Communication Method, Server, and Client Based on National Cryptography Encryption Network Protocol

Through two identity challenges and three response processes based on the national encryption network protocol, combined with software and hardware algorithm encryption, the problems of identity theft and packet forgery in remote communication are solved, and efficient and secure communication connections are achieved.

CN119814308BActive Publication Date: 2025-07-22BEIJING LINX SOFTWARE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510305361.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-22
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

When facing changeable attack methods, the existing remote communication encryption network protocol is difficult to effectively prevent user identity theft, inefficient encryption and high resource utilization, and communication data packets are easily predicted and forged, resulting in insufficient communication security.

Method used

The communication method based on the national cryptographic encryption network protocol is adopted, through two identity challenges and three response processes, combined with software and hardware algorithm encryption, the intelligent key and hardware encryption module are used to improve communication security.

Benefits of technology

It significantly improves the security and reliability of communication connections, prevents identity theft, improves encryption efficiency, reduces resource usage, and prevents data packet forgery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814308B_ABST
    Figure CN119814308B_ABST
Patent Text Reader

Abstract

The present application discloses a communication method, a server, and a client based on a national cryptographic encryption network protocol, relating to the technical field of communication transmission. The method is applied to the server and includes: in the case of receiving a first national cryptographic secure shell protocol connection request sent by the client, generating confirmation key negotiation completion information that matches the first national cryptographic secure shell protocol connection request, and sending the confirmation key negotiation completion information to the client; in the case of receiving identity authentication challenge information sent by the client, generating identity confirmation information and generating an authentication challenge data packet based on the identity confirmation information; in the case of obtaining an intelligent key and receiving a result data packet, verifying the result data packet and the intelligent key through a preset verification method; and in the case that the result data packet meets a preset threshold and the intelligent key verification meets a preset password, sending a connection request to the client. It can greatly improve the security of the communication channel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to the field of communication transmission technologies, and particularly to a communication method, a server, and a client based on a national cryptography encryption network protocol. Background Art

[0002] With the continuous development of network technologies, network security issues have become increasingly prominent.

[0003] In related technologies, remote communication is a commonly used communication method that utilizes a computer network. Specifically, a remote communication channel is established between two terminals through a server as a bridge for host communication. Among them, the remote communication channel is often a transmission channel encrypted by specific means. For example, the network protocol (Secure Shell, SSH) can be encrypted by a national cryptography algorithm to encrypt the remote communication channel through user authentication, thereby enhancing the communication security of the remote communication channel.

[0004] During the process of remote communication, the interference means for the communication channel are constantly changing, posing challenges to communication security. Summary of the Invention

[0005] In view of the above-mentioned defects or deficiencies in the related technologies, it is desirable to provide a communication method, a server, and a client based on a national cryptography encryption network protocol, which can solve the problem that during the process of remote communication, the interference means for the communication channel are constantly changing, posing challenges to communication security, and greatly improve the security of the communication channel.

[0006] In a first aspect, there is provided a communication method based on a national cryptography encryption network protocol, which is applied to a server. The method includes:

[0007] When the server receives a first national cryptography secure shell protocol connection request sent by a client, the server generates confirmation key negotiation completion information that matches the first national cryptography secure shell protocol connection request, and sends the confirmation key negotiation completion information to the client. The first national cryptography secure shell protocol connection request includes: connection method indication information, and the connection method includes: a software algorithm connection method or a hardware algorithm connection method. The confirmation key negotiation completion information is used to indicate that the client and the server reach a handshake protocol;

[0008] When the server receives the identity authentication challenge information sent by the client, it generates identity confirmation information corresponding to the identity authentication challenge information, and generates an authentication challenge data packet based on the identity confirmation information. The authentication challenge data packet is used to instruct the client to send a smart key, and the identity authentication challenge information is used to instruct the server to generate identity confirmation information;

[0009] When the server obtains the intelligent key corresponding to the client and receives the result data packet corresponding to the authentication challenge data packet, the result data packet and the intelligent key are verified through a preset verification method;

[0010] When the result data packet meets the preset threshold and the intelligent key verification meets the preset password, the server sends a connection request to the client, and the connection request is used to request the establishment of a communication connection between the client and the server.

[0011] In this application, when the server receives the first national cryptography secure shell protocol connection request sent by the client, the server generates an acknowledgment key negotiation completion message that matches the first national cryptography secure shell protocol connection request, and sends the acknowledgment key negotiation completion message to the client (the first national cryptography secure shell protocol connection request includes: connection method indication information, and the connection method includes: software algorithm connection method or hardware algorithm connection method, and the acknowledgment key negotiation completion message is used to indicate that the client and the server reach a handshake protocol); then, when the server receives the identity authentication challenge information sent by the client, an identity confirmation information corresponding to the identity authentication challenge information is generated, and an authentication challenge data packet for instructing the client to send a result data packet is generated based on the identity confirmation information, and the identity authentication challenge information is used to instruct the server to generate the identity confirmation information; then, when the server obtains the intelligent key corresponding to the client and receives the result data packet corresponding to the authentication challenge data packet, the result data packet and the intelligent key are verified through a preset verification method; when the result data packet meets the preset threshold and the intelligent key verification meets the preset password, the server sends a connection request to the client to establish a connection. In this way, before the client and the server establish a communication connection, it is necessary to complete the establishment of the communication connection through two challenge processes, namely, the identity authentication challenge corresponding to the identity authentication challenge information and the authentication challenge data packet, and three response processes, namely, the identity confirmation information, the result data packet, and the connection request, which greatly improves the security and reliability of the communication connection establishment process.

[0012] In a second aspect, a communication method based on a national cryptography encryption network protocol is provided, which is applied to a client, and the method includes:

[0013] The client sends a first national cryptography secure shell protocol connection request to the server, and the first national cryptography secure shell protocol connection request includes: connection method indication information, and the connection method includes: software algorithm connection method or hardware algorithm connection method;

[0014] The client receives the confirmation key negotiation completion information sent by the server, and the confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol;

[0015] Send the identity authentication challenge information to the server, and the identity authentication challenge information is used to indicate the server to generate identity confirmation information;

[0016] After receiving the authentication challenge data packet sent by the server, generate a result data packet corresponding to the authentication challenge data packet and send it to the server;

[0017] In the case of receiving the connection request from the server, establish a connection with the server.

[0018] In a third aspect, a server is provided, and the server includes:

[0019] A first generation unit, configured to, in the case of receiving a first national cryptographic secure shell protocol connection request sent by a client, the server generate confirmation key negotiation completion information matching the first national cryptographic secure shell protocol connection request, and send the confirmation key negotiation completion information to the server, the first national cryptographic secure shell protocol connection request includes: connection mode indication information, the connection mode includes: software algorithm connection mode or hardware algorithm connection mode, and the confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol;

[0020] A confirmation unit, configured to, in the case of receiving the identity authentication challenge information sent by the client, generate identity confirmation information corresponding to the identity authentication challenge information, generate an authentication challenge data packet based on the identity confirmation information, and the authentication challenge data packet is used to indicate the client to send a smart key, and the identity authentication challenge information is used to indicate the server to generate identity confirmation information;

[0021] A first execution unit, configured to, in the case of obtaining the smart key corresponding to the client and receiving the result data packet sent by the client corresponding to the authentication challenge data packet, verify the result data packet and the smart key through a preset verification method;

[0022] A first sending unit, configured to, in the case that the result data packet meets a preset threshold and the smart key verification meets a preset password, the server sends a connection request to the client, and the connection request is used to request to establish a communication connection between the client and the server.

[0023] In a fourth aspect, a client is provided, and the client includes:

[0024] A second sending unit, configured to send a first national cryptographic secure shell protocol connection request to the server, where the first national cryptographic secure shell protocol connection request includes: connection mode indication information, and the connection mode includes: a software algorithm connection mode or a hardware algorithm connection mode;

[0025] A receiving unit, configured to receive confirmation key negotiation completion information sent by the server, where the confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol;

[0026] The second sending unit is further configured to send identity authentication challenge information to the server, where the identity authentication challenge information is used to indicate the server to generate identity confirmation information;

[0027] A second generating unit, configured to generate a result data packet corresponding to the authentication challenge data packet after receiving the authentication challenge data packet sent by the server, and send it to the server;

[0028] A second execution unit, configured to establish a connection with the server when receiving the connection request sent by the server.

[0029] In a fifth aspect, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in the first aspect or the second aspect above is implemented.

[0030] In a sixth aspect, a computer-readable storage medium is provided, on which a computer program is stored, characterized in that when the program is executed by a processor, the method described in the first aspect or the second aspect above is implemented.

[0031] In a seventh aspect, a computer program product is provided, where the computer program product contains instructions, and when the instructions are run by a processor, the method described in the first aspect or the second aspect above is implemented.

[0032] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be understood through the practice of the present invention. Description of the Drawings

[0033] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objects, and advantages of the present application will become more apparent:

[0034] Figure 1 It is one of the flow diagrams of the communication method based on the national cryptographic encryption network protocol provided by the embodiments of the present application;

[0035] Figure 2It is the second flowchart of the communication method based on the national cryptography encryption network protocol provided by the embodiment of the present application;

[0036] Figure 3 It is the structural schematic diagram of the server provided by the embodiment of the present application;

[0037] Figure 4 It is another structural schematic diagram of the client provided by the embodiment of the present application;

[0038] Figure 5 It is the structural schematic diagram of the computer device provided by the embodiment of the present application. Detailed implementation manners

[0039] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for the convenience of description, only the parts related to the invention are shown in the drawings.

[0040] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The following will make the following descriptions for the related technologies of the present application.

[0041] Remote communication channels are often transmission channels encrypted by specific means. For example, the remote communication channel can be encrypted through an encryption network protocol by user identity authentication, so as to improve the communication security of the remote communication channel. In the specific use process of this encryption network protocol usage method, 1) the single confirmation method of user password and public key information is adopted for the identity authentication of both the server and the client. The so-called single confirmation method means that only one identity challenge is carried out between the server and the client, and after the identity is confirmed, the communication process can be started; 2) in the process of encrypting communication data, a software encryption algorithm is used to process the communication data; 3) in the process of encrypting communication data, the encryption process essentially belongs to an operation process, and the operation process is generally completed on the client side; 4) the encryption network protocol used often belongs to a standardized protocol process, and the so-called standardized protocol process is the above single identity authentication process, and this standardized protocol process is also the encryption method selected by most encryption network protocols for remote communication.

[0042] However, the encryption network protocol in the above related technologies has the following defects: 1) It is difficult to prevent the theft of user identities only by using a single identity challenge method. For example, if other users execute this process by means of identity disguise, it will lead to the leakage of encrypted communication data; 2) In the process of only using software encryption algorithms, the actual efficiency of processing data and transmitting data is relatively low; 3) Setting all encryption operations to be executed locally will actually occupy a large amount of memory and CPU resources; 4) Since almost all encryption protocols are standardized and homogenized encryption protocols (for example, the standard SSH protocol process), it is difficult to prevent the forgery of communication data packets during remote communication.

[0043] Therefore, there are often some limitations in the traditional remote communication channel protection mechanism. Especially in the protocol processing of user identity authentication, using a fixed protocol process is difficult to cope with flexible and changeable attack means. The traditional remote communication channel protection mechanism uses a fixed protocol process, resulting in the predictability of data packets during the connection establishment process, which is easily exploited by attackers.

[0044] Based on this, the present application proposes a communication method, a server, and a client based on the national cryptographic encryption network protocol, which can solve the problem that in the process of remote communication, the interference means for the communication channel are constantly changing, bringing challenges to communication security, and greatly improving the security of the communication channel.

[0045] Figure 1 FIG. is a schematic flowchart of a communication method based on the national cryptographic encryption network protocol provided by an embodiment of the present application. The execution subject of this method can be the server described above. As Figure 1 shown, this method includes the following steps 301 to step 304:

[0046] Step 301: When the above server receives a first national cryptographic secure shell protocol connection request sent by a client, the above server generates an acknowledgment key negotiation completion message that matches the above first national cryptographic secure shell protocol connection request, and sends the above acknowledgment key negotiation completion message to the above client.

[0047] In an embodiment of the present application, the above first national cryptographic secure shell protocol connection request includes: connection method indication information, and the above connection method includes: a software algorithm connection method or a hardware algorithm connection method. The above acknowledgment key negotiation completion message is used to indicate that the above client and the above server reach a handshake protocol.

[0048] In an embodiment of the present application, the first national cryptographic secure shell protocol indicated by the above first national cryptographic secure shell protocol connection request is different from the standard national cryptographic secure shell protocol. As can be seen from the foregoing content, the standard national cryptographic secure shell protocol, that is, the standard encryption protocol, is an encryption protocol that only verifies once.

[0049] It is understandable that the first national cryptographic security shell protocol in the embodiments of the present application is an exclusive national cryptographic security shell protocol that requires two challenges or two verifications and three responses.

[0050] Furthermore, the selection of the encryption protocol in the above-mentioned remote communication is indicated by the security shell protocol connection request sent by the client. When the security shell protocol connection request sent by the client is a first national cryptographic security shell protocol connection request, the server calls the communication connection algorithm for challenges and responses of the first national cryptographic security shell protocol, and completes the communication connection between the server and the client according to this communication connection algorithm.

[0051] Exemplarily, before executing the above-mentioned communication connection algorithm for challenges and responses, the server needs to first complete the handshake protocol with the client, and then the challenge and response process can be carried out to execute the communication connection.

[0052] Exemplarily, the above connection method is used to indicate the data transmission encryption method between the client and the server after the handshake protocol between the client and the server is reached.

[0053] In one example, the above software algorithm connection method means that after the handshake protocol between the client and the server is reached, the data transmission between the client and the server is encrypted by the software algorithm encryption method.

[0054] In one example, the above hardware algorithm connection method means that after the handshake protocol between the client and the server is reached, the data transmission between the client and the server is encrypted by the hardware encryption method.

[0055] Furthermore, when the connection method is the hardware algorithm connection method, there is a hardware encryption communication module on the server side. The hardware encryption communication module is connected to the server and encrypts the communication data transmitted from the server to the client. In one example, the hardware encryption communication module can be a cryptographic machine or a cryptographic card. It is understandable that after the hardware confidential communication module is connected to the server, it can receive the data to be processed transmitted by the server, and output the encrypted data after the encryption is completed. In this way, the server can directly send the encrypted data to the client without the server calling its own software algorithm for data encryption operations.

[0056] In the embodiments of the present application, the above server confirmation includes the algorithm of the first national cryptographic security shell protocol. After it is possible to connect with the client through the first national cryptographic security shell protocol, the server can send a confirmation message indicating that the key negotiation is completed to the client, so as to shake hands with the client.

[0057] It can be understood that the reason for the description here as "it is possible to connect with the client through the first national cryptographic secure shell protocol" is that the server only confirms that it has the algorithm of the first national cryptographic secure shell protocol and has the ability to communicate and connect with the client using the algorithm of the first national cryptographic secure shell protocol. However, whether the client is a real client is not judged, and the judgment needs to be completed between the subsequent step 302 and step 304.

[0058] Step 302: When the above server receives the identity authentication challenge information sent by the above client, generate an identity confirmation information corresponding to the above identity authentication challenge information, and generate an authentication challenge data packet based on the above identity confirmation information.

[0059] In the embodiment of the present application, the above authentication challenge data packet is used to instruct the above client to send a result data packet corresponding to the above authentication challenge data packet, and the above identity authentication challenge information is used to instruct the above server to generate identity confirmation information.

[0060] It can be understood that in the embodiment of the present application, it is necessary to first confirm the identity information of the above client. Therefore, when the server sends the confirmation key negotiation completion information to the client and the client reaches a handshake protocol with the server through the confirmation key negotiation completion information, the client will send identity authentication challenge information to the server, and the identity authentication challenge information is used to request the server to authenticate the identity of the client. The action of the client sending the identity authentication challenge information to the server is the first challenge before the server and the client formally communicate and connect using the first national cryptographic secure shell protocol; and the server generating the identity confirmation information is the first response.

[0061] Furthermore, when the server authenticates the identity information of the client and confirms that it is a real client, it can generate identity confirmation information and an authentication challenge data packet. The authentication challenge data packet can trigger the client to send a result data packet for authenticating its own authenticity to the server. The action of the server sending the identity authentication challenge data packet to the client is the second challenge before the server and the client formally communicate and connect using the first national cryptographic secure shell protocol; and the client sending the result data packet based on the above authentication challenge data packet is the second response.

[0062] Exemplarily, the above identity authentication challenge data packet can be composed of a random challenge value. Specifically, sign the fixed-structure data with the server private key to generate an identity authentication challenge data packet, and send the identity authentication challenge data packet to the client.

[0063] It should be noted that since there is more than one way to authenticate identity information. For example, it can be user password verification or public key verification. Therefore, in the identity authentication challenge information sent by the client to the server, it can also include an indication of the authentication method. For example, if the identity authentication challenge information sent by the client is password-based information, the authentication method is user password verification; if the identity authentication challenge information sent by the client is public key-based information, the authentication method is public key verification. The embodiments of the present application do not make any limitations in this regard.

[0064] The following verifies these two identity information authentication methods:

[0065] 1) User password verification, that is, user password authentication. The identity authentication challenge information, that is, the challenge data, is the hash operation result of (the random challenge value generated by the server || the user password after SM3 hashing); when the server verifies, it uses (the random challenge value || the user password received in the first challenge) for hashing to verify the identity authentication challenge information.

[0066] 2) Public key verification, that is, when public key authentication is performed, the identity authentication challenge information, that is, the challenge data, is the signature value obtained by signing (the session identifier (calculated by both parties during key negotiation) || the authentication request protocol number || the user name to be logged in || the service name || the verification method name || the random challenge value || the verification algorithm name || the client public key) using the client private key; when the server verifies, it uses the client public key received in the first challenge to verify the signature of the same concatenated data.

[0067] Step 303: In the case where the server obtains the intelligent key corresponding to the client and receives the result data packet corresponding to the authentication challenge data packet sent by the client, verify the result data packet and the intelligent key through a preset verification method.

[0068] In the embodiments of the present application, the intelligent cryptographic key can be a UKEY, and the key pair of the user to be logged in is stored in the UKEY.

[0069] Furthermore, the intelligent cryptographic key can directly form a hardware connection with the server or can be in hardware connection with the client.

[0070] Still further, after the server sends the identity authentication challenge data packet to the client, the server starts the step of obtaining the intelligent key.

[0071] In one example, in the case where the intelligent cryptographic key directly forms a hardware connection with the server, the server directly obtains the intelligent key from the intelligent cryptographic key connected to it.

[0072] In another example, when a hardware connection is formed between the intelligent password key and the client, the server obtains that the authentication challenge data packet sent to the client further includes a call instruction for calling the authentication random number of the intelligent key. Then, through this call instruction, the client can be triggered to generate the authentication random number of the intelligent key. When the server receives the authentication random number sent by the client and pairs it with the authentication random number of the intelligent key stored by itself, the server generates the intelligent key, and during the process of the client sending the result data packet to the server, the intelligent key is sent together.

[0073] It should be noted that in the embodiments of the present application, the intelligent key may not be generated through a hardware password facility (i.e., the intelligent password key).

[0074] Furthermore, the server generates an authentication random number of the intelligent key (the authentication random number of the intelligent key is different from the foregoing random challenge value), and the challenge data packet sent to the client includes the random challenge value and the authentication random number of the intelligent key. After the client receives the authentication random number of the intelligent key, it uses the private key in the intelligent password key to sign the received authentication random number of the intelligent key, and then sends the authentication random number of the intelligent key and the signature value to the server together. Before the server generates the intelligent key, it first compares whether the authentication random number is the same as the random number stored by itself. In the case of being the same, it waits for the logged-in username to find the corresponding public key in the database for signature verification and generates the intelligent key.

[0075] Step 304: When the above result data packet meets a preset threshold and the above intelligent key verification meets a preset password, the above server sends a connection request to the above client.

[0076] In the embodiments of the present application, the above connection request is used to request to establish a communication connection between the above client and the server.

[0077] Exemplarily, the above preset threshold may be preset or user-defined. The embodiments of the present application do not make any limitations thereto.

[0078] Exemplarily, the above preset password may be preset or user-defined. The embodiments of the present application do not make any limitations thereto.

[0079] In the case of successful verification, the server sends a connection request to the client, indicating that a communication connection can be established with the client according to the first national cryptography secure shell protocol. This connection request is the third response.

[0080] In the method provided by the embodiment of the present application, when the server receives the first national cryptographic secure shell protocol connection request sent by the client, the server generates confirmation key negotiation completion information matching the first national cryptographic secure shell protocol connection request, and sends the confirmation key negotiation completion information to the client (the first national cryptographic secure shell protocol connection request includes connection mode indication information, and the connection mode includes software algorithm connection mode or hardware algorithm connection mode, and the confirmation key negotiation completion information is used to indicate that the client and the server reach a handshake protocol); afterwards, when the server receives the identity authentication challenge information sent by the client, it generates identity confirmation information corresponding to the identity authentication challenge information, and generates an authentication challenge data packet for instructing the client to send a result data packet based on the identity confirmation information, and the identity authentication challenge information is used to instruct the server to generate identity confirmation information; afterwards, when the server obtains the intelligent key corresponding to the client and receives the result data packet corresponding to the authentication challenge data packet sent by the client, it verifies the result data packet and the intelligent key through a preset verification method; when the result data packet meets the preset threshold and the intelligent key verification meets the preset password, the server sends a connection request to the client to establish a connection. In this way, before the client and the server establish a communication connection, it is necessary to complete the establishment of the communication connection through two challenge processes, namely the identity authentication challenge corresponding to the identity authentication challenge information and the authentication challenge data packet, and three response processes, namely the identity confirmation information, the result data packet, and the connection request, which greatly improves the security and reliability of the communication connection establishment process.

[0081] In another embodiment of the present application, a specific implementation manner for generating and sending the confirmation key negotiation completion information is further provided. Exemplarily, the specific implementation of the foregoing "when the server receives the first national cryptographic secure shell protocol connection request sent by the client, the server generates confirmation key negotiation completion information matching the first national cryptographic secure shell protocol connection request, and sends the confirmation key negotiation completion information to the server" includes: when the server receives the first national cryptographic secure shell protocol connection request sent by the client, it sends the first verification information to the client; after receiving the encrypted specific value sent by the client, it decrypts the encrypted specific value with the decryption private key of the server corresponding to the encryption public key of the server to generate a server specific value, performs key negotiation through the server specific value to generate the confirmation key negotiation completion information between the server and the client, and sends the confirmation key negotiation completion information to the client.

[0082] Exemplarily, the above first verification information is used to request the client to send verification information for verifying the identity of the client. The first verification information includes a second random number that matches the first random number, the signature public key information of the server, the encryption public key information of the server, and the signature information of the server.

[0083] It can be understood that in the embodiments of the present application, the request negotiation between the client and the server, or in other words, the request to reach a handshake protocol, or the request to the server to send a confirmation key negotiation completion message, is different from the related technologies before. In the embodiments of the present application, the client generates a first random number and wraps the first random number in a first SM4 security shell protocol connection request and sends it to the server.

[0084] Next, after receiving the first SM4 security shell protocol connection request, the server will generate a second random number corresponding to the first random number. Among them, the weight ratio between the first random number and the second random number is quite equivalent.

[0085] Furthermore, in the case where the server receives the first SM4 security shell protocol connection request containing the first random number and generates the second random number, the server signs the first random number and the second random number with the server private key, and sends the signed second random number, the server signature public key, the server encryption public key, and the signature value of the server private key signing the first random number and the second random number to the client, that is, sends the first verification information to the client.

[0086] The following is an explanation of the above "the weight ratio between the first random number and the second random number is quite equivalent": When negotiating keys between the server and the client, both parties need to provide a piece of data for calculating the session key. Originally, key pairs randomly generated by both parties were provided, which is modified to random numbers here. While simplifying the calculation amount, it ensures that the data lengths provided by both parties are the same and the data is random, that is, the weight ratio is quite equivalent, and it can also be understood as the weights are the same.

[0087] In the embodiments of the present application, after the client receives the above first verification information, the client can use the server signature public key sent by the server to the client to verify the signature value of the server private key signing the first random number and the second random number, generate a random specific value, and use the server encryption public key sent by the server in the first verification information to encrypt the random specific value to generate an encrypted specific value, and the client sends the encrypted specific value to the server, that is, the server "receives the encrypted specific value sent by the client" in the foregoing content.

[0088] Exemplarily, the key negotiation by executing the encrypted specific value includes the following process: The session identifier, IV vector, symmetric key, and integrity key between the client and the server are respectively calculated according to the server specific value corresponding to the encrypted specific value between the client and the server. After the calculation is completed and the result meets the pre-designed calculation result, the information confirming the completion of the key negotiation with the client is generated, and the information confirming the completion of the key negotiation is sent to the client.

[0089] In another embodiment of the present application, a specific implementation manner for confirming the specific type of the national cryptography secure shell protocol between the server and the client is further provided. Exemplarily, before the "when the server receives the first national cryptography secure shell protocol connection request sent by the client, the server generates the information confirming the completion of the key negotiation that matches the first national cryptography secure shell protocol connection request" mentioned above, the communication method based on the national cryptography encryption network protocol provided by the embodiments of the present application includes: receiving the first information sent by the above-mentioned client, and opening a selection interface for the communication connection matching method between the above-mentioned client and the above-mentioned server according to the above-mentioned first information.

[0090] Exemplarily, after receiving the first information, on the one hand, the server knows that the client desires to establish an encrypted communication connection with the server, and on the other hand, it needs to open a common entry for selecting the encrypted communication protocol, so as to subsequently confirm that the communication connection protocol between the client and the server is the first national cryptography secure shell protocol according to the first national cryptography secure shell protocol connection request sent by the client.

[0091] It can be understood that the first national cryptography secure shell protocol and the standard secure shell protocol are different communication connection protocols. Therefore, the common entry for selecting the encrypted communication protocol includes communication protocol branches with multiple different branches. When the server subsequently receives the first national cryptography secure shell protocol connection request sent by the client, it can confirm that the communication connection protocol between the client and the server is the first national cryptography secure shell protocol.

[0092] In another embodiment of the present application, a specific implementation manner is further provided in which the communication between the server and the client is encrypted by a hardware encryption module and then the communication data is transmitted. Exemplarily, the above-mentioned server is connected to the hardware encryption communication module, and the hardware encryption communication module is used to generate a hardware communication verification password. In the case where the above-mentioned first national cryptographic secure shell protocol connection request includes a hardware algorithm connection method, the specific implementation manner of "generating an identity confirmation information corresponding to the above-mentioned identity authentication challenge information and generating an authentication challenge data packet based on the above-mentioned identity confirmation information" described above includes: triggering the above-mentioned hardware encryption module to start encrypting the communication connection between the above-mentioned client and the above-mentioned server, and generating an identity confirmation information corresponding to the above-mentioned identity authentication challenge information, and generating an authentication challenge data packet based on the above-mentioned identity confirmation information.

[0093] Exemplarily, as can be known from the foregoing content, the above-mentioned hardware encryption module can be a cryptographic machine, a cryptographic card, etc. connected to the server.

[0094] It can be understood that the interface libraries of the cryptographic machine and the cryptographic card are unified by the 0018 interface standard, so the same logic can be used for calling.

[0095] Further, in the case where the server confirms its connection to the hardware encryption module, it can trigger the hardware encryption module to start encrypting the communication connection between the above-mentioned client and the above-mentioned server, and encrypt the communication process between the server and the client after the handshake protocol is reached through the hardware communication verification password.

[0096] In another embodiment of the present application, a specific implementation manner is further provided in which the server first confirms the software algorithm and the hardware algorithm before the server and the client establish a connection. Exemplarily, before "in the case where the above-mentioned server receives a first national cryptographic secure shell protocol connection request sent by the client, the above-mentioned server generates a confirmation key negotiation completion information matching the above-mentioned first national cryptographic secure shell protocol connection request", the communication method based on the national cryptographic encryption network protocol provided by the embodiment of the present application further includes: determining the interface file path in the above-mentioned server that matches the above-mentioned hardware encryption module; the above-mentioned server obtains the configuration parameters of the above-mentioned hardware encryption module through the above-mentioned interface file path, and configures the interface corresponding to the interface file path in the above-mentioned server through the above-mentioned configuration parameters, and the above-mentioned server is connected to the hardware encryption module.

[0097] Exemplarily, in the configuration file responsible for connecting the client and the server, the interface library file path of the hardware encryption communication module can be specified, and whether the hardware algorithm connection method can be enabled is determined by whether data can be smoothly transmitted through the interface library file path.

[0098] Generally, when data can be transmitted smoothly through the interface library file path, it is determined that the hardware algorithm connection method can be enabled; when data cannot be transmitted smoothly through the interface library file path, it is determined that the hardware algorithm connection method cannot be enabled.

[0099] Exemplarily, during the process of obtaining configuration parameters, by reading the relevant configuration of the hardware algorithm connection method in the configuration file between the server and the client, the interface call initialization of the hardware encryption module can be completed. And after the initialization is completed and the hardware encryption module interface is enabled, the hardware algorithm connection method is selected to encrypt the subsequent communication data.

[0100] It can be understood that after the initialization is completed, assuming that the hardware encryption module interface fails to be enabled, the software algorithm connection method can also be switched, so as to avoid subsequent inability to communicate and connect between the server and the client due to errors in the hardware encryption module.

[0101] In another embodiment of the present application, a specific implementation manner of the hardware algorithm connection method between the server and the hardware encryption module after the hardware algorithm connection method is selected between the server and the client is also provided. Exemplarily, the above-mentioned first Guomi Secure Shell protocol connection request further includes: hardware encryption module enabling indication information. Before "triggering the above-mentioned hardware encryption module to be enabled to encrypt the communication connection between the above-mentioned client and the above-mentioned server", the communication method based on the Guomi encryption network protocol provided by the embodiments of the present application further includes: the above-mentioned server obtaining the interface state between the above-mentioned server and the above-mentioned hardware encryption module; when the interface state between the above-mentioned server and the above-mentioned hardware encryption module obtained by the above-mentioned server is in an open state, triggering the above-mentioned hardware encryption module to be enabled to encrypt the communication connection between the above-mentioned client and the above-mentioned server.

[0102] The process of triggering the above-mentioned hardware encryption module to communicate and connect between the server and the client through the hardware algorithm connection method is described below.

[0103] It can be understood that when the interface state between the server and the hardware encryption module obtained by the server is in an open state, the server enables the interface library of the hardware encryption module, starts the hardware encryption module, and obtains the session between the server and the client; then, the server calls the hardware encryption module interface, and the operation parameters between the server and the client can be input into the hardware encryption module interface.

[0104] Further, when the hardware encryption module is enabled to perform communication connection encryption on the data to be transmitted in the server, the remote communication process of the server is as follows: The server first calls the interface between the hardware encryption module and the server as the caller. Then, as the operation requestor, it encapsulates and packs the communication parameters passed into the interface of the hardware encryption module and transmits them to the hardware encryption module as the acceptor through the remote communication channel. The hardware encryption module encapsulates and packs the communication data through this remote communication channel and performs encryption operations on the communication data as the operation processor. After the hardware encryption module completes the encryption operation, it returns the operation result to the server as the operation requestor. The server can obtain the encrypted data corresponding to the data to be transmitted through the interface between the hardware encryption module and the server in the interface library.

[0105] In another embodiment of the present application, a multi-factor encryption mode between the server and the client is also provided, that is, multiple challenges and multiple responses, and a specific implementation method that can combine other hardware, such as a smart password key, to complete the communication connection. Exemplarily, when the smart password key is connected to the server, the specific implementation method of "when the above-mentioned server obtains the smart password key corresponding to the above-mentioned client and receives the result data packet corresponding to the above-mentioned authentication challenge data packet, verifying the above-mentioned result data packet and the above-mentioned smart key" involved above includes: triggering the smart password key to generate a smart key, and when receiving the result data packet corresponding to the above-mentioned authentication challenge data packet sent by the above-mentioned client, verifying the above-mentioned result data packet and the above-mentioned smart key through a preset verification method.

[0106] Exemplarily, as can be seen from the foregoing content, when the smart password key is directly connected to the server, it can directly trigger the smart password key to generate a smart key.

[0107] Specifically, the smart password key has a corresponding database, and the above-mentioned smart key can be obtained by the smart password key querying the database.

[0108] Exemplarily, the above-mentioned preset verification method can be: The server retrieves the smart key verification library (a kind of database) for verification.

[0109] Exemplarily, when both the smart key and the result data packet are successfully verified, the server sends a connection request to the client.

[0110] Figure 2 It is a flowchart of a communication method based on the national cryptography encryption network protocol provided by an embodiment of the present application. The execution subject of this method can be the client described above. As Figure 2 shown, this method includes the following steps 401 to step 405:

[0111] Step 401: The client sends a first national cryptography Secure Shell (SSH) protocol connection request to the server.

[0112] In an embodiment of the present application, the first national cryptography Secure Shell protocol connection request includes: connection method indication information.

[0113] In an embodiment of the present application, the connection method includes: a software algorithm connection method or a hardware algorithm connection method.

[0114] Step 402: The client receives the confirmation key negotiation completion information sent by the server.

[0115] In an embodiment of the present application, the confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol.

[0116] Step 403: Send an identity authentication challenge information to the server.

[0117] In an embodiment of the present application, the identity authentication challenge information is used to indicate that the server generates identity confirmation information.

[0118] Step 404: After receiving the authentication challenge data packet sent by the server, generate a result data packet corresponding to the authentication challenge data packet, and send it to the server.

[0119] Step 405: In the case of receiving the connection request from the server, establish a connection with the server.

[0120] In another embodiment of the present application, a specific implementation manner for the client and the server to complete the handshake through the confirmation key negotiation completion information is further provided. Exemplarily, the specific implementation of the "the client sends a first national cryptography Secure Shell protocol connection request to the server" mentioned above includes: the client sends a first national cryptography Secure Shell protocol connection request to the server, and the first national cryptography Secure Shell protocol connection request includes a first random number; for the "the client sends a first national cryptography Secure Shell protocol connection request to the server" mentioned above, the method further includes: after receiving the first verification information sent by the server, generate a specific value according to the first verification information, and send the specific value to the server.

[0121] Exemplarily, the specific value is a value encrypted by the public key of the server.

[0122] It can be understood that, as described above, the specific value can decrypt the encrypted specific value through the decryption private key of the server corresponding to the encryption public key of the server to generate the specific value of the server.

[0123] Exemplarily, the foregoing first verification information is used to request the client to send verification information for verifying the identity of the client. The first verification information includes a second random number that matches a first random number, the signature public key information of the server, the encryption public key information of the server, and the signature information of the server.

[0124] In another embodiment of the present application, a specific implementation manner for confirming the specific type of the national cryptographic secure shell protocol between the server and the client is further provided. Exemplarily, before the "client sends a first national cryptographic secure shell protocol connection request to the foregoing server" involved in the foregoing, the communication method based on the national cryptographic encryption network protocol provided by the embodiment of the present application includes: the client sends a first message to the server.

[0125] Exemplarily, the foregoing first message is used to indicate that the communication connection matching manner is a first national cryptographic secure shell protocol connection.

[0126] In another embodiment of the present application, a specific implementation manner for the multi-factor encryption mode between the client and the server is further provided. Exemplarily, in the case where the intelligent password key is connected to the client, the specific implementation manner of the foregoing "after receiving the authentication challenge data packet sent by the server, generating a result data packet corresponding to the authentication challenge data packet and sending it to the server" includes: after receiving the authentication challenge data packet sent by the server, triggering the intelligent password key to generate an intelligent password key, and generating a result data packet corresponding to the authentication challenge data packet; sending the intelligent key and the result data packet to the server.

[0127] Exemplarily, as can be seen from the foregoing content, in the case where the intelligent password key is directly connected to the client, after the client receives the authentication random number corresponding to the intelligent password key sent by the server, it calls the interface of the intelligent password key to view the intelligent key (such as whether there is an intelligent password key locally and the intelligent key pair therein). Then, the client signs the random number with the private key in the intelligent key pair and sends the random number and the signature value to the server; the server confirms the binding situation between the user to be logged in and the intelligent password key. If the user to be logged in is not bound to the intelligent password key, the intelligent password key verification is not performed; if the user to be logged in is bound to the intelligent password key, it is checked whether the signature value is empty and whether the random numbers are consistent.

[0128] During the comparison process, if the random number is empty, the verification fails. Therefore, it is necessary to first compare whether the random number is empty. If it is not empty, then find the corresponding public key and verify the signature value. If the signature verification passes, the verification of the intelligent password key is passed.

[0129] It should be noted that in the above process, it is assumed that the client is not connected to the intelligent password key, and the data sent is all 0.

[0130] The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the training rule determination method described in the embodiment of the present application. For example, it can execute Figure 1 Or Figure 2 Each step of the method shown.

[0131] The embodiment of the present application provides a computer program product, which contains instructions. When the instructions are run by a processor, it implements Figure 1 Or Figure 2 Each step of the method shown.

[0132] It should be noted that although the operations of the method of the present invention are described in a specific order in the drawings, this does not require or imply that these operations must be performed in this specific order, or that all the operations shown must be performed to achieve the desired result.

[0133] Figure 3 It is a block diagram of a server according to an embodiment of the present application. Refer to Figure 3 , the device includes a first generation unit 601, a confirmation unit 602, a first execution unit 603, and a first sending unit 604.

[0134] The first generation unit 601 is configured to, when receiving a first national cryptography secure shell protocol connection request sent by a client, generate confirmation key negotiation completion information that matches the first national cryptography secure shell protocol connection request, and send the confirmation key negotiation completion information to the server. The first national cryptography secure shell protocol connection request includes: connection method indication information, and the connection method includes: software algorithm connection method or hardware algorithm connection method. The confirmation key negotiation completion information is used to indicate that the client and the server reach a handshake protocol;

[0135] The confirmation unit 602 is configured to, when receiving the identity authentication challenge information sent by the client, generate identity confirmation information corresponding to the identity authentication challenge information, and generate an authentication challenge data packet based on the identity confirmation information. The authentication challenge data packet is used to instruct the client to send a result data packet corresponding to the authentication challenge data packet. The identity authentication challenge information is used to instruct the server to generate identity confirmation information;

[0136] The first execution unit 603 is configured to, when obtaining the intelligent key corresponding to the client and receiving the result data packet corresponding to the authentication challenge data packet, verify the result data packet and the intelligent key through a preset verification method;

[0137] The first sending unit 604 is configured to, when the result data packet meets a preset threshold and the intelligent key verification meets a preset password, the server sends a connection request to the client, and the connection request is used to request to establish a communication connection between the client and the server.

[0138] In one embodiment, the first generation unit 601 is specifically configured to:

[0139] When the server receives the first national cryptography secure shell protocol connection request sent by the client, the server sends first verification information to the client, and the first verification information is used to request the client to send verification information for verifying the identity of the client. The first verification information includes a second random number matching the first random number, the signature public key information of the server, the encryption public key information of the server, and the signature information of the server;

[0140] After receiving the encrypted specific value sent by the client, decrypt the encrypted specific value with the decryption private key of the server corresponding to the encryption public key of the server to generate the server specific value, perform key negotiation through the server specific value, generate information indicating that the key negotiation with the client is completed, and send the information indicating that the key negotiation with the client is completed to the client.

[0141] In one embodiment, the first execution unit 603 is further configured to:

[0142] Receive the first information sent by the client, and open a selection interface for the communication connection matching method between the client and the server according to the first information.

[0143] In one embodiment, the server is connected to a hardware encryption communication module, and the hardware encryption communication module is used to generate a hardware communication verification password. When the first national cryptography secure shell protocol connection request includes a hardware algorithm connection method, the first generation unit 601 is further configured to:

[0144] Trigger the hardware encryption module to enable encryption for the communication connection between the client and the server, generate identity confirmation information corresponding to the identity authentication challenge information, and generate an authentication challenge data packet based on the identity confirmation information.

[0145] In one embodiment, the first execution unit 603 is further configured to:

[0146] Determine the interface file path in the server that matches the hardware encryption module;

[0147] The server obtains the configuration parameters of the hardware encryption module through the interface file path, and configures the interface corresponding to the interface file path in the server through the configuration parameters. The server is connected to the hardware encryption module.

[0148] In one embodiment, the first national cryptographic secure shell protocol connection request further includes: hardware encryption module enable indication information. The first execution unit 603 is further configured to:

[0149] The server obtains the interface status between the server and the hardware encryption module;

[0150] When the server obtains that the interface status between the server and the hardware encryption module is in an open state, trigger the hardware encryption module to start encrypting the communication connection between the client and the server.

[0151] In one embodiment, when the smart password key is connected to the server, the first execution unit 603 is specifically configured to:

[0152] When triggering the smart password key to generate a smart key and receiving the result data packet corresponding to the authentication challenge data packet sent by the client, verify the result data packet and the smart key through a preset verification method.

[0153] Figure 4 It is a block diagram of a client according to an embodiment of the present application. Refer to Figure 4 , the client includes a second sending unit 701, a receiving unit 702, a second generating unit 703, and a second execution unit 704.

[0154] The second sending unit 701 is configured to send a first national cryptographic secure shell protocol connection request to the server. The first national cryptographic secure shell protocol connection request includes: connection method indication information. The connection method includes: software algorithm connection method or hardware algorithm connection method;

[0155] The receiving unit 702 is configured to receive the confirmation key negotiation completion information sent by the server. The confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol;

[0156] The second sending unit 701 is further configured to send identity authentication challenge information to the server. The identity authentication challenge information is used to indicate the server to generate identity confirmation information;

[0157] The second generation unit 703 is configured to generate a result data packet corresponding to the authentication challenge data packet after receiving the authentication challenge data packet sent by the server, and send the result data packet to the server;

[0158] The second execution unit 704 is configured to establish a connection with the server when receiving a connection request from the server.

[0159] In one embodiment, the second sending unit 701 is configured to send a first national cryptography secure shell protocol connection request to the server, and the first national cryptography secure shell protocol connection request includes a first random number;

[0160] The second sending unit 701 is further configured to generate a specific value according to the first verification information after receiving the first verification information sent by the server, and send the specific value to the server. The specific value is a value encrypted by the public key of the server. The first verification information is used to request the client to send verification information for verifying the identity of the client. The first verification information includes a second random number matching the first random number, the signature public key information of the server, the encryption public key information of the server, and the signature information of the server.

[0161] In one embodiment, the second sending unit 701 is further configured to send a first piece of information to the server, and the first piece of information is used to indicate that the communication connection matching method is the first national cryptography secure shell protocol connection.

[0162] In one embodiment, when the client is connected to the intelligent cryptographic key, the second execution unit 704 is configured to:

[0163] After receiving the authentication challenge data packet sent by the server, trigger the intelligent cryptographic key to generate an intelligent key, and generate a result data packet corresponding to the authentication challenge data packet;

[0164] Send the intelligent key and the result data packet to the server.

[0165] It should be understood that the units described in the server and the client correspond to the respective steps in the method described in the accompanying drawings. Therefore, the operations and features described above for the method also apply to the server and the client and the units included therein, and will not be repeated here. The server and the client can be pre-implemented in the browser or other security applications of the computer device, or can be loaded into the browser or its security applications of the computer device by means of downloading, etc. The corresponding units in the server and the client can cooperate with the units in the computer device to implement the solution of the embodiments of the present application.

[0166] Among the several modules or units mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0167] It should be noted that for the details not disclosed in the server and client of the embodiments of this application, please refer to the details disclosed in the above embodiments of this application, and they will not be elaborated here.

[0168] The following refers to Figure 5 , Figure 5 shows a schematic structural diagram of a computer device suitable for implementing the embodiments of this application. As Figure 5 shown, the computer system 1700 includes a central processing unit (CPU) 1701, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1702 or the program loaded from the storage section 1708 into the random access memory (RAM) 1703. In the RAM 1703, various programs and data required for the operation instructions of the system are also stored. The CPU 1701, ROM 1702, and RAM 1703 are connected to each other through a bus 1704. The input / output (I / O) interface 1705 is also connected to the bus 1704.

[0169] The following components are connected to the I / O interface 1705; an input section 1706 including a keyboard, a mouse, etc.; an output section 1707 including such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 1708 including a hard disk, etc.; and a communication section 1709 including a network interface card such as a LAN card, a modem, etc. The communication section 1709 performs communication processing via a network such as the Internet. A drive 1710 is also connected to the I / O interface 1705 as needed. A removable medium 1711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1710 as needed, so that the computer program read from it can be installed into the storage section 1708 as needed.

[0170] Specifically, according to the embodiments of this application, the above reference to the flowchart Figure 1 or Figure 2The described process can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication section 1709, and / or installed from a removable medium 1711. When the computer program is executed by a central processing unit (CPU) 1701, the above-described functions defined in the system of the present application are performed.

[0171] It should be noted that the computer-readable medium shown in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in conjunction with an instruction execution system, apparatus, or device. And in the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0172] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operation instructions of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the foregoing module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two connected blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operation instructions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0173] The units or modules involved in the embodiments described in the present application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. For example, it can be described as: a processor includes a first receiving module, a second receiving module, and a transmitting module. Among them, the names of these units or modules do not constitute a limitation on the units or modules themselves in some cases.

[0174] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments, or may exist separately without being assembled into the electronic device. The above computer-readable storage medium stores one or more programs, and when the above programs are used by one or more processors to execute the communication method based on the national secret encryption network protocol described in the present application.

[0175] The above description is only the preferred embodiments of the present application and the description of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in the present application.

Claims

1. A communication method based on a national cryptographic encryption network protocol, characterized in that, Applied to a server, including: When the server receives a first national cryptographic Secure Shell protocol connection request sent by a client, the server generates confirmation key negotiation completion information that matches the first national cryptographic Secure Shell protocol connection request, and sends the confirmation key negotiation completion information to the client. The first national cryptographic Secure Shell protocol connection request includes connection method indication information, and the connection method includes a software algorithm connection method or a hardware algorithm connection method. The confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol; When the server receives the identity authentication challenge information sent by the client, it generates identity confirmation information corresponding to the identity authentication challenge information, generates an authentication challenge data packet based on the identity confirmation information, and sends it to the client. The authentication challenge data packet is used to instruct the client to send a result data packet corresponding to the authentication challenge data packet. The identity authentication challenge information is used to instruct the server to generate identity confirmation information. The action of the server receiving the identity authentication challenge information sent by the client is the first challenge, the action of the server generating the identity confirmation information is the first response, and the action of the server sending the authentication challenge data packet to the client is the second challenge; When the server obtains the smart key corresponding to the client and receives the result data packet sent by the client that corresponds to the authentication challenge data packet, it verifies the result data packet and the smart key through a preset verification method. The action of the server receiving the result data packet sent by the client that corresponds to the authentication challenge data packet is the second response; When the result data packet meets a preset threshold and the smart key verification meets a preset password, the server sends a connection request to the client. The connection request is used to request the establishment of a communication connection between the client and the server. The action of the server sending the connection request to the client is the third response.

2. The method according to claim 1, characterized in that, When the server receives the first national cryptographic Secure Shell protocol connection request sent by the client, the server generates confirmation key negotiation completion information that matches the first national cryptographic Secure Shell protocol connection request, and sends the confirmation key negotiation completion information to the server, including: When the server receives the first national cryptographic Secure Shell protocol connection request sent by the client, it sends first verification information to the client. The first verification information is used to request the client to send verification information for verifying the identity of the client. The first verification information includes a second random number that matches a first random number, the signature public key information of the server, the encryption public key information of the server, and the signature information of the server; After receiving the encrypted specific value sent by the client, decrypt the encrypted specific value with the decryption private key of the server corresponding to the encryption public key of the server to generate a server specific value, perform key negotiation through the server specific value, generate an information indicating that the key negotiation with the client is completed, and send the information indicating that the key negotiation is completed to the client.

3. The method according to claim 1, characterized in that, Before the server generates the information indicating that the key negotiation is completed that matches the first SM4 SSH connection request sent by the client when the server receives the first SM4 SSH connection request sent by the client, the method further includes: Receiving the first information sent by the client, and opening a selection interface for the communication connection matching method between the client and the server according to the first information.

4. The method according to claim 1, wherein The server is connected to a hardware encryption communication module, and the hardware encryption communication module is used to generate a hardware communication verification password. When the first SM4 SSH connection request includes a hardware algorithm connection method, generating an identity confirmation information corresponding to the identity authentication challenge information, and generating an authentication challenge data packet based on the identity confirmation information, including: Triggering the hardware encryption communication module to enable encryption for the communication connection between the client and the server, generating an identity confirmation information corresponding to the identity authentication challenge information, and generating an authentication challenge data packet based on the identity confirmation information.

5. The method according to claim 1, wherein Before the server generates the information indicating that the key negotiation is completed that matches the first SM4 SSH connection request sent by the client when the server receives the first SM4 SSH connection request sent by the client, the method further includes: Determining the interface file path in the server that matches the hardware encryption communication module; The server obtains the configuration parameters of the hardware encryption communication module through the interface file path, and configures the interface corresponding to the interface file path in the server through the configuration parameters, and the server is connected to the hardware encryption communication module.

6. The method according to claim 4, characterized in that The first SM4 SSH connection request further includes: an enabling indication information of the hardware encryption communication module. Before triggering the hardware encryption communication module to enable encryption for the communication connection between the client and the server, the method further includes: The server obtains the interface state between the server and the hardware encryption communication module; When the interface state between the server and the hardware encryption communication module obtained by the server is in an open state, triggering the hardware encryption communication module to enable encryption for the communication connection between the client and the server.

7. The method according to claim 1, characterized in that, When the intelligent password key corresponding to the intelligent key is connected to the server, when the server obtains the intelligent key corresponding to the client and receives the result data packet corresponding to the authentication challenge data packet sent by the client, verifying the result data packet and the intelligent key through a preset verification method, including: When the intelligent password key is triggered to generate an intelligent key and the result data packet corresponding to the authentication challenge data packet sent by the client is received, the result data packet and the intelligent key are verified through a preset verification method.

8. A communication method based on a national cryptographic encryption network protocol, applied to a client, characterized in that, The method includes: The client sends a first national cryptography secure shell protocol connection request to the server, and the first national cryptography secure shell protocol connection request includes: connection mode indication information, and the connection mode includes: software algorithm connection mode or hardware algorithm connection mode; The client receives the confirmation key negotiation completion information sent by the server, and the confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol; Send identity authentication challenge information to the server, and the identity authentication challenge information is used to indicate that the server generates identity confirmation information; After receiving the authentication challenge data packet sent by the server, generate a result data packet corresponding to the authentication challenge data packet and send it to the server. The authentication challenge data packet is generated based on the identity confirmation information and is used to indicate that the client sends a result data packet corresponding to the authentication challenge data packet; When receiving the connection request sent by the server, establish a connection with the server; Wherein, when the intelligent password key is connected to the client, the step of generating a result data packet corresponding to the authentication challenge data packet after receiving the authentication challenge data packet sent by the server and sending it to the server includes: After receiving the authentication challenge data packet sent by the server, trigger the intelligent password key to generate an intelligent key and generate a result data packet corresponding to the authentication challenge data packet; Send the intelligent key and the result data packet to the server.

9. The method according to claim 8, characterized in that The client sending the first national cryptography secure shell protocol connection request to the server includes: The client sends a first national cryptography secure shell protocol connection request to the server, and the first national cryptography secure shell protocol connection request includes a first random number; After the client sends the first national cryptography secure shell protocol connection request to the server, the method further includes: After receiving the first verification information sent by the server, generate a specific value according to the first verification information and send the specific value to the server. The specific value is a value encrypted by the public key of the server. The first verification information is used to request the client to send verification information for verifying the identity of the client, and the first verification information includes a second random number matching the first random number, the signature public key information of the server, the encryption public key information of the server, and the signature information of the server.

10. The method according to claim 8, wherein Before the client sends the first national cryptography secure shell protocol connection request to the server, the method further includes: The client sends a first piece of information to the server, and the first piece of information is used to indicate that the communication connection matching mode is the first national cryptography secure shell protocol connection.

11. A server, characterized in that, The server includes: The first generation unit is used to generate, when receiving a first national cryptographic secure shell protocol connection request sent by a client, confirmation key negotiation completion information that matches the first national cryptographic secure shell protocol connection request, and send the confirmation key negotiation completion information to the server. The first national cryptographic secure shell protocol connection request includes connection mode indication information, and the connection mode includes a software algorithm connection mode or a hardware algorithm connection mode. The confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol. The confirmation unit is used to generate, when receiving identity authentication challenge information sent by the client, identity confirmation information corresponding to the identity authentication challenge information, generate an authentication challenge data packet based on the identity confirmation information, and send it to the client. The authentication challenge data packet is used to instruct the client to send a smart key. The identity authentication challenge information is used to instruct the server to generate identity confirmation information. The action of the server receiving the identity authentication challenge information sent by the client is the first challenge. The action of the server generating the identity confirmation information is the first response. The action of the server sending the authentication challenge data packet to the client is the second challenge. The first execution unit is used to verify the result data packet and the smart key through a preset verification method when obtaining the smart key corresponding to the client and receiving a result data packet sent by the client that corresponds to the authentication challenge data packet. The action of the server receiving the result data packet sent by the client that corresponds to the authentication challenge data packet is the second response. The first sending unit is used to send, when the result data packet meets a preset threshold and the smart key verification meets a preset password, a connection request from the server to the client. The connection request is used to request the establishment of a communication connection between the client and the server. The action of the server sending the connection request to the client is the third response.

12. A client, characterized in that, The client includes: The second sending unit is used to send a first national cryptographic secure shell protocol connection request to the server. The first national cryptographic secure shell protocol connection request includes connection mode indication information, and the connection mode includes a software algorithm connection mode or a hardware algorithm connection mode. The receiving unit is used to receive the confirmation key negotiation completion information sent by the server. The confirmation key negotiation completion information is used to indicate that the client and the server have reached a handshake protocol. The second sending unit is further used to send identity authentication challenge information to the server. The identity authentication challenge information is used to instruct the server to generate identity confirmation information. The second generation unit is used to generate, after receiving an authentication challenge data packet sent by the server, a result data packet corresponding to the authentication challenge data packet, and send it to the server. The authentication challenge data packet is generated based on the identity confirmation information and is used to instruct the client to send a result data packet corresponding to the authentication challenge data packet. A second execution unit, configured to establish a connection with the server when receiving a connection request from the server; The second generation unit is specifically configured to, when the intelligent cryptographic key is connected to the client, after receiving an authentication challenge data packet sent by the server, trigger the intelligent cryptographic key to generate an intelligent key and generate a result data packet corresponding to the authentication challenge data packet; and send the intelligent key and the result data packet to the server.

Citation Information

Patent Citations

  • National cryptographic office certificate authentication method, device and equipment

    CN109361681A

  • Digital certificate issuing management method for industrial control system and encryption communication method for industrial control system

    CN112350826A