A secure communication method, related device and storage medium

By establishing groups based on identity information in a classroom setting and using a key mechanism for encryption and decryption, the problem of end-to-end encryption and authentication in classroom communication is solved, realizing end-to-end encrypted communication and secure message transmission within groups.

CN119696786BActive Publication Date: 2025-11-04CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311247285.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-25
Publication Date
2025-11-04
Estimated Expiration
2043-09-25

AI Technical Summary

Technical Problem

In a classroom setting, the communication link between the client and the server is not fully encrypted, the teacher's identity is not verified, and it is impossible to determine the source and authenticity of instructions and messages. Furthermore, the Kerberos protocol is not suitable for group authentication and information sharing.

Method used

By establishing a group based on identity information after terminal registration, using a key to encrypt and decrypt messages, verifying terminal identity, and transmitting key sessions within the group, end-to-end encrypted communication is achieved using the key mechanism of network devices and terminals.

Benefits of technology

It implements end-to-end encrypted communication, ensuring the authenticity of message sources, verifying the identities of group members, preventing message forgery, and improving data security and resource management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696786B_ABST
    Figure CN119696786B_ABST
Patent Text Reader

Abstract

The application discloses a secure communication method and device, network equipment, a terminal and a storage medium. The method comprises the following steps: after the registration of at least one terminal is successful, at least one group is established based on the identity information of each terminal; a first message sent by a first terminal in the at least one terminal is received; the first message at least comprises first authentication information encrypted by a first secret key; the first secret key is generated based on the role of each terminal; the first authentication information is decrypted by using a second secret key of itself to obtain second authentication information; whether the first terminal belongs to a first group is judged based on the second authentication information; in the case that the first terminal belongs to the first group, a second message is sent to the first terminal; the second message comprises a third secret key; the third secret key is used for a secret key session between the first terminal and other terminals in the first group.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network communication, and in particular to a secure communication method, related devices and a storage medium. BACKGROUND

[0002] In a classroom scenario, teachers use new generation information devices (such as personal computers (PCs), electronic whiteboards, tablet computers) to teach, and students also use devices (tablets, PCs, virtual reality (VR) all-in-one machines) to learn and experiment. In this mode, corresponding teaching content resources, such as video resources and VR teaching resources, need to be used, and the cost of such resources is relatively high. For content resource producers, authorization is performed according to clients, and use is strictly limited. Usually, a classroom is a unit for unified management of teaching, and therefore there is a strong requirement for data security and communication process security. However, in the related art, the client and the server in the communication process do not implement full-link encryption of the communication link from the client to the server. For a teacher end user with management authority, the identity of the teacher end user is not verified, and the source and authenticity of instructions and messages cannot be determined. There is currently no effective solution to this problem. SUMMARY

[0003] To solve the problems in the related art, the embodiments of the present application provide a secure communication method, device, related equipment and storage medium.

[0004] To achieve the above-mentioned purposes, the technical solutions of the embodiments of the present application are as follows:

[0005] The embodiments of the present application provide a secure communication method, which is applied to a network device; the method comprises the following steps:

[0006] After at least one terminal is successfully registered, at least one group is established based on the identity information of each terminal;

[0007] A first message sent by a first terminal in the at least one terminal is received; the first message at least comprises first authentication information encrypted by a first secret key; the first secret key is generated based on the role of each terminal;

[0008] The first authentication information is decrypted by using a second secret key of the network device to obtain second authentication information;

[0009] It is judged whether the first terminal belongs to a first group based on the second authentication information; the first group is any group in the at least one group;

[0010] In a case that the first terminal belongs to the first group, a second message is sent to the first terminal; the second message comprises a third key; the third key is used for the first terminal to perform a key session with other terminals in the first group.

[0011] In the above scheme, the method further comprises:

[0012] After the network device is registered successfully, the second key is obtained.

[0013] In the above scheme, the method further comprises:

[0014] A terminal corresponding to an administrator of each of the groups is established based on identity information of each of the terminals;

[0015] A third message sent by the terminal corresponding to the administrator is received; the third message at least comprises third authentication information encrypted by a fourth key; the fourth key is a key of the terminal corresponding to the administrator;

[0016] The third authentication information is decrypted by using the second key to obtain fourth authentication information;

[0017] Identity information of the terminal corresponding to the administrator is verified based on the fourth authentication information;

[0018] After the identity information of the terminal corresponding to the administrator is verified successfully, the third key is generated; and the third key is sent to the terminal corresponding to the administrator.

[0019] In the above scheme, the method further comprises:

[0020] A fourth message sent by a second terminal is received; the fourth message at least comprises identity information of the second terminal; the second terminal is a terminal other than the terminal corresponding to the administrator in the first group;

[0021] The third message is decrypted by using the second key to obtain fifth authentication information;

[0022] Whether the terminal corresponding to the administrator applies for the third key is judged based on the fifth authentication information;

[0023] In a case that the terminal corresponding to the administrator has applied for the third key, the third key is sent to the second terminal.

[0024] Embodiments of the present application further provide a secure communication method, which is applied to a terminal; the method comprises:

[0025] sending a first message to a network device; the first message comprises at least first authentication information encrypted by a first key; the first key is generated based on a role of the terminal; the first authentication information is used for the network device to decrypt the first authentication information by a second key of the network device to obtain second authentication information; it is determined whether a first terminal in the terminal belongs to a first group based on the second authentication information; the first group is any group in at least one group established based on identity information of the terminal;

[0026] in a case where the first terminal belongs to the first group, receiving a second message sent by the network device; the second message comprises a third key;

[0027] establishing a key session between the first terminal and other terminals in the first group by using the third key.

[0028] In the above scheme, the terminal comprises at least a terminal corresponding to an administrator, and the method further comprises:

[0029] sending a third message to the network device; the third message comprises at least third authentication information encrypted by a fourth key; the fourth key is a key of the terminal corresponding to the administrator itself; the third authentication information is used for the network device to decrypt the third authentication information by the second key to obtain fourth authentication information; identity information of the terminal corresponding to the administrator is verified based on the fourth authentication information; and the third key is generated after the identity information of the terminal corresponding to the administrator is verified successfully;

[0030] receiving the third key sent by the network device.

[0031] In the above scheme, the terminal comprises at least a second terminal; the second terminal is a terminal other than the terminal corresponding to the administrator in the first group; and the method further comprises:

[0032] sending a fourth message to the network device; the fourth message comprises at least identification information of the second terminal; the fourth message is used for the network device to decrypt the fourth message by the second key to obtain fifth authentication information; and it is determined whether the terminal corresponding to the administrator applies for the third key based on the fifth authentication information;

[0033] in a case where the terminal corresponding to the administrator has applied for the third key, receiving the third key sent by the network device.

[0034] Embodiments of the present application also provide a secure communication device arranged on a network device, comprising:

[0035] The first establishing unit is configured to establish at least one group based on identity information of each terminal after the at least one terminal is successfully registered;

[0036] The first receiving unit is configured to receive a first message sent by a first terminal of the at least one terminal; the first message at least includes first authentication information encrypted by a first secret key; the first secret key is generated based on a role of each terminal;

[0037] The first decrypting unit is configured to decrypt the first authentication information by using a second secret key of itself to obtain second authentication information;

[0038] The first judging unit is configured to judge whether the first terminal belongs to a first group based on the second authentication information; the first group is any group of the at least one group;

[0039] The first sending unit is configured to send a second message to the first terminal in a case where the first terminal belongs to the first group; the second message includes a third secret key; the third secret key is used for a secret key session between the first terminal and other terminals in the first group.

[0040] The application further provides a secure communication device arranged on a terminal and comprising:

[0041] The second sending unit is configured to send a first message to a network device; the first message at least includes first authentication information encrypted by a first secret key; the first secret key is generated based on a role of the terminal; the first authentication information is used for the network device to decrypt the first authentication information by using a second secret key of itself to obtain second authentication information; whether a first terminal of the terminal belongs to a first group is judged based on the second authentication information; the first group is any group of at least one group established based on identity information of the terminal;

[0042] The second receiving unit is configured to receive a second message sent by the network device in a case where the first terminal belongs to the first group; the second message includes a third secret key;

[0043] The second establishing unit is configured to establish a secret key session between the first terminal and other terminals in the first group by using the third secret key.

[0044] The application further provides a network device comprising a first communication interface and a first processor;

[0045] the first communication interface is configured to, after successful registration of the at least one terminal, establish at least one group based on identity information of each terminal, receive a first message sent by a first terminal in the at least one terminal, wherein the first message at least includes first authentication information encrypted by a first secret key, and the first secret key is generated based on a role of each terminal;

[0046] the first processor is configured to decrypt the first authentication information by using a second secret key of the first processor to obtain second authentication information, and determine whether the first terminal belongs to a first group based on the second authentication information, wherein the first group is any group in the at least one group;

[0047] the first communication interface is further configured to, in a case where the first terminal belongs to the first group, send a second message to the first terminal, wherein the second message includes a third secret key, and the third secret key is used for a secret key session between the first terminal and other terminals in the first group.

[0048] Embodiments of the present application further provide a terminal, comprising: a second communication interface and a second processor;

[0049] the second communication interface is configured to send a first message to a network device, wherein the first message at least includes first authentication information encrypted by a first secret key, the first secret key is generated based on a role of the terminal, the first authentication information is used for the network device to decrypt the first authentication information by using a second secret key of the network device to obtain second authentication information, the first processor is configured to determine whether a first terminal in the terminal belongs to a first group based on the second authentication information, the first group is any group in at least one group established based on identity information of the terminal, and the second communication interface is further configured to, in a case where the first terminal belongs to the first group, receive a second message sent by the network device, wherein the second message includes a third secret key;

[0050] the second processor is configured to establish a secret key session between the first terminal and other terminals in the first group by using the third secret key.

[0051] Embodiments of the present application further provide a network device, comprising: a first processor and a first memory for storing a computer program capable of running on the processor,

[0052] When the first processor runs the computer program, the first processor is configured to perform steps of any method of the network device.

[0053] Embodiments of the present application further provide a terminal, comprising: a second processor and a second memory for storing a computer program capable of running on the processor,

[0054] The second processor is configured to execute the computer program, and perform the steps of any of the methods described above.

[0055] The embodiments of the present application also provide a storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of any of the methods described above.

[0056] The secure communication method and device, related equipment and storage medium provided by the embodiments of the present application, after the network device receives registration success of at least one terminal, establishes at least one group based on identity information of each terminal; receives a first message sent by a first terminal in the at least one terminal; the first message at least includes first authentication information encrypted by a first secret key; the first secret key is generated based on a role of each terminal; decrypts the first authentication information by using a second secret key of itself to obtain second authentication information; judges whether the first terminal belongs to a first group based on the second authentication information; the first group is any group in the at least one group; in the case that the first terminal belongs to the first group, sends a second message to the first terminal; the second message includes a third secret key; the third secret key is used for a secret key session between the first terminal and other terminals in the first group; correspondingly, a terminal sends a first message to the network device; the first message at least includes first authentication information encrypted by a first secret key; the first secret key is generated based on a role of the terminal; the first authentication information is used for the network device to decrypt the first authentication information by using a second secret key of itself to obtain second authentication information; judges whether a first terminal in the terminal belongs to a first group based on the second authentication information; the first group is any group established based on the identity information of the terminal; in the case that the first terminal belongs to the first group, receives a second message sent by the network device; the second message includes a third secret key; establishes a secret key session between the first terminal and other terminals in the first group by using the third secret key.

[0057] The technical scheme of the embodiment of the application is adopted, the terminal sends a first message to the network device; the first message at least includes first authentication information encrypted by a first secret key, the network device sends a second message to the terminal; the second message includes a third secret key, that is, in the communication process, the communication between the network device (for example, a server) and the terminal (for example, a client) is full-link encryption; and the first message sent by the terminal includes the first authentication information encrypted by the first secret key, the first secret key is generated based on the role of the terminal, that is, when receiving the message of the terminal, the network device can verify the identity of the terminal through the first secret key, to ensure the source and authenticity of the message; at least one group is established based on the identity information of each terminal, the identity information of the members in the group, such as an administrator or a member, and the group information to which each terminal belongs can be determined, so that the message is only transmitted and shared within the group. BRIEF DESCRIPTION OF DRAWINGS

[0058] Figure 1 A flowchart of a secure communication method of an embodiment of the application;

[0059] Figure 2 Another flowchart of a secure communication method of an embodiment of the application;

[0060] Figure 3 A schematic diagram of a message communication process provided by an embodiment of the application;

[0061] Figure 4 A schematic diagram of message server registration provided by an embodiment of the application;

[0062] Figure 5 A schematic diagram of administrator terminal registration provided by an embodiment of the application;

[0063] Figure 6 A schematic diagram of group data encryption secret key generation provided by an embodiment of the application;

[0064] Figure 7 A schematic diagram of message transmission between a group administrator and a message server provided by an embodiment of the application;

[0065] Figure 8 A schematic diagram of a secure communication device of an embodiment of the application;

[0066] Figure 9 Another schematic diagram of a secure communication device of an embodiment of the application;

[0067] Figure 10 A structural schematic diagram of a network device of an embodiment of the application;

[0068] Figure 11 A structural schematic diagram of a terminal of an embodiment of the application;

[0069] Figure 12 Figure 1 is a schematic diagram of a safety communication system structure according to an embodiment of the present application. DETAILED DESCRIPTION

[0070] The application will be further described below in conjunction with the drawings and specific embodiments.

[0071] In the classroom scenario, the teacher uses a new generation of information equipment (such as PC, electronic whiteboard, tablet computer) to teach, and the students also use equipment (tablet, PC, VR integrated machine) to learn and experiment. In this mode, the corresponding teaching content resources, such as video resources and VR teaching resources, need to be used, and the cost of such resources is relatively high. For the content resource producer, authorization is performed according to the client, and strict use is limited. Usually, a classroom is a unit for unified management of teaching, so there is a strong requirement for data security and communication process security. In the network communication process, in order to ensure the identity authenticity of each party in communication, a network authentication protocol (kerberos) is used for identity verification. In the kerberos communication protocol, there are three roles, which are:

[0072] Client: the party sending a request;

[0073] Server: the party receiving a request;

[0074] Key distribution center (KDC): including authentication server (AS) and ticket granting server (TGS). The ticket granting server is used to issue service granting tickets (tickets) required for the entire authentication process and for the client to access the server. The authentication server is used to authenticate the identity of the client and issue a ticket granting ticket (TGT) for the client to access the TGS.

[0075] The kerberos authentication process is described as follows:

[0076] When accessing each network service the client wants to access, he needs to carry a ticket specially used for accessing the service and proving his identity. When the server receives the ticket, he can identify the correct identity of the client and provide services to the client. Therefore, the entire process can be simplified into two steps:

[0077] (1) The client requests the KDC to obtain the service granting ticket (Ticket) of the target service he wants to access;

[0078] (2) Client takes the service grant ticket (Ticket) from KDC to access the corresponding network service.

[0079] However, in the communication process, the group management end needs to issue instruction information to the group administrator and perform other operations, and the following problems exist:

[0080] 1. The client-server communication does not realize full-link encryption of the communication link from the client to the server;

[0081] 2. The teacher management control end in the classroom scene does not verify the identity and group authority of the teacher, and there is a risk of unauthorized operation of different student ends of different groups;

[0082] 3. For the teacher end user with management authority, the identity is not verified, and the source and authenticity of the instructions and messages cannot be determined;

[0083] 4. Different clients have different authorization resource permissions according to different regional grouping, malicious users can obtain client information through channel listening, and perform message forgery to obtain unauthorized access to resources;

[0084] 5. There is no trusted third party to manage the keys at each level in the message transmission process, and some messages are stored in the configuration file in the form of configuration information;

[0085] 6. The Kerberos protocol is mainly used for individual identity verification in the communication process, and is not suitable for group identity verification and information sharing and transmission.

[0086] Therefore, the embodiments of the present application provide a secure communication method, which is applied to a network device; Figure 1 The flowchart of the secure communication method of the embodiments of the present application is shown in Figure 1 The method comprises the following steps:

[0087] Step S101: After the registration of at least one terminal is successful, at least one group is established based on the identity information of each terminal;

[0088] Step S102: Receive a first message sent by a first terminal in the at least one terminal; the first message at least includes first authentication information encrypted by a first secret key; the first secret key is generated based on the role of each terminal;

[0089] Step S103: Use the second secret key of itself to decrypt the first authentication information to obtain second authentication information;

[0090] Step S104: Determine whether the first terminal belongs to a first group based on the second authentication information; the first group is any group in the at least one group;

[0091] Step S105: in the case that the first terminal belongs to the first group, sending a second message to the first terminal; the second message includes a third key; the third key is used for the first terminal to perform a key session with other terminals in the first group.

[0092] The application scenario of the secure communication method can be determined according to actual conditions, which is not limited herein. As an example, the secure communication method can be a group control secure communication method in teaching.

[0093] It should be noted that the network device and the terminal can be determined according to actual conditions, which is not limited herein. As an example, the network device can be a message server and / or AS; the terminal can be a client in particular; the client can include an administrator end and a member end, and the administrator end can be exemplified as a teacher end; the member end can be exemplified as a student end.

[0094] In step S101, at least one group is established based on the identity information of each terminal after the registration of the at least one terminal is successful; it can be understood that a group G i is first established at the system management end (the background management end is set in the AS); the group can be understood as a unit of mutual communication; the terminal inputs the corresponding identity information to select the group during the registration process.

[0095] It should be noted that the registration of the terminal is the registration of the client, including the registration of the member and the group administrator.

[0096] The registration process of the client can be understood at the network device side that the method further includes:

[0097] The network device establishes at least one group; receives a fifth message sent by the client; the fifth message at least includes group information selected by the client;

[0098] The fifth message is decrypted by using the second key of itself to obtain sixth authentication information;

[0099] It is judged based on the sixth authentication information whether the group information selected by the client exists;

[0100] In the case that the group information exists, the client is bound with the group selected by the client, and a sixth message is sent to the client; the sixth message represents that the registration of the client is successful.

[0101] The fifth message is encrypted by using the public key of the AS in the embodiment. The fifth message includes identity information, time information and group information of the client, which can be exemplified as a username, a password and the like. The username can be denoted as ID gi_ui , the password information can be denoted as PWD gi_ui , and the group can be denoted as G i .

[0102] The fifth message can be expressed as: pub as [ID gi_ui , hpwd, T, G i ], wherein hpwd = h(PWD gi_ui ). ID gi_ui is a unique identifier of a user, PWD gi_ui is a password set by the user, T is a time stamp, G i is a group number, and h(PWD gi_ui ) is a hash value of the login password of the client.

[0103] The second secret key of the AS can be understood as a private key of the AS or a private key of the message server. In the embodiment, the second secret key can be a private key of the AS. The sixth authentication information can be understood as identity information, time information and group information included in the fourth message, which can be denoted as ID gi_ui , h(PWD gi_ui ), T, G i . The fourth message is decrypted by using the second secret key to obtain the sixth authentication information. For example, the AS decrypts the message by using the private key to obtain ID gi_ui , h(PWD gi_ui ), T, G i .

[0104] It is determined whether the group information selected by the client exists based on the sixth authentication information, which can be understood as checking whether the group G i exists. It should be noted that it is determined whether the time information sent by the client meets the requirement based on the sixth authentication information, which can be understood as whether the time stamp T is within an allowable range. The range can be determined according to actual conditions, and is not limited herein.

[0105] In the case that the group information exists, the client is bound to the group selected by the client, and a sixth message is sent to the client. It can be understood that, in the case that the group G i exists and the time stamp T is within the allowable range, the user is bound to the group, and a message of successful registration is returned. The sixth message can be denoted as E hpwd [ID gi_ui , G iIt should be noted that, in the case where the group information exists, the identity information of the client is stored, which can be understood as, in the group G i exists, the timestamp T is within the allowed range, and the ID gi_ui , h(PWD gi_ui ) and the like are stored in the database.

[0106] It should be noted that the registration process of the member terminal is the registration process of the client.

[0107] The registration of the group administrator can be understood on the network device side as, after the client registration according to the registration process of the client, the method further comprises:

[0108] receiving a seventh message sent by the administrator terminal; the seventh message at least includes identification information of the administrator terminal;

[0109] decrypting the seventh message by using the second secret key of itself to obtain seventh authentication information;

[0110] verifying the identity information of the administrator terminal based on the seventh authentication information;

[0111] after the identity information of the administrator terminal is verified successfully, sending an eighth message to the administrator terminal; the eighth message represents that the registration of the administrator terminal is completed.

[0112] It should be noted that, first, the group administrator terminal registers as a client according to the above-mentioned client registration method, and according to the deployment method, the group administrator is specified and set in the background according to the client type and offline communication information, and the AS is notified to identify and record the client group information.

[0113] In this embodiment, the seventh message is encrypted by using the public key of the AS; the seventh message includes the identity information of the administrator terminal, time information and group information. The seventh message can be denoted as pub as [ID gm_i , G i , h(PWD gm_i ), T]. Wherein, ID gm_i is a unique identifier of the group administrator, G i is the number of the group, and h(PWD gm_i ) is the hash value of the client login password.

[0114] The second secret key of itself can be understood as the private key of the AS or the private key of the message server, and in this embodiment, the second secret key can be the private key of the AS. The seventh authentication information can be understood as the identity information, time information and group information contained in the sixth message, which can be denoted as IDgm_i , h(PWD gm_i ), G i , and T. The seventh message is decrypted using the second secret key of the device itself to obtain seventh authentication information; it can be understood that the AS receives the message and decrypts it using the private key of the device itself to obtain ID gm_i , h(PWD gm_i ), G i , and T.

[0115] The identity information of the administrator terminal is verified based on the seventh authentication information; after the identity information of the administrator terminal is verified successfully, an eighth message is sent to the administrator terminal; it can be understood that the AS checks the timestamp T and the group number G i , and checks the hash value h(PWD gm_i ) of the password of the user ID gm_i , and after the verification is successful, a public-private key pair corresponding to the administrator terminal is generated, the public key of the administrator terminal can be denoted as pub gm_i , the private key of the administrator terminal can be denoted as priv gm_i , and the public-private key pair is sent to the group administrator terminal using a session secret key, which can be h(PWD gm_i ). The eighth message can be denoted as E key_gmi [ ID gm_i , pub gm_i , priv gm_i , priv as (priv gm_i ), G i , T], wherein key_gmi = h(PWD gm_i ).

[0116] In step S102, the second secret key can be understood as the private key of the message server. The first terminal can be an administrator terminal or a member terminal, and the member terminal can be understood as a terminal other than the administrator terminal in a group. The first secret key can be understood as a secret key generated by the terminal for a session with a network device; if the first terminal is an administrator terminal, the first secret key can be understood as a session secret key generated by the administrator terminal, which can be denoted as key_gm_msg; if the first terminal is a member terminal (which can also be understood as a client), the first secret key can be understood as a session secret key generated by the client (member terminal), which can be denoted as key_gui_msg.

[0117] When the first terminal is an administrator terminal, the server receives a first message sent by the first terminal among the at least one terminals; the first message includes at least first authentication information encrypted using a first key; this can be understood as the server receiving a first message sent by the administrator terminal, which can be denoted as pub. msg [ID gmi G i ,key_gm_msg,priv gmi [(key_gm_msg),T]; The first authentication information can be recorded as ID. gmi G i ,key_gm_msg,priv gmi (key_gm_msg) and T; where ID gmi It serves as a unique identifier.

[0118] In step S103, the second key can be understood as the private key of the network device. Decrypting the first authentication information using its own second key to obtain the second authentication information can be understood as the message server receiving the message and decrypting it using its private key to obtain the second authentication information; the second authentication information is an ID. gmi G i ,key_gm_msg,priv gmi (key_gm_msg) and T. It should be noted that the first authentication information and the second authentication contain the same content.

[0119] In step S104, it is determined whether the first terminal belongs to the first group based on the second authentication information; the first group is any one of the at least one groups, which can be understood as the message server verifying the received message.

[0120] Before step S105, the method further includes: sending a ninth message to the first terminal; the ninth message being encrypted using a temporary session key; the ninth message representing the establishment of a long connection between the message server and the administrator terminal, which can be denoted as E. key_gm_msg [ID gmi G i The temporary session key is the temporary session key between the message server and the terminal corresponding to the administrator, which can be denoted as key_gm_msg.

[0121] The tenth message is received from the terminal corresponding to the administrator; the tenth message includes at least a target message encrypted using the third key; the tenth message may be denoted as E. key_gm_msg [ID gmi G i E key_data(Msg), T], the third key can be recorded as key_data; the target message can be recorded as Msg.

[0122] Decrypting the tenth message to obtain eighth authentication information; and storing the target message encrypted by the third key; the eighth authentication information can be recorded as ID gmi , G i , E key_data (Msg) and T; the third encrypted target message can be recorded as E key_data (Msg). It should be noted that after the message server stores E key_data (Msg) to the message queue, the user in the first group (which can be recorded as G i ) is queried, and the user id that needs to pull the message is stored into the list.

[0123] When the first terminal is a member terminal, in step S102, the first message sent by the first terminal in the at least one terminal is received; the first message at least includes first authentication information encrypted by a first key; the first key is generated based on the role of each terminal; it can be understood that the message server receives the first message sent by the client (member terminal); the first message can be recorded as pub msg [ID gi_ui , G i , key_gui_msg, T]; the first key can be recorded as a temporary session key between the message server and the client, which can be recorded as key_gui_msg; the first authentication information can include ID gi_ui , G i , key_gui_msg and T.

[0124] In step S103, the first authentication information is decrypted by using the second key of itself to obtain the second authentication information; it can be understood that after the message server receives the message, the second authentication information can be obtained by using the private key of itself; the second authentication information is the same as the content contained in the first authentication.

[0125] In step S104, it is judged whether the first terminal belongs to the first group based on the second authentication information; it can be understood that whether the user is in the first group (which can be recorded as G i ) is queried through the second authentication information.

[0126] In step S105, the second message is sent to the first terminal in the case that the first terminal belongs to the first group; the second message comprises a third key; the third key is used for the first terminal to perform a key session with other terminals in the first group. It can be understood that the message server obtains the message from the memory and returns to the terminal corresponding to the member in the case of verification success, and the second message can be denoted as E key_gui_msg [ ID gi_ui , G i , E key_data (Msg), T]; the third key can be denoted as key_data.

[0127] According to the technical scheme of the embodiment of the application, the terminal sends a first message to the network device; the first message at least comprises first authentication information encrypted by a first key, the network device sends a second message to the terminal; the second message comprises a third key, that is, the communication between the network device (for example, a server) and the terminal (for example, a client) in the communication process is full-link encryption; and the first message sent by the terminal comprises first authentication information encrypted by the first key, and the first key is generated based on the role of the terminal, that is, when receiving the message of the terminal, the network device can verify the identity of the terminal through the first key, so as to ensure the source and authenticity of the message.

[0128] In an optional embodiment of the application, the method further comprises: obtaining the second key after the network device is successfully registered.

[0129] It should be noted that the network device comprises a message server and an AS, and the registered network device in the embodiment is the message server, and the message server is registered through the AS. The AS is an authentication center, which is a trusted third party of the whole system and has the highest security level. The master key is manually set or imported through an IC card, and the master key is used to protect the data security of the AS authentication center.

[0130] In an optional embodiment of the application, the method further comprises: establishing a terminal corresponding to an administrator of each group based on the identity information of each terminal; receiving a third message sent by the terminal corresponding to the administrator; the third message at least comprises third authentication information encrypted by a fourth key; the fourth key is a key of the terminal corresponding to the administrator; the third authentication information is decrypted by using the second key to obtain fourth authentication information; the identity information of the terminal corresponding to the administrator is verified based on the fourth authentication information; the third key is generated after the identity information of the terminal corresponding to the administrator is successfully verified; and the third key is sent to the terminal corresponding to the administrator.

[0131] In this embodiment, the fourth key can be understood as the private key of the terminal corresponding to the administrator, and the third message is a message in which the administrator terminal applies for group communication data to the AS, which can be denoted as pub as [ID gm_i ,G i ,priv gm_i (ID gm_i ‖T),T],wherein ID gm_i is a unique identifier of the GM i , ID gm_i ‖T is concatenated and signed.

[0132] The fourth authentication information can be obtained by decrypting the third authentication information using the second key; that is, the AS decrypts the message using the private key, and the fourth authentication information can be denoted as ID gm_i , G i , priv gm_i (ID gm_i ‖T) and T; the fourth authentication information and the third authentication information contain the same content.

[0133] The identity information of the terminal corresponding to the administrator is verified based on the fourth authentication information; after the identity information of the terminal corresponding to the administrator is verified successfully, the third key is generated; and the third key is sent to the terminal corresponding to the administrator; that is, the identity of the terminal corresponding to the administrator is verified using the public key of the terminal corresponding to the administrator, and in the case where the verification is passed, a data encryption key is generated and stored in a local encryption database, and is sent to the terminal corresponding to the administrator; the sent message can be denoted as pub gm_i [ID gm_i , G i , G key_data , priv as (key_data), T]. The third key is a data encryption key, which is a symmetric key and is used for encrypting data and is shared in the group.

[0134] The technical solution of the embodiment of the application can ensure the security of data, because the data encryption key can only be applied by the group administrator, and the data encryption key is a symmetric key generated by the AS, which ensures the security of data and improves the data acquisition efficiency, and the data is transmitted and shared in the group as a unit.

[0135] In an optional embodiment of the present application, the method further comprises: receiving a fourth message sent by a second terminal; the fourth message comprises at least identification information of the second terminal; the second terminal is a terminal other than the terminal corresponding to the administrator in the first group; decrypting the third message by using the second secret key to obtain fifth authentication information; judging whether the terminal corresponding to the administrator applies for the third secret key based on the fifth authentication information; and sending the third secret key to the second terminal in the case that the terminal corresponding to the administrator has applied for the third secret key.

[0136] In the embodiment, the second terminal can be understood as a terminal other than the terminal corresponding to the administrator in a group, and can also be a member terminal. The fourth message is a message for applying for a data encryption secret key by a member terminal, which can be denoted as pub as [ID gi_ui ,G i ,h(PWD gm_i ),T]。 The identification information comprises ID gi_ui , G i and h(PWD gm_i ), wherein ID gi_ui is a unique identifier of a user; and the fourth message is encrypted by using a public key of the AS.

[0137] The second secret key can be understood as a private key of the AS; and the fifth authentication information can be denoted as ID gi_ui , G i , h(PWD gm_i ) and T. The decryption of the fourth message by using the second secret key to obtain the fifth authentication information can be understood as that the AS obtains the message and decrypts the message by using the private key to obtain the fifth authentication information.

[0138] The judgment of whether the terminal corresponding to the administrator applies for the third secret key based on the fifth authentication information, and the sending of the third secret key to the second terminal in the case that the terminal corresponding to the administrator has applied for the third secret key can be understood as that the identification and the password hash value of the user are verified, the timestamp and the group information are checked, it is checked whether the data encryption secret key has been applied for by the terminal corresponding to the administrator, and the data encryption secret key is returned to the member terminal if the verification is passed; and the sent message can be denoted as E key_gui [ID gi_ui ,G i ,key_data,priv as (key_data),T] and key_gui=h(PWD gi_ui ).

[0139] The technical scheme of the embodiment of the application adopts a data encryption secret key generated by an AS, which is a symmetric secret key, thereby ensuring data security and improving data acquisition efficiency, and data is transmitted and shared in a group unit.

[0140] Correspondingly, the application also provides a secure communication method applied to a terminal. Figure 2 Another flowchart of the secure communication method of the embodiment of the application is shown in FIG. 3. Figure 2 The method comprises the following steps.

[0141] Step S201: sending a first message to a network device; the first message at least comprises first authentication information encrypted by a first secret key; the first secret key is generated based on a role of the terminal; the first authentication information is used for the network device to decrypt the first authentication information by using a second secret key of the network device to obtain second authentication information; and it is determined whether a first terminal in the terminal belongs to a first group based on the second authentication information; the first group is any group in at least one group established based on identity information of the terminal.

[0142] Step S202: receiving a second message sent by the network device in a case where the first terminal belongs to the first group; the second message comprises a third secret key.

[0143] Step S203: establishing a secret key session between the first terminal and other terminals in the first group by using the third secret key.

[0144] It should be noted that the network device and the terminal can be determined according to actual conditions, and are not limited herein. As an example, the network device can be a message server and / or an AS; the terminal can be a client; the client can comprise an administrator end and a member end, and the administrator end can be exemplified as a teacher end; and the member end can be exemplified as a student end.

[0145] Before step S201, a registration process of the terminal and the network device needs to be completed. It should be noted that the registration of the terminal is the registration of the client, including the registration of a member and a group administrator.

[0146] The registration process of the client can be understood at the terminal side as follows.

[0147] sending a fifth message to the network device; the fifth message at least comprises selected group information; the fifth message is used for the network device to decrypt the fifth message by using a second secret key of the network device to obtain sixth authentication information; it is determined whether the group information selected by the client exists based on the sixth authentication information; and in a case where the group information exists, the client and the group selected by the client are bound.

[0148] receive a sixth message sent by the network device; the sixth message represents that the registration is successful.

[0149] In the embodiment, the fifth message is encrypted by using the public key of the AS; the fifth message comprises identity information, time information and group information of the client, which can be exemplified as a username, a password and the like; the username can be denoted as ID gi_ui , the password information can be denoted as PWD gi_ui , and the group can be denoted as G i .

[0150] The fifth message can be expressed as: pub as = [ID gi_ui , hpwd, T, G i ], wherein hpwd = h(PWD gi_ui ). ID gi_ui is a unique identifier of the user, PWD gi_ui is a password set by the user, T is a time stamp, G i is a group number, and h(PWD gi_ui ) is a hash value of the login password of the client.

[0151] The second secret key of the self can be understood as a private key of the AS or a private key of the message server, and in the embodiment, the second secret key can be the private key of the AS. The sixth authentication information can be understood as the identity information, the time information and the group information contained in the fourth message, which can be denoted as ID gi_ui , h(PWD gi_ui ), T, G i . The fourth message is decrypted by using the second secret key of the self to obtain the sixth authentication information; for example, the AS receives the message and decrypts the message by using the private key of the self to obtain ID gi_ui , h(PWD gi_ui ), T, G i .

[0152] The network device judges whether the group information selected by the client exists based on the sixth authentication information; it can be understood that whether the group G i exists is checked. It should be noted that the network device judges whether the time information sent by the client meets the requirement based on the sixth authentication information, which can be understood as whether the time stamp T is within the allowed range, and the range can be determined according to the actual situation and is not limited herein.

[0153] The network device binds the client to the group selected by the client in the case that the group information exists, and sends a sixth message to the client; it can be understood that the network device binds the client to the group G iIf the group G exists and the timestamp T is within the allowed range, the relationship between the user and the group is bound, and a message indicating that the registration is successful is returned. The sixth message can be denoted as E hpwd [ID gi_ui ,G i ,h(PWD i ),T]}. It should be noted that the network device stores the identity information of the client in the case where the group information exists. It can be understood that, in the case where the group G i exists and the timestamp T is within the allowed range, the information of ID gi_ui , h(PWD gi_ui ) and the like is stored into the database. After the client receives the sixth message, the registration is successful.

[0154] It should be noted that the registration process of the member terminal is the registration process of the client.

[0155] The registration of the group administrator can be understood at the terminal side as follows: after the client is registered according to the registration process of the client, the method further includes:

[0156] sending a seventh message to the network device; the seventh message at least includes corresponding identity information; the seventh message is used for the network device to obtain seventh authentication information by decrypting the seventh message by using the second secret key of the network device; and verifying the identity information of the administrator terminal based on the seventh authentication information.

[0157] After the identity information of the management terminal is verified successfully, an eighth message sent by the network device is received; the eighth message indicates that the registration is successful.

[0158] It should be noted that first, the group administrator terminal is registered as a client according to the above-mentioned registration process of the client. According to the deployment manner, the group administrator is specified and set in the background according to the client type and offline communication information, and the AS is notified to identify and record the group information of the client.

[0159] In this embodiment, the seventh message is encrypted by using the public key of the AS; the seventh message includes the identity information of the administrator terminal, time information and group information. The seventh message can be denoted as pub as [ID gm_i ,G i ,h(PWD gm_i ),T]}. Wherein, ID gm_i is a unique identifier of the group administrator, G i is the number of the group, and h(PWD gm_i ) is the hash value of the client login password.

[0160] The second key of the self can be understood as a private key of the AS or a private key of the message server. In the embodiment, the second key can be a private key of the AS. The seventh authentication information can be understood as identity information, time information and group information contained in the sixth message, which can be denoted as ID gm_i , h(PWD gm_i ), G i and T. The seventh message is decrypted by using the second key of the self to obtain the seventh authentication information. It can be understood that the AS receives the message and decrypts it by using the private key of the self to obtain ID gm_i , h(PWD gm_i ), G i and T.

[0161] The identity information of the administrator terminal is verified based on the seventh authentication information. After the identity information of the administrator terminal is verified successfully, an eighth message is sent to the administrator terminal. It can be understood that the AS verifies the time stamp T and the group number G i , and verifies the hash value h(PWD gm_i ) of the password of the user according to the user ID gm_i . After the verification is successful, the public key and the private key corresponding to the administrator terminal are generated, the public key of the administrator terminal can be denoted as pub gm_i , the private key of the administrator terminal can be denoted as priv gm_i , and the public key and the private key are sent to the group administrator terminal by using the session key, and the session key can be h(PWD gm_i ). The eighth message can be denoted as E key_gmi [ID gm_i , pub gm_i , priv gm_i , priv as (priv gm_i ), G i , T], wherein key_gmi = h(PWD gm_i ).

[0162] When the first terminal is an administrator terminal, in step S201, the first message is sent to the network device, the first message at least includes first authentication information encrypted by using a first key. The first key is generated based on the role of the terminal. The first authentication information is used for the network device to decrypt the first authentication information by using a second key of the self to obtain second authentication information. It is judged whether the first terminal among the terminals belongs to a first group based on the second authentication information. The first group is any group in at least one group established based on the identity information of the terminal. It can be understood that the terminal corresponding to the administrator sends a first message to the server. The first message can be denoted as pub msg [IDgmi G i ,key_gm_msg,priv gmi [(key_gm_msg),T]; The first authentication information can be recorded as ID. gmi G i ,key_gm_msg,priv gmi (key_gm_msg) and T; where ID gmi This serves as a unique identifier. The second key can be understood as the private key of the network device. The step of decrypting the first authentication information using its own second key to obtain the second authentication information can be understood as the message server receiving the message and using its private key to decrypt it to obtain the second authentication information; the second authentication information is an ID. gmi G i ,key_gm_msg,priv gmi (key_gm_msg) and T. It should be noted that the first authentication information and the second authentication information contain the same content. The step of determining whether the first terminal belongs to the first group based on the second authentication information; the first group is any one of the at least one groups, which can be understood as the message server verifying the received message.

[0163] Before step S202, the method further includes: receiving a ninth message sent by a network device; the ninth message being encrypted using a temporary session key; the ninth message representing the establishment of a long connection between the message server and the administrator terminal, which can be denoted as E. key_gm_msg [ID gmi G i The temporary session key is the temporary session key between the message server and the terminal corresponding to the administrator, which can be denoted as key_gm_msg.

[0164] A tenth message is sent to the network; the tenth message is used by the network device to decrypt the tenth message to obtain the eighth authentication information; and the target message encrypted using the third key is stored. The tenth message includes at least the target message encrypted using the third key; the tenth message can be denoted as [image 1], the third key can be denoted as [image 2], and the target message can be denoted as Msg. The eighth authentication information can be denoted as ID. gmi G i E key_data (Msg) and T; the third encrypted target message can be denoted as E. key_data (Msg). It should be noted that the message server will send E key_data After storing (Msg) in the message queue, query the first group (which can be denoted as G). i For users in the list, the user IDs that need to retrieve messages are stored in the list.

[0165] When the first terminal is a member terminal, in step S201, the first message is sent to the network device, the first message at least includes first authentication information encrypted by a first key; the first key is generated based on the role of the terminal; the first authentication information is used for the network device to decrypt the first authentication information by using a second key of itself to obtain second authentication information; it is judged based on the second authentication information whether the first terminal in the terminal belongs to a first group; the first group is any group in at least one group established based on the identity information of the terminal; it can be understood that the terminal corresponding to the member sends the first message to the message server; the first message can be denoted as pub msg [ ID gi_ui , G i , key_gui_msg, T]; the first key can be denoted as a temporary session key between the message server and the client, which can be denoted as key_gui_msg; the first authentication information can include ID gi_ui , G i , key_gui_msg and T. The first authentication information is used for the network device to decrypt the first authentication information by using a second key of itself to obtain second authentication information, which can be understood that the message server can decrypt by using a private key of itself to obtain second authentication information after receiving the message; the second authentication information is the same as the content contained in the first authentication.

[0166] In step S202, in the case that the first terminal belongs to the first group, the second message sent by the network device is received; the second message includes a third key; it can be understood that the message server obtains the message from the memory and returns to the terminal corresponding to the member in the case of verification, and the second message can be denoted as E key_gui_msg [ ID gi_ui , G i , E key_data (Msg), T]; the third key can be denoted as key_data.

[0167] In step S203, the third key is used to establish a key session between the first terminal and other terminals in the first group; the third key can be understood as a data encryption key.

[0168] Using the technical solution of this application embodiment, the terminal sends a first message to the network device; the first message includes at least first authentication information encrypted using a first key, and the network device sends a second message to the terminal; the second message includes a third key, that is, during the communication process, the communication between the network device (e.g., server) and the terminal (e.g., client) is fully encrypted; and the first message sent by the terminal includes first authentication information encrypted using a first key, the first key being generated based on the role of the terminal, that is, when the network device receives a message from the terminal, it can verify the identity of the terminal through the first key to ensure the source and authenticity of the message.

[0169] In one optional embodiment of this application, the terminal includes at least a terminal corresponding to an administrator, and the method further includes: sending a third message to the network device; the third message includes at least third authentication information encrypted using a fourth key; the fourth key is the key of the terminal corresponding to the administrator; the third authentication information is used by the network device to decrypt using the second key to obtain the fourth authentication information; verifying the identity information of the terminal corresponding to the administrator based on the fourth authentication information; generating the third key after the identity information of the terminal corresponding to the administrator is successfully verified; and receiving the third key sent by the network device.

[0170] In this embodiment, the fourth key is the key of the terminal corresponding to the administrator, which can be understood as the private key of the terminal corresponding to the administrator. The third message is a message from the administrator terminal to the AS requesting group communication data, which can be denoted as pub. as [ID gm_i G i ,priv gm_i (ID gm_i ||T),T], where ID gm_i For GM i Unique identifier, cascading ID gm_i ‖T and sign it.

[0171] The third authentication information is used by the network device to decrypt using the second key to obtain the fourth authentication information. This can be understood as the AS using its private key for decryption. The fourth authentication information can be denoted as ID. gm_i G i priv gm_i (ID gm_i ||T) and T; the fourth authentication information and the third authentication information contain the same content.

[0172] The identity information of the terminal corresponding to the administrator is verified based on the fourth authentication information; the third secret key is generated after the identity information of the terminal corresponding to the administrator is verified successfully; the third secret key sent by the network device is received, that is, the AS verifies the identity of the terminal corresponding to the administrator using the public key of the terminal corresponding to the administrator, generates a data encryption secret key and stores the data encryption secret key in a local encryption database in the case of verification, and sends the data encryption secret key to the terminal corresponding to the administrator; the sent message can be recorded as pub gm_i [ID gm_i ,G i ,G key_data ,priv as (key_data),T]。The third secret key is a data encryption secret key, which is a symmetric key used for encrypting data and shared within a group.

[0173] The technical scheme of the embodiment of the application is adopted, the data encryption secret key can only be applied by a group administrator, so that the safety of data is ensured, the data encryption secret key is a symmetric key generated by the AS, the safety of data is ensured, the data acquisition efficiency is improved, and data is transmitted and shared in a group as a unit.

[0174] In an optional embodiment of the application, the terminal at least includes a second terminal; the second terminal is other terminal in the first group except the terminal corresponding to the administrator; the method further includes: sending a fourth message to the network device; the fourth message at least includes identification information of the second terminal; the fourth message is used for the network device to decrypt the fourth message using the second secret key to obtain fifth authentication information; whether the terminal corresponding to the administrator applies the third secret key is judged based on the fifth authentication information; in the case that the terminal corresponding to the administrator has applied the third secret key, the third secret key sent by the network device is received.

[0175] In the embodiment, the second terminal can be understood as other terminal in a group except the terminal corresponding to the administrator, and can also be a member terminal. The fourth message is a message for the member terminal to apply the data encryption secret key to the AS, which can be recorded as pub as [ID gi_ui ,G i ,h(PWD gm_i ),T]。The identification information includes ID gi_ui ,G i and h(PWD gm_i ), wherein ID gi_ui is a unique identifier of a user; the fourth message is encrypted using the public key of the AS. The second secret key can be understood as the private key of the AS; the fifth authentication information can be recorded as ID gi_ui ,G i , h(PWD gm_i) and T. The fourth message is decrypted by using the second secret key to obtain fifth authentication information; it can be understood that the AS obtains the message, and uses the private key to decrypt to obtain the fifth authentication information.

[0176] The fifth authentication information is used to judge whether the terminal corresponding to the administrator applies the third secret key; in the case that the terminal corresponding to the administrator has applied the third secret key, the third secret key is sent to the second terminal; it can be understood that the identity and password hash value of the user are verified, and the timestamp and group information are checked, whether the group has applied the data encryption secret key by the terminal corresponding to the administrator, and if the verification is passed, the data encryption secret key is returned to the member terminal; the sent message can be recorded as E key_gui [ID gi_ui ,G i ,key_data,priv as (key_data), T] and key_gui=h(PWD gi_ui ).

[0177] The technical scheme of the embodiment of the application is adopted, the data encryption secret key is the symmetric secret key generated by the AS, the data security is guaranteed, the data acquisition efficiency is improved, and the group is taken as a unit, and the data encryption secret key is transmitted and shared in the group.

[0178] In order to better understand the present application, an actual application scenario is exemplified, and a secure communication method is taken as a grouping control secure communication method in teaching; the network device includes an AS and a message server, and the terminal includes a client, and the client includes a member terminal and an administrator terminal.

[0179] The present application mainly solves the problem that the client and the server do not realize full-link encryption of the communication link from the client to the server in the communication process; for the teacher terminal user with management authority, the identity is not verified, and the source and authenticity of the instruction and the message cannot be judged. The specific processing scheme is as follows.

[0180] The teaching application scenario is designed for the scene of classroom teaching and grouping teaching of teachers, Figure 3 A schematic diagram of a message communication process is provided for the embodiment of the present application, as Figure 3The shown composition unit includes an authentication server, a message server, a group management terminal, a client, and uses digital signature, public key cryptography system, symmetric key and other technologies in the process. The communication between servers, the communication between the group and the server is ensured to be safe, and attacks such as message replay, message forgery, and unauthorized operation in the communication process are avoided; in the present application, multiple keys will be used, and the keys will be managed in layers, wherein the master key is used to encrypt the keys stored on the AS; the session key is generated by the AS or negotiated by both parties according to different roles; and the data key is used to encrypt the information between groups and is generated by the AS.

[0181] 1. Initialization and registration.

[0182] The whole communication scheme includes a message server, an AS, a group administrator, and a group member to form a communication system, wherein the AS is an authentication center, that is, a trusted third party (TTP), which generates part of the session key and generates a group data encryption key. The initialization and registration process of the AS, the message server, the group administrator, and the group member will be described in detail below.

[0183] 1.1 Initialization:

[0184] The AS is an authentication center, which is the trusted third party of the whole system and has the highest security level. The master key is set manually or imported through an IC card, and the master key is used to protect the data security of the AS authentication center.

[0185] 1.2 Message server registration. Figure 4 A schematic diagram of message server registration provided by an embodiment of the present application is shown in FIG. 2. Figure 4 As shown in FIG. 2, the server of the system includes the AS authentication center and the message server. When a new message server is added, it is first registered with the AS to record the server information, negotiate a temporary session key, generate a public and private key pair of the message server, and send the public and private keys encrypted by the temporary session key to the message server.

[0186] (1) The newly added message server S msg first acquires the public key pub as of the AS authentication center, calculates the following message and sends it to the AS: pub as [ID msg , g, g p , T]; wherein ID msg is the unique identifier of the message server, g is the generator selected by the message server, and a random number p is generated, the generator g and g p are sent to the AS, and T is a time stamp.

[0187] (2) After receiving the message, the AS uses its private key to decrypt ID msg , g, g p, T; first verify ID msg whether registered, if not registered, generate random number q, store the server information to the local database, and calculate g pq as a temporary session key for communication with both sides, send a message to the message server S msg ; the sent message can be recorded as priv as [ ID msg , q, T], q, T; wherein q is the private key selected by AS for random number negotiation, T is the current time, and is signed using the private key to prevent message forgery;

[0188] (3) the message server S msg received message, first use the public key of AS to decrypt the signature, verify the source of the message priv as [ ID msg , q, T] is credible. If so, calculate g pq as a temporary session key for communication with both sides, and apply to AS for public key, calculate the message, which can be recorded as key_pq = g pq ; E key_pq [ ID msg , T]; wherein ID msg is the unique identifier of the message server, T is the timestamp;

[0189] (4) AS receives the message, uses the negotiated session key key_pq = g pq to decrypt, obtains ID msg and T, checks whether the unique identifier ID msg has been registered. If not, no processing is done; if it has been registered, detect whether the timestamp T is within the allowed time range; if within the allowed range, AS generates the public and private key pair pub msg , priv msg of the message server; stores the correspondence between ID msg and the public key pub msg in the local database, and encrypts the private key priv msg using the negotiated session key key_pq = g pq and sends it to the message server, the sent message can be recorded as E key_pq [ ID msg , pub msg , priv msg , T]; wherein pub msg is the public key of the message server; priv msg is the private key of the message server; T is the current timestamp;

[0190] (5) the message server S msgAfter receiving the message, the ID is obtained by decryption using the temporary session key msg , pub msg , priv msg and T; check whether the timestamp T is within the allowed range, and whether the ID msg message receiving end is the server, if both are satisfied, the server's private key priv msg is kept secret.

[0191] The above process completes the message server S msg registration with the AS, temporary session key negotiation with the AS, and generation and transmission of the public-private key pair.

[0192] 1.3 Client registration, first establish a group G i in the system management end, the system only allows communication between users in the group, in this scenario, the group management end controls the client in the group and communication (typical scenario is the teacher end and student end in the classroom), so cross-group communication is not allowed; the client must be in a group to use the system, the client registers as a user, and needs to select a group according to actual needs during registration.

[0193] (1) First, establish a group G i in the system background management end (the background management end is set in the AS), the group is a unit of mutual communication;

[0194] (2) The client user registers on the system registration page, enters the basic information such as user ID gi_ui , password PWD gi_ui , selects the group G i , and uses the AS public key to encrypt the message and send it to the AS, the sent message can be recorded as: hpwd = h(PWD gi_ui ); pub as [ID gi_ui , hpwd, T, G i ]; wherein, ID gi_ui is the user's unique identifier, PWD gi_ui is the user's set password, T is the timestamp, G i is the group number, h(PWD gi_ui ) is the hash value of the client login password;

[0195] (3) The AS decrypts the message using the private key to obtain ID gi_ui , h(PWD gi_ui ), T, G i , first check whether the group G i exists, and whether the timestamp T is within the allowed range. If satisfied, bind the user and the group relationship, and store the IDgi_ui h(PWD) gi_ui The system stores information such as registration information in the database and returns a successful registration message, which can be denoted as E. hpwd [ID gi_ui G i ,T].

[0196] 1.4 Group administrator registration, Figure 5 This is a schematic diagram of an administrator terminal registration provided in an embodiment of this application, as shown below. Figure 5 As shown, the group administrator manages the clients of group members, and is also a client themselves, initially specified according to the deployment method. Their registration process begins with registering as a client, followed by identity registration with the AS, and requesting the group administrator's public / private key pair (pub). gm_i ,priv gm_i .

[0197] (1) First, the group administrator registers the client according to the client registration method described in 1.3;

[0198] (2) Based on the deployment method, the group administrator is designated in the background according to the client type and offline communication information, and the AS is notified to identify and record the client group information.

[0199] (3) When the group management terminal is used for the first time, it will request a public-private key pair from the AS certification center and send a message to the AS. The message sent can be recorded as pub. as [ID gm_i G i ,h(PWD gm_i ),T]; where ID gm_i G serves as the unique identifier for group administrators. i h(PWD) is the group number. gm_i () represents the hash value of the client's login password;

[0200] (4) After receiving the message, AS verifies the timestamp T and the group number G. i and based on its user ID gm_i Verify the hash value h(PWD) of its password. gm_i To ensure the reliability of message sources and prevent information spoofing by members of different groups, AS generates a public pub upon receiving a message. gm_i ,priv gm_i Public and private key pairs, and using h(PWD) gm_i The private key and encryption key are sent to the group administrator as the session key. The message is: key_gmi = h(PWD) gm_i ); E key_gmi [ID gm_i ,pubgm_i ,priv gm_i ,priv as (priv gm_i ),G i [,T]; where pub gm_i The public key for the group administrator, priv gm_i This is the group administrator's private key;

[0201] (5) After receiving the message, the group administrator uses h(PWD) gm_i Decrypt to obtain the ID. gm_i pub gm_i ,priv gm_i priv as (priv gm_i ), G i After verifying the message source using the T value, validate and save your own public-private key pair (pub). gm_i ,priv gm_i Complete registration.

[0202] 2. Group messaging.

[0203] 2.1 Group Data Encryption Key Generation. In this scheme, to ensure message security, transmitted messages are encrypted using a group message data key, which is a group-shared key. Figure 6 This is a schematic diagram illustrating the generation of a group data encryption key provided in an embodiment of this application, such as... Figure 6 As shown,

[0204] (1) Group Administrator (GM) i Request the data encryption key for group communication data from the AS and send a message to the AS, the message being pub. as [ID gm_i G i ,priv gm_i (ID gm_i ||T),T],where, ID gm_i For GM i Unique identifier, cascading ID gm_i ||T and sign it to ensure the source and freshness of the message, and prevent it from being stolen and forged after being used in other processes;

[0205] (2) After receiving the message, AS decrypts it using the private key to obtain the ID. gm_i G i priv gm_i (ID gm_iThe system checks if the timestamp (T) and T are within an acceptable range, and uses the group administrator's public key to decrypt and verify their identity. If trusted, it generates a data encryption key (key_data) and stores it in a local encrypted database. This key is a symmetric key used to encrypt data, shared within the group, and sent to the group administrator after generation. The message sent can be denoted as pub. gm_i [ID gm_i G i G key_data ,priv as [(key_data),T]; This completes the generation and transmission of the group data encryption key.

[0206] (3) After receiving the message, group members need to decrypt it. Therefore, they also need to apply for a data encryption key from the AS and send an application message to the AS. The message sent can be denoted as pub. as [ID gi_ui G i ,h(PWD gm_i ),T], where ID gi_ui A unique identifier for the user;

[0207] (4) After AS obtains the message, it decrypts it to obtain the ID. gi_ui G i h(PWD) gm_i The system verifies the user's identifier and password hash, checks the timestamp and group information, and verifies whether the group has already had a group data encryption key (key_data) generated by the administrator. If the message is correct, the system returns the data key to the client. The returned message can be denoted as E. key_gui [ID gi_ui G i ,key_data,priv as (key_data),T], key_gui=h(PWD gi_ui ), where G data_key This is the data encryption key for group communication messages. The above process completes the generation and transmission of the shared data encryption key, key_data, between groups.

[0208] 2.2 Message passing between group administrators and the message server Figure 7 This application provides a schematic diagram of message passing between a group administrator and a message server, as illustrated in an embodiment of the present application. Figure 7 As shown.

[0209] (1) The group administrator sends the generated session key_gm_msg, signs it with the private key, and sends it to the message server. The message sent can be denoted as pub. msg [ID gmi G i, key_gm_msg, priv gmi (key_gm_msg), T]; wherein ID gmi is a unique identifier;

[0210] (2) After the message server receives the message, it decrypts using the private key to obtain ID gmi , G i , key_gm_msg, priv gmi (key_gm_msg), and T, and checks the temporary session key key_gm_msg and its signature. If it passes, it establishes a long link with the group administrator and uses the temporary session key to encrypt the information communicated during the communication, and returns the message, which can be denoted as E key_gm_msg [ID gmi , G i , T];

[0211] (3) The group administrator sends a message Msg to the message server, and the sent message can be denoted as E key_gm_msg [ID gmi , G i , E key_data (Msg), T]; wherein E key_data (Msg) is a message encrypted using a data encryption key;

[0212] (4) After the message server receives it, it decrypts to obtain ID gmi , G i , E key_data (Msg), and T, and stores E key_data (Msg) to the message queue, and queries the users in G i , and stores the user id that needs to pull the message to a list; the above process completes the message sending of the group administrator.

[0213] 2.3 Message transmission between the client and the message server.

[0214] (1) The client subscribes to the message server, and first sends the following request to the message server to negotiate the session key, and requests to pull the message; the message can be denoted as pub msg [ID gi_ui , G i , key_gui_msg, T]; wherein key_gui_msg is a temporary session key selected by the client;

[0215] (2) After the message server receives the message, it decrypts using its private key to complete the session key transmission, and queries whether the user is in G i . If so, it establishes a long link with the client, the message server obtains the message from the memory and returns it to the client, and the returned message can be denoted as Ekey_gui_msg [ ID gi_ui , G i , E key_data (Msg), T]; the client decrypts the message using the group shared data encryption key after receiving the message.

[0216] According to the technical scheme of the embodiment of the application, in the aspect of session security, the temporary session keys of the AS, the message server, the group administrator and the group member communication are set according to different identities in the system, so as to guarantee the communication security of the user; in the aspect of data security, the security of the data is guaranteed by the data encryption key, wherein the data encryption key is a symmetric key generated by the AS, so as to improve the data acquisition efficiency while guaranteeing the data security, and the data is transmitted and shared in the group; in the aspect of user identity authentication, the AS is a trusted third party in the system, and the other communication parties need to complete the identity authentication by registration; the group administrator is specified in the background after registration, the group administrator initiates the application of the public and private key pair after the specification, and the subsequent identity authentication is encrypted and signed by the private key pair information; in the aspect of encryption and decryption efficiency, the data encryption key used in the communication process uses the symmetric key system, so as to guarantee the encryption and decryption efficiency of the message; when the source of the message needs to be confirmed, the private key is used for signing, and the symmetric session key is used for encryption.

[0217] In order to realize the method of the embodiment of the application, the embodiment of the application further provides a secure communication device arranged on a network device, Figure 8 The schematic diagram of the secure communication device of the embodiment of the application is shown in FIG. 8. Figure 8 As shown in FIG. 8, the device 800 includes:

[0218] A first establishing unit 801 is configured to establish at least one group based on the identity information of each terminal after the registration of the at least one terminal is successful.

[0219] A first receiving unit 802 is configured to receive a first message sent by a first terminal in the at least one terminal; the first message at least includes first authentication information encrypted by a first key; the first key is generated based on the role of each terminal.

[0220] A first decryption unit 803 is configured to decrypt the first authentication information by using a second key of itself to obtain second authentication information.

[0221] A first judging unit 804 is configured to judge whether the first terminal belongs to a first group based on the second authentication information; the first group is any group in the at least one group.

[0222] The first sending unit 805 is configured to send a second message to the first terminal in a case where the first terminal belongs to the first group; the second message comprises a third key; and the third key is used for the first terminal to perform a key session with other terminals in the first group.

[0223] In an embodiment, the apparatus 800 further comprises a first obtaining unit configured to obtain the second key after the network device is successfully registered.

[0224] In an embodiment, the first establishing unit 801 is further configured to establish a terminal corresponding to an administrator of each of the groups based on identity information of each of the terminals.

[0225] The first receiving unit 802 is further configured to receive a third message sent by the terminal corresponding to the administrator; the third message at least comprises third authentication information encrypted by a fourth key; and the fourth key is a key of the terminal corresponding to the administrator.

[0226] The first decrypting unit 803 is further configured to decrypt the third authentication information by using the second key to obtain fourth authentication information.

[0227] The apparatus 800 further comprises a verifying unit configured to verify identity information of the terminal corresponding to the administrator based on the fourth authentication information.

[0228] The first sending unit 805 is further configured to generate the third key after the identity information of the terminal corresponding to the administrator is successfully verified; and send the third key to the terminal corresponding to the administrator.

[0229] In an embodiment, the first receiving unit 802 is further configured to receive a fourth message sent by a second terminal; the fourth message at least comprises identity information of the second terminal; and the second terminal is a terminal other than the terminal corresponding to the administrator in the first group.

[0230] The first decrypting unit 803 is further configured to decrypt the fourth message by using the second key to obtain fifth authentication information.

[0231] The first judging unit 804 is further configured to judge whether the terminal corresponding to the administrator applies for the third key based on the fifth authentication information.

[0232] The first sending unit 805 is further configured to send the third key to the second terminal in a case where the terminal corresponding to the administrator has applied for the third key.

[0233] To implement the terminal-side method of this application embodiment, this application embodiment also provides a secure communication device, which is installed on the terminal. Figure 9 This is a schematic diagram of another device for secure communication according to an embodiment of this application; as shown Figure 9 As shown, the device 900 includes:

[0234] The second sending unit 901 is configured to send a first message to a network device; the first message includes at least first authentication information encrypted using a first key; the first key is generated based on the role of the terminal; the first authentication information is used by the network device to decrypt the first authentication information using its own second key to obtain second authentication information; based on the second authentication information, it is determined whether a first terminal in the terminal belongs to a first group; the first group is any group among at least one group established based on the identity information of the terminal.

[0235] The second receiving unit 902 is configured to receive a second message sent by the network device when the first terminal belongs to the first group; the second message includes a third key.

[0236] The second establishment unit 903 uses the third key to establish a key session between the first terminal and other terminals in the first group.

[0237] In one embodiment, the second sending unit 901 is further configured to send a third message to the network device; the third message includes at least third authentication information encrypted using a fourth key; the fourth key is the key of the terminal corresponding to the administrator; the third authentication information is used by the network device to decrypt using the second key to obtain the fourth authentication information; the identity information of the terminal corresponding to the administrator is verified based on the fourth authentication information; and the third key is generated after the identity information of the terminal corresponding to the administrator is successfully verified.

[0238] The second receiving unit 902 is also used to receive the third key sent by the network device.

[0239] In one embodiment, the second sending unit 901 is further configured to send a fourth message to the network device; the fourth message includes at least the identification information of the second terminal; the fourth message is used by the network device to decrypt using the second key to obtain fifth authentication information; and based on the fifth authentication information, it is determined whether the terminal corresponding to the administrator has applied for the third key;

[0240] The second receiving unit 902 is further configured to receive the third key sent by the network device when the terminal corresponding to the administrator has applied for the third key.

[0241] Based on the hardware implementation of the above program module, in order to realize the method of the network device side of the embodiment of the application, the embodiment of the application further provides a network device, Figure 10 For the structural schematic diagram of the network device of the embodiment of the application, as Figure 10 Indicated, the network device 1000 includes:

[0242] The first communication interface 1001 can interact with the terminal.

[0243] The first processor 1002 is connected with the first communication interface 1001 to realize the information interaction with the terminal, and is used to run the computer program to execute the method provided by one or more technical solutions of the network device side. And the computer program is stored on the first memory 1003.

[0244] Specifically, the first communication interface 1001 is used to establish at least one group based on the identity information of each terminal after the registration of at least one terminal is successful; receive the first message sent by the first terminal in the at least one terminal; the first message at least includes the first authentication information encrypted by the first secret key; the first secret key is generated based on the role of each terminal; the first authentication information is decrypted by using the second secret key of itself to obtain the second authentication information; judge whether the first terminal belongs to the first group based on the second authentication information; the first group is any group in the at least one group; in the case that the first terminal belongs to the first group, send the second message to the first terminal; the second message includes the third secret key; the third secret key is used for the secret key session between the first terminal and other terminals in the first group.

[0245] It should be noted that the specific processing process of the first processor 1002 and the first communication interface 1001 can be understood with reference to the above method.

[0246] Of course, in actual application, various components in the network device 1000 are coupled together through the bus system 1004. It can be understood that the bus system 1004 is used to realize the connection communication between the components. The bus system 1004 includes not only the information bus, but also the power bus, the control bus and the state signal bus. However, in order to clearly illustrate, all kinds of buses are marked as the bus system 1004 in Figure 10 .

[0247] The first memory 1003 in the embodiment of the application is used to store various types of information to support the operation of the network device 1000. Examples of these information include: any computer program used for operation on the network device 1000.

[0248] The method disclosed by the embodiments of the present application can be applied to the first processor 1002 or implemented by the first processor 1002. The first processor 1002 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits of hardware in the first processor 1002 or instructions in the form of software. The first processor 1002 described above can be a general processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 1002 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps of the method, or the hardware and software modules in the decoding processor can be combined to execute the steps of the method. The software module can be located in a storage medium, and the storage medium is located in the first memory 1003. The first processor 1002 reads the information in the first memory 1003 and combines the hardware to complete the steps of the method.

[0249] In the exemplary embodiments, the network device 1000 can be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, micro controllers (MCUs), microprocessors (Microprocessors), or other electronic elements, for executing the foregoing methods.

[0250] Based on the hardware implementation of the above program module, and in order to implement the method on the terminal side of the embodiments of the present application, the embodiments of the present application further provide a terminal, Figure 11 The structure of the terminal of the embodiments of the present application is shown in FIG. 11. As shown in FIG. 11, the terminal 1100 includes: Figure 11

[0251] The second communication interface 1101 can interact with the network device to exchange information.

[0252] ​The second processor 1102 is connected with the second communication interface 1101 to realize information interaction with a network device, and is used to run a computer program to execute the method provided in one or more technical solutions of the terminal.

[0253] It should be noted that the specific processing procedures of the second communication interface 1101 and the second processor 1102 can be understood with reference to the above method.

[0254] Of course, in actual application, various components in the terminal 1100 are coupled together through the bus system 1104. It can be understood that the bus system 1104 is used to realize the connection and communication between the components. The bus system 1104 includes not only an information bus, but also a power bus, a control bus and a status signal bus. However, for the purpose of clear illustration, all kinds of buses are marked as the bus system 1104 in the Figure 11 .

[0255] The second memory 1103 in the embodiment of the present application is used to store various types of information to support the operation of the terminal 1100. Examples of the information include any computer program used for operation on the terminal 1100.

[0256] The method disclosed in the above embodiment of the present application can be applied to the second processor 1102 or implemented by the second processor 1102. The second processor 1102 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits of hardware or instructions in the form of software in the second processor 1102. The second processor 1102 can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1102 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in a storage medium, which is located in the second memory 1103, and the second processor 1102 reads the information in the second memory 1103 and combines the hardware to complete the steps of the above method.

[0257] In the exemplary embodiment, the terminal 1100 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, Microprocessors, or other electronic elements, to execute the above method.

[0258] It can be understood that the memory (the first memory 1003 and the second memory 1103) of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as a static random access memory (SRAM), a synchronous static random access memory (SSRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a sync link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.

[0259] To implement the method provided by the embodiments of the present application, the embodiments of the present application further provide a secure communication system, Figure 12 The secure communication system structure schematic diagram of the embodiments of the present application is shown in FIG. 1. As shown in the figure, the system includes a network device 1201 and a terminal 1202. Figure 12

[0260] Here, it should be noted that the specific processing procedures of the network device 1201 and the terminal 1202 have been described in detail above, and will not be repeated here.

[0261] In exemplary embodiments, the embodiments of the present application further provide a storage medium, i.e., a computer storage medium, specifically a computer readable storage medium, for example, including a first memory 1003 storing a computer program, the computer program being executable by a first processor 1002 of a network device 1001 to complete the steps of the aforementioned network device side method. For another example, including a second memory 1103 storing a computer program, the computer program being executable by a second processor 1102 of a terminal 1100 to complete the steps of the aforementioned terminal side method. The computer readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.

[0262] It should be noted that "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.

[0263] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0264] The above is only a preferred embodiment of the present application, and is not intended to limit the protection scope of the present application.​

Claims

1. A secure communication method, characterized in that, The method is applied to a network device, which includes a message server and / or an authentication server (AS); the method includes: After at least one terminal has successfully registered, at least one group shall be established based on the identity information of each terminal. The system receives a first message sent by a first terminal among the at least one terminals; the first message includes at least first authentication information encrypted using a first key; the first key is generated based on the role of each terminal. The second authentication information is obtained by decrypting the first authentication information using the second key. Based on the second authentication information, it is determined whether the first terminal belongs to the first group; the first group is any one of the at least one groups. If the first terminal belongs to the first group, a second message is sent to the first terminal; the second message includes a third key; the third key is used by the first terminal to conduct key conversations with other terminals in the first group; the terminals in the group are used to obtain teaching content resources from the message server.

2. The method according to claim 1, characterized in that, The method further includes: After the network device is successfully registered, the second key is obtained.

3. The method according to claim 1, characterized in that, The method further includes: Based on the identity information of each terminal, establish a terminal corresponding to the administrator of each group; The system receives a third message sent by the terminal corresponding to the administrator; the third message includes at least third authentication information encrypted using a fourth key; the fourth key is the key of the terminal corresponding to the administrator. The third authentication information is decrypted using the second key to obtain the fourth authentication information; Verify the identity information of the terminal corresponding to the administrator based on the fourth authentication information; After the identity information of the terminal corresponding to the administrator is successfully verified, the third key is generated and sent to the terminal corresponding to the administrator.

4. The method according to claim 3, characterized in that, The method further includes: Receive a fourth message sent by the second terminal; the fourth message includes at least the identification information of the second terminal; the second terminal is any other terminal in the first group other than the terminal corresponding to the administrator; The fourth message is decrypted using the second key to obtain the fifth authentication information; Based on the fifth authentication information, determine whether the terminal corresponding to the administrator has applied for the third key; If the third key has been requested by the terminal corresponding to the administrator, the third key is sent to the second terminal.

5. A secure communication method, characterized in that, The method is applied to a terminal; the method includes: A first message is sent to a network device, which includes a message server and / or an authentication server. The first message includes at least first authentication information encrypted using a first key. The first key is generated based on the role of the terminal. The first authentication information is used by the network device to decrypt the first authentication information using its own second key to obtain second authentication information. Based on the second authentication information, it is determined whether a first terminal in the terminal belongs to a first group. The first group is any one of at least one group established based on the identity information of the terminal, and the terminals in the group are used to obtain teaching content resources from the message server. If the first terminal belongs to the first group, it receives a second message sent by the network device; the second message includes a third key. The first terminal establishes a key session with other terminals in the first group using the third key.

6. The method according to claim 5, characterized in that, The terminal includes at least the terminal corresponding to the administrator, and the method further includes: A third message is sent to the network device; the third message includes at least third authentication information encrypted using a fourth key; the fourth key is the key of the terminal corresponding to the administrator; the third authentication information is used by the network device to decrypt using the second key to obtain the fourth authentication information; the identity information of the terminal corresponding to the administrator is verified based on the fourth authentication information; after the identity information of the terminal corresponding to the administrator is successfully verified, the third key is generated. Receive the third key sent by the network device.

7. The method according to claim 6, characterized in that, The terminal includes at least a second terminal; the second terminal is any other terminal in the first group besides the terminal corresponding to the administrator; the method further includes: A fourth message is sent to the network device; the fourth message includes at least the identification information of the second terminal; the fourth message is used by the network device to decrypt using the second key to obtain fifth authentication information; based on the fifth authentication information, it is determined whether the terminal corresponding to the administrator has applied for the third key; If the terminal corresponding to the administrator has applied for the third key, the third key sent by the network device is received.

8. A secure communication device, installed on a network device, said network device including a message server and / or an authentication server; the secure communication device comprising: The first establishment unit is used to establish at least one group based on the identity information of each terminal after at least one terminal has successfully registered. The first receiving unit is configured to receive a first message sent by a first terminal among the at least one terminal; the first message includes at least first authentication information encrypted using a first key. The first key is generated based on the role of each terminal; The first decryption unit is used to decrypt the first authentication information using its own second key to obtain the second authentication information; The first judgment unit is used to determine whether the first terminal belongs to the first group based on the second authentication information; the first group is any one of the at least one groups; the terminal in the group is used to obtain teaching content resources from the message server; The first sending unit is configured to send a second message to the first terminal when the first terminal belongs to the first group; the second message includes a third key; the third key is used by the first terminal to conduct key conversations with other terminals in the first group.

9. A secure communication device, installed on a terminal, comprising: The second sending unit is used to send the first message to the network device; The network device includes a message server and / or an authentication server; The first message includes at least first authentication information encrypted using a first key; the first key is generated based on the role of the terminal; the first authentication information is used by the network device to decrypt the first authentication information using its own second key to obtain second authentication information; Based on the second authentication information, it is determined whether the first terminal in the terminals belongs to the first group; the first group is any one of at least one group established based on the identity information of the terminal. The second receiving unit is configured to receive a second message sent by the network device when the first terminal belongs to the first group; The second message includes a third key; terminals within the group are used to obtain teaching content resources from the message server; The second establishment unit uses the third key to establish a key session between the first terminal and other terminals in the first group.

10. A network device, characterized in that, The network device includes a message server and / or an authentication server; the network device includes: a first communication interface and a first processor; The first communication interface is used to establish at least one group based on the identity information of each terminal after at least one terminal has successfully registered; to receive a first message sent by a first terminal among the at least one terminals; the first message includes at least first authentication information encrypted using a first key; the first key is generated based on the role of each terminal; The first processor is configured to decrypt the first authentication information using its own second key to obtain second authentication information; and determine whether the first terminal belongs to a first group based on the second authentication information; the first group is any one of the at least one groups; The first communication interface is further configured to send a second message to the first terminal when the first terminal belongs to the first group; the second message includes a third key; the third key is used by the first terminal to conduct key conversations with other terminals in the first group; the terminals in the group are used to obtain teaching content resources from the message server.

11. A terminal, characterized in that, include: Second communication interface and second processor; The second communication interface is used to send a first message to a network device; the network device includes a message server and / or an authentication server; the first message includes at least first authentication information encrypted using a first key; the first key is generated based on the role of the terminal; the first authentication information is used by the network device to decrypt the first authentication information using its own second key to obtain second authentication information; Based on the second authentication information, it is determined whether the first terminal in the terminals belongs to the first group; the first group is any one of at least one group established based on the identity information of the terminal. And, if the first terminal belongs to the first group, receive the third key sent by the network device; Terminals within the group are used to obtain teaching content resources from the message server; The second processor is used to establish a key session between the first terminal and other terminals in the first group using the third key.

12. A network device, characterized in that, include: A first processor and a first memory for storing computer programs capable of running on the processor. Wherein, when the first processor is used to run the computer program, it performs the steps of the method according to any one of claims 1 to 4.

13. A terminal, characterized in that, include: A second processor and a second memory for storing computer programs that can run on the processor. Wherein, when the second processor is used to run the computer program, it performs the steps of the method according to any one of claims 5 to 7.

14. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4, or the steps of the method according to any one of claims 5 to 7.

Citation Information

Patent Citations

  • Communication method and device of Internet of Vehicles terminal, electronic equipment and storage medium

    CN115884175A

  • Verification method, communication node and system

    CN116132022A