A device activation method, device and apparatus
By generating encrypted operation codes in the switch LAN and performing security verification, the efficiency and security issues during device activation and setting up are solved, and efficient and secure device discovery and opening process is achieved.
Patent Information
- Application Number
- CN202510162081.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-02-14
AI Technical Summary
In the switch LAN, the device cannot be enabled and set up simultaneously, and there are IP address conflicts and network security threats.
By generating an encrypted operation code based on the device identifier broadcast on the switch LAN, security verification of the response device is performed, and an encrypted communication channel is established for device activation settings after the verification is passed.
Improves the efficiency of device discovery and enhances security during the device activation and setup process to prevent IP address conflicts and network security threats.
Smart Images

Figure CN119652523B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of the Internet, and in particular, to a device activation method, apparatus, and device. Background Art
[0002] With the wide use of switch products, device activation settings need to be done after the switch is deployed. Since switches all have a default IP address and the IP addresses of the same manufacturer are the same, there will be a problem of IP address conflict and duplication during activation, and the IP addresses of the devices need to be modified one by one. Secondly, the switch local area network plays an important role in modern networks, and various network security problems may be encountered during the device activation settings between the discovery device and the switch, and these problems may pose a threat to the stability of the entire network and the security of data.
[0003] Therefore, when a discovery device in a switch local area network performs device activation settings on a switch, it is particularly important to ensure the security between the discovery device and the switch while ensuring the efficiency of device discovery. Summary of the Invention
[0004] This application provides a device activation method, apparatus, and device, which are used to solve the problem that the efficiency and security cannot be ensured simultaneously when performing device activation settings on a switch in related technologies.
[0005] In a first aspect of this application, a device activation method is provided, which is applied to a discovery device. The device activation method includes:
[0006] Broadcast in the switch local area network according to a first encryption operation code generated based on a first device identifier;
[0007] After the response device in the switch local area network verifies the first encryption operation code, receive a second encryption operation code sent by the response device;
[0008] Perform security verification on the response device according to the second encryption operation code;
[0009] If the security verification of the response device passes, establish an encrypted communication channel with the response device;
[0010] Perform device activation settings on the response device according to the encrypted communication channel.
[0011] Optionally, in the first implementation manner of the first aspect of this application, the step of broadcasting in the switch local area network according to a first encryption operation code generated based on a first device identifier includes:
[0012] Generate a first operation code according to the first device identifier and a first target timestamp;
[0013] Generate a first public key and a first private key through a preset key generation algorithm;
[0014] Encrypt the first opcode with the first private key to generate the first encrypted opcode;
[0015] Broadcast the first encrypted opcode and the first public key within the switch local area network.
[0016] Optionally, in the second implementation manner of the first aspect of this application, the step of performing security verification on the response device according to the second encrypted opcode includes:
[0017] Receive a second public key sent by the response device;
[0018] Decrypt the second encrypted opcode with the second public key to obtain a second target timestamp corresponding to the second encrypted opcode;
[0019] Detect whether the deviation between the second target timestamp and the current time is less than a preset threshold;
[0020] If the deviation is within the preset threshold, determine that the security verification of the response device passes.
[0021] Optionally, in the third implementation manner of the first aspect of this application, the step of establishing an encrypted communication channel with the response device if the security verification of the response device passes includes:
[0022] Generate a shared key according to the first private key and the second public key;
[0023] Generate a session key according to the shared key and the first opcode;
[0024] Establish an encrypted communication channel with the response device according to the session key.
[0025] Optionally, in the fourth implementation manner of the first aspect of this application, the session key includes a new session key and an old session key, and the method further includes:
[0026] Generate the new session key according to a preset update period of the first opcode;
[0027] Encrypt the new session key with the old session key to generate an encrypted session key;
[0028] Send the encrypted session key and the encrypted data corresponding to the device activation setting to the response device.
[0029] The second aspect of the present application provides a device activation method, which is applied to a responsive device. The device activation method includes:
[0030] Generating a second public key and a second private key through a preset key generation algorithm;
[0031] Receiving a first encrypted operation code and a first public key sent by a discovery device;
[0032] Decrypting the first encrypted operation code according to the first public key to obtain a first target timestamp corresponding to the first operation code;
[0033] Detecting whether the deviation between the first target timestamp and the current time is less than a preset threshold;
[0034] If the deviation is within the preset threshold, determining that the security verification of the discovery device is passed;
[0035] Generating a second operation code according to a second device identifier and a second target timestamp;
[0036] Encrypting the second operation code according to the second private key to generate a second encrypted operation code;
[0037] Sending the second encrypted operation code and the second public key to the discovery device.
[0038] Optionally, in the first implementation manner of the second aspect of the present application, the method further includes:
[0039] Generating a shared key according to the second private key and the first public key;
[0040] Generating an old session key according to the shared key and the first operation code;
[0041] After receiving an encrypted session key and encrypted data corresponding to device activation settings, decrypting the encrypted session key according to the old session key to obtain a new session key;
[0042] Decrypting the encrypted data according to the new session key to determine device activation settings.
[0043] The third aspect of the present application provides a device activation device, which is applied to a discovery device. The device activation device includes:
[0044] A broadcast module, configured to broadcast within a switch local area network according to a first encrypted operation code generated based on a first device identifier;
[0045] A first receiving module, configured to receive a second encrypted operation code sent by the responsive device after the responsive device in the switch local area network passes the verification of the first encrypted operation code;
[0046] A verification module, configured to perform security verification on the response device according to the second encryption opcode;
[0047] An establishment module, configured to establish an encrypted communication channel with the response device if the security verification of the response device is passed;
[0048] A setting module, configured to perform device activation settings on the response device according to the encrypted communication channel.
[0049] The fourth aspect of the present application provides a device activation device, which is applied to a response device. The device activation device includes:
[0050] A first generation module, configured to generate a second public key and a second private key through a preset key generation algorithm;
[0051] A second receiving module, configured to receive a first encryption opcode and a first public key sent by a discovery device;
[0052] An acquisition module, configured to decrypt the first encryption opcode according to the first public key to obtain a first target timestamp corresponding to the first opcode;
[0053] A detection module, configured to detect whether the deviation between the first target timestamp and the current time is less than a preset threshold;
[0054] A determination module, configured to determine that the security verification of the discovery device is passed if the deviation is within the preset threshold;
[0055] A second generation module, configured to generate a second opcode according to a second device identifier and a second target timestamp;
[0056] A third generation module, configured to encrypt the second opcode according to the second private key to generate a second encryption opcode;
[0057] A sending module, configured to send the second encryption opcode and the second public key to the discovery device.
[0058] The fifth aspect of the embodiments of the present application provides an electronic device, including a memory and a processor. The processor is configured to execute a first computer program or a second computer program stored on the memory. When the processor executes the first computer program, it implements each step in the device activation method provided in the first aspect of the embodiments of the present application. When the processor executes the second computer program, it implements each step in the device activation method provided in the second aspect of the embodiments of the present application.
[0059] In summary, according to a device activation method, device, and apparatus provided by the solution of the present application, a first encryption operation code generated based on a first device identifier is broadcast within a switch local area network; after a response device in the switch local area network verifies the first encryption operation code, a second encryption operation code sent by the response device is received; the response device is verified for security according to the second encryption operation code; if the security verification of the response device passes, an encrypted communication channel is established with the response device; and device activation settings are performed on the response device according to the encrypted communication channel. Through the implementation of the solution of the present application, a unique operation code is generated according to the device identifier of the discovered device, simplifying the data content in the device discovery process and improving the efficiency of device discovery. During the device activation setting process, the discovered device and the response device need to perform two-way verification and establish an encrypted communication channel, thereby improving the security of device activation settings. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 FIG. is a schematic flowchart of a device activation method applied to a sending device provided by an embodiment of the present application;
[0061] Figure 2 FIG. is a schematic flowchart of a device activation method applied to a response device provided by an embodiment of the present application;
[0062] Figure 3 FIG. is a schematic diagram of program modules of a device activation apparatus applied to a sending device provided by an embodiment of the present application;
[0063] Figure 4 FIG. is a schematic diagram of program modules of a device activation apparatus applied to a response device provided by an embodiment of the present application;
[0064] Figure 5 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0065] To make the objectives, features, and advantages of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0066] To solve the problem in the related art that it is impossible to ensure both high efficiency and security when performing device activation settings on a switch, an embodiment of the present application provides a device activation method, as Figure 1The flowchart of the device activation method applied to the discovery device provided in this embodiment. The device activation method includes the following steps:
[0067] Step 110: Broadcast in the switch local area network according to the first encrypted operation code generated based on the first device identifier.
[0068] Specifically, it should be noted that the discovery device can be the total server for overall operation control in the switch local area network or the device discovery scanning software used by the administrator. In this embodiment, the device identifier (DeviceIdentifier) is a combination of characters or numbers used to uniquely identify and distinguish a specific device. In a network and computer system, device identifiers play a crucial role in ensuring the correct identification, management, and communication of devices. Device identifiers include, but are not limited to, MAC addresses, IP addresses, serial numbers, and UUIDs (Universally Unique Identifiers), etc. The operation code is the part of the instruction or field that specifies the operation to be performed in a computer program, usually represented by code. In practical applications, broadcasting the first encrypted operation code generated based on the device type of the discovery device in the switch local area network can effectively improve the efficiency of device discovery.
[0069] In an alternative implementation of this embodiment, the step of broadcasting in the switch local area network according to the first encrypted operation code generated based on the first device identifier includes: generating a first operation code according to the first device identifier and the first target timestamp; generating a first public key and a first private key through a preset key generation algorithm; encrypting the first operation code with the first private key to generate a first encrypted operation code; and broadcasting the first encrypted operation code and the first public key in the switch local area network.
[0070] Specifically, the first target timestamp represents the timestamp corresponding to the discovery device when generating the first operation code. In this embodiment, obtain the unique identifier (Device ID) of the device, which is used to uniquely identify the device in the network, and obtain the current timestamp to ensure the timeliness and uniqueness of the operation code. Combine the device identifier and the timestamp, and use a secure hash algorithm (such as SHA-256) to perform a hash operation on the combined data to generate the first operation code. Among them, the current timestamp can be replaced by any random number. Whether it is a timestamp or a random number, the purpose is to generate a unique operation code, which has an obvious identification effect and effectively improves the efficiency of device discovery. Secondly, select a suitable asymmetric encryption algorithm, such as the elliptic curve encryption algorithm (ECC), to generate a pair of public and private key pairs (Public Key PK i , Private KeySK i ), set the elliptic curve parameters E and the base point G, and the elliptic curve equation (a, b):
[0071] y 2 =x 3 +ax + b (mod p),
[0072] where p is a large prime number, and the base point G is a point on the elliptic curve (G x , G y ).
[0073] Generate the private key of the discovery device according to elliptic curve encryption :[[]]
[0074] ∈ {1, 2,..., n - 1},
[0075] Calculate the public key of the discovery device :[[]]
[0076] ,
[0077] Generate a unique operation code using the secure hash function based on the device identifier and the timestamp, and encrypt the operation code using the private key to obtain the first encrypted operation code. First, use the secure hash function (such as SHA - 256) to generate the operation code OpCode :[[]]
[0078] ,
[0079] where T i is the current timestamp, H is the hash function, is the device identifier corresponding to the discovery device. Secondly, sign the operation code using the device private key to obtain the first encrypted operation code EncOpCode :[[]]
[0080] ,
[0081] Finally, broadcast the obtained first encrypted operation code and the first public key of the discovery device within the switch local area network to initiate device discovery.[[]]
[0082] Step 120: After the response device in the switch local area network verifies the first encrypted operation code, receive the second encrypted operation code sent by the response device.[[]]
[0083] Specifically, in this embodiment, the response device includes, but is not limited to, a switch in a switch local area network. The switch in the local area network decrypts the received first encrypted operation code by using the first public key included in the broadcast, extracts the first operation code and the corresponding first target timestamp, and verifies the first operation code according to the current timestamp information. If the verification passes, a second encrypted operation code and a second public key are generated according to an encryption method similar to that of the discovery device, and the second encrypted operation code and the second public key are sent to the discovery device. At this time, the discovery device receives the second encrypted operation code and the second public key sent by the response device.
[0084] Step 130: Perform a security verification on the response device according to the second encrypted operation code;
[0085] Step 140: If the security verification of the response device passes, establish an encrypted communication channel with the response device.
[0086] Specifically, in this embodiment, after receiving the second encrypted operation code, the discovery device also needs to perform a security verification on the response device according to the second encrypted operation code and the second key. Such a process is mainly to verify whether the operation code is tampered with during transmission and to verify whether the device corresponding to the first encrypted operation code or the second encrypted operation code is a legitimate device. If the security verification of the response device also passes, both the discovery device and the response device can determine that the other party is a legitimate device, that is, the discovery device determines that the response device is the switch to be set in the switch local area network, and the response device can determine that the discovery device is the discovery device that sets itself. Therefore, an encrypted communication channel is established between the two parties to ensure the security of data transmission during subsequent setting processes.
[0087] In an alternative implementation manner of this embodiment, the step of performing a security verification on the response device according to the second encrypted operation code includes: receiving the second public key sent by the response device;
[0088] Decrypt the second encrypted operation code by using the second public key to obtain the second target timestamp corresponding to the second encrypted operation code; detect whether the deviation between the second target timestamp and the current time is less than a preset threshold; if the deviation is within the preset threshold, determine that the security verification of the response device passes.
[0089] Specifically, in this embodiment, when the discovery device receives the second encrypted operation code, it also receives the second public key sent by the response device and decrypts the second encrypted operation code by using the second public key:
[0090] ,
[0091] where PK j represents the second public key of the response deviceEncOpCode j Represents the second encryption operation code of the response body, OpCoder j Represents the second operation code for the response device. D is the decryption algorithm corresponding to the elliptic curve encryption algorithm, such as ECDSA (Elliptic Curve Digital Signature Algorithm). It can be understood that the generation principle of the second encryption operation code of the response device is the same as that of the first operation code of the discovery device. Therefore, the second operation code also contains the corresponding second target timestamp when generating the second operation code. Verify the second target timestamp according to the timestamp corresponding to when the second encryption operation code is received:
[0092] ,
[0093] Among them, is the current time, is the received target timestamp, is the preset threshold of the timestamp deviation. If the deviation between the current time and the timestamp is within the preset threshold, it is determined that the security verification of the response device passes.
[0094] In an optional implementation manner of this embodiment, if the security verification of the response device passes, the steps of establishing an encrypted communication channel with the response device include: generating a shared key according to the first private key and the second public key; generating a session key according to the shared key and the first operation code; establishing an encrypted communication channel with the response device according to the session key.
[0095] Specifically, in this embodiment, asymmetric encryption is used for key negotiation of the encrypted communication channel. During the broadcast of the discovery device and the response of the response device, the public keys of each other have been exchanged during the authentication process, and the integrity and authenticity of the public keys are guaranteed through digital signatures. Therefore, during the key negotiation process, such as the elliptic curve key exchange algorithm, the discovery device can generate a shared key according to the first private key and the second public key corresponding to the response device. Similarly, the response device can generate a shared key according to the second private key and the first public key of the discovery device. The communication parties can negotiate and generate a shared key without directly transmitting the key, thus ensuring the security of communication. Then, a session key is generated according to the shared key and the first operation code through a hash algorithm or a one-way hash function. The session key generated with the first operation code as the salt value can further enhance the randomness of the key. It can be understood that the first operation code used to generate the session key has been sent to the response device during the broadcast. Therefore, on the response device side, the session key can also be generated according to the first operation code and the shared key, and an encrypted communication channel is established between the two parties according to the session key.
[0096] In an alternative implementation of this embodiment, in order to further improve the security of the encrypted communication channel, the session key is continuously updated during the communication process of the encrypted communication channel. It can be understood that the shared key generated by the private key of one's own device and the public key of the other party is an asymmetric key. The asymmetric key itself is relatively long and has a large computational overhead, making it inconvenient to update frequently. However, the generated session key can be used as an initial symmetric key. Therefore, the session key can be updated within a preset update period, and the newly updated session key is encrypted with the old session key to generate an encrypted session key. During the communication process between the discovery device and the response device, the encrypted session key and the encrypted data corresponding to the device activation settings are sent to the response device together. The response device can decrypt the encrypted session key with the previous old session key to obtain the new session key, and decrypt the encrypted data according to the new session key to obtain the data information corresponding to the device activation settings.
[0097] Step 150: Perform device activation settings on the response device according to the encrypted communication channel.
[0098] Specifically, in this embodiment, the first encrypted opcode sent by the discovery device contains a search message for an unconfigured switch. If feedback information from the response device is received, it is determined that the response device is an unconfigured switch. Therefore, after the encrypted communication channel is established, the discovery device will send a configuration message to the response device. The definition of the message is as follows:
[0099] | Opcode(1) | reserved(1) | requestID(1) | devaddr | ipaddr(1) | mask(1) | gateway(1) |,
[0100] Among them, Opcode(1) being 0x02 represents a configuration request message, Reserved(1) being 0x00, requestID(1) is set by the client and increments from 0x0001, devaddr is the MAC address of the switch to be configured, and ipaddr(1), mask(1), and gateway(1) are the switch configurations set.
[0101] After receiving the configuration message, the response device will send a response message to the discovery device:
[0102] | Opcode(2) | reserved(2) | requestID(2) | status | reserved2 | ipaddr(2) | mask(2) | gateway(2) |,
[0103] Among them, Opcode(2) being 0x03 represents a configuration response message, Reserved(2) being 0x00, requestID(2) corresponding to the value of the request message, status being the status response: 0x00 for success, reserved2 being 0x00, ipaddr(2), mask(2), and gateway(2) being the switch information returned.
[0104] In an alternative implementation manner of this embodiment, in order to further ensure the security and reliability of the device discovery broadcast process, in this embodiment, an initial reflection sequence is generated based on the device identifier:
[0105] ,
[0106] Among them, is expressed as the initial reflection polynomial, represents the i-th bit of the device identifier, x is the reflection variable, n is the polynomial order, that is, the initial reflection sequence can be understood as splitting the device identifier ID bit by bit into , performing polynomial calculations on each bit: , accumulating all terms and taking the modulus with respect to the prime number p to obtain the final initial reflection polynomial. Through the initial reflection sequence, the direct exposure of the device identifier can be prevented, increasing the complexity of the identification information.
[0107] A dynamic reflection sequence is generated through iterative calculation of the initial reflection sequence:
[0108] ,
[0109] Among them, is expressed as the reflection sequence of the (n + 1)-th iteration, is expressed as the reflection sequence of the n-th iteration. It can be understood that when n is equal to 0, that is, it is marked as the initial reflection sequence, H represents the hash function, is the timestamp, is the exclusive OR operation.
[0110] An enhanced opcode is generated in combination with the reflection sequence:
[0111] ,
[0112] Among them, is the message authentication code based on the key K, G is the reflection sequence mapping function, and is calculated and determined according to the first encryption opcode and the reflection sequence value, and is multiplied by the mapping value of the previous reflection sequence to obtain the enhanced opcode.
[0113] Confuse the enhanced opcode with the reflection sequence:
[0114] ,
[0115] where M is the confusion matrix function, is the encryption function, is the random seed, is the tensor product operation. According to the reflection sequence generate the confusion matrix M, perform the tensor product operation on the enhanced opcode and the confusion matrix, and add the encrypted random seed for final confusion to increase the complexity of the opcode and prevent the opcode from being reverse-analyzed.
[0116] Broadcast the opcode in segments according to the characteristics of the reflection sequence:
[0117] ),
[0118] where is the i-th broadcast segment, is the i-th segment of the opcode, is the i-th segment of the reflection sequence, is the timestamp. It can be understood that the final opcode is segmented according to specific rules, the corresponding part of the reflection sequence is assigned to each segment, and the timestamp information is added to generate the segmented broadcast packet, reducing the data volume of a single broadcast and optimizing the broadcast propagation efficiency.
[0119] Figure 2 This is the schematic flowchart of the device activation method applied to the response device provided in this embodiment. The device activation method includes the following steps:
[0120] Step 210: Generate a second public key and a second private key through a preset key generation algorithm;
[0121] Step 220: Receive the first encrypted opcode and the first public key sent by the discovery device;
[0122] Step 230: Decrypt the first encrypted opcode according to the first public key to obtain the corresponding first target timestamp of the first opcode;
[0123] Step 240: Detect whether the deviation between the first target timestamp and the current time is less than a preset threshold;
[0124] Step 250: If the deviation is within the preset threshold, determine that the security verification of the discovery device passes;
[0125] Step 260: Generate a second opcode according to the second device identifier and the second target timestamp;
[0126] Step 270: Encrypt the second opcode according to the second private key to generate a second encrypted opcode;
[0127] Step 280: Send the second encryption operation code and the second public key to the discovery device.
[0128] Specifically, in this embodiment, it should be noted that all switches in the switch LAN belong to the same type of product, so there are preset keys and operation code settings at the initial stage of the device, and the second public key and the second private key are generated by the same key generation algorithm as the discovery device. After receiving the first encrypted operation code and the first public key sent by the discovery device, the first encrypted operation code is decrypted in a decryption method consistent with the discovery device. The decryption formula is as follows:
[0129] ,
[0130] After decryption is completed, the first target timestamp corresponding to the first operation code is extracted, and the timeliness of the first operation code is verified according to the current time when the first encrypted operation code is received, that is, if the deviation between the current time and the first target timestamp is less than the preset threshold, the first operation code is determined to be valid, that is, the security verification of the discovery device is passed, otherwise it is necessary to feedback invalid information to the discovery device, and notify the discovery device to send the first encrypted operation code again. After the security verification of the discovery device is passed, the second operation code is generated in the same way as the discovery device according to the second device identifier and the second target timestamp of the responding device itself, and the second operation code is further encrypted with the second private key to generate a second encrypted operation code, and the second encrypted operation code and the second public key are sent to the discovery device. At this point, the discovery response of the responding device to the discovery device is completed.
[0131] In an optional implementation of this embodiment, in the encrypted communication channel, at the responding device end, the responding device can generate a shared key based on the second private key and the first public key elliptic curve key exchange algorithm sent by the discovery device. It should be noted that, according to the properties of the elliptic curve, the shared keys generated by both parties are the same, and the responding device end has received the first operation code sent by the discovery device. Therefore, after the shared key is generated, the shared key can be further generated through a hash algorithm or a one-way hash function according to the first operation code. However, the session key at this time is outdated, and it is necessary to wait for the discovery device to send an encrypted session key, decrypt the encrypted session key according to the old session key, obtain a new session key, and then decrypt the encrypted data sent by the discovery device according to the new session key to determine its corresponding device activation settings. It should be noted that the old session key used to decrypt the encrypted session key is completely generated in the responding device, so even if the data sent by the discovery device in the encrypted communication channel is illegally intercepted, the data cannot be decrypted, thereby effectively protecting the security of data transmission.
[0132] In an alternative implementation of this embodiment, when the response device receives the segmented broadcast sent by the discovery device, it needs to verify the integrity of the received reflection sequence:
[0133] ,
[0134] Among them, is the verification result. Calculate the hash value for each reflection sequence, and calculate the cumulative product of the hash values in each broadcast packet segment, and compare it with the hash value of the final reflection sequence to verify the integrity of the reflection sequence in the broadcast received by the response device side, so as to judge whether the data is tampered with during the propagation process. If the finally obtained verification result is okay, then combine the second device identifier of the response device and the second operation code with the reflection sequence algorithm used during the discovery device broadcast to respond to the discovery device. Similarly, the reflection sequence algorithm can not only be applied in the broadcast and response phases of device discovery, but also in the encrypted transmission phase of device activation settings, further protecting the security of data transmission.
[0135] According to a device activation method provided by the solution of the present application, broadcast within the switch local area network according to the first encrypted operation code generated based on the first device identifier; after the response device in the switch local area network passes the verification of the first encrypted operation code, receive the second encrypted operation code sent by the response device; perform a security verification on the response device according to the second encrypted operation code; if the security verification of the response device passes, establish an encrypted communication channel with the response device; perform device activation settings on the response device according to the encrypted communication channel. Through the implementation of the solution of the present application, a unique operation code is generated according to the device identifier of the discovery device, simplifying the data content in the device discovery process and improving the efficiency of device discovery. During the device activation setting process, the discovery device and the response device need to perform two-way verification and establish an encrypted communication channel, thereby improving the security of device activation settings.
[0136] Figure 3 A device activation device provided for an embodiment of the present application is applied to a discovery device, and this device activation device can be used to implement the device activation method applied to the discovery device in the foregoing embodiment. As Figure 3 shown, this device activation device mainly includes:
[0137] A broadcast module 10, configured to broadcast within the switch local area network according to the first encrypted operation code generated based on the first device identifier;
[0138] A first receiving module 20, configured to receive the second encrypted operation code sent by the response device after the response device in the switch local area network passes the verification of the first encrypted operation code;
[0139] A verification module 30, configured to perform a security verification on the response device according to the second encrypted operation code;
[0140] A establishing module 40, configured to establish an encrypted communication channel with a response device if the security verification of the response device is passed;
[0141] A setting module 50, configured to perform device activation setting on the response device according to the encrypted communication channel.
[0142] In an optional implementation manner of this embodiment, the broadcasting module is specifically configured to: generate a first operation code according to a first device identifier and a first target timestamp; generate a first public key and a first private key through a preset key generation algorithm; encrypt the first operation code with the first private key to generate a first encrypted operation code; broadcast the first encrypted operation code and the first public key within the switch local area network.
[0143] In an optional implementation manner of this embodiment, the verification module is specifically configured to: receive a second public key sent by the response device; decrypt a second encrypted operation code with the second public key to obtain a second target timestamp corresponding to the second encrypted operation code; detect whether the deviation between the second target timestamp and the current time is less than a preset threshold; if the deviation is within the preset threshold, determine that the security verification of the response device is passed.
[0144] In an optional implementation manner of this embodiment, the establishing module is specifically configured to: generate a shared key according to the first private key and the second public key; generate a session key according to the shared key and the first operation code; establish an encrypted communication channel with the response device according to the session key.
[0145] In an optional implementation manner of this embodiment, the device activation device further includes: a fourth generation module and a second sending module. The fourth generation module is configured to: generate a new session key according to a preset update period of the first operation code; encrypt the new session key with the old session key to generate an encrypted session key. The second sending module is configured to: send the encrypted session key and encrypted data corresponding to the device activation setting to the response device.
[0146] Figure 4 A device activation device provided by an embodiment of the present application, which is applied to a response device, and the device activation device can be used to implement the device activation method applied to the response device in the foregoing embodiments. As Figure 4 shown, the device activation device mainly includes:
[0147] A first generation module 60, configured to generate a second public key and a second private key through a preset key generation algorithm;
[0148] A second receiving module 70, configured to receive the first encrypted operation code and the first public key sent by the discovery device;
[0149] An obtaining module 80, configured to decrypt a first encrypted operation code according to a first public key, and obtain a first target timestamp corresponding to the first operation code;
[0150] A detecting module 90, configured to detect whether a deviation between the first target timestamp and the current time is less than a preset threshold;
[0151] A determining module 100, configured to determine that the security verification of the discovered device passes if the deviation is within the preset threshold;
[0152] A second generating module 110, configured to generate a second operation code according to a second device identifier and a second target timestamp;
[0153] A third generating module 120, configured to encrypt the second operation code according to a second private key to generate a second encrypted operation code;
[0154] A sending module 130, configured to send the second encrypted operation code and a second public key to the discovered device.
[0155] In an optional implementation manner of this embodiment, the generating module is further configured to: generate a shared key according to the second private key and the first public key; generate an old session key according to the shared key and the first operation code. The obtaining module is further configured to: after receiving the encrypted session key and the encrypted data corresponding to the device activation setting, decrypt the encrypted session key according to the old session key to obtain a new session key. The determining module is further configured to: decrypt the encrypted data according to the new session key to determine the device activation setting.
[0156] An apparatus for device activation provided by the solution of this application broadcasts within a switch local area network according to a first encrypted operation code generated based on a first device identifier; after a response device in the switch local area network verifies the first encrypted operation code, receives a second encrypted operation code sent by the response device; performs security verification on the response device according to the second encrypted operation code; if the security verification on the response device passes, establishes an encrypted communication channel with the response device; and performs device activation setting on the response device according to the encrypted communication channel. Through the implementation of the solution of this application, a unique operation code is generated according to the device identifier of the discovered device, simplifying the data content in the device discovery process and improving the efficiency of device discovery. During the device activation setting process, the discovered device and the response device need to perform two-way verification and establish an encrypted communication channel, thereby improving the security of the device activation setting.
[0157] According to what is provided by the solution of this application Figure 5 An electronic device provided for an embodiment of this application. This electronic device can be used to implement the device activation method in the foregoing embodiment, and mainly includes:
[0158] A memory 501, a processor 502, and a computer program 503 stored on the memory 501 and executable on the processor 502. The memory 501 and the processor 502 are communicatively connected. When the processor 502 executes the computer program 503, the device activation method in the foregoing embodiments is implemented. Among them, the number of processors can be one or more.
[0159] The memory 501 can be a high-speed random access memory (RAM), or a non-volatile memory, such as a disk memory. The memory 501 is used to store executable program codes, and the processor 502 is coupled to the memory 501.
[0160] Furthermore, an embodiment of the present application also provides a computer-readable storage medium, which can be disposed in the electronic device in the foregoing embodiments. The computer-readable storage medium can be the memory in the foregoing Figure 5 illustrated embodiments.
[0161] A computer program is stored on the computer-readable storage medium. When the program is executed by a processor, the device activation method in the foregoing embodiments is implemented. Further, the computer-readable storage medium can also be various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a RAM, a magnetic disk, or an optical disc that can store program codes.
[0162] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0163] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.
[0164] As described above, the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A device activation method, applied to a discovery device, characterized in that Including: Broadcast within the switch local area network according to the first encryption opcode generated based on the first device identifier; After the response device in the switch local area network passes the verification of the first encryption opcode, receive the second encryption opcode sent by the response device; Perform security verification on the response device according to the second encryption opcode; If the security verification of the response device passes, establish an encrypted communication channel with the response device; Perform device activation settings on the response device according to the encrypted communication channel; The method further includes: Generate an initial reflection sequence based on the first device identifier: , Among them, is expressed as the initial reflection polynomial, is expressed as the i-th bit of the first device identifier, x is the reflection variable, and n is the polynomial order. That is, the initial reflection sequence can be understood as splitting the first device identifier ID bit by bit into , performing polynomial calculations on each bit: , adding up all terms and taking the modulus with respect to the prime number p to obtain the final initial reflection polynomial; Generate a dynamic reflection sequence through iterative calculation of the initial reflection sequence: , Among them, is represented as the reflection sequence of the (n + 1)-th iteration, is represented as the reflection sequence of the n-th iteration. It can be understood that when n is equal to 0, that is, it is identified as the initial reflection sequence, H is represented as a hash function, is a timestamp, is an exclusive OR operation; Generate an enhanced opcode in combination with the dynamic reflection sequence: , Among them, is a message authentication code based on the key K. G is a reflection sequence mapping function. The HMAC value is calculated and determined according to the first encryption operation code and the reflection sequence, and then multiplied by the mapping value of the previous reflection sequence to obtain the enhanced operation code. Perform reflection sequence obfuscation on the enhanced opcode: , Among them, M is the confusion matrix function, is the encryption function, is the random seed, is the tensor product operation. According to the reflection sequence generate the confusion matrix M, perform the tensor product operation on the enhanced opcode and the confusion matrix, and add the encrypted random seed for final confusion, increasing the complexity of the opcode and preventing the opcode from being reverse-analyzed; Segment and broadcast the opcode according to the reflection sequence characteristics: ) , wherein, is the i-th broadcast segment, is the i-th segment of the operation code, is the i-th segment of the reflection sequence, is the timestamp.
2. The device activation method according to claim 1, wherein The step of broadcasting within the switch local area network according to the first encryption opcode generated based on the first device identifier includes: Generate a first opcode according to the first device identifier and the first target timestamp; Generate a first public key and a first private key through a preset key generation algorithm; Encrypt the first opcode with the first private key to generate the first encryption opcode; Broadcast the first encryption opcode and the first public key within the switch local area network.
3. The device activation method according to claim 2, characterized in that, The step of performing security verification on the response device according to the second encryption opcode includes: Receive the second public key sent by the response device; Decrypt the second encryption opcode with the second public key to obtain the second target timestamp corresponding to the second encryption opcode; Detect whether the deviation between the second target timestamp and the current time is less than a preset threshold; If the deviation is within the preset threshold, determine that the security verification of the response device passes.
4. The device activation method according to claim 3, wherein The step of, if the security verification of the response device passes, establishing an encrypted communication channel with the response device includes: Generate a shared key according to the first private key and the second public key; Generate a session key according to the shared key and the first opcode; Establish an encrypted communication channel with the response device according to the session key.
5. The device activation method according to claim 4, wherein, The session key includes a new session key and an old session key, and the method further includes: Generate the new session key according to the preset update period of the first opcode; Encrypt the new session key with the old session key to generate an encrypted session key; Send the encrypted session key and the encrypted data corresponding to the device activation settings to the response device.
6. A device activation method, applied to a response device, where the response device is used to receive the segmented broadcast sent by the discovery device in claim 1, characterized in that, Including: Generate a second public key and a second private key through a preset key generation algorithm; Receive the first encryption opcode and the first public key sent by the discovery device; Decrypt the first encryption opcode with the first public key to obtain the first target timestamp corresponding to the first opcode; Detect whether the deviation between the first target timestamp and the current time is less than a preset threshold; If the deviation is within the preset threshold, determine that the security verification of the discovery device passes; Generate a second operation code based on the second device identifier and the second target timestamp; Encrypt the second operation code using the second private key to generate a second encrypted operation code; Send the second encrypted operation code and the second public key to the discovery device; The method further includes: When the response device receives the segmented broadcast sent by the discovery device, verify the integrity of the received reflection sequence: , Among them, For the verification result, calculate the hash value for each reflection sequence, calculate the cumulative product of the hash values in each segment of the broadcast packet, compare it with the hash value of the final reflection sequence, verify the integrity of the reflection sequence in the broadcast received by the response device, so as to judge whether the data is tampered with during the propagation process; if there is no problem with the finally obtained verification result, combine the second device identifier of the response device and the second operation code, and use the reflection sequence algorithm adopted when the discovery device broadcasts to respond to the discovery device.
7. The device activation method according to claim 6, wherein The method further includes: Generate a shared key based on the second private key and the first public key; Generate an old session key based on the shared key and the first operation code; After receiving the encrypted session key and the encrypted data corresponding to the device activation settings, decrypt the encrypted session key using the old session key to obtain a new session key; Decrypt the encrypted data using the new session key to determine the device activation settings.
8. An apparatus for device activation, applied to a discovery device, characterized in that, The device activation device includes: A broadcast module for broadcasting within the switch local area network according to the first encrypted operation code generated based on the first device identifier; A first receiving module for receiving the second encrypted operation code sent by the response device after the response device in the switch local area network passes the verification of the first encrypted operation code; A verification module for performing security verification on the response device according to the second encrypted operation code; A establishment module for establishing an encrypted communication channel with the response device if the security verification of the response device passes; A setting module for performing device activation settings on the response device according to the encrypted communication channel; The broadcast module is further used to generate an initial reflection sequence based on the first device identifier: , Among them, is represented as the initial reflection polynomial, represents the i-th bit of the first device identifier, x is the reflection variable, and n is the polynomial order. That is, the initial reflection sequence can be understood as splitting the first device identifier ID bit by bit into , performing polynomial calculations on each bit: , accumulating all terms and taking the modulus with respect to the prime number p to obtain the final initial reflection polynomial; Generate a dynamic reflection sequence through iterative calculation of the initial reflection sequence: , Among them, represents the reflection sequence of the (n + 1)-th iteration, represents the reflection sequence of the n-th iteration. It can be understood that when n is equal to 0, i.e., it is marked as the initial reflection sequence, H represents the hash function, is the time stamp, is the exclusive OR operation; Generate an enhanced operation code by combining the dynamic reflection sequence: , Among them, is a message authentication code based on the key K. G is a reflection sequence mapping function. The HMAC value is calculated and determined according to the first encryption operation code and the reflection sequence, and then multiplied by the mapping value of the previous reflection sequence to obtain the enhanced operation code. Perform reflection sequence confusion on the enhanced operation code: , where M is the confusion matrix function, is the encryption function, is the random seed, is the tensor product operation. According to the reflection sequence generate the confusion matrix M, perform the tensor product operation on the enhanced opcode and the confusion matrix, and add the encrypted random seed for final confusion to increase the complexity of the opcode and prevent the opcode from being reverse-analyzed; Segment and broadcast the operation code according to the reflection sequence characteristics: ) , Among them, is the i-th broadcast segment, is the i-th segment of the operation code, is the i-th segment of the reflection sequence, is the timestamp.
9. An apparatus for enabling a device, which is applied to a responsive device for receiving segmented broadcasts sent by the discovery device in claim 8, characterized in that, The device activation device includes: A first generation module for generating a second public key and a second private key through a preset key generation algorithm; A second receiving module for receiving the first encrypted operation code and the first public key sent by the discovery device; An acquisition module for decrypting the first encrypted operation code according to the first public key to obtain the first target timestamp corresponding to the first operation code; A detection module for detecting whether the deviation between the first target timestamp and the current time is less than a preset threshold; A determination module for determining that the security verification of the discovery device passes if the deviation is within the preset threshold; A second generation module for generating a second operation code according to the second device identifier and the second target timestamp; A third generation module for encrypting the second operation code using the second private key to generate a second encrypted operation code; A sending module for sending the second encrypted operation code and the second public key to the discovery device; The detection module is further used to verify the integrity of the received reflection sequence when the response device receives the segmented broadcast sent by the discovery device: , Among them, For the verification result, calculate the hash value for each reflection sequence, calculate the cumulative product of the hash values in each segment of the broadcast packet, compare it with the hash value of the final reflection sequence, verify the integrity of the reflection sequence in the broadcast received by the response device, so as to determine whether the data is tampered with during the propagation process; if there is no problem with the finally obtained verification result, the second device identifier and the second operation code of the response device are combined with the reflection sequence algorithm used when the discovery device broadcasts to respond to the discovery device.
10. An electronic device, characterized in that, Includes a memory and a processor, where: The processor is used to execute the first computer program or the second computer program stored on the memory; When the processor executes the computer program, it implements the steps in the device activation method described in any one of claims 1 to 5. When the processor executes the computer program, it implements the steps in the device activation method described in any one of claims 6 to 7.
Citation Information
Patent Citations
Key negotiation method and device, terminal and storage medium
CN112533213A
Channel establishment method, device and system and computing equipment
CN116996872A