Intelligent device secure networking method and system based on dynamic keys

Through a secure networking method based on dynamic keys, dynamic keys are generated in combination with device identification and initial keys, and session keys are generated using gateway verification and Diffie-Hellman algorithms, the problems of easy stealing and resource limitation in the secure networking of smart devices are solved, and efficient and flexible secure communication is achieved.

CN119814473BActive Publication Date: 2025-07-25SHENZHEN YIBANG SUNSHINE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510286314.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-07-25
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

The existing smart device security networking solutions rely on static keys or simple authentication mechanisms, which are difficult to deal with complex network security threats, and ignore the dynamic characteristics and resource limitations of smart devices, resulting in inflexible key management and encrypted communication.

Method used

A secure networking method based on dynamic key is adopted, and a dynamic key is generated through a hashing algorithm combined with device identification and initial key, and a session key is generated using gateway verification and Diffie-Hellman algorithm to realize encrypted communication, and security is improved through real-time monitoring and key update mechanisms.

Benefits of technology

It improves the security and flexibility of smart devices, prevents static keys from being stolen, adapts to dynamic operating environments, enhances the security and reliability of the system, reduces the computational complexity of the encryption and decryption process, and is suitable for smart devices with limited resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814473B_ABST
    Figure CN119814473B_ABST
Patent Text Reader

Abstract

The present invention relates to a method and system for secure networking of intelligent devices based on dynamic keys. The method includes: obtaining the device identifier and the initial key of the intelligent device, recording the current timestamp when the intelligent device starts, and generating a dynamic key through a hashing algorithm in combination with the device identifier and the initial key; generating a corresponding networking request based on the dynamic key, and sending the dynamic key and the networking request to the corresponding gateway; verifying the received networking request and the dynamic key by the gateway to obtain a verification result, and sending the verification result to the intelligent device; generating a corresponding session key by the intelligent device according to a preset Diffie-Hellman algorithm in combination with the verification result, and performing encrypted communication with the gateway based on the session key, and sending the corresponding encrypted data to the gateway. The present invention can achieve flexible key management and efficient encrypted communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of secure networking of intelligent devices, and particularly relates to a method and system for secure networking of intelligent devices based on dynamic keys. Background Art

[0002] With the rapid development of Internet of Things technology and the widespread application of intelligent devices, the problem of secure networking of intelligent devices has received increasing attention. As an important part of the Internet of Things, intelligent devices play an increasingly important role in daily life and industrial production. However, due to the characteristics of limited computing power and storage resources of intelligent devices, traditional secure communication methods are often difficult to be directly applied to these devices. Currently, most secure networking solutions for intelligent devices mainly rely on static keys or simple authentication mechanisms, and these methods are unable to cope when facing increasingly complex network security threats. Static keys are easily obtained by attackers through long-term eavesdropping or physical contact, etc., while simple authentication mechanisms may be bypassed or forged. In addition, existing secure networking methods often ignore the dynamic characteristics and resource limitations of intelligent devices, and it is difficult to achieve flexible key management and efficient encrypted communication. Summary of the Invention

[0003] The main object of the present invention is to provide a method and system for secure networking of intelligent devices based on dynamic keys, which can achieve flexible key management and efficient encrypted communication.

[0004] To achieve the above object, the present invention provides a method for secure networking of intelligent devices based on dynamic keys, including:

[0005] Obtain the device identifier and the initial key of the intelligent device. When the intelligent device starts, record the current timestamp, and generate a dynamic key through a hash algorithm in combination with the device identifier and the initial key;

[0006] Generate a corresponding networking request based on the dynamic key, and send the dynamic key and the networking request to the corresponding gateway;

[0007] Verify the received networking request and the dynamic key through the gateway to obtain a verification result, and send the verification result to the intelligent device;

[0008] Generate a corresponding session key by the intelligent device according to the preset Diffie-Hellman algorithm in combination with the verification result, and perform encrypted communication with the gateway based on the session key, and send the corresponding encrypted data to the gateway.

[0009] Further, obtaining the device identifier and the initial key of the smart device, when the smart device is started, recording the current timestamp, and generating a dynamic key by combining the device identifier and the initial key through a hashing algorithm, includes:

[0010] Reading the device identifier and the initial key preset in the smart device, and recording the system clock of the smart device to obtain the current timestamp;

[0011] Concatenating the device identifier, the initial key, and the current timestamp to obtain an original string;

[0012] Encoding the original string in UTF-8 to obtain an encoded byte array;

[0013] Performing a hashing calculation on the byte array through the hashing algorithm to obtain a byte hash value;

[0014] Converting the byte hash value into a hexadecimal string to obtain an intermediate key;

[0015] Encoding the intermediate key in Base64 to obtain an encoded string;

[0016] Extracting the first 32 characters from the encoded string to obtain the dynamic key.

[0017] Further, generating a corresponding network connection request based on the dynamic key, and sending the dynamic key and the network connection request to a corresponding gateway, includes:

[0018] Performing a segmentation process on the dynamic key to obtain a plurality of key segments;

[0019] Filling the device identifier and the current timestamp according to a preset network connection request template to obtain an initial request;

[0020] Performing a hashing operation on the initial request to obtain a request digest;

[0021] Reordering the plurality of key segments according to the request digest to obtain a key segment sequence;

[0022] Performing an exclusive OR operation on the key segment sequence to obtain a scrambled key;

[0023] Encrypting the initial request according to the scrambled key to obtain an encrypted network connection request;

[0024] Performing a chunking process on the encrypted network connection request to obtain a plurality of request data blocks;

[0025] Encapsulating the plurality of request data blocks according to a preset network protocol to obtain the network connection request;

[0026] Send the networking request and the dynamic key to the corresponding gateway through a preset secure channel.

[0027] Further, the gateway verifies the received networking request and the dynamic key to obtain a verification result, and sends the verification result to the intelligent device, including:

[0028] After sending the networking request and the dynamic key to the gateway through the intelligent device, detect whether the verification result sent by the gateway is received within a preset time period. When the verification result is not received within the preset time period, resend the networking request and the dynamic key to the gateway;

[0029] Among them, the gateway verifies the received networking request and the dynamic key to obtain a verification result, including:

[0030] After the gateway receives the networking request and the dynamic key, extract the timestamp of the networking request to obtain a request timestamp;

[0031] Compare the current gateway time with the request timestamp to obtain a time difference;

[0032] Compare the time difference with a preset time threshold to obtain a time validity result;

[0033] Filter and analyze the networking request according to the time validity result to obtain a request device identifier and the initial key;

[0034] Perform a hash operation on the initial key, the request device identifier, and the request timestamp to obtain a gateway dynamic key;

[0035] Compare and verify the gateway dynamic key with the dynamic key sent by the intelligent device to obtain the verification result.

[0036] Further, the comparing and verifying the gateway dynamic key with the dynamic key sent by the intelligent device to obtain the verification result includes:

[0037] Perform a hash operation on the request device identifier, the initial key, and the request timestamp through the gateway to obtain a first verification value;

[0038] Obtain the gateway time of the gateway, and perform a secondary hash operation in combination with the first verification value to obtain a gateway dynamic key;

[0039] Match the dynamic key of the gateway with the dynamic key sent by the intelligent device to obtain a corresponding matching result.

[0040] Determine whether the matching result is a match and generate a corresponding verification result.

[0041] When the matching result indicates a match, generate a verification result of verification passed and send it to the intelligent device.

[0042] When the matching result indicates a non-match, generate a verification result of verification failed and send it to the intelligent device.

[0043] Further, the intelligent device generates a corresponding session key according to the preset Diffie-Hellman algorithm in combination with the verification result, and performs encrypted communication with the gateway based on the session key, and sends corresponding encrypted data to the gateway, including:

[0044] Analyze the verification result to obtain verification status information.

[0045] Judge whether the verification is successful according to the verification status information. When the verification is successful, execute the subsequent steps, otherwise terminate the networking process.

[0046] Generate public parameters of the Diffie-Hellman algorithm: large prime number and primitive root.

[0047] The intelligent device generates a random private key and calculates a first public key.

[0048] Send the large prime number, the primitive root and the first public key to the gateway.

[0049] Receive the second public key sent by the gateway and calculate the shared key using the random private key and the second public key.

[0050] Perform a hash operation on the shared key to obtain the session key.

[0051] Send a notification message indicating that the session key generation is completed to the gateway and receive an acknowledgment message returned by the gateway to establish encrypted communication.

[0052] Encrypt the data to be sent based on the session key to obtain encrypted data.

[0053] Send the encrypted data to the gateway and receive the response data encrypted and sent by the gateway according to the session key.

[0054] Use the session key to decrypt the received response data to obtain the decrypted response data.

[0055] Among them, the formula for calculating the first public key is: A = g a mod p, and the formula for calculating the shared key is: K = B a mod p;

[0056] A is the first public key, p is a large prime number, g is a primitive root, a is a random private key, K is the shared key, and B is the second public key;

[0057] mod is the modulo operation symbol, representing the remainder operation.

[0058] Furthermore, the generation of the common parameters of the Diffie-Hellman algorithm: large prime number and primitive root, includes:

[0059] The steps for generating a large prime number include:

[0060] Randomly select a large odd number within a preset range as the candidate prime number. After subtracting 1 from the candidate prime number, decompose it into the product of a power of 2 and an odd number to obtain the corresponding set of test bases;

[0061] Randomly select multiple test bases from the set of test bases, and perform the Miller-Rabin primality test on each test base:

[0062] Calculate the power modulo operation of the test base with respect to the candidate prime number, and judge whether the candidate prime number may be a prime number based on the result of the power modulo operation. When any test fails, reselect the candidate prime number;

[0063] When all tests pass, the candidate prime number is considered to be the large prime number;

[0064] The steps for generating the primitive root include:

[0065] Perform prime factorization on the result of subtracting 1 from the large prime number to obtain a set of non-repeating prime factors;

[0066] Set the initial value of the candidate primitive root to 2;

[0067] Test the candidate primitive root: For each prime factor in the set of prime factors, perform the following steps:

[0068] Calculate a specific value, which is obtained by dividing the result of subtracting 1 from the large prime number by the current prime factor;

[0069] Calculate the exponential power of the candidate primitive root modulo the large prime number, and the exponent is the specific value;

[0070] When the calculation result is equal to 1, it means that the current candidate primitive root is not the primitive root. Increment the value of the current candidate primitive root by 1 and start a new test;

[0071] When all prime factors pass the test, that is, when the calculation result does not equal 1, the current candidate primitive root is the primitive root.

[0072] Further, the method further includes:

[0073] Monitor the running state of the intelligent device in real time, and record the running duration and important events;

[0074] Regularly analyze the running duration and the important events according to a preset update policy, and determine whether to update the key;

[0075] When the update condition is met, generate a key update trigger signal, re-execute the steps of the networking operation, and generate a new dynamic key and a new session key;

[0076] Encrypt and store the new dynamic key and the new session key to obtain a key backup file;

[0077] Communicate according to the new session key, and continuously monitor abnormal situations in the communication process according to a preset security policy;

[0078] When an abnormality is detected, analyze the degree of abnormality, and start a corresponding security mechanism according to the analysis result;

[0079] Real-time identify the operation requests of the user, and add sensitive operations to the operation list that requires multi-factor authentication;

[0080] When a sensitive operation request is monitored, collect multi-factor authentication data provided by the user according to the operation list, and perform verification;

[0081] When the verification passes, allow the execution of the sensitive operation request, otherwise reject the sensitive operation request;

[0082] When a request for device reset is received, extract the original key information from the key backup file;

[0083] Reconfigure the device according to the key information to restore the secure connection state of the intelligent device.

[0084] The present invention also provides an intelligent device secure networking system based on a dynamic key, which is applied to the intelligent device secure networking method based on a dynamic key in any one of the above, and includes:

[0085] An acquisition module, which is used to obtain the device identifier and the initial key of the intelligent device. When the intelligent device starts, record the current timestamp, and generate a dynamic key through a hash algorithm in combination with the device identifier and the initial key;

[0086] An analysis module, which is used to generate a corresponding networking request based on the dynamic key and send the dynamic key and the networking request to a corresponding gateway;

[0087] An association module, which is used to obtain the verification result generated by the gateway after receiving the networking request and the dynamic key;

[0088] A processing module, which is used to generate a corresponding session key by the intelligent device according to a preset Diffie-Hellman algorithm in combination with the verification result, and perform encrypted communication with the gateway based on the session key.

[0089] A method and system for secure networking of intelligent devices based on dynamic keys provided by the present invention have the following beneficial effects:

[0090] By combining the device identifier and the initial key to generate a dynamic key, the security and unpredictability of the key are improved, effectively preventing the risk of static keys being stolen or cracked, and enhancing the security protection ability of intelligent devices. Adopting a dynamic key generation mechanism based on timestamps enables the key to change dynamically with time, adapting to the dynamic operating environment of intelligent devices and improving the security and flexibility of the system. Using the Diffie-Hellman algorithm to generate session keys realizes a secure key exchange and negotiation process, avoiding the risk of keys being intercepted during network transmission, and at the same time adapting to the characteristics of resource-constrained intelligent devices. Through the dual security mechanisms of gateway verification and session key generation, the access of unauthorized devices is effectively prevented, improving the security and reliability of the entire Internet of Things system. The encrypted communication method based on session keys not only ensures the security of communication but also reduces the computational complexity of the encryption and decryption processes, suitable for the resource constraint characteristics of intelligent devices. The entire networking process takes into account the characteristics and security requirements of intelligent devices, realizes efficient and dynamic secure networking, effectively responds to various network attack threats, and provides a reliable security guarantee for the wide application of intelligent devices. Brief Description of the Drawings

[0091] Figure 1 is a flowchart of a method for secure networking of intelligent devices based on dynamic keys provided by the present invention;

[0092] Figure 2 is a structural diagram of a system for secure networking of intelligent devices based on dynamic keys provided by the present invention.

[0093] The realization, functional characteristics, and advantages of the object of the present invention will be further described in conjunction with embodiments with reference to the drawings. Detailed Embodiments

[0094] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.

[0095] Next, the present invention will be further described below in conjunction with the accompanying drawings and specific implementation manners.

[0096] Referring to Figure 1 , the present invention provides a method for secure networking of intelligent devices based on dynamic keys, including:

[0097] Step S1: Obtain the device identifier and initial key of the intelligent device. When the intelligent device starts up, record the current timestamp, and generate a dynamic key by combining the device identifier and the initial key through a hashing algorithm;

[0098] Step S2: Generate a corresponding networking request based on the dynamic key, and send the dynamic key and the networking request to the corresponding gateway;

[0099] Step S3: Verify the received networking request and dynamic key through the gateway to obtain a verification result, and send the verification result to the intelligent device;

[0100] Step S4: The intelligent device generates a corresponding session key based on the preset Diffie-Hellman algorithm in combination with the verification result, and performs encrypted communication with the gateway based on the session key, and sends the corresponding encrypted data to the gateway.

[0101] Based on the above steps, the detailed step process is as follows:

[0102] Step S1: Each intelligent device has a unique device identifier, which can be a device serial number, MAC address, etc. During device production or initialization, the device identifier is burned into the non-volatile memory of the device. When the device starts up, the device identifier is read from the memory.

[0103] The initial key is a pre-set key used to generate the dynamic key. The initial key can be pre-set when the device leaves the factory, or the initial key can be sent to the device through a secure channel. When the device starts up, the initial key is read from the secure storage area.

[0104] When the device starts up, obtain the current system time. Convert the time to a timestamp format, such as Unix timestamp. Concatenate the device identifier, initial key and timestamp. Select a suitable hashing algorithm, such as SHA-256. Use the hashing algorithm to perform a hashing calculation on the concatenated string to obtain a hash value. Use the hash value as the dynamic key.

[0105] Step S2: Define the data format of the network connection request, including fields such as request type, device identifier, timestamp, etc. Fill in the obtained device identifier and timestamp into the request. Generate a random number as the unique identifier for this request. Use the dynamic key as the key to encrypt the request content.

[0106] Encapsulate the encrypted request content and the dynamic key into a data packet. Add necessary message headers, such as version number, data length, etc.

[0107] Obtain the pre-configured gateway address. Establish a network connection with the gateway, such as a TCP connection. Send the encapsulated data packet to the gateway through the established connection.

[0108] Start a timer and wait for the gateway's response. If no response is received after the timeout, retry sending the request.

[0109] Step S3: The gateway listens on the specified port and receives connection requests from intelligent devices. Receive the data packet sent by the device and extract the network connection request and the dynamic key from it.

[0110] The gateway pre-stores the device identifiers and initial keys of all legal devices. Extract the device identifier and timestamp from the received request. Use the same method as the device to generate a dynamic key based on the device identifier, initial key, and timestamp. Compare the generated dynamic key with the received dynamic key.

[0111] If the dynamic key verification passes, use this key to decrypt the network connection request content. Check whether each field in the request is legal, such as whether the device identifier matches, whether the timestamp is within the valid range, etc.

[0112] Generate a verification result data structure based on the result of the verification process. The result contains information such as whether the verification passes and the reason for the error (if any). If the verification passes, generate a session identifier for subsequent communication.

[0113] Encrypt the verification result using the dynamic key. Send the encrypted verification result back to the intelligent device through the original connection.

[0114] Step S4: The device receives the verification result from the gateway. Decrypt the verification result using the dynamic key. Check whether the verification passes. If it does not pass, terminate subsequent operations.

[0115] The device generates a large prime number p and a primitive root g. The device selects a random number as the random private key a and calculates the first public key A = g^a mod p. The device sends p, g, and A to the gateway. The gateway selects a random number b as its own random private key and calculates the second public key B. The gateway sends B to the device. The device calculates the shared key K1 = B amod p. The gateway calculates the shared key K2 = A b mod p.

[0116] In theory, K1 = K2, and both parties obtain the same session key.

[0117] Based on the shared key K1 (or K2) generated by the Diffie-Hellman algorithm, combined with the session identifier in the verification result, use a predefined key derivation function (such as HKDF) to derive the final session key from the shared key and the session identifier. Multiple session keys can be generated for different purposes, such as encryption keys and authentication keys.

[0118] Use the generated session key to encrypt the data to be transmitted. Select a suitable symmetric encryption algorithm, such as AES. Generate a unique initialization vector (IV) for each message. Use the session key and the IV to encrypt the message content. Calculate the message authentication code (MAC) to ensure message integrity.

[0119] Construct an encrypted data packet containing the encrypted message content, IV, MAC, etc. Send the encrypted data packet to the gateway through the established secure connection.

[0120] Regularly or after transmitting a certain amount of data, trigger the key update mechanism. It can re-execute the Diffie-Hellman key exchange or use the current session key to derive a new key. The updated key is used for subsequent communication.

[0121] An intelligent device secure networking method based on dynamic keys provided by the present invention generates dynamic keys by combining device identifiers and initial keys, improving the security and unpredictability of the keys, effectively preventing the risk of static keys being stolen or cracked, and enhancing the security protection ability of intelligent devices. Adopting a dynamic key generation mechanism based on timestamps enables the keys to change dynamically over time, adapting to the dynamic operating environment of intelligent devices and improving the security and flexibility of the system. Using the Diffie-Hellman algorithm to generate session keys realizes a secure key exchange and negotiation process, avoiding the risk of keys being intercepted during network transmission, and at the same time adapting to the characteristics of resource-constrained intelligent devices. Through the dual security mechanisms of gateway verification and session key generation, it effectively prevents the access of unauthorized devices, improving the security and reliability of the entire Internet of Things system. The encryption communication method based on session keys not only ensures the security of communication but also reduces the computational complexity of the encryption and decryption processes, suitable for the resource constraint characteristics of intelligent devices. The entire networking process takes into account the characteristics and security requirements of intelligent devices, realizes efficient and dynamic secure networking, effectively responds to various network attack threats, and provides a reliable security guarantee for the wide application of intelligent devices.

[0122] In one embodiment, the device identifier and the initial key of the smart device are obtained. When the smart device starts up, the current timestamp is recorded, and a dynamic key is generated by combining the device identifier and the initial key through a hashing algorithm, including:

[0123] When the smart device starts up, the pre-set device identifier and initial key are read from the secure storage area of the device. The device identifier is usually a unique string used to distinguish different smart devices; the initial key is a pre-set string of passwords for subsequent key generation. At the same time, the current system clock is read to obtain a timestamp accurate to milliseconds. This timestamp will be used as a dynamic factor to ensure that the key generated each time is unique.

[0124] The read device identifier, initial key, and current timestamp are concatenated into a string in a predefined format. The choice of concatenation order and format affects the finally generated key, so it needs to be consistent throughout the system. After concatenation, an original string containing all necessary information is obtained.

[0125] The original string is encoded in UTF-8. UTF-8 encoding can handle characters in various languages, ensuring the generality of the method. After encoding, the original string is converted into a byte array.

[0126] The encoded byte array is hashed using a pre-selected hashing algorithm (such as SHA-256). The choice of hashing algorithm needs to consider the balance between security and computational efficiency. The result of the hashing calculation is a byte hash value of a fixed length.

[0127] The byte hash value is converted into a hexadecimal string representation. This step converts binary data into a readable character form. The resulting string is called the intermediate key.

[0128] The intermediate key is Base64 encoded to convert it into another character representation form. The main purpose of Base64 encoding is to increase the complexity of the key and ensure that the generated key contains only printable characters.

[0129] The first 32 characters are extracted from the Base64 encoded string as the final dynamic key. Selecting 32 characters is to balance security and usability. This length is sufficient to provide sufficient security strength without imposing too much storage and computational burden on the device.

[0130] In this embodiment, a dynamic key is generated by combining the device identifier, the initial key, and the timestamp, greatly enhancing the communication security. The introduction of the timestamp ensures that the keys generated by the same device at different times are different, effectively preventing replay attacks. The original information is processed using UTF-8 encoding and a hashing algorithm, enhancing the versatility and security of the method. The application of Base64 encoding ensures that the generated key only contains printable characters, improving the usability of the key. A fixed-length character is extracted as the final key, achieving a balance between security strength and device burden. The entire process does not require additional hardware support, is applicable to various intelligent devices, and has strong practicality and promotional value.

[0131] In one embodiment, a corresponding network connection request is generated based on the dynamic key, and the dynamic key and the network connection request are sent to the corresponding gateway, including:

[0132] The dynamic key is segmented to obtain multiple key segments. The segmentation process can be carried out according to a preset segmentation rule, such as segmenting by a fixed length or by a specific delimiter, to increase the complexity and security of the key.

[0133] The device identifier and the current timestamp are filled into a preset network connection request template to obtain an initial request. The network connection request template contains a fixed format and variable parameter positions, and the device identifier and the timestamp are filled into the variable parameter positions to ensure the uniqueness and timeliness of the request.

[0134] A hash operation is performed on the initial request to obtain a request digest. The hash operation uses a secure hash algorithm, such as SHA-256, to convert the variable-length initial request into a fixed-length digest for subsequent key reordering.

[0135] The multiple key segments are reordered according to the request digest to obtain a key segment sequence. The reordering process utilizes the characteristics of the request digest, such as converting the digest value into a numerical sequence, to guide the rearrangement of the key segments and increase the randomness of the key.

[0136] An exclusive OR operation is performed on the key segment sequence to obtain a scrambled key. The exclusive OR operation combines all the key segments into a new key, further enhancing the complexity and security of the key.

[0137] The initial request is encrypted according to the scrambled key to obtain an encrypted network connection request. The encryption process uses a symmetric encryption algorithm, such as AES, to encrypt the initial request using the scrambled key to ensure the confidentiality of the request content.

[0138] The encrypted network connection request is block-processed to obtain multiple request data blocks. The block processing divides the encrypted request into a size suitable for transmission according to the requirements of network transmission, facilitating network transmission and processing.

[0139] Encapsulate multiple request data blocks according to a preset network protocol to obtain a network request. The encapsulation process follows a specific network protocol, such as TCP / IP, adding necessary protocol headers and tails to the data blocks to ensure the correctness of network transmission.

[0140] Send the network request and the dynamic key to the corresponding gateway through a preset secure channel. The secure channel can be a VPN or an SSL / TLS encrypted channel to ensure the security of the network request and the dynamic key during transmission.

[0141] In this embodiment, by segmenting and reordering the dynamic key, the complexity and randomness of the key are significantly increased, greatly improving the security of the system. The method of using the request digest to guide the key reordering makes a unique obfuscated key generated for each request, effectively preventing replay attacks. By encrypting and chunking the initial request, the confidentiality and integrity of the network request during transmission are ensured. The preset network protocol encapsulation and secure channel transmission mechanism further enhance the reliability and security of data transmission. Such multi-level and multi-link security measures effectively reduce the risk of network attacks on intelligent devices during the networking process, while maintaining the flexibility and adaptability of the system, enabling it to adapt to different network environments and security requirements. Overall, this method significantly improves the security, reliability, and efficiency of intelligent device networking.

[0142] In one embodiment, the gateway verifies the received network request and dynamic key to obtain a verification result and sends the verification result to the intelligent device, including:

[0143] After the intelligent device sends the network request and the dynamic key to the gateway, start a timer to detect whether the verification result sent by the gateway is received within a preset time period. The setting of the preset time period is based on the estimation of network latency and processing time, usually ranging from a few seconds to dozens of seconds. If the verification result is not received within the preset time period, the intelligent device will automatically resend the network request and the dynamic key to the gateway. This resending mechanism ensures the reliability of communication and prevents connection failures caused by network fluctuations or packet losses.

[0144] When the gateway receives the network request and the dynamic key, extract the timestamp from the network request to obtain the request timestamp. The extraction of the timestamp is usually parsed from a specific field in the request message and is used to judge the timeliness of the request.

[0145] The gateway compares the current gateway time with the request timestamp and calculates the time difference. This step aims to detect the time validity of the request and prevent replay attacks. The calculation of the time difference takes into account network transmission latency and possible clock deviations between devices.

[0146] Compare the calculated time difference with a preset time threshold to obtain a time validity result. The setting of the preset time threshold is based on the system security policy and usually ranges from a few minutes to dozens of minutes. If the time difference exceeds the preset threshold, the request will be regarded as invalid to prevent potential security threats.

[0147] Filter and analyze the network connection requests according to the time validity result to obtain the request device identifier and the initial key. Only the requests that pass the time validity check will enter the next processing step. The analysis process extracts key information from the valid requests to prepare for subsequent key generation and verification.

[0148] Perform a hash operation on the parsed initial key, request device identifier, and request timestamp through the gateway to obtain the gateway dynamic key. The selection of the hash algorithm needs to consider security and computational efficiency, and commonly used ones are such as SHA-256 or SHA-3. This step reproduces the process of generating the dynamic key by the intelligent device at the gateway side.

[0149] Compare and verify the gateway dynamic key generated by the gateway and the dynamic key sent by the intelligent device through the gateway to obtain the verification result. The comparison process usually adopts a secure string comparison method to prevent timing attacks. The verification result includes the status of success or failure, as well as possible error codes or additional information.

[0150] In this embodiment, by segmenting and reordering the dynamic key, and performing an exclusive OR operation in combination with the request digest, the complexity and randomness of the key are greatly enhanced, effectively improving the security of the system. By using a preset network connection request template and timestamp filling mechanism, the uniqueness and timeliness of each request are ensured, effectively preventing replay attacks. Through multiple encryptions and secure channel transmissions, the confidentiality of the network connection requests and dynamic keys during the transmission process is guaranteed. The multiple verification mechanisms at the gateway side, including the timestamp validity check and the dynamic key comparison, effectively prevent potential security threats. The retransmission mechanism of the intelligent device and the timeliness check of the gateway improve the fault tolerance and communication stability of the system. The hash operation and secure string comparison methods adopted throughout the process further enhance the system's ability to resist various network attacks.

[0151] In one embodiment, compare and verify the gateway dynamic key and the dynamic key sent by the intelligent device to obtain the verification result, including:

[0152] Perform a hash operation on the request device identifier, initial key, and request timestamp through the gateway to obtain the first verification value. This step aims to encrypt the key information of the device to increase security. The hash operation is a one-way encryption algorithm that can convert the input data into an output of a fixed length, and the probability of different inputs generating the same output is extremely low, which ensures the uniqueness and security of the verification process.

[0153] The gateway obtains its own gateway time and combines it with the first verification value for a secondary hashing operation to obtain the gateway dynamic key. Introducing the gateway time as a dynamic factor makes each generated key unique. Even if the initial information is the same, the keys generated at different times will be different, which greatly improves the security of the system and effectively prevents replay attacks.

[0154] The gateway matches the gateway dynamic key generated by itself with the dynamic key sent by the intelligent device to obtain the corresponding matching result. This step is the core of the verification process, and it determines whether the identity of the device is legal by comparing whether the two keys are the same.

[0155] The gateway determines whether there is a match based on the matching result and generates the corresponding verification result. This judgment process is binary, either the match is successful or the match fails, and there is no intermediate state, ensuring the clarity of the verification result.

[0156] When the matching result indicates a match, the gateway generates a verification result of verification passed and sends it to the intelligent device. Verification passed means that the identity of the intelligent device is confirmed and subsequent communication and operations can be carried out. This positive feedback will allow the device to continue to interact securely with the gateway.

[0157] When the matching result indicates no match, the gateway generates a verification result of verification failed and sends it to the intelligent device. Verification failed indicates that there is a problem with the device identity or an abnormality occurs during the communication process, and the gateway will reject subsequent requests from the device.

[0158] In this embodiment, by adopting the intelligent device secure networking method based on dynamic keys, the security of network communication is significantly improved. The introduction of multiple hashing operations and timestamps makes each generated key unique, effectively preventing replay attacks and man-in-the-middle attacks. The generation process of the gateway dynamic key takes into account device identification, initial key, and time factors, ensuring the reliability and security of the verification process. By comparing the gateway dynamic key with the dynamic key sent by the device, fast and accurate identity verification is achieved, effectively preventing unauthorized devices from accessing. This embodiment not only improves the security of the system but also ensures the efficiency of the verification process, realizing the fast and reliable access of intelligent devices.

[0159] In one embodiment, the intelligent device generates a corresponding session key based on the preset Diffie-Hellman algorithm in combination with the verification result, and conducts encrypted communication with the gateway based on the session key, and sends the corresponding encrypted data to the gateway, including:

[0160] The verification result is parsed by the intelligent device to obtain the verification status information. This step aims to confirm the result of device authentication and provide a basis for subsequent operations. The verification status information contains the key information on whether the verification is successful and is an important basis for deciding whether to continue with secure communication.

[0161] Based on the parsed verification status information, the intelligent device determines whether the verification is successful. This is a crucial decision point. Only when the verification is successful will the device execute subsequent steps of key generation and encrypted communication. If the verification fails, the device will immediately terminate the networking process to prevent unauthorized access.

[0162] After successful verification, the intelligent device generates the public parameters required by the Diffie-Hellman algorithm: large prime number and primitive root. These parameters are the basis of the Diffie-Hellman key exchange protocol, and their selection directly affects the security of the generated key. The selection of the large prime number needs to meet specific security requirements, and the primitive root needs to be calculated based on the selected large prime number.

[0163] The intelligent device generates a random private key and calculates the first public key using this private key and the previously generated public parameters. The randomness of the private key is a key factor in ensuring the security of key exchange, and the public key is an important parameter for secure communication with the gateway.

[0164] The intelligent device sends the generated large prime number, primitive root, and first public key to the gateway. This step is the start of the Diffie-Hellman key exchange. Transmitting these parameters through a secure channel lays the foundation for subsequent key generation.

[0165] The intelligent device receives the second public key sent by the gateway and calculates the shared key using its own random private key and the received second public key. This process is the core of the Diffie-Hellman algorithm. Through their respective private keys and the public keys of the other party, both parties can independently calculate the same shared key without transmitting the private key over the network.

[0166] The intelligent device performs a hash operation on the calculated shared key to obtain the final session key. The introduction of the hash operation increases the complexity of the key. At the same time, the hash operation can also convert the shared key, which may have different lengths, into a fixed-length session key for subsequent encryption operations.

[0167] After generating the session key, the intelligent device sends a notification message indicating that the session key generation is complete to the gateway and waits to receive the confirmation message returned by the gateway.

[0168] After receiving the confirmation message from the gateway, the smart device encrypts the data to be sent using the generated session key to obtain encrypted data. This step converts the original data into ciphertext, ensuring the security of the data during transmission.

[0169] The smart device sends the encrypted data to the gateway and receives the response data encrypted by the gateway using the same session key. This process achieves two-way encrypted communication, ensuring the confidentiality of data transmission.

[0170] Among them, the formula for calculating the first public key is: A = g a mod p, and the formula for calculating the shared key is: K = B a mod p;

[0171] A is the first public key, p is a large prime number, g is a primitive root, a is a random private key, K is the shared key, B is the second public key; mod is the modulo operation symbol, representing the remainder operation.

[0172] In one embodiment, generating the public parameters of the Diffie-Hellman algorithm: large prime number and primitive root, includes:

[0173] The process of generating a large prime number first randomly selects a large odd number within a preset range as a candidate prime number. The preset range is usually 2048 bits or larger to ensure sufficient security. After subtracting 1 from the candidate prime number, it is decomposed into the product of a power of 2 and an odd number to obtain the corresponding set of test bases. This decomposition helps the efficient conduct of the Miller-Rabin primality test.

[0174] Randomly select multiple test bases from the set of test bases and perform the Miller-Rabin primality test on each test base. The number of test bases is usually set to 20 - 30 to balance the accuracy and efficiency of the test. Calculate the power modulo operation of each test base with respect to the candidate prime number and determine whether the candidate prime number is likely to be a prime number based on the result of the power modulo operation. If any test fails, reselect the candidate prime number. This iterative process ensures that the finally selected number has a high probability of being prime. When all tests pass, the candidate prime number is considered a large prime number.

[0175] The process of generating a primitive root begins with factoring the large prime number minus 1 to obtain a set of distinct prime factors. This step lays the foundation for subsequent primitive root tests. Set the initial value of the candidate primitive root to 2, which is the smallest possible primitive root value.

[0176] When testing candidate primitive roots, each prime factor in the set of prime factors is traversed. For each prime factor, a specific value is calculated, which is the result of dividing the large prime number minus 1 by the current prime factor. This specific value is used for subsequent exponentiation operations. Calculate the exponentiation of the candidate primitive root modulo the large prime number, where the exponent is the specific value calculated previously. When the calculation result is equal to 1, it indicates that the current candidate primitive root is not a primitive root. At this time, increment the value of the current candidate primitive root by 1 and start a new test.

[0177] When all prime factors pass the test, that is, there is no case where the calculation result is equal to 1, then the current candidate primitive root is the required primitive root. This method ensures that the found primitive root satisfies the necessary mathematical properties and is applicable to the Diffie-Hellman key exchange algorithm.

[0178] The method for secure networking of intelligent devices based on dynamic keys in this embodiment provides a solid foundation for secure communication between intelligent devices by generating the public parameters of the Diffie-Hellman algorithm. The method of randomly selecting a large odd number and performing the Miller-Rabin primality test to generate a large prime number ensures the randomness and security of the prime number. By finding the primitive root through prime factorization and iterative testing, the effectiveness of the primitive root is guaranteed. This embodiment not only improves the efficiency of key generation but also enhances the security of the key. By flexibly adjusting the preset range and the number of test bases, this embodiment can achieve a balance between security and efficiency and adapt to the requirements of different application scenarios. In addition, the calculation process of this embodiment can be completed locally on the intelligent device, avoiding external dependencies and improving the autonomy and reliability of the system.

[0179] In one embodiment, a method for secure networking of intelligent devices based on dynamic keys provided by the present invention further includes:

[0180] Regularly analyze the running duration and important events according to a preset update strategy and determine whether the key needs to be updated. The update strategy can be triggered based on a time period (such as updating once every 7 days) or a specific event (such as the cumulative running time exceeding 100 hours). When the update condition is met, generate a key update trigger signal and re-execute the steps of the networking operation to generate new dynamic keys and new session keys.

[0181] Encrypt and store the newly generated dynamic keys and session keys to obtain a key backup file. High-strength encryption algorithms such as AES-256 are used for encrypted storage to ensure the security of the key information. The key backup file is stored in the secure storage area of the device and can only be accessed by authorized programs.

[0182] Communicate based on the new session key, and continuously monitor for anomalies during the communication process according to the preset security policies. The security policies include multiple dimensions such as traffic anomaly detection and protocol violation detection. When an anomaly is detected, analyze the degree of the anomaly, and start the corresponding security mechanism according to the analysis result. The degree of anomaly can be divided into three levels: minor, medium, and severe, corresponding to different levels of security measures such as warnings, temporary blocking, and emergency isolation.

[0183] Real-time identify the user's operation requests, and add sensitive operations to the operation list that requires multi-factor authentication. Sensitive operations include high-risk operations such as modifying device configurations and updating firmware. When a sensitive operation request is detected, collect the multi-factor authentication data provided by the user according to the operation list and verify it. Multi-factor authentication can include various forms such as passwords, biometric features, and hardware tokens. When the verification passes, the sensitive operation request is allowed to be executed; otherwise, the sensitive operation request is rejected.

[0184] When a request for device reset is received, extract the original key information from the key backup file. The device reset may be triggered actively by the user or may be part of the system's automatic recovery mechanism. Reconfigure the device based on the extracted key information to restore the secure connection state of the intelligent device. The reconfiguration process includes steps such as re-initializing the security module and reconstructing the encryption channel to ensure that the device is restored to a secure and usable state.

[0185] This embodiment significantly improves the security of the system by real-time monitoring the device running state and regularly updating the key, effectively preventing the security risks that may be brought by using the same key for a long time. The use of a multi-factor authentication mechanism to strictly control sensitive operations greatly reduces the possibility of unauthorized access and misoperations, protecting the core functions and data security of the device. The dynamic key generation and encrypted storage mechanism in the embodiment ensure that even in the case of device reset or attack, the secure connection state can be quickly restored, improving the reliability and recovery ability of the system. By continuously monitoring for anomalies during the communication process and starting the corresponding security mechanism according to the degree of anomaly, the timely discovery and handling of potential threats are realized, enhancing the overall defense ability of the system.

[0186] Refer to Figure 2 As shown, the present invention provides an intelligent device secure networking system based on dynamic keys, which is applied to the intelligent device secure networking method based on dynamic keys in any one of the above, including:

[0187] A collection module, which is used to obtain the device identifier and the initial key of the intelligent device. When the intelligent device starts, record the current timestamp, and generate a dynamic key through a hash algorithm in combination with the device identifier and the initial key;

[0188] An analysis module, which is used to generate a corresponding network connection request based on a dynamic key and send the dynamic key and the network connection request to a corresponding gateway;

[0189] An association module, which is used to obtain the verification result generated after the gateway receives the network connection request and the dynamic key;

[0190] A processing module, which is used to generate a corresponding session key by an intelligent device according to a preset Diffie-Hellman algorithm in combination with the verification result and perform encrypted communication with the gateway based on the session key.

[0191] An intelligent device secure networking system based on a dynamic key provided by the present invention generates a dynamic key by combining a device identifier and an initial key, improves the security and unpredictability of the key, effectively prevents the risk of the static key being stolen or cracked, and enhances the security protection ability of the intelligent device. By adopting a dynamic key generation mechanism based on a time stamp, the key can change dynamically with time, adapts to the dynamic operating environment of the intelligent device, and improves the security and flexibility of the system. Using the Diffie-Hellman algorithm to generate a session key realizes a secure key exchange and negotiation process, avoids the risk of the key being intercepted during network transmission, and at the same time adapts to the characteristics of limited resources of the intelligent device. Through the dual security mechanisms of gateway verification and session key generation, it effectively prevents the access of unauthorized devices and improves the security and reliability of the entire Internet of Things system. The encrypted communication method based on the session key not only ensures the security of communication, but also reduces the computational complexity of the encryption and decryption processes, which is suitable for the resource constraint characteristics of the intelligent device. The entire networking process takes into account the characteristics and security requirements of the intelligent device, realizes efficient and dynamic secure networking, effectively responds to various network attack threats, and provides a reliable security guarantee for the wide application of the intelligent device.

[0192] It should be noted that those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described system and each module can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0193] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied to other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. An intelligent device secure networking method based on dynamic keys, characterized in that, Including: Obtain the device identifier and the initial key of the intelligent device. When the intelligent device starts, record the current timestamp, and generate a dynamic key through a hashing algorithm in combination with the device identifier and the initial key; Generate a corresponding networking request based on the dynamic key, and send the dynamic key and the networking request to the corresponding gateway; Verify the received networking request and the dynamic key through the gateway to obtain a verification result, and send the verification result to the intelligent device; Generate a corresponding session key by the intelligent device according to a preset Diffie-Hellman algorithm in combination with the verification result, and perform encrypted communication with the gateway based on the session key, and send the corresponding encrypted data to the gateway; The step of generating a corresponding session key by the intelligent device according to a preset Diffie-Hellman algorithm in combination with the verification result, and performing encrypted communication with the gateway based on the session key, and sending the corresponding encrypted data to the gateway includes: Parse the verification result to obtain verification status information; Judge whether the verification is successful according to the verification status information. When the verification is successful, execute the subsequent steps, otherwise terminate the networking process; Generate the public parameters of the Diffie-Hellman algorithm: large prime number and primitive root; Generate a random private key by the intelligent device and calculate the first public key; Send the large prime number, the primitive root, and the first public key to the gateway; Receive the second public key sent by the gateway, and calculate the shared key using the random private key and the second public key; Perform a hashing operation on the shared key to obtain the session key; Send a notification message indicating that the session key generation is completed to the gateway, and receive an acknowledgment message returned by the gateway to establish encrypted communication; Encrypt the data to be sent based on the session key to obtain encrypted data; Send the encrypted data to the gateway, and receive the response data encrypted and sent by the gateway according to the session key; Decrypt the received response data using the session key to obtain the decrypted response data; Among them, the formula for calculating the first public key is: A = g a mod p, and the formula for calculating the shared key is: K = B a mod p; A is the first public key, p is the large prime number, g is the primitive root, a is the random private key, K is the shared key, B is the second public key; mod is the modulo operation symbol, indicating the remainder operation; The step of generating the public parameters of the Diffie-Hellman algorithm: large prime number and primitive root includes: The steps of generating a large prime number include: Randomly select a large odd number within a preset range as a candidate prime number. After subtracting 1 from the candidate prime number, decompose it into the product of a power of 2 and an odd number to obtain a corresponding set of test bases; Randomly select multiple test bases from the set of test bases, and perform the Miller-Rabin primality test on each test base: Calculate the power modulo operation of the test base to the candidate prime number, and judge whether the candidate prime number may be a prime number according to the result of the power modulo operation. When any test fails, reselect the candidate prime number; When all tests pass, the candidate prime number is considered the large prime number; The steps for generating the primitive root include: Subtract 1 from the large prime number and perform prime factorization to obtain a set of non-repeating prime factors; Set the initial value of the candidate primitive root to 2; Test the candidate primitive root: For each prime factor in the set of prime factors, perform the following steps: Calculate a specific value, which is obtained by dividing the large prime number minus 1 by the current prime factor; Calculate the exponential power of the candidate primitive root modulo the large prime number, where the exponent is the specific value; When the calculation result is equal to 1, it means that the current candidate primitive root is not the primitive root. Increment the value of the current candidate primitive root by 1 and start a new test; When all prime factors pass the test, that is, there is no case where the calculation result is equal to 1, then the current candidate primitive root is the primitive root.

2. The method for secure networking of intelligent devices based on dynamic keys according to claim 1, wherein, Obtaining the device identifier and initial key of the intelligent device, when the intelligent device is started, recording the current timestamp, and generating a dynamic key through a hashing algorithm in combination with the device identifier and the initial key, includes: Read the device identifier and initial key preset in the intelligent device, and record the system clock of the intelligent device to obtain the current timestamp; Concatenate the device identifier, the initial key, and the current timestamp to obtain an original string; Perform UTF-8 encoding on the original string to obtain an encoded byte array; Perform hashing calculation on the byte array through the hashing algorithm to obtain a byte hash value; Convert the byte hash value to a hexadecimal string to obtain an intermediate key; Perform Base64 encoding on the intermediate key to obtain an encoded string; Extract the first 32 characters from the encoded string to obtain the dynamic key.

3. The method for secure networking of intelligent devices based on dynamic keys according to claim 1, characterized in that, Generating a corresponding network connection request based on the dynamic key and sending the dynamic key and the network connection request to the corresponding gateway, includes: Perform segmentation processing on the dynamic key to obtain multiple key segments; Fill the device identifier and the current timestamp according to a preset network connection request template to obtain an initial request; Perform a hashing operation on the initial request to obtain a request digest; Reorder the multiple key segments according to the request digest to obtain a key segment sequence; Perform an exclusive OR operation on the key segment sequence to obtain a scrambled key; Encrypt the initial request according to the scrambled key to obtain an encrypted network connection request; Perform block processing on the encrypted network connection request to obtain multiple request data blocks; Encapsulate the multiple request data blocks according to a preset network protocol to obtain the network connection request; Send the network connection request and the dynamic key to the corresponding gateway through a preset secure channel.

4. The method for secure networking of intelligent devices based on dynamic keys according to claim 1, wherein Verifying the received network connection request and the dynamic key through the gateway to obtain a verification result, and sending the verification result to the intelligent device, includes: After sending the networking request and the dynamic key to the gateway through the intelligent device, detect whether the verification result sent by the gateway is received within a preset time period. When the verification result is not received within the preset time period, resend the networking request and the dynamic key to the gateway; Among them, the verification of the received networking request and dynamic key by the gateway to obtain a verification result includes: When the gateway receives the networking request and the dynamic key, extract the timestamp of the networking request to obtain the request timestamp; Compare the current gateway time with the request timestamp to obtain a time difference; Compare the time difference with a preset time threshold to obtain a time validity result; Filter and parse the networking request according to the time validity result to obtain the request device identifier and the initial key; Perform a hash operation on the initial key, the request device identifier, and the request timestamp to obtain the gateway dynamic key; Compare and verify the gateway dynamic key and the dynamic key sent by the intelligent device to obtain the verification result.

5. The method for secure networking of intelligent devices based on dynamic keys according to claim 4, wherein, The comparison and verification of the gateway dynamic key and the dynamic key sent by the intelligent device to obtain the verification result includes: Perform a hash operation on the request device identifier, the initial key, and the request timestamp through the gateway to obtain a first verification value; Obtain the gateway time of the gateway, and perform a secondary hash operation in combination with the first verification value to obtain the gateway dynamic key; Match the gateway dynamic key and the dynamic key sent by the intelligent device to obtain a corresponding matching result, Judge whether the matching result is a match, and generate a corresponding verification result; When the matching result indicates a match, generate a verification result of verification passed and send it to the intelligent device; When the matching result indicates a non-match, generate a verification result of verification failed and send it to the intelligent device.

6. The method for secure networking of intelligent devices based on dynamic keys according to claim 1, characterized in that The method further includes: Monitor the running status of the intelligent device in real time, and record the running duration and important events; Regularly analyze the running duration and the important events according to a preset update policy, and judge whether the key needs to be updated; When the update condition is met, generate a key update trigger signal, re-execute the steps of the networking operation, generate a new dynamic key and a new session key; Encrypt and store the new dynamic key and the new session key to obtain a key backup file; Communicate according to the new session key, and continuously monitor abnormal situations during the communication process according to a preset security policy; When an abnormality is detected, analyze the degree of abnormality, and start a corresponding security mechanism according to the analysis result; Real-time identify the user's operation request, and add sensitive operations to the operation list that requires multi-factor authentication; When a sensitive operation request is monitored, collect the multi-factor authentication data provided by the user according to the operation list and perform verification; When the verification is passed, the sensitive operation request is allowed to be executed, otherwise the sensitive operation request is rejected; When a request for device reset is received, extract the original key information from the key backup file; Reconfigure the device according to the key information to restore the secure connection state of the intelligent device.

7. An intelligent device secure networking system based on dynamic keys, characterized in that, The method for secure networking of an intelligent device based on a dynamic key applied to any one of the above claims 1-6 includes: An acquisition module, which is used to obtain the device identifier and the initial key of the intelligent device. When the intelligent device is started, record the current timestamp, and generate a dynamic key through a hash algorithm in combination with the device identifier and the initial key; An analysis module, which is used to generate a corresponding networking request based on the dynamic key, and send the dynamic key and the networking request to the corresponding gateway; An association module, which is used to obtain the verification result generated by the gateway after receiving the networking request and the dynamic key; A processing module, which is used to generate a corresponding session key by the intelligent device according to a preset Diffie-Hellman algorithm in combination with the verification result, and perform encrypted communication with the gateway based on the session key; The process of generating a corresponding session key by the intelligent device according to a preset Diffie-Hellman algorithm in combination with the verification result, performing encrypted communication with the gateway based on the session key, and sending the corresponding encrypted data to the gateway includes: Parse the verification result to obtain verification status information; Judge whether the verification is successful according to the verification status information. When the verification is successful, execute the subsequent steps, otherwise terminate the networking process; Generate the public parameters of the Diffie-Hellman algorithm: a large prime number and a primitive root; Generate a random private key by the intelligent device and calculate the first public key; Send the large prime number, the primitive root and the first public key to the gateway; Receive the second public key sent by the gateway, and calculate the shared key using the random private key and the second public key; Perform a hash operation on the shared key to obtain the session key; Send a notification message indicating that the session key generation is completed to the gateway, and receive an acknowledgment message returned by the gateway to establish encrypted communication; Encrypt the data to be sent based on the session key to obtain encrypted data; Send the encrypted data to the gateway, and receive the response data encrypted and sent by the gateway according to the session key; Decrypt the received response data using the session key to obtain the decrypted response data; Among them, the formula for calculating the first public key is: A = g a mod p, and the formula for calculating the shared key is: K = B a mod p; A is the first public key, p is the large prime number, g is the primitive root, a is the random private key, K is the shared key, B is the second public key; mod is the modulo operation symbol, indicating the remainder operation; The generation of the public parameters of the Diffie-Hellman algorithm: a large prime number and a primitive root, includes: The steps for generating a large prime number include: Randomly select a large odd number within a preset range as a candidate prime number. After subtracting 1 from the candidate prime number, decompose it into the product of a power of 2 and an odd number to obtain the corresponding test base set; Randomly select multiple test bases from the set of test bases, and perform the Miller-Rabin primality test on each of the test bases: Calculate the power modulo operation of the test base with respect to the candidate prime number, and determine whether the candidate prime number may be a prime number based on the result of the power modulo operation. When any test fails, reselect the candidate prime number; When all tests pass, the candidate prime number is considered to be the large prime number; The steps for generating the primitive root include: Subtract 1 from the large prime number and perform prime factorization to obtain a set of distinct prime factors; Set the initial value of the candidate primitive root to 2; Test the candidate primitive root: For each prime factor in the set of prime factors, perform the following steps: Calculate a specific value, which is obtained by dividing the large prime number minus 1 by the current prime factor; Calculate the exponential power of the candidate primitive root modulo the large prime number, where the exponent is the specific value; When the calculation result is equal to 1, it means that the current candidate primitive root is not the primitive root. Increment the value of the current candidate primitive root by 1 and start a new test; When all prime factors pass the test, that is, there is no case where the calculation result is equal to 1, the current candidate primitive root is the primitive root.

Citation Information

Patent Citations

  • Log file encryption method and device, storage medium and electronic equipment

    CN112788012A

  • Session key generation method, communication network system, storage medium and electronic equipment

    CN116055033A