Method, device and storage medium for security authentication encryption in initial stage of communication link establishment

By pre-generating the complete set of public keys during the device activation phase and combining it with offline and online public key acquisition methods, the security protection problem in the initial stage of end-to-end wireless communication chain establishment is solved, realizing secure encryption and device interoperability under narrow bandwidth conditions, and improving user experience and system adaptability.

CN119835019BActive Publication Date: 2025-10-21NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411857068.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-10-21
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

The initial stage of establishing a connection for existing end-to-end wireless communication lacks security protection. The narrow bandwidth makes it impossible to apply conventional encryption methods, and the pre-set symmetric key is insufficient to ensure interoperability of new devices, which can easily lead to malicious control.

Method used

During the device activation phase, the key source pre-generates a complete set of public keys based on the size of the communication device's key storage area. Combined with offline pre-setting and online acquisition of public keys, the encryption of chain establishment information is achieved, and symmetric encryption is performed using an emergency key in extremely narrowband conditions.

Benefits of technology

While minimizing the occupation of temporary channels, it achieved secure transmission of chain information, improved user experience, adapted to the interoperability needs of environmental degradation and new equipment, and reduced manual maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835019B_ABST
    Figure CN119835019B_ABST
Patent Text Reader

Abstract

The application discloses a kind of communication link establishment initial stage security authentication encryption method, device and storage medium, the present application is limited to narrow bandwidth for end-to-end wireless communication link establishment, cannot apply conventional encryption preparation, it is difficult to guarantee that preset symmetric key is added after planning, abandon password protection is also prone to be maliciously controlled and so on Problem, an authentication encryption adaptive method based on pre-stored and diffusion key is proposed, by making full use of the key storage space of end device pre-stored key, supplemented by the diffusion transmission of new key with the process of link establishment, combined with the two modes of offline preset loading when opening and automatic online interaction after new communication terminal joins interworking, under the premise of no manual participation, maximum reduction to the occupation of link establishment narrow band, the security of information transmission is greatly improved, so as to improve user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a method, device and storage medium for secure authentication and encryption in the initial stage of communication link establishment. Background Art

[0002] End-to-end wireless communications often require secure transmission (e.g., authentication and encryption). However, while current security designs for service transmission are being enhanced, the fundamental foundation for service transmission is often overlooked: the lack of security design for the transmission of link establishment information. This lack of security protection for the initial communication link establishment phase makes it easy for attackers (during the power-up phase) to create risks such as device loss of control and exposure of transmitted signaling. In other words, because link establishment information, including communication parameters and security parameters, is transmitted over the channel, whether represented as characters or numbers, it carries the risk of being exposed, inferred, and manipulated by malicious actors. Summary of the Invention

[0003] The present invention provides a method, device and storage medium for secure authentication and encryption in the initial stage of communication link establishment, so as to solve the problems in the initial stage of existing end-to-end wireless communication link establishment, such as the communication is limited by narrow bandwidth and conventional encryption preparation cannot be applied, the pre-set symmetric key is difficult to protect the newly added unplanned equipment, and abandoning password protection can easily lead to malicious control.

[0004] In a first aspect, the present invention provides a method for secure authentication and encryption in the initial stage of communication link establishment, which is applied to a key source, and the method includes:

[0005] During the activation key loading phase, the key source pre-generates keys for the communication device based on the size of the communication device's key storage area, where the communication device includes devices within the current interoperability plan and devices to be added for interoperability in the future. The keys include the keys of each communication device within the current interoperability plan, the full set of public and private key pairs for the full set of device IDs reserved for future newly added interoperable devices, and a set of network-wide shared emergency keys. The full set of public keys, the shared emergency key group, the device's own ID, the device's own private key, and the device's own public key signature are loaded into the communication device in an offline manner.

[0006] When the pre-generated keys are distributed and there are still new communication devices that need to be activated, the key source will generate a new ID and a pair of public and private keys to cover the public and private keys with the smallest ID number, and load the keys to the activated devices;

[0007] When the emergency key update time has arrived, the key source will generate a new emergency key with a larger version number to overwrite the one with the smallest version number in the original emergency key group, and load the key to the activation device;

[0008] When it is necessary to use the signaling channel to transmit link establishment information with the communication peer, it is determined whether the public key corresponding to the communication peer exists in the key set based on the ID information sent by the communication peer. If so, the key set is queried to obtain the public key corresponding to the communication peer, and the obtained result is fed back to the communication peer. The obtained public key is used to decrypt the subsequent link establishment information received from the communication peer. If it does not exist, the communication peer is triggered to determine whether to transmit its own public key online according to its own bandwidth situation, or directly use the highest version of the emergency key shared by both parties to encrypt the link establishment information.

[0009] For the first narrowband situation, the public key and signature of the communication peer are obtained online. After the signature verification is completed, the obtained public key is used to decrypt the link establishment information sent by the communication peer. For the second extremely narrowband situation, the highest version emergency key shared by both parties is directly used to decrypt the link establishment information sent by the communication peer to establish a secure channel between the communication device and the communication peer.

[0010] Optionally, the complete set of public keys and key sources are generated and stored in the communication device, including: the key source is based on the size of the key storage area of ​​this type of communication device, in addition to generating IDs, public and private keys for all devices in the intercommunication plan, it also pre-generates as many IDs and public and private keys as possible for possible new intercommunication devices in the future; during the device activation key loading phase, the complete set of IDs and public keys generated above are loaded into each communication device of this type.

[0011] Optionally, the method also includes: the key source determines whether there is any surplus in the key storage area outside the key storage area of ​​the communication device occupied by the intercommunication plan; if so, the obtained public key of the communication counterpart is saved in the public key collection of the communication device to reduce the repeated occupation of the initial temporary channel when the link is established next time; otherwise, the obtained public key of the communication counterpart is discarded.

[0012] Optionally, the key source determines whether there is any surplus in the key storage area outside the key storage area occupied by the communication device in the intercommunication plan, including: determining whether the key storage space of the communication device is greater than the threshold of the key occupied storage space in the communication plan; if so, it is determined that the key storage space is surplus; otherwise, it is determined that the key storage space is not surplus.

[0013] Optionally, the method also includes: obtaining the ID and emergency key version number of the communication peer, and feeding back the ID' and emergency key version number of the communication device itself to the communication peer; querying from the public key set according to the ID and emergency key version number of the communication peer (the result needs to be informed to the communication peer), and attempting to obtain the public key corresponding to the communication peer; using the obtained public key to encrypt the link establishment information and then send it to the communication peer; so that the communication peer uses its own private key to decrypt the received encrypted communication parameters and security parameters, and establish a secure channel between the communication device and the communication peer.

[0014] Optionally, based on the ID of the communication peer, query from the public key set and try to obtain the public key corresponding to the communication peer. Based on the emergency key version number of the communication peer, query and obtain the highest version emergency key shared by both parties from the emergency key group, and inform the communication peer of the above results.

[0015] In a second aspect, the present invention provides a key source and a communication device for implementing any one of the above methods, wherein the key source includes:

[0016] During the device activation key loading phase, the key source pre-generates keys for the device of the type to the maximum extent possible based on the size of the device key storage area (including the full set of device IDs within the current interoperability plan and reserved for future newly added interoperable devices, the full set of public and private key pairs, and a set of emergency keys shared by the entire network), and loads the full set of public keys, shared emergency keys, the device's own ID, the device's own private key, and the device's own public key signature to the activated device in an offline manner. If new devices still need to be activated after the pre-generated keys have been distributed, the key source will generate a new ID and a pair of public and private keys (to cover the public and private key with the smallest ID number) and load the keys to the activated device in the same way as before. When the emergency key update time has arrived, the key source will generate a new emergency key with a larger version number (to cover the one with the smallest version number in the original emergency key) and load the key to the activated device in the same way as before.

[0017] In a second aspect, an embodiment of the present invention further provides a communication device for implementing any of the above methods, the communication device comprising:

[0018] A generation unit, configured to pre-generate a complete key set for the communication device in an offline manner based on the size of the key storage area of ​​the communication device during the initial stage of establishing a communication link, and send the generated complete key set to the corresponding communication device;

[0019] The processing unit is configured to determine, when it is necessary to transmit link establishment information with a communication peer via a signaling channel, whether the public key corresponding to the communication peer exists in the key set based on the ID information sent by the communication peer; if so, query the key set to obtain the public key corresponding to the communication peer, feed back the obtained result to the communication peer, and use the obtained public key to decrypt subsequently received link establishment information from the communication peer; if not, trigger the communication peer to determine, based on its own bandwidth conditions, whether to transmit its own public key online or directly use the highest version of the emergency key shared by both parties to encrypt the link establishment information.

[0020] Optionally, the key source is also used to determine, based on the size of the key storage area of ​​this type of communication device, whether there is any surplus key storage area of ​​the communication device in addition to the key storage area occupied by the intercommunication plan. If so, in addition to generating IDs and public and private keys for all devices in the intercommunication plan, as many IDs and public and private keys as possible are pre-generated for possible new intercommunication devices in the future; during the device activation key loading phase, the complete set of IDs and public keys generated above are loaded into each communication device of this type.

[0021] The setting unit is also used to, during the device activation key loading phase, load the IDs and public keys of all devices within the intercommunication plan as well as the IDs and public keys of intercommunication devices that may be added in the future; the processing unit is also used to, during the communication link establishment phase, obtain the public key of the communication peer and save it to the public key collection of the communication device in a manner that covers the public key that was used least frequently previously, so as to reduce the repeated occupation of the initial temporary channel when establishing a link with the same communication peer next time.

[0022] In a third aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-mentioned methods for security authentication and encryption in the initial stage of communication link establishment.

[0023] The beneficial effects of the present invention are as follows:

[0024] The present invention aims to solve the problems that the transmission of link establishment information in the initial stage of end-to-end wireless communication is limited by narrow bandwidth and conventional encryption preparation cannot be applied, it is difficult to protect and add new unplanned equipment after pre-setting symmetric keys, and abandoning password protection can easily lead to malicious control. The present invention analyzes and proposes a communication link establishment security authentication encryption method, which uses a key source in the device activation stage to pre-generate a full set of public keys based on the maximum size of the key storage area of ​​this type of communication device, and combines the two methods of offline pre-setting the full set of public keys at activation and online obtaining the public key of the communication peer after the temporary addition of the new communication peer. Under the premise of minimizing the occupation of the initial temporary channel, the transmission of link establishment information is encrypted. At the same time, in the extremely narrow bandwidth situation where the environment deteriorates and the public key of the new communication peer cannot be obtained online, the emergency key can be automatically enabled to implement symmetric encryption, thereby improving the user experience.

[0025] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0027] Figure 1 This is a flow chart of a method for security authentication and encryption in the initial stage of communication link establishment provided by an embodiment of the present invention;

[0028] Figure 2 This is a flow chart of another method for security authentication and encryption in the initial stage of communication link establishment provided by an embodiment of the present invention during the device activation key loading stage;

[0029] Figure 3 1 is a flow chart of a method for security authentication and encryption in the initial stage of communication link establishment provided by an embodiment of the present invention;

[0030] Figure 4 The present invention provides a schematic diagram of a device for secure authentication and encryption in the initial stage of communication link establishment. DETAILED DESCRIPTION

[0031] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0032] Existing end-to-end wireless communication systems lack cryptographic security during the initial link establishment phase. This means they lack the necessary authentication for the device identity of the communicating peer and the confidentiality of the transmitted information. Furthermore, due to the limited bandwidth, conventional key exchange methods cannot be used to complete encryption preparations during this initial phase. Furthermore, the introduction of pre-configured symmetric keys increases the key exchange burden and hinders interoperability with newly added, unplanned devices. This burden increases exponentially over time and as the number of communicating peers increases, efficiency decreases exponentially. Furthermore, current security designs for service transmission cannot be directly applied to link establishment. Unlike the wide bandwidth available after link establishment, the bandwidth during link establishment is very narrow, unable to support conventional real-time symmetric key exchange. Sometimes, environmental degradation can further reduce bandwidth, making even asymmetric keys inaccessible. If pre-configured symmetric keys are used instead of exchange, key freshness becomes a problem. Furthermore, key adjustment for older devices becomes a challenge when new devices are added. (While adopting a network-wide consistent key eliminates the network-wide key adjustment issue, it does pose security risks such as "a single loss can compromise the entire network.")

[0033] In order to solve the above problems, the embodiment of the present invention provides a method for secure authentication and encryption in the initial stage of communication link establishment. Figure 1 , applied to a key source, the method comprises:

[0034] S101. In the initial stage of establishing a communication link, the key source pre-generates a complete key set for the communication device in an offline manner based on the size of the key storage area of ​​the communication device, and sends the generated complete key set to the corresponding communication device;

[0035] That is, in the embodiment of the present invention, during the device activation key loading phase, the key source pre-generates keys for the device of this type to the maximum extent possible based on the size of the device key storage area (including the full set of device IDs within the current interoperability plan and reserved for future newly added interoperable devices, the full set of public and private key pairs, and a set of emergency keys shared by the entire network), and loads the full set of public keys, shared emergency keys, the device's own ID, the device's own private key, and the device's own public key signature to the activation device in an offline manner; when new devices still need to be activated after the pre-generated keys are distributed, the key source will generate a new ID and a pair of public and private keys (to cover the public and private key with the smallest ID number), and load the keys to the activation device in the same manner as before; when the emergency key update time has arrived, the key source will generate a new emergency key with a larger version (to cover the one with the smallest version number in the original emergency key), and load the key to the activation device in the same manner as before;

[0036] Furthermore, the communication devices in the embodiment of the present invention include devices within the current intercommunication plan and devices to be intercommunication-added in the future, wherein the keys in the embodiment of the present invention include the keys of each communication device within the current intercommunication plan and the full set of public and private key pairs of the device IDs reserved for the new intercommunication devices to be intercommunication-added in the future, and a set of emergency keys shared by the entire network, and the full set of public keys, the shared emergency key group, the device's own ID, the device's own private key, and the device's own public key signature are loaded into the communication device in an offline manner;

[0037] It should be noted that the embodiment of the present invention is designed to meet the initial security authentication and encryption preparation requirements between communication terminals with minimal overhead by pre-generating keys in a scenario where conventional security encryption channels are not protected and the bandwidth is too narrow to apply conventional encryption preparations before the conventional security encryption channel is established.

[0038] In addition, the key source described in the embodiment of the present invention can be various communication devices. Those skilled in the art can make any settings according to actual needs, and the present invention does not make any specific limitations on this.

[0039] Specifically, each communication terminal in the embodiment of the present invention needs to complete key loading at the key source before it is activated and used. The present invention is that the key source is based on the size of the key storage area of ​​this type of communication equipment. In addition to generating IDs and public and private keys for all devices in the intercommunication plan, it also pre-generates as many IDs and public and private keys as possible for new intercommunication devices that may be added in the future; in the device activation key loading stage, the above-generated complete set of IDs and public keys are loaded to each communication device of this type, and when used subsequently, the required public key is retrieved from the key storage area, so as to finally use the public key to establish a secure channel between the communication device and the communication counterpart, thereby maximizing the communication security between the ends.

[0040] S102. When it is necessary to transmit link establishment information to the communication peer via the signaling channel, determine whether the public key corresponding to the communication peer is stored in the key set based on the ID information sent by the communication peer. If so, execute S103; otherwise, execute S104.

[0041] Specifically, in the embodiment of the present invention, before using the signaling channel to transmit the link establishment information with the communication peer, it is determined whether the public key corresponding to the communication peer exists in the public key set through the ID transmitted by the peer. If so, S103 is executed; otherwise, S104 is executed.

[0042] S103: Query the public key set (the result of which needs to be notified to the communication peer), attempt to obtain the public key corresponding to the communication peer, and use the obtained public key to decrypt the link establishment information subsequently sent by the communication peer;

[0043] S104: Triggering the communication peer to determine whether to transmit its own public key online or directly use the highest version of the emergency key shared by both parties to encrypt the link establishment information based on its own bandwidth situation;

[0044] Specifically, the embodiment of the present invention notifies the communication peer of the judgment result that the public key does not exist. The communication peer then decides, based on its own bandwidth conditions, whether to first transmit its own public key online (narrowband situation) or directly use the highest version of the emergency key shared by both parties to encrypt subsequent outgoing link establishment information (extremely narrowband situation);

[0045] S105: The communication peer receives bandwidth information to determine whether the corresponding public key sent by the communication peer is received online. If so, execute S106; otherwise, execute S107.

[0046] S106. For narrowband, obtain the public key and signature of the communication peer online, and after completing the signature verification, decrypt the link establishment information sent by the communication peer using the obtained public key.

[0047] S107: For an extremely narrowband situation, directly use the highest version of the emergency key shared by both parties to decrypt the link establishment information sent by the communication peer to establish a secure channel between the communication device and the communication peer.

[0048] That is to say, the method described in the embodiment of the present invention is aimed at the problems that the transmission of link establishment information in the initial stage of end-to-end wireless communication is limited by narrow bandwidth and conventional encryption preparation cannot be applied, it is difficult to ensure that new unplanned equipment is added after pre-setting symmetric keys, and abandoning password protection can easily lead to malicious control. A communication link establishment security authentication encryption method is analyzed and proposed. By using the key source in the device activation stage to pre-generate a full set of public keys based on the maximum size of the key storage area of ​​this type of communication device, and combining the two methods of offline pre-setting the full set of public keys at the time of activation and online obtaining the public key of the communication peer after the temporary joining of the new communication peer, the transmission of link establishment information is encrypted while minimizing the occupation of the initial temporary channel. At the same time, in the extremely narrow bandwidth situation where the environment deteriorates and the public key of the new communication peer cannot be obtained online, the emergency key can be automatically enabled to implement symmetric encryption, thereby improving the user experience.

[0049] Since the initial stage of communication link establishment is limited by narrow bandwidth, conventional key exchange methods cannot be applied to complete encryption preparations. In addition, after the introduction of preset symmetric keys, the burden of key exchange increases and it is difficult to enable newly added unplanned devices to communicate with each other. In particular, as time goes by and the scale of communication terminals expands, the burden will increase exponentially and the efficiency will decrease exponentially. Therefore, the present invention combines the two methods of offline presetting the full set of public keys at the time of activation and online obtaining the public key of the communication terminal after the new communication terminal temporarily joins. This greatly improves the security of information transmission while minimizing the occupation of the initial temporary channel.

[0050] In addition, although the above burden can be alleviated by presetting symmetric keys, as time goes by and the scale of communication terminals expands, the burden of periodic key changes increases. Newly added unplanned devices need to adjust the keys at all original planned communication devices to achieve intercommunication, and the pressure of manual security increases. Therefore, the preset method is only applicable to situations where all communication plans have been clearly defined and all communication terminal keys are available during the activation phase. It is not applicable to scenarios where there is a need to adjust the communication plan later. To this end, the present invention provides an online public key exchange method, that is, a method of obtaining the unplanned terminal public key through online interaction and covering the public key with the least frequency of use before, so as to establish a communication link security channel between the communication device and the newly added unplanned communication terminal without manual participation.

[0051] The present invention realizes device identity authentication through the pre-production and online signature verification of public keys. For the identity authentication of planned and unplanned communication terminals with preset public keys, zero-overhead device identity authentication is achieved by using a method based on public key preset. Compared with the conventional independent identity authentication and confidentiality protection that consume double consumption of (communication or storage) resources respectively, the present invention only consumes a single storage resource for the communication link establishment security authentication and encryption of planned and unplanned communication terminals with preset public keys.

[0052] Similar to the resource consumption (communication or storage) encountered in device authentication in the aforementioned issue, the confidentiality protection of pre-set symmetric keys also incurs the cost of periodic key rotation over time, compared to the confidentiality protection of pre-set public keys. Even if a communication device has sufficient storage space and pre-sets a large number of symmetric keys, this will be depleted over time. If channel resources are not promptly used to obtain new keys, confidentiality protection will be compromised due to the lack of fresh keys. Using channel resources to obtain new symmetric keys requires not only the introduction of new mechanisms but also new equipment, significantly increasing system costs.

[0053] In this regard, the present invention not only uses a preset public key to provide encryption for link establishment information, but also generates new symmetric emergency keys used in extremely narrowband situations regularly according to a preset period through a key source. These keys are carried by newly opened devices outside the plan when loading the keys. The new version of the emergency key is propagated to communication devices that did not have this new version of the emergency key before this period through subsequent link establishment and communication, thereby clearing and overwriting the oldest version of the emergency key. Similarly, when the communication device of the present invention receives a public key sent by a new communication peer online that it does not have, it can complete the storage of the new communication peer public key without increasing the key storage space by overwriting the public key of the communication peer with the lowest interaction frequency, based on the interaction frequency between the ends. Specific settings can be made by those skilled in the art according to actual needs, and the present invention does not impose specific limitations on this.

[0054] Specifically, the embodiment of the present invention determines whether the key storage space of the communication device is greater than the storage space threshold occupied by the key in the communication plan. If it is, it is determined that the key storage space is sufficient, and the public key of the communication counterpart that may be newly added outside the plan in the future can be pre-generated and stored. Otherwise, it is determined that the key storage space is not sufficient, and the public key of the communication counterpart that is not pre-stored can only be obtained online and overwritten in the subsequent link establishment and intercommunication, and the public key of the communication counterpart that is used for a long time is finally determined and stored according to the interaction frequency between the ends.

[0055] In specific implementation, the embodiment of the present invention evaluates the situation of the intercommunication plan occupying the key storage area of ​​this type of communication equipment through the key source, and determines whether there is any surplus in the key storage area. If so, it pre-generates as many public keys of unplanned communication equipment as possible and adds them to the public key collection to reduce the occupation of the initial temporary channel by newly added devices and old devices when establishing a communication link in the future.

[0056] That is, when determining the size of the key storage area of ​​this type of communication device, a storage space threshold that maintains storage space and processing efficiency can be set to reduce resource consumption while maintaining processing efficiency.

[0057] The following will be combined Figure 2-Figure 3 The method described in the embodiment of the present invention is explained and illustrated in detail by taking a specific example:

[0058] The embodiment of the present invention provides a method for secure authentication and encryption in the initial stage of communication link establishment, which is used to solve the problems that the existing link establishment information transmission is limited by narrow bandwidth and cannot be applied to conventional encryption methods; after pre-setting symmetric keys, it is difficult to protect and add unplanned devices; and abandoning password protection can easily lead to malicious control.

[0059] Specifically, an embodiment of the present invention provides a method for security authentication and encryption in the initial stage of communication link establishment, which includes two sub-methods, namely, the first sub-method is used in the device activation key loading stage; the second sub-method is used in the communication link establishment stage.

[0060] See also Figure 2During the key loading phase of device activation, the key source generates keys for the communication terminal that has not generated keys, and according to the size of the key storage area reported by the communication terminal, generates keys for the model to the maximum extent possible (including a full set of device IDs, a full set of public and private key pairs, and an emergency key group). The communication terminal receives and stores the generated keys (including its own ID, its own private key, a full set of public keys, and an emergency key group) offline. For communication terminals whose key storage area is larger than the space required for keys in the communication plan, after activation, this type of communication terminal no longer occupies the link establishment channel to transmit public keys, and does not affect the original startup link establishment process; for communication terminals whose key storage area is not larger than the space required for keys in the communication plan, after activation, the link establishment channel will only be occupied to transmit public keys after receiving the identity identification number (i.e., ID) sent by a new member outside the public key set, which slightly reduces the startup link establishment efficiency.

[0061] At this time, the method is applied to the key source, the communication device and the communication peer respectively.

[0062] For the key source, the steps performed include:

[0063] a) Determine that the key for this type of communication terminal has not been generated, and generate keys for this model to the maximum extent possible based on the size of the received key storage area (including a full set of device IDs, a full set of public and private key pairs (and public key signatures), and a set of shared emergency keys);

[0064] b) Bind the number to the smallest device ID (hereinafter referred to as "ID"), select a private key corresponding to the ID, and send it together with the full set of public keys and a unique set of emergency keys to the device with the number (the emergency key replacement timer starts at this time);

[0065] c) Determine that the key for this type of communication terminal has been generated and the ID has not been used up, bind the number to the smallest value among the IDs that have not been issued, select the private key, full set of public keys and emergency key corresponding to the ID and issue them to the device with the number;

[0066] d) If it is determined that the key for this type of communication terminal has been generated but the ID has been used up, a new ID and a pair of public and private keys are generated, the device number is bound to the newly generated ID, and the "pre-stored key" is issued in the same manner as before;

[0067] e) (When the emergency key replacement time comes) a new emergency key is generated (the version number is greater than all the version numbers in the generated set of emergency keys), and then the one with the smallest version number in the original emergency key is overwritten to form a new set of emergency keys.

[0068] The operations performed on the communication peer include:

[0069] a) Report the model, serial number and key storage area size;

[0070] b) Receive and store the ID, private key, full set of public keys (and own public key signature) and emergency key.

[0071] See also Figure 3 , which refers to all interactions between the communication terminal and the communication peer, including communication link establishment. In this case, the method is applied to the communication device and the communication peer respectively (taking the communication peer as the initiator as an example, the roles and steps can be exchanged when the communication device is the initiator). For the communication peer, the operation steps performed include:

[0072] a) Send your own ID (including emergency key version);

[0073] b) Obtain the peer search result. If the peer has its own public key, all subsequent outgoing information will be encrypted with its own private key before being sent out. If the peer does not have its own public key, it will decide whether to first pass its own public key to the peer (in the case of narrow bandwidth) or directly use the shared version of the emergency key to encrypt the subsequent outgoing information (in the case of extremely narrow bandwidth);

[0074] c) Obtain the peer ID', search for the peer's public key in the "pre-stored keys", and search for the emergency key with the highest version shared by both parties. Encrypt the result (along with the public key in the case of narrowband) and send it to the peer;

[0075] d) Decrypt and obtain the plaintext (complete public key storage if it contains the public key), and determine the subsequent decryption method based on the response;

[0076] e) Complete communication link establishment;

[0077] f) If the previous situation is extremely narrowband and the public key is not held by both parties, public key exchange is performed at this time;

[0078] g) If one party previously has a higher version of the emergency key, the higher version of the emergency key will be pushed;

[0079] h) Conventional negotiation and exchange of user information encryption keys;

[0080] i) Enable the user information encryption key to symmetrically encrypt subsequent messages (the link establishment information encryption is no longer used).

[0081] For communication equipment, the following steps are performed:

[0082] a) Obtain the peer ID, search for the peer public key in the "Pre-stored Keys" and find the emergency key with the highest version shared by both parties;

[0083] b) Send the search result along with its own ID' to the peer end;

[0084] c) Determine the decryption method and decrypt (including the public key and the storage of the public key). Select the method based on the peer search result. If the peer has its own public key, all subsequent outgoing information will be encrypted with its own private key before being sent out. If the peer does not have its own public key, decide whether to first pass its own public key to the peer (in the case of narrow bandwidth) or directly use the shared version of the emergency key to encrypt the subsequent outgoing information (in the case of extremely narrow bandwidth). Finally, encrypt the response (along with the public key in the case of narrow bandwidth) and send it to the peer.

[0085] d) Complete communication link establishment;

[0086] e) If the previous bandwidth is extremely narrow and the public key is not held by both parties, public key exchange is performed at this time;

[0087] f) If one party previously has a higher version of the emergency key, the higher version of the emergency key will be pushed;

[0088] g) Conventional negotiation and exchange of user information encryption keys;

[0089] h) Enable the user information encryption key to symmetrically encrypt subsequent messages (the link establishment information encryption is no longer used).

[0090] In summary, the method described in the embodiment of the present invention is a security authentication encryption method based on public key cryptography (supplemented by symmetric encryption), that is, the public key is used to complete the decryption of the link establishment information while completing the authentication of the identity of the communication counterpart; and the present invention combines the two public key transmission methods of offline preset and online interaction, while minimizing the occupation of the link establishment channel, it also supports online automatic acquisition of the public key from the newly added unplanned communication counterpart, and supports the function of automatically changing the public key cryptography to symmetric encryption under special extremely narrow band conditions; and after the communication link is completed and the bandwidth is widened, it supports the automatic online sharing and transmission of high-version emergency keys to spread the high-version emergency keys newly generated by the key source to the entire network.

[0091] In general, in response to the current situation in which link establishment information transmission in the initial stage of end-to-end wireless communication is limited by narrow bandwidth and cannot be applied to conventional encryption preparations, pre-setting symmetric keys is difficult to secure and cannot add new unplanned devices, and abandoning password protection can easily lead to malicious control, a communication link establishment security authentication encryption method based on public key cryptography is proposed. The implementation examples have verified that this method has the advantages of not requiring manual periodic key protection, not doubling labor consumption due to scale expansion and the addition of new unplanned devices, and being able to adapt to extremely narrowband link establishment encryption after environmental deterioration. At the same time, due to the introduction of an adaptive mechanism, this method can also automatically pre-store public keys for possible new unplanned devices when the storage space of the communication equipment is large. If the pre-stored public keys cannot meet the scale expansion, the key source can automatically continue to generate new public keys to complete the activation of the new devices. At the same time, the new public keys can also be automatically propagated online to the communication peers that communicate with it, along with the regularly updated emergency keys, reducing the cost of manual protection. Finally, this method can also complete the storage of new public keys by overwriting the public key of the communication counterpart with the lowest interaction frequency in the entire set of public keys without increasing storage space, thereby maximizing the use of space to save subsequent chain establishment time and eliminating the repeated occupation of channels by new public keys.

[0092] Accordingly, an embodiment of the present invention provides a device for implementing any of the above methods, see Figure 4 The device includes: a generation unit, which is used to trigger a key source to pre-generate a full set of keys for the communication device in an offline manner according to the size of the key storage area of ​​the communication device in the initial stage of communication link establishment, and send the generated full set of keys to the corresponding communication device; a processing unit, which is used to determine whether the public key corresponding to the communication peer is stored in the full set of keys according to the ID information sent by the communication peer when the communication device needs to use a signaling channel to transmit link establishment information with the communication peer; if so, query the key set to obtain the public key corresponding to the communication peer, feed back the obtained result to the communication peer, and use the obtained public key to decrypt the subsequently received link establishment information of the communication peer; if not, trigger the communication peer to determine whether to transmit its own public key online according to its own bandwidth situation, or directly use the highest version of the emergency key shared by both parties to encrypt the link establishment information.

[0093] Furthermore, the generation unit described in this embodiment of the present invention is also used to trigger the key source to generate IDs and public and private keys for all devices within the interoperability plan according to the size of the key storage area of ​​the communication device of this type, and also to pre-generate as many IDs and public and private keys as possible for future interoperability devices. During the device activation key loading phase, the complete set of IDs and public keys generated above is loaded into each communication device of this type. The processing unit is also used to overwrite the public key of the lowest interaction frequency communication peer in the complete set of public keys with the newly obtained public key to achieve an update of the complete set of public keys, and to overwrite the lowest version emergency key with the newly obtained higher version emergency key to achieve an update of the emergency key group.

[0094] That is to say, the embodiment of the present invention provides an adaptive method of security authentication encryption based on public key cryptography for the initial stage of communication link establishment; by combining the offline pre-set public key set at the time of activation and the online acquisition of public keys when new ones are added, and combining multiple complementary methods such as public key cryptography and symmetric encryption, it adapts to the security authentication encryption of narrowband and ultra-narrowband communication link establishment, and minimizes the occupation of the initial temporary channel; and automatically completes the evaluation and local coverage storage after receiving the new public key and the high-version emergency key, while completing the full network diffusion of the newly generated key from the key source, reducing the repeated occupation of the initial temporary channel by the new public key transmission; the present invention balances the contradiction between storage space and channel resources, maximizes the use of space, and adaptively completes the enhancement of communication link establishment security.

[0095] Furthermore, embodiments of the present invention provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the aforementioned methods for secure authentication and encryption in the initial stage of communication link establishment. The relevant details of the apparatus and storage medium embodiments of the present invention can be understood with reference to the method embodiments of the present invention and are not discussed in detail here.

[0096] Although the preferred embodiments of the present invention have been disclosed for illustrative purposes, those skilled in the art will appreciate that various modifications, additions and substitutions are possible, and thus, the scope of the present invention should not be limited to the above embodiments.

Claims

1. A method for secure authentication and encryption in the initial stage of communication link establishment, characterized in that: The method comprises: In the initial stage of establishing a communication link, the key source pre-generates a full set of keys for the communication device in an offline manner based on the size of the key storage area of ​​the communication device, and sends the generated full set of keys to the corresponding communication device; When a communication device needs to use a signaling channel to transmit link establishment information with a communication peer, it determines whether the public key corresponding to the communication peer exists in the key set based on the ID information sent by the communication peer. If so, it searches the key set to obtain the public key corresponding to the communication peer, feeds the obtained result back to the communication peer, and uses the obtained public key to decrypt the subsequent link establishment information received from the communication peer. If not, it triggers the communication peer to determine whether to transmit its own public key online based on its own bandwidth situation, or directly use the highest version of the emergency key shared by both parties to encrypt the link establishment information.

2. The method according to claim 1, characterized in that In the initial stage of establishing a communication link, the key source pre-generates a complete key set for the communication device in an offline manner according to the size of the key storage area of ​​the communication device, and sends the generated complete key set to the corresponding communication device, including: During the activation key loading phase, the key source pre-generates a maximum number of keys for the communication device in an offline manner based on the upper limit of the communication device's key storage area, wherein the communication device includes devices in the current interoperability plan and devices that will be newly interoperable in the future. The keys include the keys of each communication device in the current interoperability plan, the full set of public and private key pairs for the full set of device IDs reserved for newly interoperable devices in the future, and a set of emergency keys shared by the entire network; The complete set of public keys, the shared emergency key group, the device's own ID, the device's own private key, and the device's own public key signature are sent to the communication device.

3. The method according to claim 1, characterized in that The method further comprises: When the pre-generated keys are distributed and there are still new communication devices that need to be activated, the key source will generate a new ID and a pair of public and private keys to cover the public and private key with the smallest ID number in the entire key set, and trigger the newly activated communication device to load the newly generated key.

4. The method according to claim 1, wherein The method further comprises: When the preset emergency key update time is reached, the key source will generate a new emergency key to overwrite the key with the smallest version number in the original emergency key group, and trigger the activation device to load the newly generated key.

5. The method according to claim 3 or 4, characterized in that The online transmission of one's own public key includes: The key source determines whether there is sufficient storage space in the key storage area of ​​the communication device occupied by the intercommunication plan. If so, the obtained public key of the communication peer is saved in the public key collection of the communication device to reduce the repeated occupation of the initial temporary channel when the link is established next time. Otherwise, the obtained public key of the communication peer is discarded.

6. The method according to claim 5, characterized in that The determining whether the key storage area of ​​the communication device occupied by the intercommunication plan has sufficient storage space includes: It is determined whether the key storage space of the communication device is greater than a threshold of the key occupied storage space in the communication plan; if so, it is determined that the key storage space is abundant; otherwise, it is determined that the key storage space is not abundant.

7. The method according to claim 5, characterized in that The method further comprises: Obtain the ID and emergency key version number of the communication peer, and feed back the communication device's own ID' and emergency key version number to the communication peer; According to the ID and emergency key version number of the communication peer, query and obtain the public key corresponding to the communication peer from the full key set; The link establishment information is encrypted using the obtained public key and then sent to the communication peer, so that the communication peer uses its own private key to decrypt the received encrypted communication parameters and security parameters, and establish a secure channel between the communication device and the communication peer.

8. The method according to claim 7, characterized in that Obtain the ID and emergency key version number of the communication peer, including: According to the ID of the communication peer, query from the key set to obtain the public key corresponding to the communication peer, and according to the emergency key version number of the communication peer, query from the emergency key group to obtain the emergency key with the highest version shared by both parties.

9. A communication device for implementing the method according to any one of claims 1 to 8, characterized in that: The communication device comprises: A generation unit is configured to trigger a key source to pre-generate a full set of keys for a communication device in an offline manner based on the size of a key storage area of ​​the communication device during the initial stage of establishing a communication link, and to send the generated full set of keys to the corresponding communication device; The processing unit is used to determine whether the public key corresponding to the communication peer exists in the key set according to the ID information sent by the communication peer when the communication device needs to use the signaling channel to transmit link establishment information with the communication peer. If so, query the key set to obtain the public key corresponding to the communication peer, feed back the acquisition result to the communication peer, and use the obtained public key to decrypt the subsequently received link establishment information of the communication peer. If not, trigger the communication peer to determine whether to transmit its own public key online according to its own bandwidth situation, or directly use the highest version of the emergency key shared by both parties to encrypt the link establishment information.

10. A computer-readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, the method for security authentication and encryption in the initial stage of communication link establishment according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Method, system and readable medium for setting up secure direct links between wireless network stations using direct link set-up (DLS) protocol

    CN101300809A

  • Authentication key configuration method, equipment and system and storage medium

    CN112118210A