Point-to-point secure communication method, device and electronic device of trusted controller

By using physical key switches and random inputs in the industrial control system to generate the initial product shared key, and combining the Dragonfly key exchange protocol algorithm for key negotiation, two-way identity authentication and information encryption are realized, the security problem of point-to-point communication between controllers is solved and the security and reliability of the system is improved.

CN119519971BActive Publication Date: 2025-05-09NINGBO HOLLYSHI INFORMATION SECURITY RES INST CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510074353.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-09
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

The inter-point-to-point communication between controllers in existing industrial control systems lacks effective authentication and encryption measures, and is vulnerable to monitoring, counterfeiting, tampering and replay attacks, resulting in increased system risks.

Method used

A point-to-point secure communication method of a trusted controller is adopted, and the initial product shared key is generated through physical key switches and random inputs, and the key negotiation is carried out in combination with the Dragonfly key exchange protocol algorithm to realize two-way identity authentication, and the transmission information is encrypted using the associated data authentication encryption algorithm.

Benefits of technology

Effectively resist monitoring, counterfeiting, tampering and replay attacks, ensure the authenticity and integrity of communication content between controllers, and improve the security and reliability of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119519971B_ABST
    Figure CN119519971B_ABST
Patent Text Reader

Abstract

The present invention discloses a point-to-point secure communication method, device and electronic device of a trusted controller, and relates to the field of point-to-point communication. The point-to-point communication deployment of the trusted controller is divided into a configuration phase, a connection phase and a working phase. In the configuration phase, based on a physical key switch and a key generated by a random input, and based on a random number generated by a built-in trusted platform control module and a dragonfly key exchange protocol algorithm, pairing is performed between controller nodes, so that the password is visible only to both devices, greatly enhancing the security of the point-to-point channel. In the working phase, the HKDF algorithm is adopted to implement the adaptation of the encryption algorithm and the encryption strength based on the synchronous data feature definition, and different encryption algorithms and strengths are adopted for different data types, thereby improving the real-time performance while ensuring the communication security. The present invention effectively resists eavesdropping, counterfeiting, tampering and replay attacks, and ensures the authenticity, integrity, security and reliability of the communication content between controllers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of point-to-point communication in industrial automation systems, and in particular relates to a point-to-point secure communication method, device and electronic equipment of a trusted controller. Background Art

[0002] In addition to communicating with programming platforms / SCADA / HMI, large PLC / DCS controllers also need to communicate point-to-point. For example, for redundant functions, the host and backup machines work simultaneously and keep status synchronized based on point-to-point communication. The information they interact with is the calculation results of the control system control unit, system status, engineering files and other sensitive information. Malicious third parties can analyze the interactive information through monitoring, and then counterfeit and tamper with it to control the system output behavior. Since large PLC / DCS controller systems are generally used in critical infrastructure such as water conservancy / hydropower / nuclear power / oil and gas, which have high requirements for stability and reliability, this type of horizontal attack on controllers is different from traditional north-south communication. The attack is hidden and diverse, such as frequently triggering redundant switching, tampering with calculation results and status information, and triggering it when necessary. The purpose of communication between controllers is to improve the reliability of the system and the efficiency of system information interaction, and to collaborate to form a control network. If there are no communication security precautions, they are easy to become the target of attack, resulting in increased control system risks. The typical logic block diagram of a point-to-point controller is as follows: Figure 1 The traditional communication method between controllers does not consider the authentication and encryption between controllers, and the information is easily eavesdropped or forged, and cannot resist replay attacks.

[0003] CN118041646A proposes a central negotiation unilateral distribution point-to-point instant communication encryption method, medium and terminal. According to the point-to-point communication characteristics of instant communication, when the sender applies for a key from the central end, the key generated by the central end is protected by the sender's key and the receiver's key respectively and then sent to the sender at one time. The key generated by the central end is completely different from the key generated by negotiation between endpoints, and the application field is also different.

[0004] CN110505263A proposes a point-to-point communication network system, including a backplane, a communication module, and multiple groups of sequences; the processor module controls the input and output modules in the sequence in a point-to-point manner, realizing point-to-point communication within the controller system, and point-to-point communication between non-involved controllers.

[0005] CN116614291A proposes a method and system for secure information transmission based on a multi-redundant CNC bus, which uses encryption and integrity verification measures between the master station and the slave station, but does not mention the encryption method between the master station and the slave station.

[0006] CN107835157A proposes a data redundancy encryption method based on a heartbeat mechanism, and describes a method for detecting the operating status of the other end through a heartbeat mechanism and performing service configuration between a master and a slave encryption machine, which is different from the encryption process and mechanism described in the present invention.

[0007] Therefore, currently no public documents and materials with solutions similar to the present invention have been found. Summary of the invention

[0008] In order to solve the above problems, the present invention proposes a point-to-point secure communication method, device and electronic device for a trusted controller, which can authenticate and encrypt point-to-point communication information between controllers, effectively resist eavesdropping, counterfeiting, tampering and replay attacks, ensure that the communication content between controllers is authentic and complete, and improve the security and reliability of industrial control systems in critical infrastructure.

[0009] In a first aspect, the present invention provides a point-to-point secure communication method of a trusted controller, which is applied to a first secure trusted controller, and the method includes:

[0010] Entering a pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user;

[0011] Obtaining an initial product shared key sent by an engineer station; wherein the initial product shared key is generated by the engineer station based on random input by a user;

[0012] Perform key negotiation with the second secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain a product shared key;

[0013] The product shared key is stored so as to perform two-way identity authentication based on the product shared key when connecting with the second secure trusted controller.

[0014] In an optional implementation, the key agreement algorithm includes a Dragonfly key exchange protocol algorithm.

[0015] In an optional implementation manner, performing key negotiation with the second secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain the product shared key includes:

[0016] Sending an authentication request to the second secure trusted controller;

[0017] In response to the authentication reply of the second secure and trusted controller, generate a first random number; wherein the first random number is generated based on a trusted platform control module built into the first secure and trusted controller;

[0018] Determine a first commitment value according to the first random number and a unique mapping of the initial product shared key on a preset elliptic curve;

[0019] sending the first commitment value to the second secure trusted controller;

[0020] Obtaining a second commitment value sent by the second security trusted controller;

[0021] Determine a first confirmation value based on the second commitment value, the first random number and the initial product shared key in combination with the elliptic curve Diffie-Hellman key exchange protocol algorithm;

[0022] Determine a first verification value based on the first confirmation value, the second commitment value, and the initial product shared key in combination with a hash algorithm;

[0023] Obtaining a second verification value sent by the second security trusted controller;

[0024] Whether the verification is successful is determined based on the first verification value and the second verification value, and if so, the first confirmation value is used as a product shared key.

[0025] In an optional implementation manner, storing the product shared key includes:

[0026] The product shared key is stored in a trusted platform control module of the first secure trusted controller.

[0027] In an optional implementation manner, when connecting with the second secure trusted controller, performing two-way identity authentication based on the product shared key includes:

[0028] Obtaining the product shared key;

[0029] Based on the product shared key and the Dragonfly key exchange protocol algorithm, using the second secure trusted controller to perform identity authentication;

[0030] In response to successful authentication, generating a pre-master key using the Dragonfly key exchange protocol algorithm;

[0031] The pre-master key is stored in the trusted platform control module of the first secure trusted controller, so as to synchronously transmit the target information to be transmitted between the first secure trusted controller and the second secure trusted controller by using the pre-master key.

[0032] In an optional implementation manner, the synchronously transmitting the target information to be transmitted between the first secure trusted controller and the second secure trusted controller by using the pre-master key includes:

[0033] Determining a target data type corresponding to target information transmitted between the first secure and trusted controller and the second secure and trusted controller;

[0034] Encrypting key support feature information using an associated data authentication encryption algorithm and the pre-master key; wherein the key support feature information includes the target data type, the target encryption algorithm corresponding to the target data type, and the target key length corresponding to the target encryption algorithm; the target encryption algorithm and the target key length are determined from a pre-configured data encryption type table;

[0035] Sending the key support feature information to the second secure trusted controller;

[0036] In response to the support information sent by the second secure trusted controller, determine whether the pre-master key meets the target key length; if so, encrypt the target information according to the pre-master key and the target encryption algorithm; if not, according to the target key length, use the HKDF algorithm to expand the pre-master key to obtain an extended key with a length of the target key length, and encrypt the target information according to the extended key and the target encryption algorithm; and, in response to the non-support information sent by the second secure trusted controller, encrypt the target information according to the associated data authentication encryption algorithm and the pre-master key.

[0037] In an optional implementation, the step of performing key expansion on the pre-master key using the HKDF algorithm according to the target key length to obtain an extended key having a length equal to the target key length includes:

[0038] Obtain the pre-master key, the salt value, the target key length and an optional information string; wherein the salt value is the current time;

[0039] Determine a pseudo-random key according to a message authentication code algorithm based on a hash function, the pre-master key and the salt value;

[0040] Initialize extended key;

[0041] Iterate the following steps (1) to (2) until the updated extended key length is no less than the target key length:

[0042] Step (1), determining a current HMAC value according to the HMAC algorithm, the optional information string and the pseudo-random key;

[0043] Step (2), splicing the current HMAC value into the extended key to obtain an updated extended key;

[0044] Determine whether the length of the updated extended key is greater than the target key length. If so, truncate the updated extended key to obtain an extended key with a length equal to the target key length. If not, proceed to the next step.

[0045] Returns an extended key of the length of the target key.

[0046] In a second aspect, the present invention provides a point-to-point secure communication method of a trusted controller, which is applied to a second secure trusted controller, and the method includes:

[0047] Entering a pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user;

[0048] Obtaining an initial product shared key sent by an engineer station; wherein the initial product shared key is generated by the engineer station based on random input by a user;

[0049] Perform key negotiation with the first secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain a product shared key;

[0050] The product shared key is stored so as to perform two-way identity authentication based on the product shared key when connecting with the first secure trusted controller.

[0051] In a third aspect, the present invention provides a point-to-point secure communication device of a trusted controller, which is applied to a first secure trusted controller, and the device includes:

[0052] A first pairing module, configured to enter a pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user;

[0053] A first data acquisition module is used to acquire an initial product shared key sent by an engineer station; wherein the initial product shared key is generated by the engineer station based on random input by a user;

[0054] A first key negotiation module, configured to perform key negotiation with the second secure and trusted controller based on a key negotiation algorithm and the initial product shared key to obtain a product shared key;

[0055] The first key storage module is used to store the product shared key so as to perform two-way identity authentication based on the product shared key when connecting with the second secure trusted controller.

[0056] In a fourth aspect, the present invention provides a point-to-point secure communication device of a trusted controller, which is applied to a second secure trusted controller, and the device includes:

[0057] A second pairing module, configured to enter a pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user;

[0058] A second data acquisition module is used to acquire an initial product shared key sent by an engineer station; wherein the initial product shared key is generated by the engineer station based on random input by a user;

[0059] A second key negotiation module, configured to perform key negotiation with the first secure and trusted controller based on a key negotiation algorithm and the initial product shared key to obtain a product shared key;

[0060] The second key storage module is used to store the product shared key so as to perform two-way identity authentication based on the product shared key when connecting to the first secure trusted controller.

[0061] In a fifth aspect, the present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of the aforementioned implementations when executing the computer program.

[0062] In a sixth aspect, the present invention provides a computer-readable medium having a non-volatile program code executable by a processor, wherein the program code enables the processor to execute the method described in any one of the aforementioned embodiments.

[0063] The technical solution provided by the embodiment of the present invention has the following beneficial effects: the point-to-point secure communication method, device and electronic device of the trusted controller of the present invention, in the configuration stage, generates a key based on a physical key switch and random input, combines the random number generated by the trusted platform control module and the key negotiation algorithm, and performs pairing between controller nodes, thereby realizing point-to-point secure communication of the trusted controller; and because the pairing instruction is triggered by the engineer station based on the physical key switch inserted by the user, and the product shared key is determined based on the dynamic negotiation of the algorithm, the steps of factory default configuration key and the risk of cracking are avoided, and the system insecurity caused by the leakage of internal system developers is avoided; and it is operated in a secure environment with user authorization and restricted physical dialing, and the negotiation process is controllable; the negotiated product pre-shared key is stored in the physical security storage space inside the trusted controller, which is convenient for the separate management of the configuration and use processes; the present invention can effectively resist eavesdropping, counterfeiting, tampering and replay attacks, ensure the authenticity and completeness of the communication content between controllers, and improve the security and reliability of industrial control systems in critical infrastructure. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 It is a schematic diagram of the point-to-point communication principle of the existing trusted controller;

[0065] Figure 2 A schematic flow chart of a point-to-point secure communication method applied to a first secure and trusted controller provided in an embodiment of the present invention;

[0066] Figure 3 A schematic diagram of a point-to-point data exchange process of a trusted controller provided in an embodiment of the present invention;

[0067] Figure 4 A schematic diagram of a point-to-point data exchange process in a connection phase of a trusted controller provided by an embodiment of the present invention;

[0068] Figure 5 A schematic diagram of the SAE key negotiation principle provided by an embodiment of the present invention;

[0069] Figure 6 A schematic diagram of the principle of key expansion using the HKDF algorithm provided in an embodiment of the present invention;

[0070] Figure 7 A schematic flow chart of a point-to-point secure communication method applied to a second secure and trusted controller provided in an embodiment of the present invention;

[0071] Figure 8 A schematic diagram of the system principle of a point-to-point secure communication device applied to a first trusted controller provided by an embodiment of the present invention;

[0072] Fig. 9 A schematic diagram of the system principle of a point-to-point secure communication device applied to a second trusted controller provided by an embodiment of the present invention;

[0073] Fig.10 A schematic diagram of the system principle of an electronic device provided by an embodiment of the present invention.

[0074] In the figure: 100-first configuration unit; 110-first pairing module; 120-first data acquisition module; 130-first key negotiation module; 140-first key storage module; 200-first connection unit; 300-first working unit; 400-second configuration unit; 410-second pairing module; 420-second data acquisition module; 430-second key negotiation module; 440-second key storage module; 500-second connection unit; 600-second working unit; 700-electronic device; 701-communication interface; 702-processor; 703-memory; 704-bus. DETAILED DESCRIPTION

[0075] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0076] See also Figure 2The point-to-point secure communication method of the trusted controller provided in this embodiment is applied to the first secure trusted controller and includes the following steps S110 to S140.

[0077] Step S110, entering pairing mode in response to a pairing instruction sent by the engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by the user.

[0078] Specifically, the engineer station is connected to the first secure trusted controller and the second secure trusted controller through a switch, such as Figure 1 As shown. The user (can be an administrator, engineer, etc.) configures the configuration information of the first secure and trusted controller and the second secure and trusted controller in the configuration software in the engineer station. During configuration, add hardware configuration, and configure the first secure and trusted controller and the second secure and trusted controller to start pairing; the user clicks the pairing button, and the engineer station prompts to set the first secure and trusted controller and the second secure and trusted controller to pairing mode through the key switch; the user inserts the physical key into the first secure and trusted controller and the second secure and trusted controller respectively, and the engineer station sends pairing instructions to the first secure and trusted controller and the second secure and trusted controller respectively. The user randomly enters a paragraph in the engineer station, and the engineer station generates the initial product shared key of the first secure and trusted controller and the second secure and trusted controller according to this paragraph. The initial product shared key is the initial value of the product shared key, and the product shared key is also called PSK (pre-shared key); then, the engineer station sends the initial product shared key to the first secure and trusted controller and the second secure and trusted controller.

[0079] Step S120, obtaining an initial product shared key sent by the engineer station; wherein the initial product shared key is generated by the engineer station based on random input by the user.

[0080] Step S130: performing key negotiation with the second secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain the product shared key.

[0081] The product shared key of this embodiment is generated by negotiation using the Dragonfly key exchange protocol algorithm based on the random configuration parameters of the host computer under the protection of a specific physical key switch. The obtained product shared key is only known to the two communicating parties (the first secure and trusted controller and the second secure and trusted controller), and the subsequent authentication and working keys are derived from this product shared key. The key negotiation algorithm of this embodiment is based on the Dragonfly key exchange protocol algorithm, that is, based on the Dragonfly key exchange protocol algorithm, and an elliptic curve algorithm is used at the bottom layer. Among them, the Dragonfly key exchange protocol is also called the SAE (Simultaneous Athentication of Equals) protocol. Step S130 of this embodiment specifically includes the following steps S1301 to S1309.

[0082] Step S1301: Send an authentication request to the second secure and trusted controller.

[0083] Step S1302: Generate a first random number in response to the authentication reply of the second secure and trusted controller; wherein the first random number is generated based on a trusted platform control module built into the first secure and trusted controller.

[0084] Specifically, this step is used to realize the generation of random numbers. After receiving the reply from the second secure and trusted controller, the SAE handshake is started, the first secure and trusted controller generates a first random number rS, and the second secure and trusted controller generates a second random number rB.

[0085] Step S1303, determining a first commitment value according to the first random number and a unique mapping of the initial product shared key on a preset elliptic curve.

[0086] Specifically, this step is used to implement the exchange of commitment messages. The first secure and trusted controller uses the first random number rS and the elliptic curve unique mapping P of the initial product shared key PSK to calculate the first commitment value C1, and the calculation formula is C1=P·rS (· represents the point multiplication of the finite field). Among them, P is the mapping of PSK through Elliptic Curve Cryptography (ECC).

[0087] Similarly, the second secure and trusted controller uses the second random number rB and the elliptic curve unique mapping P of the initial product shared key PSK to calculate the second commitment value C2, and the calculation formula is C2=P·rB.

[0088] Step S1304: Send the first commitment value to the second secure and trusted controller.

[0089] Specifically, the first commitment value C1 is sent to the second secure and trusted controller. Similarly, the second secure and trusted controller sends the second commitment value C2 to the first secure and trusted controller.

[0090] Step S1305: Obtain a second commitment value C2 sent by the second secure and trusted controller.

[0091] Step S1306, determining a first confirmation value according to the second commitment value, the first random number and the initial product shared key in combination with the Elliptic Curve Diffie-Hellman Key Exchange (ECDH, a variant of Diffie-Hellman key exchange) algorithm.

[0092] Specifically, this step is used to implement key calculation. The first secure and trusted controller calculates the first confirmation value S1 based on the second commitment value C2, the first random number rS, the initial product shared key PSK, and the elliptic curve Diffie-Hellman key exchange protocol algorithm, that is, S1=FFC(C2·rS). Among them, FFC (Finite Field Convert) represents finite field multiplication conversion, and the elliptic curve Diffie-Hellman key exchange protocol algorithm is a specific application and implementation subclass of FFC on the mathematical structure of elliptic curves. It uses point operations on elliptic curves to realize key negotiation and exchange, thereby enhancing the security and efficiency of keys.

[0093] Similarly, the second secure and trusted controller calculates a second confirmation value S2 based on the first commitment value C1, the second random number rB and the initial product shared key PSK based on the elliptic curve Diffie-Hellman key exchange protocol algorithm, that is, S2=FFC(C1·rB).

[0094] Step S1307, determining a first verification value based on the first confirmation value, the second commitment value, and the initial product shared key in combination with a hash algorithm.

[0095] Specifically, this step is used to implement key verification. The first secure and trusted controller calculates the first verification value HA based on the hash algorithm (HASH) according to the first confirmation value S1, the second commitment value C2 and the initial product shared key PSK, and sends the first verification value HA to the second secure and trusted controller. When calculating, the first confirmation value S1 is used as KCK (key confirmation key). HA = hash (KCK||C2||PSK).

[0096] Similarly, the second secure and trusted controller calculates the second verification value HB based on the hash algorithm (HASH) according to the second confirmation value S2, the first commitment value C1 and the initial product shared key PSK, and sends the first verification value HB to the first secure and trusted controller. In the calculation, the second confirmation value S2 is used as KCK. In the calculation, HB=hash(KCK||C1||PSK).

[0097] Step S1308: Obtain a second verification value sent by the second secure and trusted controller.

[0098] Step S1309: determine whether the verification is successful based on the first verification value and the second verification value. If so, use the first confirmation value as the product shared key.

[0099] The first verification value HA is compared with the second verification value HB. If HA and HB are equal, the verification succeeds. If HA and HB are not equal, the verification fails, and verification failure information is replied to the second security trusted controller.

[0100] If the verification is successful, the first confirmation value S1 (which is equal to the second confirmation value S2 at this time) is used as the latest product shared key PSK.

[0101] Step S140: store the product shared key so as to perform two-way identity authentication based on the product shared key when connecting with the second secure trusted controller.

[0102] Here, the product shared key PSK is stored in a trusted platform control module (Trusted Platform Control Module, TPCM) of the first secure and trusted controller, and similarly, it is also stored in a trusted platform control module of the second secure and trusted controller.

[0103] The principles of step S110 to step S140 are further described below from the perspectives of the engineer station, the first secure trusted controller, and the second secure trusted controller, with specific reference to FIG. 4 .

[0104] Step 1: The user configures two secure and trusted controllers on the engineering station to enable the pairing feature.

[0105] Step ②, setting the pairing mode through the key switch, that is, the user inserts the physical key into the first secure and trusted controller and the second secure and trusted controller respectively, so that the two secure and trusted controllers enter the pairing mode.

[0106] Step ③: Generate and issue a random key at the engineer station.

[0107] Step ④: The first secure and trusted controller and the second secure and trusted controller generate true random numbers respectively.

[0108] Step ⑤, SAE key negotiation. The specific principle of the first secure and trusted controller performing SAE key negotiation is shown in Figure 5 The principle of SAE key negotiation performed by the second secure and trusted controller is the same as that of the first secure and trusted controller.

[0109] like Figure 5 As shown, the first secure trusted controller and the second secure trusted controller pre-share PSK respectively, and then sequentially generate the first random number rS and the second random number rB through PSK map (map) P (that is, PSK maps a value P through ECC), and calculate the first confirmation value S1, the second confirmation value S2, KCK (replaced with PMK in the connection stage below), the first verification value HA, and the second verification value HB respectively; finally, if both parties pass the verification, they are stored in their own internal trusted platform control module. Among them, Figure 5 The same principle applies to two-way authentication during the connection phase. The PMK (Pairwise Master Key) is generated during the connection phase for authentication based on the product shared key PSK.

[0110] Step ⑥: The first secure and trusted controller and the second secure and trusted controller store the product shared key respectively.

[0111] Here, step S110 to step S140 are the controller point-to-point data exchange process in the configuration phase. This embodiment builds a complete set of authentication and encryption communication methods for the point-to-point information exchange of controllers within the trusted control network, which includes a connection phase and a working phase in addition to the configuration phase of step S110 to step S140.

[0112] During the connection phase, two-way identity authentication is performed based on the product shared key, specifically including the following steps S210 to S240.

[0113] Step S210, obtaining a product shared key. The product shared key here refers to the product shared key stored in the trusted platform control module of each secure and trusted controller in step S1309.

[0114] Step S220: Based on the product shared key and the Dragonfly key exchange protocol algorithm, the second secure and trusted controller is used to perform identity authentication. The specific principle of identity authentication is the same as that of steps S1301 to S1309.

[0115] Step S230, in response to successful authentication, generating a pre-master key using the Dragonfly key exchange protocol algorithm.

[0116] Step S240: storing the pre-master key in the trusted platform control module of the first secure trusted controller, so as to synchronously transmit the target information to be transmitted between the first secure trusted controller and the second secure trusted controller using the pre-master key.

[0117] Specifically, in the connection phase, the first secure trusted controller and the second secure trusted controller obtain the product shared key PSK through their respective trusted platform control modules, and both parties perform identity authentication based on the product shared key PSK to generate a pre-master key PMK. The authentication principle in the connection phase is the same as the principle in the configuration phase mentioned above, which is to generate another product shared key by combining a product shared key with the Dragonfly key exchange protocol algorithm (also known as the Dragonfly algorithm). Finally, the first secure trusted controller and the second secure trusted controller store the pre-master key PMK in their respective trusted platform control modules. Since this embodiment adopts the Dragonfly key exchange protocol algorithm, a unique session key, the pre-master key PMK, is generated, so that even if the product shared key is leaked, the security of historical communications can be guaranteed.

[0118] In the working phase, the target information to be transmitted between the first secure and trusted controller and the second secure and trusted controller is synchronously transmitted using the pre-master key, including the following steps S310 to S340.

[0119] Step S310: determining a target data type corresponding to target information transmitted between the first secure and trusted controller and the second secure and trusted controller.

[0120] Here, the user of the engineering station configures four or more different types of data encryption algorithms and key lengths in the security configuration items according to the business characteristics of the point-to-point controller transmission information. For example, the IEC operation results are generally synchronized before the IO control signal is output. The data volume is small, the transmission is frequent, the real-time performance requirements are high, and the configuration data synchronization timeliness is high. The XTEA series encryption function. Configuration projects are mostly project source files, which are of great importance, but are only triggered when the configuration is downloaded. The timeliness is relatively loose, and algorithms with higher encryption strength such as SM4 / AES are selected. For operating status information, such as heartbeat data, diagnostic information and other information of general importance, the lighter Ascon-AEAD algorithm can be selected, and a fixed password length can be selected. As shown in Table 1.

[0121] Table 1 Data encryption type table

[0122]

[0123] In Table 1, the Ascon-AEAD algorithm (authenticated encryption) is a lightweight cryptographic algorithm that can ensure data confidentiality while ensuring data integrity and authenticity. It is very suitable for protecting the data creation and transmission of IoT and micro devices with limited computing resources. In addition, the Ascon-AEAD algorithm has high security and low implementation cost, and is very fast and has very low energy consumption. In practical applications, it can run on hardware for a long time.

[0124] TEA (Tiny Encryption Algorithm) is known for its simplicity, high efficiency and applicability to various environments. It uses 64-bit plaintext blocks and 128-bit keys to ensure data security through 64 rounds (or less 32 rounds) of iterative encryption.

[0125] XTEA (Extended Tiny Encryption Algorithm) is an improved version of the TEA algorithm, providing higher security. Compared with TEA, XTEA performs additional shift operations on the key during the encryption process and adds XOR operations to enhance the diffusion and obfuscation of the key. XTEA also uses 64-bit plaintext blocks and 128-bit keys, but the operational details of the encryption process are different from TEA, which allows XTEA to maintain high efficiency while improving resistance to cryptanalysis attacks.

[0126] XXTEA (eXtended eXtended Tiny Encryption Algorithm) is a further extension of the XTEA algorithm, providing a larger block size and greater flexibility. It allows multiple data blocks to be encrypted at one time, which is suitable for encrypting long text or binary data streams. XXTEA uses a 128-bit key to encrypt information blocks in 32-bit units, mixing plaintext and keys through more complex shift, XOR and addition operations. While maintaining simplicity and efficiency, XXTEA provides stronger security and larger data block processing capabilities, making it an ideal choice for solutions that require fast and secure encryption.

[0127] SM4 (SM4 Block Cipher Algorithm) is a commercial cryptographic algorithm standard with the characteristics of high security, high efficiency, easy implementation and strong compatibility. It uses 128-bit keys and 128-bit block lengths, and implements encryption and decryption through 32 rounds of iterative calculations. It is widely used in communication encryption, data storage encryption, network security, privacy protection and security authentication.

[0128] AES (Advanced Encryption Standard) also uses a 128-bit block length, but the key length can be 128, 192 or 256 bits, providing different levels of security. The AES algorithm has the advantages of high efficiency, security, easy implementation and standardization, and is widely used in various data encryption and network security fields.

[0129] Step S320, encrypt the key support feature information using the associated data authentication encryption algorithm and the pre-master key; wherein the key support feature information includes the target data type, the target encryption algorithm corresponding to the target data type, and the target key length corresponding to the target encryption algorithm; the target encryption algorithm and the target key length are determined from a pre-configured data encryption type table.

[0130] Specifically, for the security of information communication, it is necessary to select an encryption algorithm to be used before determining the final encryption algorithm. In this step, when the first secure trusted controller and the second secure trusted controller initially communicate, they first use the Ascon-AEAD algorithm and the pre-master key PMK to encrypt and transmit the information. Moreover, the initially transmitted information is accompanied by key support feature information (i.e., associated data, AD information), which is obtained from Table 1, including data type, encryption algorithm, and key length.

[0131] Step S330: Send key support feature information to the second secure trusted controller.

[0132] After receiving the key support feature information, the second secure trusted controller returns information on whether it is supported to the first secure trusted controller. The returned information is also encrypted using the Ascon-AEAD algorithm.

[0133] Step S340, in response to the support information sent by the second secure trusted controller, determine whether the pre-master key meets the target key length, if so, encrypt the target information according to the pre-master key and the target encryption algorithm; if not, according to the target key length, use the HKDF algorithm to expand the pre-master key to obtain an extended key with a length of the target key length, and encrypt the target information according to the extended key and the target encryption algorithm; and in response to the non-support information sent by the second secure trusted controller, encrypt the target information according to the associated data authentication encryption algorithm and the pre-master key.

[0134] Specifically, when the first secure and trusted controller receives the support information, it first determines whether the current pre-master key PMK meets the target key length in the key support feature information. If not, key expansion is required until the target key length is met. When the first secure and trusted controller receives the non-support information, all message categories between the first secure and trusted controller and the second secure and trusted controller continue to use the Ascon-AEAD algorithm for encrypted communication. In addition, when the user reconfigures Table 1 (i.e., updates Table 1), the aforementioned steps S310 to S340 are repeated.

[0135] It should also be noted that the support information / non-support information can only reflect the literal meaning of support / non-support. For example, the first secure and trusted controller sends all data types, encryption algorithms, and key lengths in Table 1 to the second secure and trusted controller. When the second secure and trusted controller returns the support information, it means that the encryption algorithms corresponding to all data types in Table 1 are supported. When the second secure and trusted controller returns the non-support information, it means that the encryption algorithm corresponding to at least one data type in Table 1 is not supported. In some embodiments, the support information / non-support information can also be accompanied by the supported data types, encryption algorithms, and key lengths. For example, when the second secure and trusted controller only supports some of the encryption algorithms in Table 1, when returning the support information, the supported data types, encryption algorithms, and key lengths are accompanied.

[0136] In step S340, according to the target key length, the pre-master key is key expanded using the HKDF algorithm to obtain an extended key with a length equal to the target key length, including the following steps S3401 to S3406.

[0137] Step S3401, obtain a pre-master key, a salt value, a target key length, and an optional information string; wherein the salt value is the current time.

[0138] Specifically, the salt value salt is specified as the current time and is accurate to seconds; the target key length is obtained from the key support feature information; the optional information string can be a message type, such as a status message type, a diagnostic message type, a synchronization result message type, etc.

[0139] Step S3402, determining a pseudo-random key according to a message authentication code algorithm based on a hash function, a pre-master key and a salt value.

[0140] Step S3403, initialize the extended key.

[0141] Step S3404, iteratively perform the following steps (1) to (2) until the updated extended key length is not less than the target key length:

[0142] Step (1), determining the current HMAC value based on the HMAC algorithm, the optional information string and the pseudo-random key;

[0143] Step (2), concatenate the current HMAC value into the extended key to obtain an updated extended key.

[0144] Step S3405, determine whether the length of the updated extended key is greater than the target key length. If so, truncate the updated extended key to obtain an extended key with a length equal to the target key length; if not, continue to execute step S3406.

[0145] Step S3406, returning an extended key with a length equal to the target key length.

[0146] Specifically, the HKDF algorithm (HMAC-based key Derivation Function) uses HMAC as a pseudo-random function to derive a secure key from a given key material, and is commonly used in encryption, decryption, identity authentication and other scenarios. The principle of step 3401-step 3402 is the extraction phase (Extract) of the HKDF algorithm. The pseudo-random key (PRK) is a fixed length, PRK=HMAC(salt, IKM), where IKM (Input Keying Material) is the pre-master key.

[0147] The principle of step 3403-step 3406 is the expansion phase (Expand) of the HKDF algorithm. In the expansion phase, Figure 6 As shown, first initialize the extended key. In this embodiment, the extended key after initialization is an empty output key T, T(0)=NULL. Calculate the HMAC value T(1) of the first round, that is, T(1)=HMAC(PRK, info||0x01), where || represents byte string concatenation. Add T(1) to the output key T. If a longer output key is required, continue with the next round of calculation, calculate T(2), T(3)...T(n) until the target key length L is reached. The calculation formula for the HMAC value of each round is: T(i)=HMAC(PRK, T(i-1)||info||0x0i), where i is an integer starting from 2. Splice the results of each round into T until the length of T is at least equal to the target key length L. If the length of T exceeds the target key length L, truncate T so that its length is exactly the target key length L. Figure 6 Where hashLen indicates the required length of the hash code.

[0148] Combine the following Figure 3The configuration phase, connection phase and working phase of this embodiment are further described. In the configuration phase, the engineer station configures the P2P (Peer-to-Peer) mode for the first secure trusted controller and the second secure trusted controller respectively, and the first secure trusted controller and the second secure trusted controller respectively configure the key switch; the engineer station downloads the random key, and the first secure trusted controller and the second secure trusted controller perform SAE key negotiation to obtain the product shared key PSK; the first secure trusted controller and the second secure trusted controller respectively store the product shared key PSK in their respective trusted platform control modules. In the connection phase, the first secure trusted controller and the second secure trusted controller respectively obtain the product shared key PSK, perform SAE authentication / negotiation, obtain the latest product shared key PSK, and store the latest product shared key PSK in their respective trusted platform control modules. During the working phase, the engineer station configures the encryption algorithm and key strength for the first secure and trusted controller and the second secure and trusted controller respectively. The first secure and trusted controller sends diagnostic information (the diagnostic information is encrypted by AEEAD) to the second secure and trusted controller, and the second secure and trusted controller parses the encrypted diagnostic information. After successful parsing, the first secure and trusted controller and the second secure and trusted controller synchronize IEC calculation results, configuration engineering, and operating status.

[0149] The point-to-point secure communication method of the trusted controller of this embodiment adopts a physical key switch and an algorithm-based dynamic negotiation method to obtain the product pre-shared key. It avoids the steps and cracking risks of the factory default configuration key, as well as the leakage of internal system developers, and ensures the security of the system. Since it runs in a secure environment with administrator authorization and limited physical dial codes, the negotiation process is controllable. The negotiated product pre-shared key is stored in the trusted platform control module inside the trusted controller, which facilitates the separate management of the configuration and use processes.

[0150] This embodiment is based on the Dragonfly key exchange protocol algorithm to perform identity authentication and key negotiation between the active and standby controllers, avoiding the complexity of certificate management in the PKI (Public Key Infrastructure) mode while ensuring security consistent with PKI (the underlying algorithms are all based on elliptic curves). There is no need for a handshake process, saving key negotiation time.

[0151] This embodiment also predefines encryption algorithms and key strengths according to the characteristics of exchanged information, matches the real-time and security characteristics of data characteristics in different business scenarios based on the HKDF algorithm, and opens user configuration to ensure the availability of communication between controllers to the greatest extent.

[0152] In summary, this embodiment deploys the trusted controller point-to-point communication into configuration, connection phase and working phase. In the configuration phase, a product shared key is generated based on a physical key switch and random input, a true random number is generated based on a built-in trusted platform control module, and the controller nodes are paired in combination with the Dragonfly key exchange protocol algorithm, so that the password is visible only to both parties of the communication device, greatly enhancing the security of the point-to-point channel; in the working phase, an improved HMAC key derivation algorithm (i.e., HKDF algorithm) is used to define the adaptive encryption algorithm and encryption strength based on the characteristics of the synchronous data, and different data types use different encryption algorithms and strengths, which improves real-time performance while ensuring communication security.

[0153] See also Figure 7 This embodiment also provides a point-to-point secure communication method of a trusted controller, which is applied to a second secure trusted controller. The method includes the following steps S410 to S440.

[0154] Step S410, entering pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user;

[0155] Step S420, obtaining an initial product shared key sent by the engineer station; wherein the initial product shared key is generated by the engineer station based on random input by the user;

[0156] Step S430, performing key negotiation with the first secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain the product shared key;

[0157] Step S440: store the product shared key so as to perform two-way identity authentication based on the product shared key when connecting to the first secure and trusted controller.

[0158] In an optional embodiment, the key agreement algorithm includes a dragonfly key exchange protocol algorithm.

[0159] In an optional embodiment, step S430 includes the following steps S4301 to S4309.

[0160] Step S4301: Send an authentication request to the first secure and trusted controller.

[0161] Step S4302, in response to the authentication reply of the first secure and trusted controller, generate a second random number; wherein the second random number is generated based on a trusted platform control module built into the second secure and trusted controller.

[0162] Step S4303, determining a second commitment value based on the second random number and the unique mapping of the initial product shared key on the preset elliptic curve.

[0163] Step S4304: Send the second commitment value to the first secure and trusted controller.

[0164] Step S4305: Obtain a first commitment value sent by the first secure and trusted controller.

[0165] Step S4306, determining a second confirmation value based on the first commitment value, the second random number and the initial product shared key in combination with the elliptic curve Diffie-Hellman key exchange protocol algorithm.

[0166] Step S4307, determining a second verification value based on the second confirmation value, the first commitment value, and the initial product shared key in combination with a hash algorithm.

[0167] Step S4308: Obtain a first verification value sent by the first secure and trusted controller.

[0168] Step S4309: determine whether the verification is successful based on the first verification value and the second verification value. If so, use the second confirmation value as the product shared key.

[0169] In an optional embodiment, step S440 includes storing the product shared key in a trusted platform control module of the second secure trusted controller.

[0170] In an optional embodiment, when connecting to the first secure and trusted controller, two-way identity authentication is performed based on the product shared key, including the following steps S510 to S540.

[0171] Step S510, obtaining a product shared key.

[0172] Step S520: Based on the product shared key and the Dragonfly key exchange protocol algorithm, identity authentication is performed using the first secure and trusted controller.

[0173] Step S530, in response to successful authentication, generating a pre-master key using the Dragonfly key exchange protocol algorithm.

[0174] Step S540: store the pre-master key in the trusted platform control module of the second secure trusted controller, so as to synchronously transmit the target information to be transmitted between the second secure trusted controller and the first secure trusted controller using the pre-master key.

[0175] In an optional embodiment, the target information to be transmitted between the second secure and trusted controller and the first secure and trusted controller is synchronously transmitted using the pre-master key, including the following steps S610 to S640.

[0176] Step S610: receiving key support feature information sent by a first secure and trusted controller.

[0177] Step S620, decrypt the key support feature information using the associated data authentication encryption algorithm and the pre-master key; wherein the key support feature information includes the target data type, the target encryption algorithm corresponding to the target data type, and the target key length corresponding to the target encryption algorithm; the target encryption algorithm and the target key length are determined by the first secure and trusted controller from a pre-configured data encryption type table.

[0178] Step S630, determine whether the target data type, target encryption algorithm, and target key length in the key support feature information are supported, obtain a determination result, and send the determination result to the first secure and trusted controller; wherein the determination result includes support information or non-support information.

[0179] Step S640, responding to the target information sent by the first secure and trusted controller; if the judgment result in step S630 is support, decrypting the target information according to the target encryption algorithm in the key support feature information to obtain the decrypted target information; and, subsequently, information transmission between the first secure and trusted controller is performed through the target encryption algorithm; if the judgment result in step S630 is not support, decrypting the target information according to the associated data authentication encryption algorithm and the pre-master key to obtain the decrypted target information; and, subsequently, information transmission between the first secure and trusted controller is performed through the associated data authentication encryption algorithm.

[0180] Among them, when decrypting the target information according to the target encryption algorithm in the key support characteristic information, it also includes: judging whether the pre-master key meets the target key length, if so, decrypting the target information according to the pre-master key and the target encryption algorithm; if not, according to the target key length, using the HKDF algorithm to expand the pre-master key to obtain an extended key with a length of the target key length, and decrypting the target information according to the extended key with a length of the target key length and the target encryption algorithm.

[0181] In an optional embodiment, step S640 uses the HKDF algorithm to expand the pre-master key according to the target key length to obtain an extended key with a length equal to the target key length, including the following steps S6401 to S6406.

[0182] Step S6401, obtain the pre-master key, salt value, target key length and optional information string; wherein the salt value is the current time.

[0183] Step S6402, determining a pseudo-random key according to a message authentication code algorithm based on a hash function, a pre-master key and a salt value.

[0184] Step S6403, initialize the extended key.

[0185] Step S6404, iteratively executing the following steps (1) to (2) until the updated extended key length is not less than the target key length;

[0186] Step (1), determining the current HMAC value based on the HMAC algorithm, the optional information string and the pseudo-random key;

[0187] Step (2), concatenate the current HMAC value into the extended key to obtain an updated extended key.

[0188] Step S6405, determine whether the length of the updated extended key is greater than the target key length. If so, truncate the updated extended key to obtain an extended key with a length equal to the target key length; if not, continue to step S6406.

[0189] Step S6406, returning an extended key with a length equal to the target key length.

[0190] The method applied to the second secure and trusted controller provided in the embodiment of the present application is adopted. Since the method adopts the same inventive concept as the method applied to the first secure and trusted controller provided in the embodiment of the present application, the possible embodiments of the method applied to the first secure and trusted controller are also the same as the method applied to the second secure and trusted controller in the embodiment of the present application, which will not be repeated here. On the premise that the aforementioned method can solve the technical problem, the method of this embodiment can also solve the same technical problem and achieve the same technical effect, which will not be repeated here.

[0191] See also Figure 8 The point-to-point secure communication device of the trusted controller provided in this embodiment is applied to the first secure trusted controller, and includes a first configuration unit 100, a first connection unit 200 and a first working unit 300; wherein the first configuration unit 100 includes a first pairing module 110, a first data acquisition module 120, a first key negotiation module 130 and a first key storage module 140. The first pairing module 110 is used to enter the pairing mode in response to the pairing instruction sent by the engineer station; wherein the pairing instruction is triggered by the engineer station based on the physical key switch inserted by the user. The first data acquisition module 120 is used to obtain the initial product shared key sent by the engineer station; wherein the initial product shared key is generated by the engineer station based on random input by the user. The first key negotiation module 130 is used to perform key negotiation with the second secure trusted controller based on the key negotiation algorithm and the initial product shared key to obtain the product shared key. The first key storage module 140 is used to store the product shared key so as to perform two-way identity authentication based on the product shared key when connecting with the second secure trusted controller.

[0192] In an optional embodiment, the key agreement algorithm includes a dragonfly key exchange protocol algorithm.

[0193] In an optional embodiment, the first key negotiation module 130 includes an authentication request sending module, a first random number module, a first commitment value module, a first commitment value sending module, a second commitment value acquisition module, a first confirmation value module, a first verification value module, a second verification value acquisition module and a verification module. The authentication request sending module is used to send an authentication request to the second secure and trusted controller. The first random number module is used to generate a first random number in response to the authentication reply of the second secure and trusted controller; wherein the first random number is generated based on the trusted platform control module built into the first secure and trusted controller. The first commitment value module is used to determine the first commitment value according to the first random number and the unique mapping of the initial product shared key on the preset elliptic curve. The first commitment value sending module is used to send the first commitment value to the second secure and trusted controller. The second commitment value acquisition module is used to acquire the second commitment value sent by the second secure and trusted controller. The first confirmation value module is used to determine the first confirmation value according to the second commitment value, the first random number and the initial product shared key, combined with the elliptic curve Diffie-Hellman key exchange protocol algorithm. The first verification value module is used to determine the first verification value according to the first confirmation value, the second commitment value, the initial product shared key, combined with the hash algorithm. The second verification value acquisition module is used to obtain the second verification value sent by the second security trusted controller. The verification module is used to determine whether the verification is successful according to the first verification value and the second verification value, and if so, use the first confirmation value as the product shared key.

[0194] In an optional embodiment, the first key storage module 140 is specifically used to store the product shared key in a trusted platform control module of the first secure trusted controller.

[0195] In an optional embodiment, the first connection unit 200 includes a first acquisition module, an identity authentication module, a pre-master key generation module and a storage module. The first acquisition module is used to obtain a product shared key. The identity authentication module is used to perform identity authentication using the second secure trusted controller based on the product shared key and the dragonfly key exchange protocol algorithm. The pre-master key generation module is used to generate a pre-master key using the dragonfly key exchange protocol algorithm in response to successful authentication. The storage module is used to store the pre-master key in the trusted platform control module of the first secure trusted controller, so as to synchronize the target information to be transmitted between the first secure trusted controller and the second secure trusted controller using the pre-master key.

[0196] In an optional embodiment, the first working unit 300 includes an information confirmation module, an information encryption module, a key support feature information sending module and a response module. The information confirmation module is used to determine the target data type corresponding to the target information transmitted between the first secure trusted controller and the second secure trusted controller. The information encryption module is used to encrypt the key support feature information using the associated data authentication encryption algorithm and the pre-master key; wherein the key support feature information includes the target data type, the target encryption algorithm corresponding to the target data type, and the target key length corresponding to the target encryption algorithm; the target encryption algorithm and the target key length are determined from a pre-configured data encryption type table. The key support feature information sending module is used to send the key support feature information to the second secure trusted controller. The response module is used to respond to the support information sent by the second security and trusted controller, determine whether the pre-master key meets the target key length, and if so, encrypt the target information according to the pre-master key and the target encryption algorithm; if not, according to the target key length, use the HKDF algorithm to expand the pre-master key to obtain an extended key with a length of the target key length, and encrypt the target information according to the extended key and the target encryption algorithm. In response to the unsupported information sent by the second security and trusted controller, encrypt the target information according to the associated data authentication encryption algorithm and the pre-master key.

[0197] In an optional embodiment, the response module includes a second acquisition module, a pseudo-random key module, an initialization module, an iteration module, a key length judgment module and a return module. The second acquisition module is used to obtain a pre-master key, a salt value, a target key length and an optional information string; wherein the salt value is the current time. The pseudo-random key module is used to determine a pseudo-random key according to a message authentication code algorithm based on a hash function, a pre-master key and a salt value. The initialization module is used to initialize an extended key. The iteration module is used to iteratively execute the first extension module and the second extension module until the updated extended key length is not less than the target key length: the first extension module is used to determine the current HMAC value according to the HMAC algorithm, the optional information string and the pseudo-random key; the second extension module is used to splice the current HMAC value into the extended key to obtain an updated extended key. The key length judgment module is used to determine whether the length of the updated extended key is greater than the target key length. If so, the updated extended key is truncated to obtain an extended key with a length of the target key length; if not, the return module is executed. The return module is used to return an extended key with a length of the target key length.

[0198] The device applied to the first secure and trusted controller provided in the embodiment of the present application is adopted. Since the device adopts the same inventive concept as the above-mentioned method applied to the first secure and trusted controller provided in the embodiment of the present application, on the premise that the method can solve the technical problem, the device can also solve the technical problem, and no further details are given here.

[0199] See also Fig. 9 The point-to-point secure communication device of the trusted controller provided in this embodiment is applied to the second secure trusted controller, and includes a second configuration unit 400, a second connection unit 500, a second working unit 600; wherein the second configuration unit 400 includes a second pairing module 410, a second data acquisition module 420, a second key negotiation module 430 and a second key storage module 440. The second pairing module 410 is used to enter the pairing mode in response to the pairing instruction sent by the engineer station; wherein the pairing instruction is triggered by the engineer station based on the physical key switch inserted by the user. The second data acquisition module 420 is used to obtain the initial product shared key sent by the engineer station; wherein the initial product shared key is generated by the engineer station based on random input by the user. The second key negotiation module 430 is used to perform key negotiation with the first secure trusted controller based on the key negotiation algorithm and the initial product shared key to obtain the product shared key. The second key storage module 440 is used to store the product shared key so as to perform two-way identity authentication based on the product shared key when connecting with the first secure trusted controller. It should be noted that the point-to-point secure communication device of the trusted controller applied to the second secure trusted controller and the point-to-point secure communication device of the trusted controller applied to the first secure trusted controller have the same inventive concept. The remaining optional embodiments can refer to the aforementioned point-to-point secure communication device of the trusted controller applied to the first secure trusted controller, which will not be repeated here.

[0200] The device provided by the embodiment of the present application applied to the second secure and trusted controller adopts the same inventive concept as the method provided by the embodiment of the present application applied to the second secure and trusted controller, and the possible embodiments of the device applied to the first secure and trusted controller are also the same as the embodiments of the device applied to the second secure and trusted controller in the embodiment of the present application, which are not described in detail here. On the premise that the method can solve the technical problem, the device can also solve the same technical problem and achieve the same technical effect, which is not described in detail here.

[0201] Reference Fig.10 An embodiment of the present invention further provides an electronic device 700, including a communication interface 701, a processor 702, a memory 703 and a bus 704, wherein the processor 702, the communication interface 701 and the memory 703 are connected via the bus 704; the memory 703 is used to store a computer program that supports the processor 702 to execute the point-to-point secure communication method of the trusted controller, and the processor 702 is configured to execute the program stored in the memory 703.

[0202] Optionally, an embodiment of the present invention further provides a computer-readable medium having a non-volatile program code executable by the processor 702 , wherein the program code enables the processor 702 to execute the point-to-point secure communication method of the trusted controller as in the above embodiment.

[0203] It is known from common technical knowledge that the present invention can be implemented by other embodiments that do not deviate from its spirit or essential features. Therefore, the above disclosed embodiments are only illustrative in all respects and are not exclusive. All changes within the scope of the present invention or within the scope equivalent to the present invention are included in the present invention.

Claims

1. A point-to-point secure communication method of a trusted controller, characterized in that: Applied to a first secure and trusted controller, the method comprises: Entering a pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user; Obtaining an initial product shared key sent by an engineer station; wherein the initial product shared key is generated by the engineer station based on random input by a user; Perform key negotiation with the second secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain a product shared key; storing the product shared key so as to perform two-way identity authentication based on the product shared key when connecting with the second secure trusted controller; The key agreement algorithm includes the Dragonfly key exchange protocol algorithm; The performing key negotiation with the second secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain the product shared key includes: Sending an authentication request to the second secure trusted controller; In response to the authentication reply of the second secure and trusted controller, generate a first random number; wherein the first random number is generated based on a trusted platform control module built into the first secure and trusted controller; Determine a first commitment value according to the first random number and a unique mapping of the initial product shared key on a preset elliptic curve; sending the first commitment value to the second secure trusted controller; Obtaining a second commitment value sent by the second security trusted controller; Determine a first confirmation value based on the second commitment value, the first random number and the initial product shared key in combination with the elliptic curve Diffie-Hellman key exchange protocol algorithm; Determine a first verification value based on the first confirmation value, the second commitment value, and the initial product shared key in combination with a hash algorithm; Obtaining a second verification value sent by the second security trusted controller; It is determined whether the verification is successful according to the first verification value and the second verification value, and if so, the first confirmation value is used as the product shared key.

2. The point-to-point secure communication method of a trusted controller according to claim 1, characterized in that: The storing of the product shared key comprises: The product shared key is stored in a trusted platform control module of the first secure trusted controller.

3. The point-to-point secure communication method of a trusted controller according to claim 1, characterized in that: The method of performing two-way identity authentication based on the product shared key when connecting with the second secure trusted controller includes: Obtaining the product shared key; Based on the product shared key and the Dragonfly key exchange protocol algorithm, using the second secure trusted controller to perform identity authentication; In response to successful authentication, generating a pre-master key using the Dragonfly key exchange protocol algorithm; The pre-master key is stored in the trusted platform control module of the first secure trusted controller, so as to synchronously transmit the target information to be transmitted between the first secure trusted controller and the second secure trusted controller by using the pre-master key.

4. The point-to-point secure communication method of a trusted controller according to claim 3, characterized in that: The using the pre-master key to synchronously transmit target information to be transmitted between the first secure and trusted controller and the second secure and trusted controller includes: Determining a target data type corresponding to target information transmitted between the first secure and trusted controller and the second secure and trusted controller; Encrypting key support feature information using an associated data authentication encryption algorithm and the pre-master key; wherein the key support feature information includes the target data type, the target encryption algorithm corresponding to the target data type, and the target key length corresponding to the target encryption algorithm; the target encryption algorithm and the target key length are determined from a pre-configured data encryption type table; Sending the key support feature information to the second secure trusted controller; In response to the support information sent by the second secure trusted controller, determine whether the pre-master key meets the target key length; if so, encrypt the target information according to the pre-master key and the target encryption algorithm; if not, according to the target key length, use the HKDF algorithm to expand the pre-master key to obtain an extended key with a length of the target key length, and encrypt the target information according to the extended key and the target encryption algorithm; and, in response to the non-support information sent by the second secure trusted controller, encrypt the target information according to the associated data authentication encryption algorithm and the pre-master key.

5. The point-to-point secure communication method of a trusted controller according to claim 4, characterized in that: The step of performing key expansion on the pre-master key by using the HKDF algorithm according to the target key length to obtain an extended key having a length equal to the target key length includes: Obtain the pre-master key, the salt value, the target key length and an optional information string; wherein the salt value is the current time; Determine a pseudo-random key according to a message authentication code algorithm based on a hash function, the pre-master key and the salt value; Initialize extended key; Iterate the following steps (1) to (2) until the updated extended key length is no less than the target key length: Step (1), determining a current HMAC value according to the HMAC algorithm, the optional information string and the pseudo-random key; Step (2), splicing the current HMAC value into the extended key to obtain an updated extended key; Determine whether the length of the updated extended key is greater than the target key length. If so, truncate the updated extended key to obtain an extended key with a length equal to the target key length; if not, execute the next step; Returns an extended key of the length of the target key.

6. A point-to-point secure communication method of a trusted controller, characterized in that: Applied to a second secure and trusted controller, the method comprises: Entering a pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user; Obtaining an initial product shared key sent by an engineer station; wherein the initial product shared key is generated by the engineer station based on random input by a user; Perform key negotiation with the first secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain a product shared key; storing the product shared key so as to perform two-way identity authentication based on the product shared key when connecting with the first secure trusted controller; Wherein, the key agreement algorithm includes the Dragonfly key exchange protocol algorithm; The performing key negotiation with the first secure and trusted controller based on the key negotiation algorithm and the initial product shared key to obtain the product shared key includes: Sending an authentication request to the first secure trusted controller; In response to the authentication reply of the first secure and trusted controller, a second random number is generated; wherein the second random number is generated based on a trusted platform control module built into the second secure and trusted controller; Determine a second commitment value according to the second random number and a unique mapping of the initial product shared key on a preset elliptic curve; sending the second commitment value to the first secure trusted controller; Obtaining a first commitment value sent by the first security trusted controller; Determine a second confirmation value based on the first commitment value, the second random number and the initial product shared key in combination with the elliptic curve Diffie-Hellman key exchange protocol algorithm; Determine a second verification value based on the second confirmation value, the first commitment value, and the initial product shared key in combination with a hash algorithm; Obtaining a first verification value sent by the first security trusted controller; Whether the verification is successful is determined according to the first verification value and the second verification value, and if so, the second confirmation value is used as the product shared key.

7. A point-to-point secure communication device of a trusted controller, characterized in that: Applied to a first secure and trusted controller, the device comprises: A first pairing module, configured to enter a pairing mode in response to a pairing instruction sent by an engineer station; wherein the pairing instruction is triggered by the engineer station based on a physical key switch inserted by a user; A first data acquisition module is used to acquire an initial product shared key sent by an engineer station; wherein the initial product shared key is generated by the engineer station based on random input by a user; A first key negotiation module, configured to perform key negotiation with the second secure and trusted controller based on a key negotiation algorithm and the initial product shared key to obtain a product shared key; A first key storage module, used for storing the product shared key, so as to perform two-way identity authentication based on the product shared key when connecting with the second secure trusted controller; Wherein, the key agreement algorithm includes the Dragonfly key exchange protocol algorithm; The first key agreement module includes an authentication request sending module, a first random number module, a first commitment value module, a first commitment value sending module, a second commitment value acquisition module, a first confirmation value module, a first verification value module, a second verification value acquisition module and a verification module; The authentication request sending module is used to send an authentication request to the second security trusted controller; The first random number module is used to generate a first random number in response to the authentication reply of the second secure and trusted controller; wherein the first random number is generated based on a trusted platform control module built into the first secure and trusted controller; The first commitment value module is used to determine a first commitment value according to the first random number and a unique mapping of the initial product shared key on a preset elliptic curve; The first commitment value sending module is used for sending the first commitment value to the second secure and trusted controller; The second commitment value acquisition module is used to acquire a second commitment value sent by the second security trusted controller; The first confirmation value module is used to determine the first confirmation value according to the second commitment value, the first random number and the initial product shared key in combination with the elliptic curve Diffie-Hellman key exchange protocol algorithm; The first verification value module is used to determine a first verification value according to the first confirmation value, the second commitment value, and the initial product shared key in combination with a hash algorithm; The second verification value acquisition module is used to obtain a second verification value sent by the second security trusted controller; The verification module is used to determine whether the verification is successful based on the first verification value and the second verification value, and if so, use the first confirmation value as a product shared key.

8. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of claims 1 to 6 when executing the computer program.

Citation Information

Patent Citations

  • Heartbeat mechanism based data redundancy encryption method

    CN107835157A

  • Communication network system based on point-to-point

    CN110505263A

  • Physical key activation method, system, device, equipment and medium

    CN115273289A

  • Narrowband Internet of Things authentication method based on hardware physical key

    CN116249112A