptography algorithms SM2, SM3, and SM4 to encrypt the communication during vehicle-to-ground data transmission, but this patent does not describe the specific encryption form.

[0006] In order to overcome the above-mentioned defects existing in the prior art, there is an urgent need in the art for a key negotiation technology based on national cryptography IPSec VPN technology, which can establish a security negotiation process independent of the service, build a secure communication tunnel to ensure the security of the transmitted data, achieve the effect of reliable data transmission in the wireless channel, and can achieve the reliability of symmetric key negotiation. Summary of the Invention

[0007] The following presents a brief overview of one or more aspects to provide a basic understanding of these aspects. This overview is not an exhaustive survey of all contemplated aspects, and is neither intended to identify key or decisive elements of all aspects nor to define the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description that follows.

[0008] To overcome the above-mentioned defects existing in the prior art, the present invention provides a key negotiation method for an initiating end, a key negotiation system for an initiating end, and a computer-readable storage medium, as well as a key negotiation method for a responding end, a key negotiation system for a responding end, and a computer-readable storage medium, which can establish a security negotiation process independent of services, build a secure communication tunnel to ensure the security of transmitted data, achieve the effect of reliably transmitting data in a wireless channel, and can realize the reliability of symmetric key negotiation.

[0009] Specifically, the above-mentioned key negotiation method for an initiating end provided by the first aspect of the present invention includes the steps: Step S11: Sending a first data packet including a first random number to the responding party; Step S12: Obtaining a second data packet returned by the responding party including a second random number and the digital certificate of the responding party; Step S13: Generating a first key source random number and a third random number, symmetrically encrypting the first key source random number based on the third random number, and asymmetrically encrypting the third random number based on the public key of the responding party in the digital certificate of the responding party; Step S14: Sending the digital certificate of the initiating party to the responding party to obtain the encrypted second key source random number and a fourth random number returned by the responding party; Step S15: Determining the fourth random number according to the public key of the initiating party in the digital certificate of the initiating party, and determining the second key source random number according to the fourth random number; and Step S16: Determining the symmetric key between the initiating party and the responding party based on the first random number, the second random number, the first key source random number, and the second key source random number.

[0010] Preferably, in an embodiment of the present invention, Step S14 further includes: Sending the encrypted third random number and the encrypted first key source random number to the responding party, and the responding party determines the third random number according to the public key of the responding party and determines the first key source random number according to the third random number.

[0011] Preferably, in an embodiment of the present invention, Steps S13 and S14 further include: Symmetrically encrypting the first local identifier of the initiating party based on the third random number; and Sending the encrypted first local identifier to the responding party to identify the identity of the initiating party.

[0012] Preferably, in an embodiment of the present invention, Steps S13 and S14 further include: Overall signing the digital certificate of the initiating party, the encrypted third random number, the encrypted first key source random number, and the encrypted first local identifier based on the private key of the initiating party; and Sending the signature to the responding party together to ensure the authenticity of the transmitted data.

[0013] Preferably, in an embodiment of the present invention, the step S13 includes: performing the symmetric encryption by using the SM1 algorithm or the SM4 algorithm, and performing the asymmetric encryption by using the SM2 algorithm or the SM9 algorithm.

[0014] Preferably, in an embodiment of the present invention, the step S14 includes: generating a digital certificate of the initiator based on the SM2 algorithm.

[0015] Preferably, in an embodiment of the present invention, the step S16 includes: determining a symmetric key between the initiator and the responder by using the hashing operation of the SM3 algorithm.

[0016] Preferably, in an embodiment of the present invention, the initiator is an in-vehicle wireless replacement device, and the responder is a ground server.

[0017] In addition, a key negotiation method for a responder provided according to the second aspect of the present invention includes steps: Step S21: In response to receiving a first data packet including a first random number from the initiator, sending back a second data packet including a second random number and a digital certificate of the responder to the initiator; Step S22: In response to receiving the digital certificate of the initiator, the encrypted first key source random number, and the encrypted third random number, determining the third random number according to the responder public key in the digital certificate of the responder, and determining the first key source random number according to the third random number; Step S23: Generating a second key source random number and a fourth random number, performing symmetric encryption on the second key source random number based on the fourth random number, performing asymmetric encryption on the fourth random number based on the initiator public key in the digital certificate of the initiator, and sending the encrypted fourth random number and the encrypted second key source random number back to the initiator; and Step S24: Determining a symmetric key between the initiator and the responder based on the first random number, the second random number, the first key source random number, and the second key source random number.

[0018] Preferably, in an embodiment of the present invention, the step S23 further includes: performing symmetric encryption on a second local identifier of the responder based on the fourth random number; and sending back the encrypted second local identifier to the sender to identify the identity of the responder.

[0019] Preferably, in an embodiment of the present invention, the step S23 further includes: performing an overall signature on the encrypted fourth random number, the encrypted second key source random number, and the encrypted second local identifier based on the responder private key; and sending the signature back to the sender together to ensure the authenticity of the data sent back.

[0020] Preferably, in an embodiment of the present invention, the step S21 includes: generating a digital certificate of the responder based on the SM2 algorithm.

[0021] Preferably, in an embodiment of the present invention, the step S23 includes: performing the symmetric encryption using the SM1 algorithm or the SM4 algorithm, and performing the asymmetric encryption using the SM2 algorithm or the SM9 algorithm.

[0022] Preferably, in an embodiment of the present invention, the step S24 includes: determining the symmetric key between the initiator and the responder using the hashing operation of the SM3 algorithm.

[0023] Preferably, in an embodiment of the present invention, the initiator is an in-vehicle wireless replacement device, and the responder is a ground server.

[0024] In addition, the above-mentioned key negotiation system for the initiator provided by the third aspect of the present invention includes a memory and a processor. A computer instruction is stored on the memory. The processor is connected to the memory and is configured to execute the computer instruction stored on the memory to implement the key negotiation method for the initiator provided by the first aspect of the present invention.

[0025] In addition, the above-mentioned key negotiation system for the responder provided by the fourth aspect of the present invention includes a memory and a processor. A computer instruction is stored on the memory. The processor is connected to the memory and is configured to execute the computer instruction stored on the memory to implement the key negotiation method for the responder provided by the second aspect of the present invention.

[0026] In addition, a computer instruction is stored on the above-mentioned computer-readable storage medium provided by the fifth aspect of the present invention. When the computer instruction is executed by a processor, the key negotiation method for the initiator provided by the first aspect of the present invention is implemented.

[0027] In addition, a computer instruction is stored on the above-mentioned computer-readable storage medium provided by the sixth aspect of the present invention. When the computer instruction is executed by a processor, the key negotiation method for the responder provided by the second aspect of the present invention is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] After reading the detailed description of the embodiments of the present disclosure in conjunction with the following drawings, the above features and advantages of the present invention can be better understood. In the drawings, the components are not necessarily drawn to scale, and components with similar related characteristics or features may have the same or similar reference numerals.

[0029] Figure 1 Shows a schematic diagram of the wireless replacement network topology of a typical train control system;

[0030] Figure 2 shows a flowchart of a key negotiation method for an initiating end provided according to some embodiments of the present invention;

[0031] Figure 3 shows a flowchart of a key negotiation method for a responding end provided according to some embodiments of the present invention;

[0032] Figure 4 shows a schematic diagram of a key negotiation system for an initiating end provided according to some embodiments of the present invention; and

[0033] Figure 5 shows a schematic diagram of a key negotiation system for a responding end provided according to some embodiments of the present invention.

[0034] Reference numerals:

[0035] 110: vehicle-mounted LKJ system;

[0036] 120: wireless communication network;

[0037] 130: ground system;

[0038] 131: ground replacement console;

[0039] 10: key negotiation method for an initiating end;

[0040] 20: key negotiation method for a responding end;

[0041] S11~S16: steps;

[0042] S21~S24: steps;

[0043] 400: key negotiation system for an initiating end;

[0044] 500: key negotiation system for a responding end;

[0045] 410, 510: memories;

[0046] 411, 511: computer-readable storage media; and

[0047] 420, 520: processors. Detailed implementation manners

[0048] The present invention will be described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that the aspects described below in conjunction with the accompanying drawings and specific embodiments are merely exemplary and should not be construed as imposing any limitation on the protection scope of the present invention.

[0049] In the description of the present invention, it should be noted that, unless otherwise clearly specified and defined, the terms "installed", "connected", and "coupled" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0050] In addition, the "upper", "lower", "left", "right", "top", "bottom", "horizontal", and "vertical" used in the following description should be understood as the orientations shown in this section and the relevant drawings. Such relative terms are only for convenience of description and do not represent that the devices described need to be manufactured or operated in a specific orientation. Therefore, it should not be construed as a limitation to the present invention.

[0051] It can be understood that although terms such as "first", "second", and "third" can be used herein to describe various components, regions, layers, and / or parts, these components, regions, layers, and / or parts should not be limited by these terms, and these terms are only used to distinguish different components, regions, layers, and / or parts. Therefore, the first component, region, layer, and / or part discussed below can be referred to as the second component, region, layer, and / or part without departing from some embodiments of the present invention.

[0052] As mentioned above, due to the natural defects of wireless channels, there are security risks such as the theft of replacement data or man-in-the-middle attacks. The prior art (for example, Chinese Patent CN220043678U) is mainly used to implement the wireless replacement function on the LKJ and lacks a description of security content. The method provided by the prior art (for example, Chinese Patent CN115913727A) is mainly used for the mutual recognition and identification of the identities of vehicle-to-ground communication, focusing on the confirmation of the identities of both the vehicle and the ground. When the authentication fails, a prohibited access action is initiated through the ground firewall, lacking the protection of the security of the wireless communication network. The prior art (for example, Chinese Patent CN114162190A) improves the transmission efficiency by transmitting the LKJ wireless replacement data to the ground server through multi-threading technology, focusing on the transmission efficiency. However, the establishment of the existing secure channel for communication has a strong coupling with the service and poor flexibility.

[0053] In addition, traditional RFC-based IPSec VPNs are based on internationally common ciphers such as AES, SHA256, and RSA, which are designed by foreign institutions and lack controllability. Moreover, there are certain security risks in the negotiation process of RFC-based IPSec VPNs. For example, the basis of its main mode key exchange is DH key exchange, and the identity of both communication parties is not authenticated during the exchange process, making it impossible to judge the credibility of messages. Existing technologies (e.g., Chinese Patent CN116647824A) use SM2, SM3, and SM4 to encrypt communications in vehicle-ground data transmission, but this patent does not describe the specific encryption form.

[0054] To overcome the above-mentioned defects existing in the prior art, the present invention provides a key negotiation method for an initiating end, a key negotiation system for an initiating end, and a computer-readable storage medium, as well as a key negotiation method for a responding end, a key negotiation system for a responding end, and a computer-readable storage medium, which can establish a security negotiation process independent of services, build a secure communication tunnel to ensure the security of transmitted data, achieve the effect of reliable data transmission in a wireless channel, and realize the reliability of symmetric key negotiation.

[0055] In some non-limiting embodiments, the above-mentioned key negotiation method for the initiating end provided by the first aspect of the present invention can be implemented via the above-mentioned key negotiation system for the initiating end provided by the third aspect of the present invention. The above-mentioned key negotiation method for the responding end provided by the second aspect of the present invention can be implemented via the above-mentioned key negotiation system for the responding end provided by the fourth aspect of the present invention.

[0056] The above-mentioned key negotiation method for the initiating end and the above-mentioned key negotiation method for the responding end provided by the present invention can be used to solve the security problem of train control wireless reloading, and ensure the security of train control wireless reloading based on the national cipher IPSec VPN technology. Moreover, it can decouple the network security of wireless communication from the specific wireless reloading service, and thus is also applicable to other service scenarios. When the above-mentioned key negotiation method for the initiating end and the above-mentioned key negotiation method for the responding end provided by the present invention are used to solve the security problem of train control wireless reloading, the initiating end can be an on-vehicle wireless reloading device, and the responding end can be a ground server.

[0057] The working principle of the above-mentioned key negotiation system for the initiating end will be described below in conjunction with some embodiments of the key negotiation method for the initiating end. Those skilled in the art can understand that these embodiments of the key negotiation method for the initiating end are only some non-limiting implementation manners provided by the present invention, aiming to clearly show the main concept of the present invention and provide some specific solutions convenient for the public to implement, rather than limiting all functions or all working manners of the key negotiation system for the initiating end. Similarly, the key negotiation system for the initiating end is also a non-limiting implementation manner provided by the present invention, and does not limit the execution subject and execution order of each step in these key negotiation methods for the initiating end.

[0058] In addition, the working principle of the above-mentioned key negotiation system for the responding end will be described below in conjunction with some embodiments of the key negotiation method for the responding end. Those skilled in the art can understand that these embodiments of the key negotiation method for the responding end are only some non-limiting implementation manners provided by the present invention, aiming to clearly show the main concept of the present invention and provide some specific solutions convenient for the public to implement, rather than limiting all functions or all working manners of the key negotiation system for the responding end. Similarly, the key negotiation system for the responding end is also a non-limiting implementation manner provided by the present invention, and does not limit the execution subject and execution order of each step in these key negotiation methods for the responding end.

[0059] Please refer to Figure 2 and Figure 3 , Figure 2 which shows a flowchart of a key negotiation method for the initiating end provided according to some embodiments of the present invention, Figure 3 which shows a flowchart of a key negotiation method for the responding end provided according to some embodiments of the present invention.

[0060] As Figure 2 shown, the key negotiation method 10 for the initiating end may include step S11: sending a first data packet including a first random number to the responding party.

[0061] The initiating party may be an in-vehicle wireless replacement device, and the responding party may be a ground server. The initiating party may generate a first random number CKY_I and send the first random number CKY_I as a field of the first data packet to the responding party.

[0062] After that, as Figure 3 shown, the key negotiation method 20 for the responding end may include step S21: in response to receiving the first data packet including the first random number from the initiating party, sending a second data packet including a second random number and the digital certificate of the responding party back to the initiating party.

[0063] After receiving the first data packet including the first random number from the initiating party, the responding party can generate a second random number CKY_R and send the second random number CKY_R back to the initiating party as a field of the second data packet. The second data packet may also include the digital certificate of the responding party. The digital certificate can be the signature certificate and encryption certificate of the responding party. Here, the digital certificate can be generated based on SM2.

[0064] In addition, in step S11, the first data packet may further include a payload, and the payload can be used for the user data part of the actual transmission. In the wireless dressing change scenario, the vehicle-mounted wireless dressing change device can send an SA (Security Association) payload encapsulating a proposed payload to the responding end ground server, and the proposed payload can further encapsulate a transformed payload. Here, SA is an agreement established through negotiation between two concentric entities. Through the SA payload, the security protocol between the initiating party and the responding party, the encapsulation method of the message, the encryption and verification algorithms, etc. can be agreed upon.

[0065] Correspondingly, the second data packet also includes the SA payload sent back to the initiating party, and the SA payload in the second data packet is used to respond to the proposed payload encapsulated in the SA payload sent by the initiating party in step S11.

[0066] Please continue to refer to Figure 2 , the key negotiation method 10 for the initiating end may include step S12 and step S13:

[0067] Obtain the second data packet sent back by the responding party including the second random number and the digital certificate of the responding party;

[0068] Generate a first key source random number and a third random number, perform symmetric encryption on the first key source random number based on the third random number, and perform asymmetric encryption on the third random number based on the public key of the responding party in the digital certificate of the responding party.

[0069] After receiving the second random number and the digital certificate of the responding party sent back by the responding party, the initiating party can obtain the public key pub_r of the responding party in the certificate according to the digital certificate of the responding party. Then, the initiating party can randomly generate a first key source random number Nonce_i and a third random number Ski_i.

[0070] The first key source random number Nonce_i is symmetrically encrypted by the third random number Ski_i. The symmetric encryption algorithm can use the SM1 algorithm or the SM4 algorithm; then the third random number Ski_i is asymmetrically encrypted using the responder's public key pub_r, thereby implementing the digital envelope mechanism to protect the third random number Ski_i and prevent the first key source random number Nonce_i from being easily cracked, so that the key for each negotiation session (i.e., the third random number Ski_i) is carried out under the protection of the digital envelope, effectively enhancing the security of the key. Preferably, the SM2 algorithm or the SM9 algorithm can be used for asymmetric encryption. By using the national cryptographic algorithms SM1, SM2, SM3, SM4, and SM9, the controllability of cryptographic technology can be achieved.

[0071] After that, the key negotiation method 10 for the initiator can execute step S14: sending the digital certificate of the initiator to the responder to obtain the encrypted second key source random number and the fourth random number sent back by the responder. Here, the digital certificate of the initiator can be generated based on SM2.

[0072] Preferably, in addition to sending the digital certificate of the initiator, the initiator can also send the encrypted third random number and the encrypted first key source random number to the responder.

[0073] Please refer to Figure 3 For the key negotiation method 20 for the responder, it can include step S22: in response to receiving the digital certificate of the initiator, the encrypted first key source random number, and the encrypted third random number, determining the third random number according to the responder's public key in the responder's digital certificate, and determining the first key source random number according to the third random number.

[0074] In this preferred embodiment, the responder can determine the third random number Ski_i according to the responder's public key pub_r, and then determine the first key source random number Nonce_i according to the third random number Ski_i.

[0075] More preferably, in step S13, the initiator can also symmetrically encrypt the first local identifier IDi of the initiator based on the third random number Ski_i. The symmetric encryption algorithm can use the SM1 algorithm or the SM4 algorithm. After that, in step S14, the encrypted first local identifier IDi is sent to the responder, and the responder can identify the identity of the initiator based on this. This can improve the problem of being unable to verify the identity of the other party in the traditional IPSec VPN technology using the DH negotiation algorithm in RFC. Here, the first local identifier IDi can be a specific wireless dressing equipment ID number or a train number.

[0076] In this more preferred embodiment, in step S13, the initiator may perform an overall signature on the initiator's digital certificate, the encrypted third random number, the encrypted first key source random number, and the encrypted first local identifier based on the initiator's private key; and in step S14, send the signature to the responder together, so as to ensure the authenticity of the content of the data sent.

[0077] After that, as Figure 3 shown, the key negotiation method 20 for the responder may include step S23: generating a second key source random number and a fourth random number, symmetrically encrypting the second key source random number based on the fourth random number, asymmetrically encrypting the fourth random number based on the initiator's public key in the initiator's digital certificate, and sending the encrypted fourth random number and the encrypted second key source random number back to the initiator.

[0078] The responder obtains the initiator's public key pub_i in the certificate according to the initiator's digital certificate received in step S22. After that, the responder may randomly generate a second key source random number Nonce_r and a fourth random number Ski_r.

[0079] Symmetrically encrypt the second key source random number Nonce_r with the fourth random number Ski_r. The symmetric encryption algorithm may adopt the SM1 algorithm or the SM4 algorithm; then asymmetrically encrypt the fourth random number Ski_r with the initiator's public key pub_i, thereby implementing the digital envelope mechanism to protect the fourth random number Ski_r and prevent the second key source random number Nonce_r from being easily cracked, so that the fourth random number Ski_r of each negotiation session is protected under the digital envelope, effectively improving the security of the key. Preferably, the SM2 algorithm or the SM9 algorithm may be used for asymmetric encryption. Thus, the symmetric key is protected by the asymmetric key to achieve reliable key negotiation and realize the unification of the subsequent keys at both ends.

[0080] After the responder encrypts the randomly generated second key source random number Nonce_r and the fourth random number Ski_r, it may send the encrypted fourth random number and the encrypted second key source random number back to the initiator. Preferably, the responder may also symmetrically encrypt the responder's second local identifier IDr with the fourth random number Ski_r. The symmetric encryption algorithm may adopt the SM1 algorithm or the SM4 algorithm. When sending back the encrypted fourth random number and the encrypted second key source random number, send the encrypted second local identifier IDr back to the initiator, and the initiator may identify the responder's identity based on this.

[0081] Preferably, the data including the encrypted fourth random number, the encrypted second key source random number, and the encrypted second local identifier sent back to the initiator can also be overall signed with the responder's private key to ensure the authenticity of the sent-back data.

[0082] As Figure 1 shown, after receiving the encrypted fourth random number and the encrypted second key source random number sent back by the responder, the initiator can execute step S15 of the key negotiation method 10 for the initiator side: determine the fourth random number according to the initiator's public key in the initiator's digital certificate, and determine the second key source random number according to the fourth random number.

[0083] The initiator can decrypt the encrypted fourth random number according to its own initiator's public key pub_i to determine the fourth random number Ski_r, and then decrypt the encrypted second key source random number according to the determined fourth random number Ski_r to determine the second key source random number Nonce_r.

[0084] Thus, in this preferred embodiment, through steps S11 - S15 of the key negotiation method 10 for the initiator side and steps S21 - S23 of the key negotiation method 20 for the responder side, both the initiator side and the responder side can confirm the first random number CKY_I, the second random number CKY_R, the first key source random number Nonce_i, and the second key source random number Nonce_r.

[0085] As Figure 2 、 Figure 3 shown, the initiator side can execute step S16, and the responder side can execute step S24 to determine the symmetric key between the initiator and the responder based on the first random number CKY_I, the second random number CKY_R, the first key source random number Nonce_i, and the second key source random number Nonce_r. The generated symmetric key can be used for subsequent business communication between the initiator and the responder.

[0086] Preferably, the initiator and the responder can use the hashing operation of SM3 to determine the symmetric key between the two ends. For example, use the HMAC (Keyed - Hash Message Authentication Code, hashing operation with a key) of SM3 to determine the symmetric key SKEYID. The specific calculation method is as follows:

[0087] SKEYID = HMAC(HASH(Nonce_i|Nonce_r),CKY_I|CKY_R)

[0088] The first key source random number Nonce_i and the second key source random number Nonce_r are concatenated and then the output value is determined using the HASH algorithm. Then, the HMAC algorithm is used to perform a hashing operation on the concatenated value of this output value and the first random number CKY_I and the second random number CKY_R to determine the final symmetric key SKEYID. This final symmetric key SKEYID can unify the keys at both ends, and the symmetric key SKEYID can be used to symmetrically encrypt data during subsequent communication between the initiating end and the responding end. Preferably, the symmetric encryption of subsequent communication between the two ends can be implemented using the SM4 algorithm.

[0089] In summary, the key negotiation method provided by the present invention adopts the mechanism of a digital envelope based on the national cryptographic algorithm, uses the SM2 algorithm to generate a digital certificate to first verify the identities of both parties. On this premise, the key source random number generated by this device is encrypted and protected using the public key of the other party, and then received by the other party and decrypted using the public key and private key of this end to obtain the key source random number of the other end. The key source random number of the other end and the key source random number generated by this end are used as input sources to calculate and generate the session key for subsequent services.

[0090] Thus, the key negotiation method provided by the present invention can be independent of services, have low coupling, and establish a set of secure communication tunnels, solve potential security hazards in wireless communication, and effectively improve the security of keys.

[0091] In addition, please refer to Figure 4 and Figure 5 , Figure 4 which shows a schematic diagram of a key negotiation system for an initiating end provided according to some embodiments of the present invention, Figure 5 which shows a schematic diagram of a key negotiation system for a responding end provided according to some embodiments of the present invention.

[0092] As Figure 4 shown, the key negotiation system 400 for the initiating end may be configured with a memory 410 and a processor 420. The memory 410 includes but is not limited to the above-mentioned computer-readable storage medium 411 provided in the fifth aspect of the present invention, on which computer instructions are stored. The processor 420 is connected to the memory 410 and is configured to execute the computer instructions stored on the memory 410 to implement the key negotiation method for the initiating end provided in the first aspect of the present invention.

[0093] Similarly, Figure 5In the key negotiation system 500 for the response end shown, a memory 510 and a processor 520 can be configured. The memory 510 includes, but is not limited to, the above-mentioned computer-readable storage medium 511 provided in the sixth aspect of the present invention, on which computer instructions are stored. The processor 520 is connected to the memory 510 and is configured to execute the computer instructions stored on the memory 510 to implement the key negotiation method for the response end provided in the second aspect of the present invention.

[0094] Although the above methods are illustrated and described as a series of actions for simplicity of explanation, it should be understood and appreciated that these methods are not limited by the order of the actions, because according to one or more embodiments, some actions may occur in a different order and / or concurrently with other actions that are illustrated and described herein or that are not illustrated and described herein but are understood by those skilled in the art.

[0095] Those skilled in the art will understand that information, signals, and data can be represented using any of a variety of different technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips described throughout the above description may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or optical particles, or any combination thereof.

[0096] Those skilled in the art will further appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of the two. To clearly illustrate this interchangeability of hardware and software, the various illustrative components, blocks, modules, circuits, and steps are described above in terms of their functionality in a generalized form. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. A person skilled in the art can implement the described functionality in different ways for each specific application, but such implementation decisions should not be construed as causing a departure from the scope of the present invention.

[0097] The various illustrative logical modules and circuits described in connection with the embodiments disclosed herein can be implemented or executed using a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gates or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. The general-purpose processor can be a microprocessor, but in an alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors cooperating with a DSP core, or any other such configuration.

[0098] The steps of a method or algorithm described in connection with the embodiments disclosed in this specification can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read from, and write to, the storage medium. In an alternative, the storage medium may be integrated into the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. In an alternative, the processor and the storage medium may reside as discrete components in a user terminal.

[0099] In one or more exemplary embodiments, the described functionality may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software as a computer program product, the functions may be stored on or transmitted via a computer-readable medium as one or more instructions or code. The computer-readable medium includes both a computer storage medium and a communication medium including any medium that facilitates transfer of a computer program from one place to another. A storage medium may be any available medium that can be accessed by a computer. By way of example and not limitation, such a computer-readable medium may comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a web site, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable medium.

[0100] The prior description of the present disclosure is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to the present disclosure will be apparent to those skilled in the art, and the general principles defined herein can be applied to other variations without departing from the spirit or scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the examples and designs described herein, but should be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A key negotiation method for an initiating end, characterized in that, Including steps: Step S11: Sending a first data packet including a first random number to the responder; Step S12: Obtaining a second data packet sent back by the responder, which includes a second random number and the digital certificate of the responder; Step S13: Generating a first key source random number and a third random number, symmetrically encrypting the first key source random number and the first local identifier of the initiator based on the third random number, and asymmetrically encrypting the third random number based on the responder public key in the digital certificate of the responder; Step S14: Sending the digital certificate of the initiator, the encrypted first key source random number, the third random number, and the first local identifier for identity recognition to the responder, so as to obtain the encrypted second key source random number, the fourth random number, and the second local identifier of the responder sent back by the responder; Step S15: Determining the fourth random number according to the initiator public key in the digital certificate of the initiator, determining the second key source random number according to the fourth random number, and determining the second local identifier to verify the identity of the responder; And Step S16: Determining the symmetric key between the initiator and the responder based on the first random number, the second random number, the first key source random number, and the second key source random number.

2. The key negotiation method according to claim 1, wherein Step S14 further includes: Sending the encrypted third random number and the encrypted first key source random number to the responder, and the responder determines the third random number according to the responder public key and determines the first key source random number according to the third random number.

3. The key negotiation method according to claim 1, wherein Steps S13 and S14 further include: Overall signing the digital certificate of the initiator, the encrypted third random number, the encrypted first key source random number, and the encrypted first local identifier based on the initiator private key; and Sending the signature to the responder together to ensure the authenticity of the data sent.

4. The key negotiation method according to claim 1, wherein Step S13 includes: Performing the symmetric encryption using the SM1 algorithm or the SM4 algorithm, and performing the asymmetric encryption using the SM2 algorithm or the SM9 algorithm.

5. The key negotiation method according to claim 1, wherein Step S14 includes: Generating the digital certificate of the initiator based on the SM2 algorithm.

6. The key negotiation method according to claim 1, wherein Step S16 includes: Determining the symmetric key between the initiator and the responder using the hash operation of the SM3 algorithm.

7. The key negotiation method according to claim 1, wherein The initiator is an in-vehicle wireless replacement device, and the responder is a ground server.

8. A key negotiation method for a response end, characterized in that, Including steps: Step S21: In response to receiving the first data packet including the first random number from the initiator, sending back a second data packet including the second random number and the digital certificate of the responder to the initiator; Step S22: In response to receiving the digital certificate of the initiator, the encrypted first key source random number, the encrypted third random number, and the first local identifier of the initiator, determining the third random number according to the responder public key in the digital certificate of the responder, determining the first key source random number according to the third random number, and determining the first local identifier to verify the identity of the initiator; Step S23: Generate a second key source random number and a fourth random number, symmetrically encrypt the second key source random number and the second local identifier of the responder based on the fourth random number, asymmetrically encrypt the fourth random number based on the public key of the initiator in the digital certificate of the initiator, and send the encrypted fourth random number, the encrypted second key source random number, and the encrypted second local identifier back to the initiator; And Step S24: Determine the symmetric key between the initiator and the responder based on the first random number, the second random number, the first key source random number, and the second key source random number.

9. The key negotiation method according to claim 8, wherein The step S23 further includes: Overall sign the encrypted fourth random number, the encrypted second key source random number, and the encrypted second local identifier based on the private key of the responder; and Send the signature back to the initiator together to ensure the authenticity of the data sent back.

10. The key negotiation method according to claim 8, wherein The step S21 includes: Generate the digital certificate of the responder based on the SM2 algorithm.

11. The key negotiation method according to claim 8, wherein The step S23 includes: Perform the symmetric encryption using the SM1 algorithm or the SM4 algorithm, and perform the asymmetric encryption using the SM2 algorithm or the SM9 algorithm.

12. The key negotiation method according to claim 8, wherein The step S24 includes: Determine the symmetric key between the initiator and the responder by means of the hashing operation of the SM3 algorithm.

13. The key negotiation method according to claim 8, wherein, The initiator is an in-vehicle wireless replacement device, and the responder is a ground server.

14. A key negotiation system for an initiating end, characterized in that, Comprising: A memory storing computer instructions thereon; And A processor connected to the memory and configured to execute the computer instructions stored on the memory to implement the key negotiation method for the initiator according to any one of claims 1 to 7.

15. A key negotiation system for a response end, characterized in that, Comprising: A memory storing computer instructions thereon; And A processor connected to the memory and configured to execute the computer instructions stored on the memory to implement the key negotiation method for the responder according to any one of claims 8 to 13.

16. A computer-readable storage medium having computer instructions stored thereon, characterized in that, When the computer instructions are executed by the processor, the key negotiation method for the initiator according to any one of claims 1 to 7 is implemented.

17. A computer-readable storage medium having computer instructions stored thereon, characterized in that, When the computer instructions are executed by the processor, the key negotiation method for the responder according to any one of claims 8 to 13 is implemented.

Citation Information

Patent Citations

  • Multi-thread LKJ vehicle-mounted data wireless reloading data file transmission technical method

    CN114162190A

  • Method and system for realizing wireless reloading uniqueness identification of LKJ data based on digital certificate

    CN115913727A

  • Vehicle-mounted basic data and temporary data wireless reloading system and reloading method

    CN116647824A

  • LKJ vehicle-mounted data wireless reloading device

    CN220043678U

  • Information security management and control method under cloud manufacturing environment

    CN102710605A