A signaling service system and a communication method based on the signaling service system

By using quantum encryption technology for authentication and key negotiation, the security challenges of the signaling system are solved, achieving high security and low-risk communication in the signaling channel, and improving the system's flexibility and resource utilization efficiency.

CN119652554BActive Publication Date: 2026-02-27CHINA TELECOM QUANTUM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411568927.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-05
Publication Date
2026-02-27
Estimated Expiration
2044-11-05

AI Technical Summary

Technical Problem

As communication networks become more complex and the number of devices increases, signaling systems face security challenges, especially during information exchange and control between devices, where there is a risk of information leakage and malicious attacks.

Method used

An authentication mechanism based on quantum encryption technology is adopted to conduct two-way identity authentication and quantum key negotiation. The security of identity verification and key negotiation process between the two communicating parties is ensured through the key management platform and identity authentication platform in the signaling service system.

Benefits of technology

It improves the security of signaling channels, reduces the risk of information leakage and malicious attacks, enhances the flexibility and scalability of the system, reduces system integration and maintenance costs, and optimizes resource allocation and security response through AI technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652554B_ABST
    Figure CN119652554B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a signaling service system and a communication method based on the signaling service system, the method is applied to a first client, a two-way authentication request for a second client is sent to a key management platform, and a session key handle sent by the key management platform after two-way authentication is passed is received, key negotiation is carried out between the key management platform and the second client, and a negotiation key handle and first public key information sent by the key management platform are received; a second key negotiation request is sent to the second client, the second key negotiation request comprises the session key handle, a negotiation key length and the first public key information, a session key sent by the key management platform is received, and communication is carried out with the second client according to the session key. Through the authentication mechanism based on quantum encryption technology, two-way identity authentication and quantum key negotiation are carried out, the security of a signaling channel can be ensured, and the risk of information leakage and malicious attack is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of quantum secure communication, in particular to a signaling service system and a communication method based on the signaling service system. BACKGROUND

[0002] The communication dispatch signaling service system is a system for managing and coordinating various signaling and control information in a communication network, which realizes information interaction and control between devices through standardized protocols and interfaces, and is mainly used to ensure that devices and users in the communication network can efficiently and reliably communicate. However, with the increase of network complexity and the number of devices, the signaling system faces security challenges. SUMMARY

[0003] In view of the above problems, the embodiments of the present application are proposed to provide a signaling service system and a communication method based on the signaling service system which can overcome the above problems or at least partially solve the above problems.

[0004] In order to solve the above problems, the embodiments of the present application disclose a communication method based on a signaling service system, applied to a first client, the method comprising:

[0005] sending a two-way authentication request for a second client to a key management platform, and receiving a session key handle sent by the key management platform after the two-way authentication is passed;

[0006] sending a first key negotiation request to the key management platform, and receiving a negotiation key handle and first public key information sent by the key management platform;

[0007] sending a second key negotiation request to the second client, the second key negotiation request comprising the session key handle, the negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length and the first public key information;

[0008] receiving second public key information sent by the second client; the second public key information is sent to the second client by the key management platform;

[0009] sending a fourth key negotiation request to the key management platform, the fourth key negotiation request comprising the negotiation key handle;

[0010] receiving a session key sent by the key management platform, and communicating with the second client according to the session key.

[0011] Optionally, the method further comprises:

[0012] Obtaining first authentication information from the key management platform;

[0013] Sending the first authentication information to the second client, so that the second client verifies the first authentication information through the key management platform;

[0014] Receiving second authentication information sent by the second client, the second authentication information being sent to the second client after the key management platform verifies the first authentication information;

[0015] Verifying the second authentication information through the key management platform, and receiving a session key handle sent by the key management platform after the key management platform verifies the second authentication information.

[0016] Optionally, the method further comprises:

[0017] Sending a registration session request to an identity authentication platform, the registration session request comprising third authentication information;

[0018] Receiving an authorization code sent by the identity authentication platform after verifying that the third authentication information is verified;

[0019] Sending a connection establishment request to the second client, the connection establishment request comprising the authorization code, so that the second client verifies the authorization code through the identity authentication platform, and receives an access code sent by the identity authentication platform after verifying that the authorization code is verified.

[0020] Optionally, the method further comprises:

[0021] Receiving communication path information sent by the identity authentication platform, and configuring a communication path according to the communication path information, so that the second client communicates through the communication path according to the session key.

[0022] Optionally, the method further comprises:

[0023] Receiving a session state synchronization request sent by the identity authentication platform, the session state synchronization request comprising session state information;

[0024] Synchronizing a session state with the second client according to the session state information.

[0025] Correspondingly, the embodiment of the application discloses a communication method based on a signaling service system, which is applied to a key management platform, and the method comprises the following steps:

[0026] receiving a bidirectional authentication request sent by a first client for a second client, and sending a session key handle to the first client after the bidirectional authentication is passed;

[0027] receiving a first key negotiation request sent by the first client, sending a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, the negotiation key length and the first public key information;

[0028] receiving a third key negotiation request sent by the second client, the third key negotiation request comprising the session key handle, the negotiation key length and the first public key information, generating a session key and sending second public key information to the second client;

[0029] receiving a fourth key negotiation request sent by the first client, the fourth key negotiation request comprising the negotiation key handle, and sending a session key to the first client, so that the first client communicates with the second client according to the session key.

[0030] Optionally, the receiving of the bidirectional authentication request sent by the first client for the second client and the sending of the session key handle to the first client after the bidirectional authentication is passed comprise the following steps:

[0031] receiving a first authentication information acquisition request sent by the first client, and sending first authentication information to the first client;

[0032] receiving a first authentication information verification request sent by the second client, and sending second authentication information to the second client after the first authentication information verification is passed;

[0033] receiving a second authentication information verification request sent by the first client, and sending a session key handle to the first client after the second authentication information verification is passed.

[0034] Correspondingly, the embodiment of the application discloses a signaling service system, which comprises a first client, a second client and a key management platform;

[0035] The first client is configured to send a two-way authentication request for the second client to the key management platform and receive a session key handle sent by the key management platform after the two-way authentication is passed; send a first key negotiation request to the key management platform and receive a negotiation key handle and first public key information sent by the key management platform; send a second key negotiation request to the second client, the second key negotiation request comprising the session key handle, negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, negotiation key length and the first public key information; receive second public key information sent by the second client; the second public key information is sent to the second client by the key management platform; send a fourth key negotiation request to the key management platform, the fourth key negotiation request comprising the negotiation key handle; and receive a session key sent by the key management platform and communicate with the second client according to the session key.

[0036] The second client is configured to receive a second key negotiation request sent by the first client; send a third key negotiation request to the key management platform, the third key negotiation request comprising the session key handle, negotiation key length and the first public key information; receive second public key information sent by the key management platform; and send the second public key information to the first client.

[0037] The key management platform is configured to receive a two-way authentication request for a second client sent by a first client and send a session key handle to the first client after the two-way authentication is passed; receive a first key negotiation request sent by the first client, send a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, negotiation key length and the first public key information; receive a third key negotiation request sent by the second client, the third key negotiation request comprising the session key handle, negotiation key length and the first public key information; generate a session key and send second public key information to the second client; receive a fourth key negotiation request sent by the first client, the fourth key negotiation request comprising the negotiation key handle; and send a session key to the first client, so that the first client communicates with the second client according to the session key.

[0038] Optionally, the first client is configured to acquire first verification information from the key management platform, send the first verification information to the second client to enable the second client to verify the first verification information through the key management platform, receive second verification information sent by the second client, the second verification information being sent to the second client after the key management platform verifies the first verification information, verify the second verification information through the key management platform, and receive a session key handle sent by the key management platform after the key management platform verifies the second verification information;

[0039] The second client is configured to receive the first verification information sent by the first client, verify the first verification information through the key management platform, receive second verification information sent by the key management platform after the key management platform verifies the first verification information, and send the second verification information to the first client.

[0040] The key management platform is configured to receive a first verification information acquisition request sent by the first client, send first verification information to the first client, receive a first verification information verification request sent by the second client, send second verification information to the second client after the first verification information verification passes, receive a second verification information verification request sent by the first client, and send a session key handle to the first client after the second verification information verification passes.

[0041] Optionally, the system further comprises an identity authentication platform, and the first client is configured to send a registration session request to the identity authentication platform, the registration session request comprising third verification information, receive an authorization code sent by the identity authentication platform after the third verification information passes verification, send a connection establishment request to the second client, the connection establishment request comprising the authorization code to enable the second client to verify the authorization code through the identity authentication platform and receive an access code sent by the identity authentication platform after the authorization code passes verification, receive communication path information sent by the identity authentication platform, and configure a communication path according to the communication path information to communicate with the second client through the communication path according to the session key.

[0042] The second client is configured to receive the connection establishment request sent by the first client, verify the authorization code through the identity authentication platform, and receive the access code sent by the identity authentication platform after the authorization code passes verification.

[0043] The identity authentication platform is configured to receive a registration session request sent by the first client, wherein the registration session request comprises third verification information; send an authorization code to the first client after the third verification information is verified; receive an authorization code verification request sent by the second client, wherein the authorization code verification request comprises the authorization code; send an access code to the second client after the authorization code is verified; send communication path information to the first client and the second client, so that the first client configures a communication path according to the communication path information, and the first client and the second client communicate with each other through the communication path according to the session key.

[0044] Optionally, the first client is configured to receive a session state synchronization request sent by the identity authentication platform, wherein the session state synchronization request comprises session state information; and synchronize the session state with the second client according to the session state information.

[0045] The second client is configured to receive a session state synchronization request sent by the identity authentication platform, wherein the session state synchronization request comprises session state information; and synchronize the session state with the first client according to the session state information.

[0046] The identity authentication platform is configured to send a session state synchronization request to the first client and the second client, wherein the session state synchronization request comprises session state information, so that the first client and the second client synchronize the session state according to the session state information.

[0047] Correspondingly, the embodiment of the application discloses a communication device based on a signaling service system, which is applied to a first client, and the device comprises:

[0048] A bidirectional authentication request sending module is configured to send a bidirectional authentication request for a second client to a key management platform, and receive a session key handle sent by the key management platform after the bidirectional authentication is passed.

[0049] A first key negotiation request sending module is configured to send a first key negotiation request to the key management platform, and receive a negotiation key handle and first public key information sent by the key management platform.

[0050] A second key negotiation request sending module is configured to send a second key negotiation request to the second client, wherein the second key negotiation request comprises the session key handle, negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length and the first public key information.

[0051] The second public key information receiving module is configured to receive second public key information sent by the second client; and the second public key information is sent by the key management platform to the second client.

[0052] The fourth key negotiation request sending module is configured to send a fourth key negotiation request to the key management platform, wherein the fourth key negotiation request comprises the negotiation key handle.

[0053] The session key receiving module is configured to receive a session key sent by the key management platform, and communicate with the second client according to the session key.

[0054] Optionally, the bidirectional authentication request sending module comprises:

[0055] The first verification information obtaining submodule is configured to obtain first verification information from the key management platform.

[0056] The first verification information sending submodule is configured to send the first verification information to the second client, so that the second client verifies the first verification information through the key management platform.

[0057] The second verification information obtaining submodule is configured to receive second verification information sent by the second client, wherein the second verification information is sent to the second client after the key management platform verifies the first verification information.

[0058] The session key handle obtaining submodule is configured to verify the second verification information through the key management platform, and receive a session key handle sent by the key management platform after the key management platform verifies the second verification information.

[0059] Optionally, the apparatus further comprises:

[0060] The registration session request sending module is configured to send a registration session request to the identity authentication platform, wherein the registration session request comprises third verification information.

[0061] The authorization code receiving module is configured to receive an authorization code sent by the identity authentication platform after the third verification information is verified.

[0062] The connection establishment request sending module is configured to send a connection establishment request to the second client, wherein the connection establishment request comprises the authorization code, so that the second client verifies the authorization code through the identity authentication platform, and receives an access code sent by the key management platform after the authorization code is verified.

[0063] Optionally, the session key receiving module comprises:

[0064] A communication submodule is configured to receive the communication path information sent by the identity authentication platform, and configure a communication path according to the communication path information, so that the second client communicates with the first client through the communication path according to the session key.

[0065] Optionally, the apparatus further comprises:

[0066] A session state synchronization request receiving module is configured to receive a session state synchronization request sent by the identity authentication platform, wherein the session state synchronization request comprises session state information.

[0067] A session state synchronization module is configured to synchronize the session state with the second client according to the session state information.

[0068] Correspondingly, the application discloses a communication apparatus based on a signaling service system, which is applied to a key management platform, and comprises:

[0069] A bidirectional authentication request receiving module is configured to receive a bidirectional authentication request sent by a first client for a second client, and send a session key handle to the first client after the bidirectional authentication is passed.

[0070] A first key negotiation request receiving module is configured to receive a first key negotiation request sent by the first client, and send a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, negotiation key length and the first public key information.

[0071] A third key negotiation request receiving module is configured to receive a third key negotiation request sent by the second client, wherein the third key negotiation request comprises the session key handle, the negotiation key length and the first public key information, generate a session key, and send second public key information to the second client.

[0072] A fourth key negotiation request receiving module is configured to receive a fourth key negotiation request sent by the first client, wherein the fourth key negotiation request comprises the negotiation key handle, and send a session key to the first client, so that the first client communicates with the second client according to the session key.

[0073] Optionally, the bidirectional authentication request receiving module comprises:

[0074] A first verification information sending submodule is configured to receive a first verification information obtaining request sent by the first client, and send first verification information to the first client.

[0075] The second verification information sending sub-module is configured to receive a first verification information verification request sent by the second client, and send second verification information to the second client after the first verification information verification is passed.

[0076] The session key handle sending sub-module is configured to receive a second verification information verification request sent by the first client, and send a session key handle to the first client after the second verification information verification is passed.

[0077] Correspondingly, the embodiment of the application discloses an electronic device, comprising a processor, a memory, and a computer program stored in the memory and capable of running on the processor, and each step of the communication method based on the signaling service system is implemented when the computer program is executed by the processor.

[0078] Correspondingly, the embodiment of the application discloses a computer readable storage medium, and the computer readable storage medium stores a computer program, and each step of the communication method based on the signaling service system is implemented when the computer program is executed by a processor.

[0079] The embodiment of the application has the following advantages:

[0080] The communication method based on the signaling service system of the embodiment of the application is applied to a first client, sends a two-way authentication request for a second client to a key management platform, and receives a session key handle sent by the key management platform after two-way authentication is passed; sends a first key negotiation request to the key management platform, receives a negotiation key handle and first public key information sent by the key management platform; sends a second key negotiation request to the second client, the second key negotiation request comprising the session key handle, negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length and the first public key information; receives second public key information sent by the second client; the second public key information is sent to the second client by the key management platform; sends a fourth key negotiation request to the key management platform, the fourth key negotiation request comprising the negotiation key handle; receives a session key sent by the key management platform, and communicates with the second client according to the session key. Through the authentication mechanism based on quantum encryption technology, two-way identity authentication and quantum key negotiation are performed, the security of a signaling channel is ensured, and the risk of information leakage and malicious attacks is reduced. BRIEF DESCRIPTION OF DRAWINGS

[0081] Figure 1 is a step flowchart of a communication method based on a signaling service system according to an embodiment of the application;

[0082] Figure 2 is a flowchart of another communication method based on a signaling service system according to an embodiment of the present application;

[0083] Figure 3 is a flowchart of another communication method based on a signaling service system according to an embodiment of the present application;

[0084] Figure 4 is a flowchart of another communication method based on a signaling service system according to an embodiment of the present application;

[0085] Figure 5 is a flowchart of another communication method based on a signaling service system according to an embodiment of the present application;

[0086] Figure 6 is a structural block diagram of a communication device based on a signaling service system according to an embodiment of the present application;

[0087] Figure 7 is a structural block diagram of another communication device based on a signaling service system according to an embodiment of the present application. DETAILED DESCRIPTION

[0088] In order to make the above objectives, features and advantages of the present application more apparent, further detailed description will be made to the present application with reference to the accompanying drawings and specific embodiments.

[0089] The communication dispatch signaling service system is a system for managing and coordinating various signaling and control information in a communication network, and realizes information interaction and control between devices through standardized protocols and interfaces, and is mainly used to ensure that devices and users in the communication network can efficiently and reliably communicate. However, with the increase of network complexity and the number of devices, the signaling system faces security challenges.

[0090] One of the core ideas of the embodiments of the present application is to perform two-way identity authentication and key agreement based on security authentication, and to perform two-way identity authentication and quantum key agreement through an authentication mechanism based on quantum encryption technology, which can ensure the security of the signaling channel and reduce the risk of information leakage and malicious attacks.

[0091] Referring to Figure 1 , a step flowchart of a communication method based on a signaling service system according to an embodiment of the present application is shown, which is applied to a first client and can specifically include the following steps:

[0092] Step 101, sending a two-way authentication request for a second client to a key management platform, and receiving a session key handle sent by the key management platform after the two-way authentication is passed.

[0093] Specifically,Figure 2 A flowchart of another communication method based on a signaling service system is shown, a first client sends a two-way authentication request for a second client to a key management platform, and receives a session key handle sent by the key management platform after two-way authentication is passed. The key management platform can be a key management service (KMS) platform, and the two-way authentication request can be a two-way identity authentication request for two-way identity authentication between the first client and the second client. The first client and the second client verify each other's identity when establishing a connection to ensure that only legitimate entities can communicate. Two-way identity authentication has many advantages, such as enhancing security, ensuring the identity of both parties in communication, preventing man-in-the-middle attacks, and preventing impersonation attacks by verifying the identity of the first client and the second client. Two-way identity authentication establishes a trust relationship between the two parties in communication, ensuring that only legitimate entities can communicate, meeting the requirements of various data protection laws and standards, and being flexible and applicable to various protocols and scenarios, supporting various identity verification methods such as certificates, tokens, and biometric identification.

[0094] Step 102, send a first key negotiation request to the key management platform, and receive a negotiation key handle and first public key information sent by the key management platform.

[0095] Specifically, after two-way identity verification is completed, the key negotiation process is entered, the first client carries the negotiated key length and the initiator's identity, that is, the first client's identity, to send a first key negotiation request to the key management platform, receives the negotiation key handle and the first public key information returned by the key management platform, and caches the negotiation key handle. The first public key information is the public key information of the first client, and the identity of the first client can be the ID of the first client, which is not limited by the embodiments of the application.

[0096] The key negotiation process is a key link in cryptography, which involves two or more entities securely generating or exchanging encryption keys over an insecure communication channel. This process ensures that even if the communication is eavesdropped, the attacker cannot easily obtain the key information. The key negotiation of the embodiments of the application generates a symmetric key through a quantum key distribution protocol when the two parties in communication establish a connection, which is used for subsequent encryption and decryption of signaling messages.

[0097] Step 103, send a second key negotiation request to the second client, the second key negotiation request including the session key handle, the negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length and the first public key information.

[0098] Specifically, after receiving the negotiation key handle and the first public key information returned by the key management platform, the first client sends a second key negotiation request to the second client, carrying the identity of the first client, the session key handle, the negotiation key length, and the first public key information. After receiving the second key negotiation request sent by the first client, the second client sends a third key negotiation request to the key management platform, carrying the identity of the first client, the identity of the second client, the session key handle, the negotiation key length, and the first public key information.

[0099] Step 104, receiving the second public key information sent by the second client; the second public key information is sent to the second client by the key management platform.

[0100] Specifically, after the second client sends the third key negotiation request to the key management platform, the key management platform generates a session key and returns the second public key information and the negotiation key handle to the second client, wherein the second public key information is the public key information of the second client. After receiving the second public key information and the negotiation key handle returned by the key management platform, the second client returns the second public key information and the identity of the second client to the first client. The first client receives the second public key information and the identity of the second client sent by the second client.

[0101] Step 105, sending a fourth key negotiation request to the key management platform, the fourth key negotiation request including the negotiation key handle.

[0102] Specifically, after receiving the second public key information and the identity of the second client sent by the second client, the negotiation key handle is carried to send a fourth key negotiation request to the key management platform.

[0103] Step 106, receiving the session key sent by the key management platform, and communicating with the second client according to the session key.

[0104] Specifically, after sending the fourth key negotiation request to the key management platform, the session key returned by the key management platform is received. At this point, the initiator first client and the receiver second client have established a secure channel link, and the first client can communicate with the second client according to the session key.

[0105] The embodiment of the application is based on a communication method of a signaling service system, applied to a first client, sending a two-way authentication request for a second client to a key management platform, and receiving a session key handle sent by the key management platform after two-way authentication is passed; sending a first key negotiation request to the key management platform, and receiving a negotiation key handle and first public key information sent by the key management platform; sending a second key negotiation request to the second client, the second key negotiation request including the session key handle, negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length and the first public key information; receiving second public key information sent by the second client; the second public key information is sent to the second client by the key management platform; sending a fourth key negotiation request to the key management platform, the fourth key negotiation request including the negotiation key handle; receiving a session key sent by the key management platform, and communicating with the second client according to the session key. Through the authentication mechanism based on quantum encryption technology, two-way identity authentication and quantum key negotiation are performed, which can ensure the security of the signaling channel and reduce the risk of information leakage and malicious attacks.

[0106] In the embodiment of the application, step 101 includes the following sub-steps:

[0107] Sub-step S11, obtaining first verification information from the key management platform.

[0108] Specifically, Figure 3 A flowchart of another communication method of a signaling service system is shown, when the first client tries to establish a connection with the second client, the first client initiates a request to the key management platform to obtain first verification information, the first verification information including a random number RA and a signature of the random number RA, and receiving the random number RA and the signature of the random number RA returned by the key management platform.

[0109] Sub-step S12, sending the first verification information to the second client, so that the second client verifies the first verification information through the key management platform.

[0110] Specifically, after obtaining the random number RA and the signature of the random number RA, the first client initiates a verification request to the second client, carrying the random number RA, the signature of the random number RA and the SM2 certificate of the first client. After receiving the random number RA, the signature of the random number RA and the SM2 certificate of the first client, the second client sends the random number RA, the signature of the random number RA and the SM2 certificate of the first client to the key management platform. After receiving the random number RA, the signature of the random number RA and the SM2 certificate of the first client, the key management platform verifies the signature of the random number RA according to the SM2 certificate of the first client.

[0111] The SM2 certificate is a digital certificate based on the SM2 elliptic curve public key cryptography algorithm (SM2 for short) issued by the China National Cryptography Administration. The SM2 algorithm is a kind of asymmetric encryption algorithm, similar to RSA and ECC (Elliptic Curve Cryptography), but with higher security and efficiency. The SM2 certificate is usually used in scenarios such as identity verification, digital signature and data encryption.

[0112] Sub-step S13, receiving the second verification information sent by the second client, wherein the second verification information is sent to the second client after the key management platform verifies that the first verification information is passed.

[0113] Specifically, the second client verifies the signature of the random number RA through the key management platform, and after the verification is passed, the second client initiates a request to the key management platform to obtain the second verification information, which includes the random number RB and the signature of the combination of the random number RB and the random number RB. The second client receives the random number RB and the signature of the combination of the random number RB and the random number RB returned by the key management platform, and sends the random number RB, the signature of the combination of the random number RB and the random number RB and the SM2 certificate of the second client to the first client.

[0114] Sub-step S14, verifying the second verification information through the key management platform, and receiving the session key handle sent by the key management platform after verifying that the second verification information is passed.

[0115] Specifically, after receiving the random number RB, the signature of the combination of the random number RB and the random number RB and the SM2 certificate of the second client sent by the second client, the first client sends a verification request to the key management platform, carrying the random number RB, the signature of the combination of the random number RB and the random number RB and the SM2 certificate of the second client. The key management platform verifies the signature of the combination of the random number RB and the random number RB according to the SM2 certificate of the second client, and returns the session key handle to the first client after the verification is passed. Thus, the two-way identity authentication process is completed.

[0116] In the embodiment of the application, the method further comprises:

[0117] Step 201: Send a registration session request to the identity authentication platform. The registration session request includes third-party verification information.

[0118] Specifically, Figure 4 This diagram illustrates a flowchart of another communication method based on a signaling service system according to an embodiment of the present invention. In a cross-domain session scenario, the first client may be located in system A, and the second client may be located in system B. These two systems are connected via a network but may belong to different domains or network environments. Cross-domain refers to the interaction between different systems or network environments. These systems can be different physical servers, cloud service instances, virtual machines, or physical machines, etc., which are connected via a network but managed and maintained independently. In the cross-domain session scenario, the key management platform of the first client is the key management platform of the domain where the first client resides, and the key management platform of the second client is the key management platform of the domain where the second client resides.

[0119] The first client sends a registration session request to the identity authentication platform, carrying third-party verification information, which is a token. The token includes the second client's ID, IP address, port number, and other information. The identity authentication platform can be an Identity and Access Management (IAM) platform, featuring single sign-on, robust authentication management, policy-based centralized authorization and auditing, dynamic authorization, and enterprise manageability.

[0120] Step 202: Receive the authorization code sent by the identity authentication platform after verifying that the third verification information has been verified.

[0121] Specifically, the identity authentication platform verifies the token, generates a short-term valid code authorization code after successful verification, and returns the short-term valid code authorization code to the first client.

[0122] Step 203: Send a connection establishment request to the second client. The connection establishment request includes the authorization code, so that the second client can verify the authorization code through the identity authentication platform, and after the authorization code is verified, receive an access code sent by the identity authentication platform.

[0123] Specifically, after receiving the authorization code, the first client sends a connection request to the second client, carrying the authorization code. The second client verifies the authorization code through the identity authentication platform and receives the access code sent by the identity authentication platform after successful verification. At this point, the session between the first client and the second client is successfully established.

[0124] In the embodiment of the present application, the communication with the second client according to the session key comprises:

[0125] Receiving the communication path information sent by the identity authentication platform, and configuring a communication path according to the communication path information, so as to communicate with the second client through the communication path according to the session key.

[0126] Specifically, after the first client registers a session on the identity authentication platform, the identity authentication platform can identify and manage the cross-domain session, and when the first client tries to establish a connection with the second client, the identity authentication platform can determine a suitable communication path according to the registered session information, combined with network topology and security policy, which may involve firewall rules, NAT configuration, and VPN tunnel, to ensure that data can safely cross different networks and systems, and send the determined communication path information to the first client and the second client, so that the first client and the second client can configure network settings according to the communication path information, thereby establishing a connection and starting communication.

[0127] In the embodiment of the present application, the method further comprises:

[0128] Receiving a session state synchronization request sent by the identity authentication platform; the session state synchronization request comprises session state information;

[0129] Synchronizing the session state with the second client according to the session state information.

[0130] Specifically, in order to ensure the consistency of the session state among multiple systems, the identity authentication platform can periodically synchronize the session state information of the first client and the second client, which includes session ID, connection state, authentication information, and session timeout time. Periodic synchronization rather than instant synchronization is for performance consideration to reduce network traffic and computing resource consumption.

[0131] The embodiment of the present application generates a symmetric key using a quantum key distribution protocol, and combines digital signature technology to encrypt and verify the signaling message. The authentication mechanism based on quantum encryption has higher security. Quantum encryption technology uses the principles of quantum mechanics to provide theoretical unconditional security, which cannot be cracked even by quantum computers. In addition, the digital signature technology ensures the integrity and authenticity of the message, effectively preventing the message from being tampered with or forged. Therefore, the present application greatly improves the security of the communication system and reduces the risk of information leakage and malicious attacks.

[0132] Through mechanisms such as session registration, session routing, and session synchronization, signaling and session intercommunication between different systems or networks are realized. The cross-domain session management mechanism enhances the cross-domain intercommunication and interoperability of the system. It solves the compatibility problem between different systems or networks, enabling multiple independently deployed systems to seamlessly connect and work together. This not only improves the flexibility and scalability of the system, but also reduces the cost of system integration and maintenance.

[0133] AI technology can also be used to analyze historical data and real-time traffic, predict future communication demand, and dynamically adjust resource allocation and scheduling strategies accordingly. For example, when the system detects that a large number of users attempt to establish requests during a certain period of time, the AI algorithm can predict that a traffic peak will soon occur and increase the bandwidth and server resources of the system in advance. In addition, the AI algorithm can also identify abnormal traffic and attack behaviors such as DDoS attacks, and take appropriate security measures such as flow limiting, IP blocking, etc. in time. AI optimization of communication scheduling improves the scheduling efficiency and response speed of the system. AI algorithms can accurately predict communication demand and dynamically adjust resource allocation according to demand, thereby achieving fast response and efficient processing of communication requests. This not only improves the efficiency of the system, but also reduces resource waste and cost expenditure. At the same time, the AI algorithm can automatically identify abnormal traffic and attack behaviors and take appropriate security measures to further enhance the security of the system.

[0134] Referring to Figure 5 , another step flow chart of a communication method based on a signaling service system is shown, which is applied to a key management platform and can specifically include the following steps:

[0135] Step 301, receiving a two-way authentication request sent by a first client to a second client, and sending a session key handle to the first client after the two-way authentication is passed.

[0136] Step 302, receiving a first key negotiation request sent by the first client, sending a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, the negotiation key handle length and the first public key information.

[0137] Step 303, receiving a third key negotiation request sent by a second client, the third key negotiation request including the session key handle, the negotiation key handle length and the first public key information; generating a session key and sending second public key information to the second client.

[0138] Step 304, receiving the fourth key negotiation request sent by the first client, the fourth key negotiation request comprising the negotiation key handle; sending a session key to the first client, so that the first client communicates with the second client according to the session key.

[0139] In the embodiment of the present application, step 301 can specifically include the following sub-steps:

[0140] Sub-step S21, receiving a first authentication information obtaining request sent by the first client, and sending first authentication information to the first client.

[0141] Sub-step S22, receiving a first authentication information verification request sent by the second client, and sending second authentication information to the second client after the first authentication information verification passes.

[0142] Sub-step S23, receiving a second authentication information verification request sent by the first client, and sending a session key handle to the first client after the second authentication information verification passes.

[0143] It should be noted that, for the method embodiment, in order to simply describe, all are described as a series of action combinations, but those skilled in the art should know that the embodiment of the present application is not limited by the action sequence described, because according to the embodiment of the present application, some steps can be in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily the embodiment of the present application.

[0144] In the embodiment of the present application, the system comprises a first client, a second client and a key management platform;

[0145] The first client is configured to send a two-way authentication request for the second client to the key management platform and receive a session key handle sent by the key management platform after the two-way authentication is passed; send a first key negotiation request to the key management platform and receive a negotiation key handle and first public key information sent by the key management platform; send a second key negotiation request to the second client, the second key negotiation request comprising the session key handle, the negotiation key handle length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key handle length and the first public key information; receive second public key information sent by the second client; the second public key information is sent by the key management platform to the second client; send a fourth key negotiation request to the key management platform, the fourth key negotiation request comprising the negotiation key handle; and receive a session key sent by the key management platform and communicate with the second client according to the session key.

[0146] The second client is configured to receive a second key negotiation request sent by the first client; send a third key negotiation request to the key management platform, the third key negotiation request comprising the session key handle, the negotiation key handle length and the first public key information; receive second public key information sent by the key management platform; and send the second public key information to the first client.

[0147] The key management platform is configured to receive a two-way authentication request for a second client sent by a first client and send a session key handle to the first client after the two-way authentication is passed; receive a first key negotiation request sent by the first client, send a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, the negotiation key handle length and the first public key information; receive a third key negotiation request sent by the second client, the third key negotiation request comprising the session key handle, the negotiation key handle length and the first public key information; generate a session key and send second public key information to the second client; receive a fourth key negotiation request sent by the first client, the fourth key negotiation request comprising the negotiation key handle; and send a session key to the first client, so that the first client communicates with the second client according to the session key.

[0148] In the embodiment of the present application, the first client is configured to acquire first verification information from the key management platform, send the first verification information to the second client to enable the second client to verify the first verification information through the key management platform, receive second verification information sent by the second client, the second verification information being sent to the second client after the first verification information is verified by the key management platform, verify the second verification information through the key management platform, and receive a session key handle sent by the key management platform after the second verification information is verified by the key management platform;

[0149] The second client is configured to receive the first verification information sent by the first client, verify the first verification information through the key management platform, receive second verification information sent by the key management platform after the first verification information is verified by the key management platform, and send the second verification information to the first client.

[0150] The key management platform is configured to receive a first verification information acquisition request sent by the first client, send first verification information to the first client, receive a first verification information verification request sent by the second client, send second verification information to the second client after the first verification information verification is passed, receive a second verification information verification request sent by the first client, and send a session key handle to the first client after the second verification information verification is passed.

[0151] In the embodiment of the present application, the system further comprises an identity authentication platform, the first client is configured to send a registration session request to the identity authentication key management platform, the registration session request comprising third verification information, receive an authorization code sent by the identity authentication key management platform after the third verification information is verified, send a connection establishment request to the second client, the connection establishment request comprising the authorization code to enable the second client to verify the authorization code through the identity authentication key management platform and receive an access code sent by the identity authentication key management platform after the authorization code is verified, receive communication path information sent by the identity authentication key management platform, and configure a communication path according to the communication path information to communicate with the second client through the communication path according to the session key.

[0152] The second client is configured to receive the connection establishment request sent by the first client, verify the authorization code through the identity authentication key management platform, and receive an access code sent by the identity authentication key management platform after the authorization code is verified.

[0153] The identity authentication key management platform is configured to receive a registration session request sent by the first client, wherein the registration session request comprises third verification information; send an authorization code to the first client after the third verification information is verified; receive an authorization code verification request sent by the second client, wherein the authorization code verification request comprises the authorization code; send an access code to the second client after the authorization code is verified; send communication path information to the first client and the second client, so that the first client configures a communication path according to the communication path information, and the second client communicates with the first client through the communication path according to the session key.

[0154] In the embodiment of the present application, the first client is configured to receive a session state synchronization request sent by the identity authentication key management platform, wherein the session state synchronization request comprises session state information; and synchronize the session state with the second client according to the session state information.

[0155] The second client is configured to receive a session state synchronization request sent by the identity authentication key management platform, wherein the session state synchronization request comprises session state information; and synchronize the session state with the first client according to the session state information.

[0156] The identity authentication key management platform is configured to send a session state synchronization request to the first client and the second client, wherein the session state synchronization request comprises session state information, so that the first client and the second client synchronize the session state according to the session state information.

[0157] Referring to Figure 6 , a structure block diagram of a communication device based on a signaling service system is shown, which is applied to a first client and can specifically include the following modules:

[0158] The bidirectional authentication request sending module 401 is configured to send a bidirectional authentication request for a second client to a key management platform, and receive a session key handle sent by the key management platform after the bidirectional authentication is passed;

[0159] The first key negotiation request sending module 402 is configured to send a first key negotiation request to the key management platform, and receive a negotiation key handle and first public key information sent by the key management platform;

[0160] The second key negotiation request sending module 403 is configured to send a second key negotiation request to the second client, wherein the second key negotiation request comprises the session key handle, the negotiation key length handle and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length handle and the first public key information;

[0161] The second public key information receiving module 404 is configured to receive second public key information sent by the second client, wherein the second public key information is sent to the second client by the key management platform.

[0162] The fourth key negotiation request sending module 405 is configured to send a fourth key negotiation request to the key management platform, wherein the fourth key negotiation request comprises the negotiation key handle.

[0163] The session key receiving module 406 is configured to receive a session key sent by the key management platform, and communicate with the second client according to the session key.

[0164] In the embodiment of the application, the bidirectional authentication request sending module comprises:

[0165] The first verification information obtaining submodule is configured to obtain first verification information from the key management platform.

[0166] The first verification information sending submodule is configured to send the first verification information to the second client, so that the second client verifies the first verification information through the key management platform.

[0167] The second verification information obtaining submodule is configured to receive second verification information sent by the second client, wherein the second verification information is sent to the second client after the key management platform verifies the first verification information.

[0168] The session key handle obtaining submodule is configured to verify the second verification information through the key management platform, and receive a session key handle sent by the key management platform after the key management platform verifies the second verification information.

[0169] In the embodiment of the application, the apparatus further comprises:

[0170] The registration session request sending module is configured to send a registration session request to the identity authentication key management platform, wherein the registration session request comprises third verification information.

[0171] The authorization code receiving module is configured to receive an authorization code sent by the identity authentication key management platform after verifying that the third verification information is verified.

[0172] The connection establishment request sending module is configured to send a connection establishment request to the second client, the connection establishment request comprising the authorization code, so that the second client verifies the authorization code through the identity authentication key management platform, and receives an access code sent by the key management platform after the authorization code is verified to be correct.

[0173] In the embodiment of the application, the session key receiving module comprises:

[0174] The communication submodule is configured to receive communication path information sent by the identity authentication key management platform, and configure a communication path according to the communication path information, so that the second client communicates with the first client through the communication path according to the session key.

[0175] In the embodiment of the application, the apparatus further comprises:

[0176] The session state synchronization request receiving module is configured to receive a session state synchronization request sent by the identity authentication key management platform, the session state synchronization request comprising session state information.

[0177] The session state synchronization module is configured to synchronize a session state with the second client according to the session state information.

[0178] Referring to Figure 7 , another structural block diagram of a communication apparatus based on a signaling service system according to an embodiment of the application is shown, which is applied to a key management platform and can specifically comprise the following modules:

[0179] The bidirectional authentication request receiving module 501 is configured to receive a bidirectional authentication request sent by a first client for a second client, and send a session key handle to the first client after the bidirectional authentication is passed.

[0180] The first key negotiation request receiving module 502 is configured to receive a first key negotiation request sent by the first client, send a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, negotiation key length and the first public key information.

[0181] The third key negotiation request receiving module 503 is configured to receive a third key negotiation request sent by the second client, the third key negotiation request comprising the session key handle, the negotiation key length and the first public key information, generate a session key and send second public key information to the second client.

[0182] The fourth key negotiation request receiving module 504 is configured to receive a fourth key negotiation request sent by the first client, wherein the fourth key negotiation request comprises the negotiation key handle; and send a session key to the first client, so that the first client communicates with the second client according to the session key.

[0183] In the embodiment of the present application, the bidirectional authentication request receiving module comprises:

[0184] The first authentication information sending sub-module is configured to receive a first authentication information obtaining request sent by the first client, and send first authentication information to the first client.

[0185] The second authentication information sending sub-module is configured to receive a first authentication information verification request sent by the second client, and send second authentication information to the second client after the first authentication information verification is passed.

[0186] The session key handle sending sub-module is configured to receive a second authentication information verification request sent by the first client, and send a session key handle to the first client after the second authentication information verification is passed.

[0187] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the related parts refer to the part of the method embodiment.

[0188] The embodiment of the present application further provides an electronic device, comprising:

[0189] The electronic device comprises a processor, a memory and a computer program stored in the memory and capable of running on the processor, wherein the computer program is executed by the processor to realize each process of the communication method based on the signaling service system and achieve the same technical effects, and thus the details are not described herein again.

[0190] The embodiment of the present application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to realize each process of the communication method based on the signaling service system and achieve the same technical effects, and thus the details are not described herein again.

[0191] Each embodiment in the specification is described in a progressive manner, and each embodiment mainly describes the difference from other embodiments, and the same and similar parts of each embodiment can be referred to.

[0192] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, apparatus, or computer program product. Accordingly, embodiments of the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer program instructions.

[0193] Embodiments of the present application are described herein with reference to the drawings, which are as follows: Figure 1 Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing terminal, such that a series of operational steps are carried out on the computer or other programmable data terminal to produce computer-implemented processing, such that the instructions which execute on the computer or other programmable terminal provide steps for implementing the functions specified in the flowchart block or blocks.

[0194] The computer program instructions can also be loaded onto a computer or other programmable data processing terminal, such that a series of operational steps are carried out on the computer or other programmable data terminal to produce computer-implemented processing, such that the instructions which execute on the computer or other programmable terminal provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing terminal, such that a series of operational steps are carried out on the computer or other programmable data terminal to produce computer-implemented processing, such that the instructions which execute on the computer or other programmable terminal provide steps for implementing the functions specified in the flowchart block or blocks.

[0195] The computer program instructions can also be loaded onto a computer or other programmable data processing terminal, such that a series of operational steps are carried out on the computer or other programmable data terminal to produce computer-implemented processing, such that the instructions which execute on the computer or other programmable terminal provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing terminal, such that a series of operational steps are carried out on the computer or other programmable data terminal to produce computer-implemented processing, such that the instructions which execute on the computer or other programmable terminal provide steps for implementing the functions specified in the flowchart block or blocks.

[0196] While preferred embodiments of the present application have been described, modifications and alterations thereto can occur to those skilled in the art upon reading the preceding description. It is intended to include all such modifications and alterations insofar as they come within the scope of the embodiments of the present application. Accordingly, the following claims are intended to cover all embodiments of the present application, including all equivalents thereof.

[0197] ​​​Finally, it is to be understood that the phraseology or terminology such as "first" and "second" etc. used herein is merely intended to differentiate one entity or operation from another entity or operation, without necessarily requiring or implying any actual such relationship or order between such entities or operations. Moreover, the terms "comprising", "including", or any other closure, are intended to cover the non-exclusive inclusion such that a process, method, article, or apparatus that comprises a list of elements does not include those elements alone but can include other elements not expressly listed or even include elements inherent in such process, method, article, or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0198] The above describes in detail the signaling service system and the communication method based on the signaling service system provided by the present application. The principles and implementation modes of the present application are described by using specific examples. The above description of the examples is only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, the specific implementation modes and application ranges can be changed according to the idea of the present application. In summary, the content of the specification should not be understood as a limitation of the present application.

Claims

1. A communication method based on a signaling service system, characterized by, The method applied to the first client comprises: sending a two-way authentication request for the second client to the key management platform, and receiving a session key handle sent by the key management platform after the two-way authentication is passed; sending a first key negotiation request to the key management platform, and receiving a negotiation key handle and first public key information sent by the key management platform; sending a second key negotiation request to the second client, the second key negotiation request comprising the session key handle, negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, negotiation key length and the first public key information, and the key management platform generates a session key after receiving the third key negotiation request; receiving second public key information sent by the second client; the second public key information is sent to the second client by the key management platform; sending a fourth key negotiation request to the key management platform, the fourth key negotiation request comprising the negotiation key handle; receiving the session key sent by the key management platform, and communicating with the second client according to the session key.

2. The method of claim 1, wherein, The method further comprises: obtaining first verification information from the key management platform; sending the first verification information to the second client, so that the second client verifies the first verification information through the key management platform; receiving second verification information sent by the second client, the second verification information being sent to the second client after the key management platform verifies the first verification information; verifying the second verification information through the key management platform, and receiving a session key handle sent by the key management platform after verifying the second verification information.

3. The method of claim 1, wherein, The method further comprises: sending a registration session request to an identity authentication platform, the registration session request comprising third verification information; receiving an authorization code sent by the identity authentication platform after verifying the third verification information; sending a connection establishment request to the second client, the connection establishment request comprising the authorization code, so that the second client verifies the authorization code through the identity authentication platform, and receives an access code sent by the key management platform after verifying the authorization code.

4. The method of claim 3, wherein, The method further comprises: receiving communication path information sent by the identity authentication platform, and configuring a communication path according to the communication path information, so that the second client communicates through the communication path according to the session key.

5. The method of claim 4, wherein, The method further comprises: receiving a session state synchronization request sent by the identity authentication platform; the session state synchronization request comprising session state information; synchronizing session states with the second client according to the session state information.

6. A communication method based on a signaling service system, characterized by, The method applied to the key management platform comprises: receive a two-way authentication request for a second client sent by a first client, and send a session key handle to the first client after the two-way authentication is passed; receive a first key negotiation request sent by the first client, send a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, negotiation key length and the first public key information; receive a third key negotiation request sent by the second client, the third key negotiation request including the session key handle, the negotiation key length and the first public key information; generate a session key and send second public key information to the second client; receive a fourth key negotiation request sent by the first client, the fourth key negotiation request including the negotiation key handle; send a session key to the first client, so that the first client communicates with the second client according to the session key.

7. The method of claim 6, wherein, The receiving a two-way authentication request for a second client sent by a first client, and sending a session key handle to the first client after the two-way authentication is passed, includes: receive a first authentication information acquisition request sent by the first client, and send first authentication information to the first client; receive a first authentication information verification request sent by the second client, and send second authentication information to the second client after the first authentication information verification is passed; receive a second authentication information verification request sent by the first client, and send a session key handle to the first client after the second authentication information verification is passed.

8. A signaling service system, characterized by The system includes a first client, a second client and a key management platform; The first client is configured to send a two-way authentication request for the second client to the key management platform, and receive a session key handle sent by the key management platform after the two-way authentication is passed; send a first key negotiation request to the key management platform, and receive a negotiation key handle and first public key information sent by the key management platform; send a second key negotiation request to the second client, the second key negotiation request including the session key handle, negotiation key length and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length and the first public key information; receive second public key information sent by the second client; the second public key information is sent to the second client by the key management platform; send a fourth key negotiation request to the key management platform, the fourth key negotiation request including the negotiation key handle; receive a session key sent by the key management platform, and communicate with the second client according to the session key; The second client is configured to receive a second key negotiation request sent by the first client. sending a third key negotiation request to the key management platform, the third key negotiation request comprising the session key handle, the negotiation key length and the first public key information; receiving second public key information sent by the key management platform; and sending the second public key information to the first client; the key management platform configured to receive a bidirectional authentication request sent by the first client for the second client, and send a session key handle to the first client after the bidirectional authentication is passed; receive a first key negotiation request sent by the first client, and send negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, the negotiation key length and the first public key information; receiving a third key negotiation request sent by the second client, the third key negotiation request comprising the session key handle, the negotiation key length and the first public key information; generating a session key and sending second public key information to the second client; receiving a fourth key negotiation request sent by the first client, the fourth key negotiation request comprising the negotiation key handle; sending the session key to the first client, so that the first client communicates with the second client according to the session key.

9. The system of claim 8, wherein the first client is configured to obtain first verification information from the key management platform, and send the first verification information to the second client, so that the second client verifies the first verification information through the key management platform; receiving second verification information sent by the second client, the second verification information being sent to the second client after the key management platform verifies the first verification information; verifying the second verification information through the key management platform, and receiving a session key handle sent by the key management platform after the key management platform verifies the second verification information; the second client is configured to receive the first verification information sent by the first client; verifying the first verification information through the key management platform, and receiving second verification information sent by the key management platform after the key management platform verifies the first verification information; and sending the second verification information to the first client; the key management platform is configured to receive a first verification information obtaining request sent by the first client, and send first verification information to the first client; receiving a first verification information verification request sent by the second client, and sending second verification information to the second client after the first verification information verification is passed; receiving a second verification information verification request sent by the first client, and sending a session key handle to the first client after the second verification information verification is passed.

10. The system of claim 8, wherein, The system further comprises an identity authentication platform. The first client is configured to send a registration session request to the identity authentication platform, the registration session request comprising third verification information; receive an authorization code sent by the identity authentication platform after the third verification information is verified to be correct; The first client is configured to send a registration session request to the identity authentication platform, the registration session request comprising third verification information; receive an authorization code sent by the identity authentication platform after the third verification information is verified to be correct; The first client is configured to send a registration session request to the identity authentication platform, the registration session request comprising third verification information; receive an authorization code sent by the identity authentication platform after the third verification information is verified to be correct; The second client is configured to receive the establishment connection request sent by the first client; verify the authorization code through the identity authentication platform; and receive an access code sent by the identity authentication platform after the authorization code is verified to be correct. The identity authentication platform is configured to receive the registration session request sent by the first client, the registration session request comprising third verification information; send an authorization code to the first client after the third verification information is verified to be correct; receive an authorization code verification request sent by the second client, the authorization code verification request comprising the authorization code; send an access code to the second client after the authorization code is verified to be correct; and send communication path information to the first client and the second client, so that the first client configures a communication path according to the communication path information, and communicates with the second client through the communication path according to the session key.

11. The system of claim 10, wherein The first client is configured to receive a session state synchronization request sent by the identity authentication platform, the session state synchronization request comprising session state information; and synchronize session state with the second client according to the session state information. The second client is configured to receive a session state synchronization request sent by the identity authentication platform, the session state synchronization request comprising session state information; and synchronize session state with the first client according to the session state information. The identity authentication platform is configured to send a session state synchronization request to the first client and the second client, the session state synchronization request comprising session state information, so that the first client and the second client synchronize session state according to the session state information.

12. A communication apparatus based on a signaling service system, characterized by The device applied to the first client comprises: A bidirectional authentication request sending module configured to send a bidirectional authentication request for a second client to a key management platform, and receive a session key handle sent by the key management platform after bidirectional authentication is passed; A first key agreement request sending module configured to send a first key agreement request to the key management platform, and receive a negotiation key handle and first public key information sent by the key management platform; The second key negotiation request sending module is configured to send a second key negotiation request to the second client, the second key negotiation request comprising the session key handle, a negotiation key length, and the first public key information, so that the second client sends a third key negotiation request to the key management platform according to the session key handle, the negotiation key length, and the first public key information; The second public key information receiving module is configured to receive second public key information sent by the second client; the second public key information is sent to the second client by the key management platform; The fourth key negotiation request sending module is configured to send a fourth key negotiation request to the key management platform, the fourth key negotiation request comprising the negotiation key handle; The session key receiving module is configured to receive a session key sent by the key management platform, and communicate with the second client according to the session key.

13. A communication apparatus based on a signaling service system, characterized by The device is applied to a key management platform, and the device comprises: The bidirectional authentication request receiving module is configured to receive a bidirectional authentication request for a second client sent by a first client, and send a session key handle to the first client after the bidirectional authentication is passed; The first key negotiation request receiving module is configured to receive a first key negotiation request sent by the first client, send a negotiation key handle and first public key information to the first client, so that the first client sends a second key negotiation request to the second client according to the session key handle, a negotiation key length, and the first public key information; The third key negotiation request receiving module is configured to receive a third key negotiation request sent by the second client, the third key negotiation request comprising the session key handle, the negotiation key length, and the first public key information; generate a session key and send second public key information to the second client; The fourth key negotiation request receiving module is configured to receive a fourth key negotiation request sent by the first client, the fourth key negotiation request comprising the negotiation key handle; send a session key to the first client, so that the first client communicates with the second client according to the session key.

14. An electronic device, comprising: The device comprises: A processor, a memory, and a computer program stored on the memory and capable of running on the processor, the computer program being executed by the processor to implement the steps of the communication method based on the signaling service system according to any one of claims 1-5 or claims 6-7.

15. A computer-readable storage medium, characterized in that, A computer program is stored on the computer readable storage medium, and the computer program is executed by the processor to implement the steps of the communication method based on the signaling service system according to any one of claims 1-5 or claims 6-7.

Citation Information

Patent Citations

  • Quantum communication service station key negotiation method, system and equipment based on asymmetric key pool pair and QKD

    CN110266483A

  • Identity authentication method and data transmission method of MQTT protocol based on IPK

    CN118540167A