GDOI multicast security association allocation method and system

By generating and verifying tokens in the GDOI registration stage and establishing target security associations, the problem of low security in the GDOI registration stage is solved, and high security and reliability of multicast data transmission is achieved.

CN119728307BActive Publication Date: 2025-05-06LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510229220.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-06
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

The security of the GDOI registration stage is low, making it difficult to effectively ensure the security of multicast data transmission.

Method used

By generating and verifying tokens, establishing target security associations, ensuring secure communication between the key management server and group members, and improving the security of the GDOI registration stage.

Benefits of technology

It improves the security of the GDOI registration stage, ensures the security and reliability of multicast data transmission, and prevents potential security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728307B_ABST
    Figure CN119728307B_ABST
Patent Text Reader

Abstract

The present application discloses a GDOI multicast security association allocation method and system, the method comprising: generating a first token based on a first random number and a first identifier; sending a first message to a key management server, the first message indicating that the first token is to be verified according to the first random number and the first identifier, and generating a second token based on a second random number and SA agreement information if the verification is successful, so as to generate a second message; in response to receiving the second message, verifying the second token based on the second random number and SA agreement information, and sending a third message to the key management server if the verification is successful and it is determined that the SA policy indicated by the SA agreement information is available, the third message is used to request to establish a target security association; receiving a fourth message from the key management server for responding to the third message, and establishing a target security association according to the fourth message and the SA agreement information, so as to improve the security of the GDOI registration phase.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a GDOI multicast security association allocation method and system. Background Art

[0002] In the development of multimedia network data transmission, the unicast and broadcast data transmission methods that were once widely used can no longer meet the needs of large-scale multimedia transmission containing massive data such as video conferencing, online teaching, and network audio and video. In these applications, the bandwidth consumption and delay problems of unicast have become particularly obvious, while the congestion caused by broadcast in large networks is even more prominent. To this end, multicast data transmission has emerged in response to demand. It greatly improves bandwidth utilization and reduces network load by sending data to multiple receivers at one time. The flexibility and efficiency of multicast make it an ideal choice for modern multimedia applications because it can meet the requirements of real-time and scalability. In particular, the introduction of IP (Internet Protocol) multicast technology has more effectively saved bandwidth, reduced data transmission delay, and achieved efficient resource utilization. As a result, the potential security risks of IP multicast have gradually attracted people's attention. At the same time, many solutions to improve the security of unicast data communication have been proposed, such as the IPSec (Internet Protocol Security) protocol running at the network layer.

[0003] SA (Security Association) is an agreement established and maintained by the end-to-end unicast key exchange protocol IKE (Internet Key Exchange) in the IPSec protocol. Its contents include a series of keys, encryption algorithms, key cycles, protocols, working modes, etc. SA is the core mechanism to ensure the secure transmission of data streams. It clearly stipulates how to encrypt and verify data and which keys to use.

[0004] Since the IPSec protocol can protect the reliability of unicast data transmission, more and more research is focused on how to extend the IPSec protocol to use its encryption security services in multicast scenarios. The GDOI (Group Domain of Interpretation) protocol is an extension based on the IPSec protocol. It runs between the GCKS (Group Controller / Key Server) and the GMs (Group Members) and can provide security for the generation, transmission, storage, and update of keys for the data security protocol. The GCKS is responsible for authenticating the GMs in the multicast group and assisting in the key management and distribution between the GMs and the functional modules. Therefore, how to ensure the security of the GDOI registration phase has become a major problem in the application of the GDOI protocol. Summary of the invention

[0005] In order to solve the above technical problems, the embodiments of the present application propose a GDOI multicast security association allocation method and system, which can improve the security of the GDOI registration phase.

[0006] In a first aspect, an embodiment of the present application provides a GDOI multicast security association allocation method, which is applicable to a first group member in a GDOI communication system, wherein the GDOI communication system further includes a key management server, and the method includes:

[0007] Generate a first token based on a first random number and a first identifier of a target multicast group to be joined;

[0008] Sending a first message carrying the first random number, the first identifier, and the first token to the key management server, wherein the first message is used to instruct the key management server to verify the first token according to the first random number and the first identifier, and if the verification passes, to generate a second token based on a second random number and the SA agreement information matching the target multicast group, so as to generate a second message carrying the second token, the second random number, and the SA agreement information;

[0009] In response to receiving the second message, verifying the second token based on the second random number and the SA agreement information, and sending a third message to the key management server if the verification passes and it is determined that the SA policy indicated by the SA agreement information is available, wherein the third message is used to request to establish a target security association matching the target multicast group;

[0010] A fourth message for responding to the third message is received from the key management server, and the target security association is established according to the fourth message and the SA agreement information.

[0011] Optionally, the first random number is associated with the time when the first token is generated, and the second random number is associated with the time when the second token is generated.

[0012] Optionally, the third message carries a third token, a first key exchange payload, a certificate payload and a first POP payload, wherein the third token is generated based on the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload;

[0013] The third message is used to instruct the key management server to verify the third token based on the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload, and return the fourth message to the first group member if the verification passes.

[0014] Optionally, the fourth message carries a KD payload, a fourth token, a public-private key pair generated by the key management server for the first group member, the certificate payload, a second key exchange payload corresponding to the first key exchange payload, and a second POP payload corresponding to the first POP payload, wherein the fourth token is generated based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload, and the KD payload;

[0015] The establishing the target security association according to the fourth message and the SA agreement information includes:

[0016] Verify the fourth token based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload, and the KD payload;

[0017] Determine the key in the KD payload and the key in the SA agreement information respectively;

[0018] When the verification result for the fourth token indicates that the verification is successful and it is determined that the key in the KD payload matches the key in the SA agreement information, the target security association is established according to the SA agreement information.

[0019] Optionally, after establishing the target security association according to the fourth message and the SA agreement information, the method further includes:

[0020] In response to a fifth message carrying update information sent by the key management server, the SA agreement information is updated according to the update information, wherein the update information is used to indicate changes in the target multicast group detected by the key management server.

[0021] Optionally, the target multicast group includes a plurality of group members, the plurality of group members include the first group member and the second group member, and each of the plurality of group members stores the SA agreement information;

[0022] After establishing the target security association according to the fourth message and the SA agreement information, the method further includes:

[0023] In case of needing to communicate with the second group member, generating a sixth message using the SA agreement information, wherein the sixth message carries at least the SPI, SPI signature and first hash value corresponding to the first group member;

[0024] The sixth message is sent to the second group member, so that the second group member verifies the SPI signature and the first hash value using the SA agreement information, and if the verification passes, establishes communication between the first group member and the second group member according to the SPI.

[0025] Optionally, each of the plurality of group members further stores an identity public key pair corresponding to each of the plurality of group members, wherein the identity public key pair corresponding to any group member of the plurality of group members includes an identity identifier and a public key corresponding to the group member;

[0026] The generating the sixth message by using the SA agreement information includes:

[0027] Using the private key corresponding to the first group member, encrypt according to the SPI to obtain the SPI signature;

[0028] Using the private key corresponding to the first group member, encrypt according to the SPI, the identity identifier of the first group member and the third random value corresponding to the first group member to obtain the first Hash value;

[0029] Using the SA agreement information, encrypt the SPI, the SPI signature, the third random value, the first hash value, and the identity of the first group member to generate the sixth message;

[0030] Among them, the sixth message is used to instruct the second group member: use the SA agreement information to decrypt the sixth message to obtain the SPI, the SPI signature, the third random value, the first hash value and the identity of the first group member, and according to the identity of the first group member, search for the identity public key pair corresponding to the first group member in the stored identity public key pairs corresponding to each of the multiple group members, and use the public key contained in the searched identity public key pair to verify the SPI signature and the first hash value based on the third random value, the SPI and the identity of the first group member, and when the verification of the SPI signature and the first hash value are passed, determine the SA of the first group member according to the SPI to establish communication between the first group member and the second group member.

[0031] Optionally, after establishing the target security association according to the fourth message and the SA agreement information, the method further includes:

[0032] In response to the seventh message carrying the heartbeat signal from the key management server, an eighth message carrying the heartbeat feedback signal is sent to the key management server.

[0033] In a second aspect, an embodiment of the present application provides a GDOI multicast security association allocation method, which is applicable to a key management server in a GDOI communication system, wherein the GDOI communication system further includes a first group member, and the method includes:

[0034] receiving a first message sent by the first group member, wherein the first message carries a first random number, a first token, and a first identifier of a target multicast group that the first group member wants to join, and the first token is generated based on the first random number and the first identifier;

[0035] Verify the first token according to the first random number and the first identifier, and if the verification passes, generate a second token based on a second random number and the SA agreement information matching the target multicast group, so as to generate a second message carrying the second token, the second random number and the SA agreement information;

[0036] Sending the second message to the first group member, wherein the second message is used to instruct the first group member to verify the second token based on the second random number and the SA agreement information, and sending a third message to the key management server when the verification is successful and it is determined that the SA policy indicated by the SA agreement information is available, wherein the third message is used to request to establish a target security association matching the target multicast group;

[0037] In response to the third message, a fourth message is sent to the first group member, so that the first group member establishes the target security association according to the fourth message and the SA agreement information.

[0038] In a third aspect, an embodiment of the present application provides a GDOI multicast security association allocation system, including:

[0039] A first group member is configured to execute the GDOI multicast security association allocation method according to any one of the first aspects above; and

[0040] The key management server is configured to execute the GDOI multicast security association allocation method described in the second aspect above.

[0041] In summary, the embodiments of the present application have at least the following beneficial effects:

[0042] According to an embodiment of the present application, a first token is generated based on a first random number and a first identifier of a target multicast group to be joined; a first message carrying the first random number, the first identifier and the first token is sent to the key management server, wherein the first message is used to instruct the key management server to verify the first token according to the first random number and the first identifier, and if the verification passes, a second token is generated based on a second random number and SA agreement information matching the target multicast group, so as to generate a second message carrying the second token, the second random number and the SA agreement information; in response to receiving the second message, the second token is verified based on the second random number and the SA agreement information, and if the verification passes and it is determined that the SA policy indicated by the SA agreement information is available, a third message is sent to the key management server, wherein the third message is used to request to establish a target security association matching the target multicast group; a fourth message from the key management server for responding to the third message is received, and the target security association is established according to the fourth message and the SA agreement information, thereby improving the security of the GDOI registration phase. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 It is a flowchart of a GDOI multicast security association allocation method provided in an embodiment of the present application;

[0044] Figure 2 It is a schematic diagram of GDOI multicast security association allocation provided by an embodiment of the present application;

[0045] Figure 3 It is a schematic diagram of GDOI multicast security association allocation provided by an embodiment of the present application;

[0046] Figure 4It is a flowchart of a GDOI multicast security association allocation method provided in an embodiment of the present application;

[0047] Figure 5 It is a schematic diagram of a GDOI multicast security association allocation system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0048] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0049] In the description of the present application, the terms "first", "second", "third", etc. are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, features defined as "first", "second", "third", etc. may explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "multiple" is two or more. In the description of the present application, the term "including" and its variations are open inclusions, i.e., "including but not limited to". The term "based on" means "at least partially based on". The term "according to" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments".

[0050] In the description of this application, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in this application can be understood according to specific circumstances.

[0051] In the description of this application, it should be noted that, unless otherwise defined, all technical and scientific terms used in this application have the same meaning as those commonly understood by those skilled in the art. The terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood by specific circumstances.

[0052] The following is an explanation of some terminology concepts involved in the embodiments of the present application:

[0053] The Group Domain of Interpretation (GDOI) protocol is an extension of the IPSec protocol. It runs between the Group Controller / Key Server (GCKS) and the GMs (Group Members) and can provide security for the generation, transmission, storage and update of keys for data security protocols. The GCKS is responsible for authenticating the GMs in the multicast group and assisting in the key management and distribution between the GMs and the functional modules.

[0054] SA (Security Association) is an agreement established and maintained by the end-to-end unicast key exchange protocol IKE (Internet Key Exchange) in the IPSec protocol. Its contents include a series of keys, encryption algorithms, key cycles, protocols, working modes, etc. SA is the core mechanism to ensure the secure transmission of data streams. It clearly stipulates how to encrypt and verify data and which keys to use.

[0055] SPI (SecurityParameterIndex) is a unique parameter that distinguishes one security association from other security associations.

[0056] The GDOI protocol extends the concept of SA in the IPSec protocol and introduces GSA (Group Security Association), making it more suitable for key management in a multicast environment. GSA includes three types of SA:

[0057] (1) PULL SA: When a new member wants to join a multicast group, it needs to perform unicast communication with GCKS to download the encryption algorithm, protocol, life cycle, key material, security parameter index (SPI) and other information of the multicast group. In order to safely transmit this sensitive information, the group member GM needs to perform PULL exchange with GCKS to obtain PULL SA to protect the download process. All members joining the group should establish a PULL SA with GCKS to protect the GSA download process, and establish a key update SA (Re-key SA) and a data security SA (Data-security SA).

[0058] (2) Re-key SA: When a member joins or leaves a multicast group, in order to ensure the security of communication within the group, GCKS uses the PUSH process to push the updated group key to the GM. When the key life cycle specified in the group expires, GCKS also performs the same PUSH operation to update the key. During the push process of the group key protected by the Re-key SA, GCKS uses the multicast key update algorithm to multicast the updated group key to all current GMs, thereby updating the data security SA.

[0059] (3) Data-security SA: The core purpose of the GDOI protocol is to provide an up-to-date data-security SA for data security protocols such as IPSec on user hosts, thereby providing confidentiality, data integrity, authentication, and other services for data communications between group members. In a multicast environment, since the sender needs to share the data-security SA with group members, the GCKS usually specifies, issues, and updates the data-security SA based on the group's security policy.

[0060] See Table 1 below for the corresponding symbols and explanations of GDOI protocol related concepts:

[0061] Table 1

[0062]

[0063] First, see Figure 1 , shows a flow chart of a GDOI multicast security association allocation method provided by an embodiment of the present application, the method is applicable to a first group member in a GDOI communication system, the GDOI communication system further includes a key management server, the method includes steps S101-S104, specifically as follows:

[0064] S101, generating a first token based on a first random number and a first identifier of a target multicast group to be joined.

[0065] In an example, the first identifier may be an ID (Identity document) of a target multicast group, the first random number may be subsequently represented by Ni, and the first token may be subsequently represented by HASH (1).

[0066] In one example, the first message may be structured as<HDR*,HASH(1),Ni,ID> , where HASH(1) =prf(SKEYID_a, M-ID | Ni | ID).

[0067] S102, sending a first message carrying the first random number, the first identifier and the first token to the key management server, wherein the first message is used to instruct the key management server to verify the first token according to the first random number and the first identifier, and if the verification passes, generate a second token based on a second random number and the SA agreement information matching the target multicast group, so as to generate a second message carrying the second token, the second random number and the SA agreement information;

[0068] In an example, the second random number may be subsequently represented by Nr, and the second token may be subsequently represented by HASH(2).

[0069] In one example, verifying the first token based on the first random number and the first identifier may include: the key management server generates a first verification token according to the first random number and the first identifier in a format used to generate the first token, and compares the first token with the first verification token; if the first token is the same as the first verification token, the verification is determined to be successful, otherwise the verification fails.

[0070] In an example, the SA agreement information may be in the form of an SA payload, which may include a KD (Key Download) payload, public and private key pairs of group members, and the like.

[0071] In one example, the second message may be structured as<HDR*,HASH(2), Nr, SA> , where SA indicates SA policy, HASH(2) =prf(SKEYID_a, M-ID |Ni_b| Nr | SA).

[0072] S103, in response to receiving the second message, verifying the second token based on the second random number and the SA agreement information, and sending a third message to the key management server if the verification passes and it is determined that the SA policy indicated by the SA agreement information is available, wherein the third message is used to request to establish a target security association matching the target multicast group;

[0073] In one example, whether the SA policy is available may be determined by parsing the SA agreement information, where the SA policy being available may mean that the SA policy is receivable.

[0074] In one example, verifying the second token based on the second random number and the SA agreement information may include: generating a second verification token in a manner used to generate the second token based on the second random number and the SA agreement information, and comparing the second token with the second verification token; if the second token is the same as the second verification token, determining that the verification is successful, otherwise the verification fails.

[0075] S104, receiving a fourth message from the key management server in response to the third message, and establishing the target security association according to the fourth message and the SA agreement information. Figure 2 The SA agreement information can be used to indicate at least one of the following: encryption policy, SPI, heartbeat interval, key, encryption algorithm, key period, protocol, working mode, and at least one of the above three types of SA.

[0076] In some cases, establishing GSA is the core function of the GDOI protocol. The GDOI protocol in the related art defines a method for allocating security associations so that all message senders in a multicast group use the same data security SA. For this type of allocation method, message receivers can only implement group authentication, but mutual authentication between group members cannot be achieved due to the use of the same data security SA. In addition, this method cannot confirm the integrity of the transmitted message, nor can it guarantee the monotonic growth characteristics of the replay sequence number field within the group.

[0077] Accordingly, in one example, the target security association established in this embodiment can enable the first group member to have a first data security SA corresponding to it, wherein the first data security SA is a unique data security SA corresponding to the first group member, which can be carried in any of the above-mentioned messages sent by the key management server, and is officially enabled after the target security association is successfully established, so as to achieve mutual authentication between group members, ensure the data communication security and message source authentication within the multicast group, and confirm the integrity of the transmitted message. Furthermore, the first data security SA can be generated based on the monotonic growth of the replay sequence number field, thereby ensuring the monotonic growth characteristics of the replay sequence number field within the group. At this time, each group member in the target multicast group has a different data security SA.

[0078] In an example, whether the data security SA is the same may be determined by the security parameter index SPI in the triple <data target address, SPI, security protocol> constituting the data security SA.

[0079] In one example, the key management server GCKS can be responsible for the management and distribution of keys between group members and functional modules within the multicast group, ensuring that each group member can securely receive and use keys, thereby maintaining the confidentiality and integrity of communications within the group. In addition, GCKS also assumes the responsibility of authenticating group members, ensuring that only authorized users can join the multicast group and participate in communications. Group member GM registers to join the group (i.e., establishes the corresponding security association) after passing the authentication of GCKS, and can subsequently communicate with other group members. When a member joins or leaves the group, GM updates the group key with the help of GCKS.

[0080] In an optional implementation, the first random number is associated with the time when the first token is generated, and the second random number is associated with the time when the second token is generated.

[0081] In an optional embodiment, the third message carries a third token, a first key exchange payload, a certificate payload and a first POP payload, wherein the third token is generated based on the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload; in one example, the third token can subsequently be represented by HASH(3).

[0082] The third message is used to instruct the key management server to verify the third token based on the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload, and return the fourth message to the first group member if the verification passes.

[0083] In one example, verifying the third token according to the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload may include: generating a third verification token in a manner used to generate the third token according to the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload, and comparing the third token with the third verification token; if the third token is the same as the third verification token, determining that the verification is passed, otherwise the verification fails.

[0084] In one example, the third message may be constructed as<HDR*,HASH(3), KE_I, CERT, POP_I> , where the third token HASH(3) =prf(SKEYID_a, M-ID |Ni_b|Nr_b[ | KE_I ] [ | CERT ][ |POP_I ]), where KE_I is the first key exchange payload and POP_I is the first POP payload.

[0085] In an optional implementation, the fourth message carries a KD payload, a fourth token, a public-private key pair generated by the key management server for the first group member, the certificate payload, a second key exchange payload corresponding to the first key exchange payload, and a second POP payload corresponding to the first POP payload, wherein the fourth token is generated based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload, and the KD payload;

[0086] The establishing the target security association according to the fourth message and the SA agreement information includes:

[0087] The fourth token is verified based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload and the KD payload; in one example, this step may include: based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload and the KD payload, a fourth verification token is generated in a manner used to generate the fourth token, and the fourth token is compared with the fourth verification token; if the fourth token is the same as the fourth verification token, the verification is determined to be successful, otherwise the verification fails.

[0088] Determine the key in the KD payload and the key in the SA agreement information respectively;

[0089] When the verification result for the fourth token indicates that the verification is successful and it is determined that the key in the KD payload matches the key in the SA agreement information, the target security association is established according to the SA agreement information.

[0090] In one example, when the verification result for the fourth token indicates that the verification is successful and it is determined that the key in the KD payload matches the key in the SA agreement information, a data security association, namely the target security association, can be established by receiving the corresponding (matching) key and based on the group key TEK in the SA agreement information and the corresponding encryption policy.

[0091] In an example, the KD payload may include a key package, and the key package may be parsed to verify whether the key in the KD payload matches the key in the SA agreement information.

[0092] In one example, the fourth message may be structured as<HDR*,HASH(4), Ki, HB, DD, KE_R,SEQ, KD, CERT, POP_R> , where the fourth token HASH(4) =prf(SKEYID_a, M-ID |Ni_b|Nr_b[ |KE_R ] [ | SEQ | ]KD [ | CERT ] [ | POP_R]), where KE_R is the second key exchange payload and POP_R is the second POP payload.

[0093] In one or more of the above embodiments, it can be called the group member registration phase, or the GROUPKYE-PULL exchange phase, and its main function is to register a new group member with GCKS so that it can obtain encryption policies, key materials, SPI, private keys, and other related values ​​for subsequent data communication. The exchange uses a total of four messages, which is initiated by the first group member who applies to join the multicast group. The first group member pulls down various information required for multicast group communication from GCKS, and finally establishes a key update SA for the multicast group and a data security SA between group members. The exchange is carried out under the protection of the registration SA.

[0094] In an optional implementation, after establishing the target security association according to the fourth message and the SA agreement information, the method further includes:

[0095] In response to a fifth message carrying update information sent by the key management server, the SA agreement information is updated according to the update information, wherein the update information is used to indicate changes in the target multicast group detected by the key management server.

[0096] In one example, when the changes in the target multicast group detected by the key management server at least include a new member joining the target multicast group or a group member leaving the target multicast group, the fifth message and / or the update information may be constructed as follows: <HDR*, SEQ, SA, KD, CERT, SIG, {<IDi,Pubi> ,<IDj,Pubj> ,......}>, where {<IDi, Pubi> ,<IDj,Pubj> , ......} represent the identity and public key of each group member in the target multicast group, and i and j represent group member i and group member j respectively.

[0097] In an example, the key management server may push the fifth message to each group member in the target multicast group in a multicast manner.

[0098] In some cases, in the related art, there are also certain problems with the group key update of the GDOI protocol. In the GDOI protocol, the group key update relies on the communication between the group server and the group members. The key server generates a new group SA and pushes the new SA down to the group members through the GROUPKEY-PUSH process. However, the standard document RFC 3547 of the GDOI protocol does not clearly specify how to ensure that all group members update the SA in a timely manner. There is no strict expiration time, specific process for verification of invalidation, or corrective measures. This may lead to inconsistent SA update processes, with some members using old SAs, posing risks to the security of the entire group communication.

[0099] In an optional implementation manner, the target multicast group includes a plurality of group members, the plurality of group members include the first group member and the second group member, and each of the plurality of group members stores the SA agreement information;

[0100] After establishing the target security association according to the fourth message and the SA agreement information, the method further includes:

[0101] In case of needing to communicate with the second group member, generating a sixth message using the SA agreement information, wherein the sixth message carries at least the SPI, SPI signature and first hash value corresponding to the first group member;

[0102] The sixth message is sent to the second group member, so that the second group member verifies the SPI signature and the first hash value using the SA agreement information, and if the verification passes, establishes communication between the first group member and the second group member according to the SPI.

[0103] In an example, the sixth message may be generated by encrypting the group key TEK indicated by the SA agreement information.

[0104] In some cases, establishing GSA is the core function of the GDOI protocol. The GDOI protocol in the related art defines a method for allocating security associations, using different data security SAs for all members in a multicast group. However, for this type of allocation method, since each member in a multicast group will exist as a message sender and a message receiver, frequent message transmission will cause a large number of data security SAs to be stored in the memory of group members, thus wasting storage resources.

[0105] Accordingly, in one example, in order to reduce the storage burden of group members, the present embodiment is designed so that each group member, in addition to storing its own data security SA (or data transmission SA, or data security transmission SA), only temporarily stores the data security SA of the current message sender (the data security SA corresponding to the first group member is calculated based on the SPI corresponding to the first group member and temporarily stored). At this time, the SA agreement information in the present embodiment may not contain the respective data security SAs of the multiple group members included in the target multicast group to avoid wasting storage resources.

[0106] In this embodiment, each group member does not need to store the data security SA of all group members in advance, and the second group member can calculate the data security SA of the first group member before establishing contact. Since the data security SA of other members is not stored in the memory of the group members, when a member joins or leaves the group, GCKS only updates the group key (that is, the update information can only contain the group key update information at this time), and there is no need to delete the expired data security SA.

[0107] In an optional implementation, each of the plurality of group members further stores an identity public key pair corresponding to each of the plurality of group members, wherein the identity public key pair corresponding to any group member of the plurality of group members includes an identity identifier and a public key corresponding to the group member;

[0108] The generating the sixth message by using the SA agreement information includes:

[0109] Using the private key corresponding to the first group member, encrypt according to the SPI to obtain the SPI signature;

[0110] Using the private key corresponding to the first group member, encrypt according to the SPI, the identity identifier of the first group member and the third random value corresponding to the first group member to obtain the first Hash value;

[0111] Using the SA agreement information, encrypt the SPI, the SPI signature, the third random value, the first hash value, and the identity of the first group member to generate the sixth message;

[0112] Among them, the sixth message is used to instruct the second group member: use the SA agreement information to decrypt the sixth message to obtain the SPI, the SPI signature, the third random value, the first hash value and the identity of the first group member, and according to the identity of the first group member, search for the identity public key pair corresponding to the first group member in the stored identity public key pairs corresponding to each of the multiple group members, and use the public key contained in the searched identity public key pair to verify the SPI signature and the first hash value based on the third random value, the SPI and the identity of the first group member, and when the verification of the SPI signature and the first hash value are passed, determine the SA of the first group member according to the SPI to establish communication between the first group member and the second group member.

[0113] In one example, see Figure 2 , assuming that the first group member is GMi and the second group member is GMr. The sixth message can be constructed as <{IDi, SPI, sig, Ne, hash(i)} TEK >, where SPI is the unique security parameter index of GMi, sig is the SPI signature generated by encrypting SPI using the private key Ki corresponding to GMi, sig={SPI} Ki , hash(i) =prf(IDi| SPI | Ne).

[0114] In one example, using the public key included in the searched identity public key pair, based on the third random value, the SPI and the identity of the first group member, verifying the SPI signature and the first hash value can include: using the public key included in the searched identity public key pair, decrypting the SPI signature and comparing the decrypted value with the SPI, and determining that the verification of the SPI signature is successful when they are the same, and then, based on the third random value, the SPI and the identity of the first group member, generating a second hash value in a manner used to generate the first hash value, and comparing the first hash value with the second hash value, and if the first hash value is the same as the second hash value, determining that the verification of the first hash value is successful.

[0115] In an optional implementation, after establishing the target security association according to the fourth message and the SA agreement information, the method further includes:

[0116] In response to the seventh message carrying the heartbeat signal from the key management server, an eighth message carrying the heartbeat feedback signal is sent to the key management server.

[0117] In an example, the key management server may send the corresponding seventh message to each group member according to the HB interval specified by each group member in the registration phase.

[0118] In one example, the heartbeat signal and / or the seventh message may be constructed as follows: <Keepalive, ID GCKS , T1>, used to confirm whether the group members are still using the valid group key normally, T is the timestamp, so the heartbeat feedback signal and / or the eighth message can be constructed as<ACK, T2> , used to send a confirmation message to the key server. For further information, see Figure 3 The key management server can be configured to: check whether the time interval between T1 and T2 is within the DD time. If the group member does not reply to the eighth message or the time to reply to the eighth message exceeds the expiration interval DD set by GCKS (that is, the time interval between T1 and T2 is greater than DD), GCKS automatically triggers key redistribution.

[0119] In this embodiment, a heartbeat signal is introduced to enable the key management server GCKS to regularly confirm the status of each group member to achieve automatic key update. In addition, it prevents group members from missing key updates due to network interruptions, equipment failures, etc., ensuring that all members always stay synchronized and use the latest keys. Specifically, GCKS can send a "Keepalive" signal to detect the online status of group members in the valid interval. If the GM does not reply to the ACK confirmation message within the invalid interval, key redistribution is automatically triggered. This further enhances the robustness of the system.

[0120] Based on the above embodiments, the present application has at least one of the following advantages:

[0121] 1) Message source authentication: Since each member has an independent data security SA, the receiver can identify the specific source of the message based on different data security SAs.

[0122] 2) Replay protection of application data: Since the data security SA of each current sender is stored in the receiver's memory, and each data security SA contains an independent SPI value, the received data packets with different SPI values ​​will be processed according to the corresponding data security SA, thereby ensuring the monotonicity and continuity of the sequence number of each sender's data packet at the receiving end, allowing the system to implement replay protection based on the sequence number in the IPSec datagram header.

[0123] 3) Prevent SPI forgery: Non-multicast group members cannot obtain the group key TEK, so they cannot forge the SPI and application data of a sending member. At the same time, since the sender needs to send the SPI signed by the group members, it can prevent malicious members in the group from forging the SPI.

[0124] 4) Management overhead of security associations: GCKS is only responsible for allocating data security SAs to newly joined members and updating group keys when group members exit. It does not need to notify all group members to add or delete data security SAs when group members change. Group members only need to maintain the data security SA of the current sending member and do not need to store the data security SAs of all members in the group.

[0125] 5) Automatic group key distribution: When GCKS detects that a group member has not responded to the heartbeat signal confirmation information within the specified time, it automatically triggers the redistribution of the group key, thereby avoiding problems such as untimely group key updates.

[0126] Second, see Figure 4 , shows a flow chart of a GDOI multicast security association allocation method provided by an embodiment of the present application, the method is applicable to a key management server in a GDOI communication system, the GDOI communication system also includes a first group member, the method includes steps S401-S404, specifically as follows:

[0127] S401, receiving a first message sent by the first group member, wherein the first message carries a first random number, a first token, and a first identifier of a target multicast group that the first group member wants to join, and the first token is generated based on the first random number and the first identifier;

[0128] S402, verifying the first token according to the first random number and the first identifier, and generating a second token based on a second random number and SA agreement information matching the target multicast group if the verification passes, so as to generate a second message carrying the second token, the second random number and the SA agreement information;

[0129] S403, sending the second message to the first group member, wherein the second message is used to instruct the first group member to verify the second token based on the second random number and the SA agreement information, and when the verification is passed and it is determined that the SA policy indicated by the SA agreement information is available, sending a third message to the key management server, wherein the third message is used to request to establish a target security association matching the target multicast group;

[0130] S404: In response to the third message, send a fourth message to the first group member, so that the first group member establishes the target security association according to the fourth message and the SA agreement information.

[0131] In an optional implementation, the first random number is associated with the time when the first token is generated, and the second random number is associated with the time when the second token is generated.

[0132] In an optional implementation, the third message carries a third token, a first key exchange payload, a certificate payload, and a first POP payload, wherein the third token is generated based on the first random number, the second random number, the first key exchange payload, the certificate payload, and the first POP payload;

[0133] The sending a fourth message to the first group member in response to the third message includes:

[0134] The key management server verifies the third token based on the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload, and returns the fourth message to the first group member if the verification passes.

[0135] In an optional implementation, the fourth message carries a KD payload, a fourth token, a public-private key pair generated by the key management server for the first group member, the certificate payload, a second key exchange payload corresponding to the first key exchange payload, and a second POP payload corresponding to the first POP payload, wherein the fourth token is generated based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload, and the KD payload;

[0136] The fourth message is used to indicate the first group member:

[0137] Verify the fourth token based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload, and the KD payload;

[0138] Determine the key in the KD payload and the key in the SA agreement information respectively;

[0139] When the verification result for the fourth token indicates that the verification is successful and it is determined that the key in the KD payload matches the key in the SA agreement information, the target security association is established according to the SA agreement information.

[0140] In an optional implementation, after sending the fourth message to the first group member, the method further includes:

[0141] When a change is detected in the target multicast group, a fifth message carrying update information is sent to the first group members, so that the first group members update the SA agreement information according to the update information, wherein the update information is used to indicate the changes in the target multicast group detected by the key management server.

[0142] In an optional implementation manner, the target multicast group includes a plurality of group members, the plurality of group members include the first group member and the second group member, and each of the plurality of group members stores the SA agreement information;

[0143] The first group of members is configured as follows:

[0144] After establishing the target security association according to the fourth message and the SA agreement information, generating a sixth message using the SA agreement information when communication with the second group member is required, wherein the sixth message carries at least the SPI, SPI signature and first hash value corresponding to the first group member;

[0145] The sixth message is sent to the second group member, so that the second group member verifies the SPI signature and the first hash value using the SA agreement information, and if the verification passes, establishes communication between the first group member and the second group member according to the SPI.

[0146] In an optional implementation, each of the plurality of group members further stores an identity public key pair corresponding to each of the plurality of group members, wherein the identity public key pair corresponding to any group member of the plurality of group members includes an identity identifier and a public key corresponding to the group member;

[0147] The generating the sixth message by using the SA agreement information includes:

[0148] Using the private key corresponding to the first group member, encrypt according to the SPI to obtain the SPI signature;

[0149] Using the private key corresponding to the first group member, encrypt according to the SPI, the identity identifier of the first group member and the third random value corresponding to the first group member to obtain the first Hash value;

[0150] Using the SA agreement information, encrypt the SPI, the SPI signature, the third random value, the first hash value, and the identity of the first group member to generate the sixth message;

[0151] Among them, the sixth message is used to instruct the second group member: use the SA agreement information to decrypt the sixth message to obtain the SPI, the SPI signature, the third random value, the first hash value and the identity of the first group member, and according to the identity of the first group member, search for the identity public key pair corresponding to the first group member in the stored identity public key pairs corresponding to each of the multiple group members, and use the public key contained in the searched identity public key pair to verify the SPI signature and the first hash value based on the third random value, the SPI and the identity of the first group member, and when the verification of the SPI signature and the first hash value are passed, determine the SA of the first group member according to the SPI to establish communication between the first group member and the second group member.

[0152] In an optional implementation, after sending the fourth message to the first group member, the method further includes:

[0153] The seventh message carrying the heartbeat signal is periodically sent to the first group member, so that the first group member returns an eighth message carrying the heartbeat feedback signal in response to the seventh message.

[0154] Thirdly, see Figure 5 , shows a schematic diagram of a GDOI multicast security association allocation system provided in an embodiment of the present application, the GDOI multicast security association allocation system comprising:

[0155] The first group member 501 is configured to execute the GDOI multicast security association allocation method according to any one of the first aspects above; and

[0156] The key management server 502 is configured to execute the GDOI multicast security association allocation method described in the second aspect.

[0157] In summary, the embodiments of the present application have at least the following beneficial effects:

[0158] According to an embodiment of the present application, a first token is generated based on a first random number and a first identifier of a target multicast group to be joined; a first message carrying the first random number, the first identifier and the first token is sent to the key management server, wherein the first message is used to instruct the key management server to verify the first token according to the first random number and the first identifier, and if the verification passes, a second token is generated based on a second random number and SA agreement information matching the target multicast group, so as to generate a second message carrying the second token, the second random number and the SA agreement information; in response to receiving the second message, the second token is verified based on the second random number and the SA agreement information, and if the verification passes and it is determined that the SA policy indicated by the SA agreement information is available, a third message is sent to the key management server, wherein the third message is used to request to establish a target security association matching the target multicast group; a fourth message from the key management server for responding to the third message is received, and the target security association is established according to the fourth message and the SA agreement information, thereby improving the security of the GDOI registration phase.

[0159] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present application can be implemented by means of software plus the necessary hardware platform, and of course it can also be implemented entirely by hardware. Based on such an understanding, all or part of the contribution of the technical solution of the present application to the background technology can be embodied in the form of a software product, and the computer software product can be stored in a storage medium, such as ROM (Read-Only Memory) / RAM (Random Access Memory), a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present application or some parts of the embodiments.

[0160] The above is a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications are also considered to be within the scope of protection of the present application.

Claims

1. A GDOI multicast security association allocation method, characterized in that: Applicable to a first group of members in a GDOI communication system, the GDOI communication system further comprising a key management server, the method comprising: Generate a first token based on a first random number and a first identifier of a target multicast group to be joined; Sending a first message carrying the first random number, the first identifier, and the first token to the key management server, wherein the first message is used to instruct the key management server to verify the first token according to the first random number and the first identifier, and if the verification passes, to generate a second token based on a second random number and the SA agreement information matching the target multicast group, so as to generate a second message carrying the second token, the second random number, and the SA agreement information; In response to receiving the second message, verifying the second token based on the second random number and the SA agreement information, and sending a third message to the key management server if the verification passes and it is determined that the SA policy indicated by the SA agreement information is available, wherein the third message is used to request to establish a target security association matching the target multicast group; A fourth message for responding to the third message is received from the key management server, and the target security association is established according to the fourth message and the SA agreement information.

2. The GDOI multicast security association allocation method according to claim 1, characterized in that: The first random number is associated with a time when the first token is generated, and the second random number is associated with a time when the second token is generated.

3. The GDOI multicast security association allocation method according to claim 1, characterized in that: The third message carries a third token, a first key exchange payload, a certificate payload, and a first POP payload, wherein the third token is generated based on the first random number, the second random number, the first key exchange payload, the certificate payload, and the first POP payload; The third message is used to instruct the key management server to verify the third token based on the first random number, the second random number, the first key exchange payload, the certificate payload and the first POP payload, and return the fourth message to the first group member if the verification passes.

4. The GDOI multicast security association allocation method according to claim 3, characterized in that: The fourth message carries a KD payload, a fourth token, a public-private key pair generated by the key management server for the first group member, the certificate payload, a second key exchange payload corresponding to the first key exchange payload, and a second POP payload corresponding to the first POP payload, wherein the fourth token is generated based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload, and the KD payload; The establishing the target security association according to the fourth message and the SA agreement information includes: Verify the fourth token based on the first random number, the second random number, the certificate payload, the second key exchange payload, the second POP payload, and the KD payload; Determine the key in the KD payload and the key in the SA agreement information respectively; When the verification result for the fourth token indicates that the verification is successful and it is determined that the key in the KD payload matches the key in the SA agreement information, the target security association is established according to the SA agreement information.

5. The GDOI multicast security association allocation method according to any one of claims 1 to 4, characterized in that: After establishing the target security association according to the fourth message and the SA agreement information, the method further includes: In response to a fifth message carrying update information sent by the key management server, the SA agreement information is updated according to the update information, wherein the update information is used to indicate changes in the target multicast group detected by the key management server.

6. The GDOI multicast security association allocation method according to any one of claims 1 to 4, characterized in that: The target multicast group includes a plurality of group members, the plurality of group members include the first group member and the second group member, and each of the plurality of group members stores the SA agreement information; After establishing the target security association according to the fourth message and the SA agreement information, the method further includes: In case of needing to communicate with the second group member, generating a sixth message using the SA agreement information, wherein the sixth message carries at least the SPI, SPI signature and first hash value corresponding to the first group member; The sixth message is sent to the second group member, so that the second group member verifies the SPI signature and the first hash value using the SA agreement information, and if the verification passes, establishes communication between the first group member and the second group member according to the SPI.

7. The GDOI multicast security association allocation method according to claim 6, characterized in that: Each of the plurality of group members further stores an identity public key pair corresponding to each of the plurality of group members, wherein the identity public key pair corresponding to any group member of the plurality of group members includes an identity identifier and a public key corresponding to the group member; The generating the sixth message by using the SA agreement information includes: Using the private key corresponding to the first group member, encrypt according to the SPI to obtain the SPI signature; Using the private key corresponding to the first group member, encrypt according to the SPI, the identity identifier of the first group member and the third random value corresponding to the first group member to obtain the first Hash value; Using the SA agreement information, encrypt the SPI, the SPI signature, the third random value, the first hash value, and the identity of the first group member to generate the sixth message; Among them, the sixth message is used to instruct the second group member: use the SA agreement information to decrypt the sixth message to obtain the SPI, the SPI signature, the third random value, the first hash value and the identity of the first group member, and according to the identity of the first group member, search for the identity public key pair corresponding to the first group member in the stored identity public key pairs corresponding to each of the multiple group members, and use the public key contained in the searched identity public key pair to verify the SPI signature and the first hash value based on the third random value, the SPI and the identity of the first group member, and when the verification of the SPI signature and the first hash value are passed, determine the SA of the first group member according to the SPI to establish communication between the first group member and the second group member.

8. The GDOI multicast security association allocation method according to any one of claims 1 to 4, characterized in that: After establishing the target security association according to the fourth message and the SA agreement information, the method further includes: In response to the seventh message carrying the heartbeat signal from the key management server, an eighth message carrying the heartbeat feedback signal is sent to the key management server.

9. A GDOI multicast security association allocation method, characterized in that: Applicable to a key management server in a GDOI communication system, the GDOI communication system further comprising a first group of members, the method comprising: receiving a first message sent by the first group member, wherein the first message carries a first random number, a first token, and a first identifier of a target multicast group that the first group member wants to join, and the first token is generated based on the first random number and the first identifier; Verify the first token according to the first random number and the first identifier, and if the verification passes, generate a second token based on a second random number and the SA agreement information matching the target multicast group, so as to generate a second message carrying the second token, the second random number and the SA agreement information; Sending the second message to the first group member, wherein the second message is used to instruct the first group member to verify the second token based on the second random number and the SA agreement information, and sending a third message to the key management server when the verification is successful and it is determined that the SA policy indicated by the SA agreement information is available, wherein the third message is used to request to establish a target security association matching the target multicast group; In response to the third message, a fourth message is sent to the first group member, so that the first group member establishes the target security association according to the fourth message and the SA agreement information.

10. A GDOI multicast security association allocation system, characterized in that: include: A first group member is configured to execute the GDOI multicast security association allocation method according to any one of claims 1 to 8; as well as, The key management server is configured to execute the GDOI multicast security association allocation method according to claim 9.

Citation Information

Patent Citations

  • Method, apparatus and system for registering new member in group key management

    US20100122084A1

  • Group key management re-registration method

    US20100142711A1